Skip to main content
Mallory
2 malware families

VexTrio Viper

Also known asvextrio_viper

VexTrio Viper is a cybercriminal threat actor centered on malicious advertising technology and traffic distribution system (TDS) operations. The content describes it as operating a large TDS infrastructure since early 2020 and running one of the most extensive known cybercriminal affiliate programs, with reporting citing over 65 affiliates in one source and over 165 affiliates in another. Reported affiliates or associated partners include GoRefresh, SocGholish, and ClearFake. Los Pollos is described as a malicious advertising technology company operating under the VexTrio Viper umbrella. The actor has been observed using compromised and hijacked domains to route traffic through its TDS, including domains taken over via the Sitting Ducks DNS hijacking technique. Reporting states VexTrio Viper first hijacked a domain using Sitting Ducks in early 2020 and has hijacked domains across multiple DNS services. Its stolen or compromised domains are used for redirection, scam delivery, and broader malicious infrastructure operations. Observed tactics and techniques in the provided content include multi-stage redirect chains, device and geolocation profiling, fake robot CAPTCHA lures, abuse of browser push-notification permissions, and use of compromised websites with minimal injected code to funnel victims into TDS workflows. The content links VexTrio Viper to push-notification abuse that can generate high-volume deceptive alerts and route users to fake giveaways, fake dating sites, fake surveys, fake crypto-mining sites, fake apps or adware, malware delivery, disinformation, and antivirus scareware flows. Example redirect chains involve multiple intermediary domains before final destinations, and the actor’s infrastructure is described as tailoring payloads based on device and location. The content also states that VexTrio Viper has developed malicious applications that were published on Apple and Google official app storefronts while posing as useful apps. VexTrio Viper is not described in the provided content as a nation-state actor. The reporting instead characterizes it as a financially motivated cybercriminal ecosystem focused on adtech abuse, traffic monetization, scam enablement, and affiliate-driven malicious redirection.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

2 of 15 tactics6 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
1 technique
T1587
Develop Capabilities
T1587.003
Digital Certificates
TA0011
Command and Control
2 techniques
T1071
Application Layer Protocol
T1071.004
DNS
T1568
Dynamic Resolution
T1568.002
Domain Generation Algorithms
IOCS

Observables

2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping3

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables2

Domains, IPs, and hashes tied to this actor, refreshed continuously.