DollyWay is a long-running malware campaign/strain associated with malicious website injections on compromised WordPress sites. It is explicitly cited alongside Balada, Sign1, and DNS TXT record campaigns as an example of injected malicious code used to redirect visitors through criminal traffic distribution systems (TDSs). Reporting states that DollyWay consistently redirected victims to the VexTrio TDS for roughly eight years, and then abruptly changed behavior in November 2024: GoDaddy observed that it stopped routing traffic to VexTrio on November 20, 2024 and began sending victims to Help TDS instead. This places DollyWay within the broader VexTrio/Help TDS malvertising and scam-delivery ecosystem.
Based on the provided content, DollyWay’s primary observed behavior is web-based redirection of victims from compromised sites into downstream malicious monetization and delivery chains. Those downstream chains, as described for VexTrio and related TDS infrastructure, have included scams, phishing, fake updates, exploit-kit activity, fake CAPTCHA lures, push-notification abuse, and malware delivery. DollyWay is also specifically linked by researchers to Los Pollos, which served as a traffic broker to VexTrio and malvertising campaigns such as DollyWay. The campaign is therefore associated with the commercialized malicious adtech ecosystem tied to VexTrio, Los Pollos, and later Help TDS.
High-confidence context from the content indicates that DollyWay has been observed in compromises of WordPress websites, where malicious scripts or injections redirect site visitors. It is not directly attributed in the content to a named threat actor distinct from that ecosystem, but it is repeatedly linked to VexTrio-affiliated infrastructure and the adtech entities supporting that network. No standalone malware hashes, filenames, or other specific IOCs for DollyWay are provided in the supplied material.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malvertising campaign that Los Pollos allegedly helped broker traffic to alongside VexTrio.
DollyWay is a malware strain that has been active for at least eight years, primarily used to redirect victims' web traffic to malicious traffic distribution systems (TDS) such as VexTrio and, more recently, Help TDS. It facilitates the delivery of scams, adware, and other malware by redirecting compromised users to malicious destinations.
DollyWay is a long-running website malware that infects WordPress sites and redirects visitors to malicious traffic distribution systems (TDS) such as VexTrio and, more recently, Help TDS. It is known for persistent redirection and evolving techniques to evade detection and removal.
DollyWay is a malicious script used in compromised websites to redirect visitors to malicious destinations as part of TDS campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.