Help TDS is a malicious traffic distribution system closely associated with the VexTrio cybercriminal ecosystem. It has been active for years as part of web-based redirection chains that monetize or weaponize traffic from compromised websites, especially compromised WordPress sites. Help TDS has been observed receiving traffic from malware and web-injection campaigns and then forwarding victims to downstream affiliate advertising platforms, scams, push-notification abuse, and malware delivery infrastructure. It has also been described as closely related to, or effectively the same service as, Disposable TDS.
Historically, Help TDS maintained a tight relationship with VexTrio and was used in redirect chains tied to malicious adtech operations with a strong Russian nexus. After disruption to parts of the VexTrio ecosystem in late 2024, multiple malware and web-compromise campaigns that had previously routed traffic through VexTrio shifted to Help TDS. It has been linked to campaigns involving Balada, DollyWay, and Sign1, and to older Keitaro-style handoff chains used to pass victims onward to affiliate smartlinks. More recently, Help TDS has been observed redirecting traffic to Monetizer, a monetization platform using TDS technology.
Help TDS functions as intermediary infrastructure rather than as a host-resident payload. Its core role is traffic brokering, selective redirection, and cloaking within malicious web ecosystems. It enables downstream delivery of scams and malware while obscuring the ultimate destination and supporting affiliate monetization. The available information supports classification as malicious TDS infrastructure, but does not establish a conventional endpoint malware family type such as a trojan, loader, or infostealer.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Traffic distribution system used in a redirection chain; the report suggests a previously unpublished attack chain where Keitaro responses redirected victims into Help TDS.
Help TDS is a traffic distribution system that began receiving redirected traffic from malware families such as DollyWay after November 2024. It is associated with the same malicious adtech ecosystem as VexTrio and is used to distribute scams, adware, and malware.
Help TDS is a traffic distribution system with a strong Russian nexus, historically redirecting web traffic to VexTrio domains. It is closely associated with VexTrio and Disposable TDS, and is used to distribute malicious content and scams via compromised websites and affiliate networks.
Help TDS (also known as Disposable TDS) is a malicious traffic distribution system that has been active since at least 2017. It is closely linked to VexTrio, sharing code, infrastructure, and operational history. It is used by website malware actors to redirect compromised website visitors to scams, malware, and push notification lures.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.