When Infoblox researchers set out to disrupt the notorious Traffic Distribution System (TDS) known as VexTrio, they werenβt expecting to uncover one of the most sprawling and persistent malware ecosystems in existence. What began as a βperturb and observeβ experiment became a sweeping expose of the deeply entangled world of malicious adtech, DNS-based malware campaigns, and global website compromises.
On November 13, 2024, Qurium exposed: Swiss-Czech adtech firm Los Pollos was linked to VexTrio, the largest known malicious TDS. Just days later, Los Pollos abruptly shut down their “push link monetization” service. To outsiders, this might have seemed like a victory for defenders. But as Infoblox observed, the criminal network didn’t disintegrate β it simply shifted gears.
By November 20, multiple long-active malware campaignsβlike DollyWay, Balada, and Sign1βsimultaneously stopped redirecting victims to VexTrio and instead funneled them into a βnewβ service: the Help TDS. But it wasnβt new at all.
βHelp TDS is not new but has been intertwined with VexTrio for years,β the researchers discovered. In fact, it is the same system previously dubbed the Disposable TDSβmerely rebranded but architecturally identical.
A major part of this investigation revolved around DNS-based command-and-control (C2) infrastructure. Malware embedded in over 25,000 WordPress sites used DNS TXT records to relay encoded redirection instructions. These C2 servers β split into two independently hosted clusters β once routed traffic to VexTrio but, following Los Pollos’ shutdown, synchronized their operations to pivot toward the Help TDS.

βBy analyzing 4.5 million DNS TXT record responsesβ¦ we discovered that the domains used in the campaigns fell into two distinct sets, each with a distinct C2 server.β
The pivot showed not just technical coordination, but organizational resilience. Even as GoDaddy’s researchers confirmed DollyWayβs transition away from VexTrio, Infoblox noted that some DNS-based campaigns continued steering victims to Help TDS into May 2025.
The report lifts the veil on the murky business model driving these campaigns: malicious adtech.
At the core are commercial operatorsβLos Pollos, Taco Loco, BroPush, Partners House, and RichAdsβmasquerading as affiliate advertising networks. They distribute malicious payloads, fake sweepstakes, and push notification scams under the guise of online ads.
βThese firms vet network affiliates before allowing them to joinβwe know, weβve triedβand they maintain personal information about the affiliates and their payments that could lead to their identities.β
The so-called βpublishing affiliatesβ β often website hackers β redirect traffic into the TDS, earning money based on victim interactions. The delivered content is rarely innocent. Itβs weaponized ads, infostealers, and browser-hijacking push notifications disguised as CAPTCHAs.
Technical artifacts further confirmed the deep interconnection among these malicious networks. Infoblox identified rare JavaScript used to trap users on scam pages and unique lure images like logo.png and bot.pngβshared across six TDSs including VexTrio, Help TDS, and RichAds.
βThe six TDSs share image luresβ¦ their SHA256 file hash values matchβ¦ All are operated by large public affiliate networks that specialize in push advertising.β
These firms even use the same infrastructure quirks: DNS misconfigurations, PowerDNS installations, and custom URL parameters that track victims across platforms.
The malware actors exploiting hundreds of thousands of sites are not anonymous to the adtech companies they partner with.
βThe adtech firms know. They vet their publishing affiliates and collect information like Telegram accounts and cryptocurrency wallets.β
Companies like Los Pollos operate under a thin veneer of legitimacy, yet maintain full knowledge of the identities of malware distributors and scam operators.
The Infoblox report doesnβt just dissect the machinery of VexTrioβit exposes an entire underworld built on exploitative advertising, mass website compromise, and DNS trickery. While individual actors like Los Pollos may shutter operations under scrutiny, the core network continues β agile, adaptable, and dangerously effective.
Unless commercial adtech firms are held accountable, VexTrio and its many clones will persist in the shadows of the internet, profiting from the suffering of unsuspecting users.
Related Posts:
- The Hidden Cyber Trap: How Compromised Websites and Malicious AdTech Manipulate Users
- Infoblox Uncovers Malicious Wave in .US Domain Registrations
- 13,000 MikroTik Routers Hijacked for Global Malspam Operation
- Los Angeles County data breach exposes 3.2 million files containing terrifyingly sensitive data
- Ransomware Attack Forces Closure of LA County Courts
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.