Global Scam Network Exploits WordPress Sites: Inside VexTrio and Its Affiliate Operations

The threat actors behind the VexTrio Viper Traffic Distribution Service (TDS) are linked to other TDS services like Help TDS and Disposable TDS, indicating a sophisticated cybercriminal operation designed to distribute malicious content.
According to a report, VexTrio comprises malicious adtech companies that disseminate scams and harmful software through various advertising formats, including smartlinks and push notifications. Notable companies under VexTrio include Los Pollos, Taco Loco, and Adtrafico, which operate a commercial affiliate network connecting malware actors with "advertising affiliates" promoting illicit schemes such as gift card fraud and phishing sites.
These malicious traffic distribution systems redirect victims to scam destinations via SmartLinks or direct offers. For instance, Los Pollos recruits malware distributors with high-paying offers, while Taco Loco focuses on push monetization.


A significant aspect of these attacks involves compromising WordPress websites to inject malicious code that initiates redirection to VexTrio's scam infrastructure. Examples of such injections include Balada, DollyWay, and Sign1.
In March 2025, GoDaddy reported that these scripts redirect visitors to various scam pages through traffic broker networks associated with VexTrio, one of the largest known cybercriminal affiliate networks utilizing advanced DNS techniques and domain generation algorithms.
VexTrio faced setbacks in mid-November 2024 when Qurium revealed Los Pollos' connection to VexTrio, leading to the cessation of their push link monetization. This prompted many threat actors to shift to alternative redirect destinations like Help TDS and Disposable TDS.
Infoblox's analysis of 4.5 million DNS TXT record responses from compromised websites over six months revealed that the domains involved could be categorized into two sets, each with distinct command-and-control (C2) servers, both hosted on Russian-connected infrastructure.


Further investigation indicated that Help TDS and Disposable TDS are essentially the same, having maintained an exclusive relationship with VexTrio until November 2024. Help TDS, which previously redirected traffic to VexTrio domains, has since transitioned to Monetizer, a platform that connects web traffic from publisher affiliates to advertisers.
Infoblox noted that VexTrio is among several TDSs identified as commercial adtech firms, including Partners House, BroPush, and RichAds, many of which utilize Google Firebase Cloud Messaging (FCM) to distribute links to malicious content via push notifications.
"Every year, hundreds of thousands of compromised websites redirect victims to the tangled web of VexTrio and its affiliate TDSs," the report stated. "VexTrio and other affiliate advertising companies are aware of the malware actors involved, or at least have enough information to track them down."
- Other (42)
- Ransomware (152)
- Events and News (27)
- Features (45)
- Security (481)
- Tips (79)
- Google (24)
- Achievements (11)
- Products (35)
- Activation (7)
- Dealers (1)
- Bank Phishing (46)
- Malware Alerts (223)
- Cyber Attack (274)
- Data Backup (12)
- Data Breach (111)
- Phishing (160)
- Securty Tips (2)
- Browser Hijack (19)
- Adware (15)
- Email And Password (69)
- Android Security (71)
- Knoweldgebase (38)
- Botnet (16)
- Updates (4)
- Alert (71)
- Hacking (59)
- Social Media (8)
- vulnerability (63)
- Hacker (33)
- Spyware (11)
- Windows (7)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (3)
- Website hacks (6)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (8)
- Mozilla (2)
- COVID-19 (5)
- Instagram (3)
- NPAV Announcement (9)
- IoT Security (1)
- Deals and Offers (2)
- Cloud Security (12)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (3)
- WhatsApp (5)
- Amazon (2)
- DMart (1)
- Payment Risk (4)
- Occasion (3)
- firewall (2)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (13)
- Impersonation phishing (1)
- DDoS (7)
- Smishing (2)
- Whale (0)
- Whale phishing (4)
- WINRAR (2)
- ZIP (2)