VexTrio is a long-running malicious traffic distribution system (TDS) and broader cybercriminal adtech operation active since at least 2015, and described in multiple reports as the largest and oldest known malicious TDS. It redirects traffic from compromised or spoofed websites to malicious destinations including tech support scams, fake updates, phishing domains, exploit kits, cryptocurrency scams, fake CAPTCHA schemes, ransomware-related activity, and malware delivery chains. Researchers also reported that VexTrio has distributed malicious mobile applications disguised as legitimate VPN and system optimizer apps, including via Google Play and Apple’s App Store.
VexTrio operates through a network of malicious or complicit adtech companies and affiliate programs, including Los Pollos, TacoLoco, and Adtrafico, and has been linked to Adspro Group (later AimedGlobal), Teknology SA, ByteCore AG, SkyForge Digital AG, and Tekka Group. Reporting states that it uses both its own underground TDS infrastructure and commercial platforms such as Keitaro. The ecosystem has been tied to more than 60 affiliates and at least 70,000 malicious domains, and hundreds of thousands of compromised websites have redirected victims to VexTrio and its affiliates annually. GoDaddy reported that nearly 40% of compromised websites it observed in 2024 redirected to VexTrio via Los Pollos smartlinks.
Infection and traffic acquisition commonly involve compromised WordPress sites, malicious script injections, DNS TXT record-based C2/redirection, smartlinks, push-notification lures, and fake CAPTCHA prompts. Campaigns and malware families observed using VexTrio-related redirection chains include Balada, DollyWay, Sign1, SocGholish, and ClearFake. The infrastructure filters traffic by geography, device type, and technical characteristics, and excludes antimalware and sandbox environments to evade detection. VexTrio and related TDSs use push-notification delivery mechanisms including Firebase Cloud Messaging and custom Push API scripts.
Researchers linked VexTrio infrastructure and operations to Russian-connected hosting and domain registration, and reporting describes a strong Russian nexus across related TDS operators such as Help TDS, Disposable TDS, Partners House, BroPush, RichAds, and RexPush. VexTrio also shared infrastructure with services used in the Kremlin-linked Doppelganger disinformation campaign. After Qurium exposed Los Pollos’ role in November 2024, Los Pollos halted push-link monetization and some malware traffic shifted to Help TDS and Disposable TDS, which researchers assessed were closely intertwined with VexTrio.
High-confidence indicators and characteristics mentioned in the content include use of compromised WordPress sites, DNS TXT record redirect infrastructure, smartlinks, fake CAPTCHA push-notification lures, PowerDNS-managed infrastructure, Russian-connected hosting, and associations with Los Pollos, TacoLoco, Adtrafico, Help TDS, and Disposable TDS.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
Other indicator types observed in public reporting.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cybercriminal traffic distribution system used to route victims to malicious content; reported here as distributing malicious mobile apps masquerading as legitimate VPNs and system optimizers via Google Play and Apple’s App Store.
VexTrio is a cybercriminal organization that operates a malicious traffic distribution system (TDS), redirecting web users from compromised websites to malicious destinations such as tech support scams, phishing domains, and exploit kits. It uses advanced DNS manipulation techniques to maintain persistent access and evade detection.
VexTrio is a large-scale, malicious traffic distribution system (TDS) operated by a network of seemingly legitimate ad tech companies. It hijacks web traffic from compromised websites and redirects users to a range of malicious destinations, including scams, phishing, exploit kits, and malware delivery frameworks. VexTrio acts as a broker, supplying hijacked traffic to various cybercriminal affiliates and malware operations.
VexTrio is a large, long-running malicious traffic distribution system (TDS) and adtech operation that monetizes compromised website traffic by redirecting victims to scams, malware, and fraudulent push notification schemes. It operates through a network of affiliated adtech companies and has deep connections to other TDSs and commercial ad networks.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.