Vane Viper Malvertising Network Linked to 1 Trillion DNS Queries

Vane Viper: The Shadowy Ad Network Powering Global Malvertising, Malware, and Ad Fraud for Over a Decade

  • The group known as Vane Viper is linked to a major network supporting malvertising, ad fraud, and Malware for over ten years.
  • Vane Viper operates through shell companies and a complex ownership structure to avoid accountability.
  • About 60,000 domains are part of their network, with many only active for less than a month before shutting down.
  • The network uses push notification abuse and compromised sites to spread riskware, spyware, and unwanted software, affecting both computers and mobile devices.
  • Vane Viper is connected to commercial ad companies like PropellerAds and AdTech Holding, which deny any wrongdoing.

Security researchers from Infoblox, Guardio, and Confiant have revealed that the group called Vane Viper is behind a large-scale network spreading malicious ads and cyber threats worldwide. The findings show the group relies on a complex set of shell companies and hidden ownership to avoid consequences for their actions. Vane Viper has operated for at least a decade, providing infrastructure for malware delivery, phishing, and ad fraud.

- Advertisement -

Investigators estimate that about 1 trillion DNS queries associated with Vane Viper passed through networks over the past year, impacting about half of Infoblox customer environments. The group manages close to 60,000 domains, using them to redirect users to threats like fake shopping websites, scam surveys, adult sites, sketchy software, and even mobile malware. Some domains stay active for years, while most disappear after a few weeks.

A report explained that Vane Viper abuses web browser push notification permissions, continuing to deliver ads and unwanted notifications even after users leave the original page. This method uses “service workers,” a web technology that enables sites to run background processes in the browser.

Guardio Labs documented a campaign called DeceptionAds, which used this infrastructure for social engineering attacks. The group was linked to a company named Monetag, stated as a subsidiary of the commercial ad network PropellerAds. In turn, PropellerAds is owned by AdTech Holding, based in Cyprus. Domains connected to PropellerAds have previously been flagged for supporting malvertising and distributing malware through exploit kits.

Research suggests Vane Viper shares infrastructure and staff with other companies, such as URL Solutions, Webzilla, and XBT Holdings. URL Solutions has also been linked to Russian disinformation campaigns. Other companies connected to AdTech Holding include ProPushMe, Zeydoo, Notix, and Adex.

- Advertisement -

While PropellerAds has publicly denied any involvement, calling itself just an automated ad service, analysis shows that many malicious domains and fraudulent ad campaigns originate from its infrastructure. Activity spiked in late 2024, with a new high of 3,500 domains registered in one month.

Infoblox concluded, “Vane Viper isn’t just a threat actor hiding behind an adtech platform. It’s a threat actor as an adtech platform.” They added, “Vane Viper hides behind the plausible deniability of operating as an advertising network, while using their TDS [traffic distribution system] to deliver multiple kinds of threats.”

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Copper Surges to Record High, Bank of America Predicts $11,000 Target

Copper prices have reached a record high, rising nearly 20% year-to-date. Bank of America forecasts...

Shopify, Etsy Stocks Surge on OpenAI Deal Despite Analyst Caution

Shopify and Etsy shares rose 6.2% and 15.8% after announcing an e-commerce partnership with...

Solana ETF Approval Seen as Imminent After S-1 Amendment Filing

The U.S. Securities and Exchange Commission (SEC) has made the 19b-4 review timeline irrelevant...

Wisconsin Bill Proposes Crypto Mining, Staking License Exemptions

Wisconsin lawmakers propose a bill to exempt individuals and businesses from money transmitter licenses...

Dormant Bitcoin Whale Moves $44M After 12 Years, Spooking Market

An inactive Bitcoin wallet holding 400 BTC, valued at over $44 million, moved funds...
- Advertisement -

Must Read

14 Ways On How to Make Money with Cryptocurrency

Many people want to make money with cryptocurrency because they have heard the success stories of people who became millionaires from zero.If you...