Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Beware of hidden costs of penetration testing

Accelerating Québec’s advanced materials ecosystem

$15B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Vane Viper generates 1 trillion DNS queries to power global malware and AD fraud networks
Identity

Vane Viper generates 1 trillion DNS queries to power global malware and AD fraud networks

userBy userSeptember 25, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

September 25, 2025Ravi LakshmananAggravated/Threat Intelligence

A threat actor known as Vane Viper is out as a provider of malicious advertising technology (ADTECH). Meanwhile, it relies on the tangled web and opaque ownership structure of shell companies to deliberately circumvent liability.

“Vane Viper has been providing core infrastructure for the spread of widespread fraud, AD fraud and cyber threats for at least 10 years,” Infoblox said in a technical report released last week in collaboration with Guardio and Confiant.

“It appears that Vane Viper is not only brokering malware droppers and fisher traffic, but also running its own campaign, consistent with previously documented ad fuller techniques.”

Vane Viper, also known as Omnatuor, was previously documented by DNS threat intelligence companies in August 2022 and described it as a rogue network similar to Vextrio Viper, which uses vulnerable WordPress sites to harness large networks of compromised domains to spread riskware, spyware and adware.

DFIR Retainer Service

One notable aspect of threat actor persistence techniques is the abuse of push notification permissions to serve ads even after users change their browser settings and leave the initial page. This approach relies on service workers who maintain a permanent headless browser process to listen for events and provide unwanted notifications.

Late last year, Guardio Labs exposed a campaign called Deceptionads, which was found to leverage Vane Viper’s malicious ad network to promote Clickfix-style social engineering campaigns. The activity is attributed to a company named MoneTag, a commercial advertising technology company that is a subsidiary of PropellerAds, according to Infoblox, which is a subsidiary of AdTech Holding, a Cyprus-based holding company.

Domains linked to Properllerads have long been flagged to drive campaigns and drive traffic to leverage kits and other unauthorized sites. Further analysis reveals evidence suggesting that several AD-FRAUD campaigns arise from infrastructure caused by PropellerAds.

The cybersecurity company says Vane Viper has accounted for around 1 trillion DNS queries for about half its customer network over the past year, and threat actors will use hundreds of thousands of compromised websites and malicious ads to redirect unsuspecting site users to redirect malicious browser extensions, malicious browser extensions, including malicious browser input, including malicious Mallaws. In one case, it is called a Triada.

Additionally, Vane Viper appears to share the bond between infrastructure and HR with URL Solutions (Pananaam), Webzilla and XBT Holdings. The former is also linked to a disinformation site set up by a Russian influence operation called Doppelgänger. Other companies owned by Adtech Holding include Propushme, Zeydoo, Notix, and Adex.

CIS Build Kit

Approximately 60,000 domains are rated as part of Vane Viper’s infrastructure, most of which remain active within a month. However, there are several domains that are active for more than 1,200 days, including the original Omnatuor.[.]com, propeller tracking[.]com and some others are centered around push notification services.

This operation is known to register a huge number of new domains each month and scale a high of 3,500 domains in October 2024 alone. This is a major jump from less than 500 domains registered in April 2023. Vane Viper domains account for almost 50% of bulk registration domains via URL solutions since 2023.

However, PropellerAds has previously denied fraud, saying it is “just an automated intermediary that helps advertisers find the best publisher to publish their ads,” and it “does not support, support or encourage malicious ads on the network.”

“Vane Viper isn’t just a threat actor hiding behind the Adtech platform,” Infoblox said. “This is a threat actor as an Adtech platform. AdtechHolding claims to provide reach and monetization to advertisers at scale, but that actually poses risk.”

“Vane Viper hides behind the plausible negativity of working as an ad network while using TD. [traffic distribution system] To pose multiple types of threats. ”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleOpenai launches ChatGpt Pulse and actively writes morning briefs
Next Article A million-year-old skull from China holds cues of Neanderthals, Denisovans and human origin
user
  • Website

Related Posts

Beware of hidden costs of penetration testing

October 16, 2025

$15B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More

October 16, 2025

CISA reports flaw in Adobe AEM with perfect 10.0 score – already under active attack

October 16, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Beware of hidden costs of penetration testing

Accelerating Québec’s advanced materials ecosystem

$15B Crypto Bust, Satellite Spying, Billion-Dollar Smishing, Android RATs & More

£30m partnership between Toyota and UK to boost zero-emission vehicle research and development

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

The AI Revolution: Beyond Superintelligence – TwinH Leads the Charge in Personalized, Secure Digital Identities

Revolutionize Your Workflow: TwinH Automates Tasks Without Your Presence

FySelf’s TwinH Unlocks 6 Vertical Ecosystems: Your Smart Digital Double for Every Aspect of Life

Beyond the Algorithm: How FySelf’s TwinH and Reinforcement Learning are Reshaping Future Education

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.