Balada is a website injection campaign observed on compromised WordPress sites. It is referenced alongside DollyWay and Sign1 as one of several malicious injections used to redirect victim traffic through the VexTrio traffic distribution system (TDS) ecosystem. High-confidence reporting indicates these compromises involved injected malicious scripts and, in related WordPress compromise activity, DNS TXT record-based command-and-control mechanisms that encoded redirect URLs. Balada-linked redirections were associated first with VexTrio infrastructure, including Los Pollos smartlinks, and later with Help TDS after disruption to Los Pollos in November 2024. The broader ecosystem uses compromised websites at scale, fake CAPTCHA and push-notification lures, server-side redirects, and malicious adtech infrastructure to deliver scams and malware. Balada is therefore associated with large-scale website compromise and traffic monetization operations tied to the VexTrio ecosystem, which has strong Russian-connected hosting and domain-registration links. The provided content does not include family-specific file-based IOCs for Balada beyond its identification as a named website injection campaign used in these redirection chains.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Balada is a type of website malware that infects WordPress sites, injecting malicious code to redirect visitors to TDSs like VexTrio. It is part of a family of injection campaigns that leverage vulnerabilities in WordPress to compromise sites and monetize traffic through malicious adtech networks.
Balada is a malicious script injected into compromised WordPress websites to initiate redirection chains leading to scam infrastructure and malware distribution networks like VexTrio.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.