logo

Deniability by Design: DNS-Driven Insights into a Malicious Ad Network

ID: 88fdf7c5-69e1-582a-8324-5f00b9a8c29c

STIX ID: report--88fdf7c5-69e1-582a-8324-5f00b9a8c29c

Feed Name: Infoblox Threat Intel Blog

Threat Score
78/100

Date Published: 2025-09-16

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

This report attributes a large-scale malvertising and ad-fraud ecosystem, tracked as “Vane Viper,” to AdTech Holding and its PropellerAds subsidiary, documenting ~60,000 domains, TDS-driven redirection and cloaking, push-notification persistence abuse, and active malware distribution (including Triada APKs). It maps corporate and infrastructure ties (URL Solutions/Pananames, Webzilla/XBT, CloudOne/Fozzy) that facilitate registration, hosting, and resilience, and provides indicators of compromise and campaign technical details showing sustained, high-volume malicious activity across the adtech supply chain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.