logo

Deniability by Design: DNS-Driven Insights into a Malicious Ad Network

ID: 20259189-3118-5847-b0c1-bd40875a805d

STIX ID: report--20259189-3118-5847-b0c1-bd40875a805d

Feed Name: Infoblox Threat Intel Blog

Threat Score
75/100

Date Published: 2025-09-16

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

The report exposes “Vane Viper” — an adtech-backed threat actor (linked to AdTech Holding/PropellerAds and related firms) that operates a large traffic distribution system abusing push notifications, service workers, and cloaking to deliver malvertising, malware (including mobile trojans like Triada and reported infostealer campaigns), and ad-fraud at scale via tens of thousands of ephemeral domains and overlapping registrar/hosting infrastructure; the analysis provides technical TTPs, infrastructure attributions (WHOIS/RIPE), campaign flows, and indicators for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.