By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network
Computing

Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network

News Room
Last updated: 2025/09/25 at 4:09 PM
News Room Published 25 September 2025
Share
SHARE

Sep 25, 2025Ravie LakshmananMalvertising / Threat Intelligence

The threat actor known as Vane Viper has been outed as a purveyor of malicious ad technology (adtech), while relying on a tangled web of shell companies and opaque ownership structures to deliberately evade responsibility.

“Vane Viper has provided core infrastructure in widespread malvertising, ad fraud, and cyberthreat proliferation for at least a decade,” Infoblox said in a technical report published last week in collaboration with Guardio and Confiant.

“Vane Viper not only brokers traffic for malware droppers and phishers, but appears to run their own campaigns, consistent with previously documented ad-fraud techniques.”

Vane Viper, also called Omnatuor, was previously documented by the DNS threat intelligence firm in August 2022, describing it as a malvertising network akin to VexTrio Viper that takes advantage of vulnerable WordPress sites to build a massive network of compromised domains and use them to spread riskware, spyware, and adware.

DFIR Retainer Services

One of the notable aspects of the threat actor’s persistence techniques is the abuse of push notification permissions to serve ads even after the user navigates away from the initial page by altering browser settings. This approach relies on service workers, which maintain a persistent headless browser process to listen for events and serve unwanted notifications.

Late last year, Guardio Labs laid bare a campaign dubbed DeceptionAds that was found to leverage Vane Viper’s malicious ad network to facilitate ClickFix-style social engineering campaigns. The activity was attributed to a company named Monetag, which, according to Infoblox, is a subsidiary of PropellerAds, a commercial ad technology company that, in turn, is a subsidiary of AdTech Holding, a holding company based in Cyprus.

Domains linked to ProperllerAds have long been flagged for facilitating malvertising campaigns and driving traffic to exploit kits or other fraudulent sites. Further analysis has uncovered evidence suggesting that several ad-fraud campaigns have originated from infrastructure attributed to PropellerAds.

The cybersecurity company said Vane Viper has accounted for about 1 trillion DNS queries over the past year in about half of its customer networks, adding the threat actor takes advantage of hundreds of thousands of compromised websites and malicious ads that redirect unsuspecting site users to malicious browser extensions, fake shopping sites, adult content, survey scams, fake apps, sketchy software downloads, and malware, including an Android malware called Triada in one case.

What’s more, Vane Viper appears to share infrastructure and personnel ties with URL Solutions (aka Pananames), Webzilla, and XBT Holdings, with the former also linked to disinformation sites set up by a Russian influence operation called Doppelgänger. Some of the other companies owned by AdTech Holding include ProPushMe, Zeydoo, Notix, and Adex.

CIS Build Kits

About 60,000 domains are assessed to be part of Vane Viper’s infrastructure, most of which only remain active for less than a month. However, there are a few domains that have been active for over 1,200 days, including the original omnatuor[.]com, propeller-tracking[.]com, and several others centered around push notification services.

The operation has been found to register vast numbers of new domains each month, scaling a high of 3,500 domains in the month of October 2024 alone, a significant jump from less than 500 domains registered in April 2023. Vane Viper domains make up nearly 50% of bulk-registered domains via URL Solutions since 2023, per the company.

PropellerAds, however, has previously denied any wrongdoing, stating it’s “nothing more than an automated intermediary to help advertisers find the best publishers to publish their advertisements,” and that it “does not endorse, support, or encourage any malicious advertisement on its network.”

“Vane Viper isn’t just a threat actor hiding behind an adtech platform,” Infoblox noted. “It’s a threat actor as an adtech platform. AdTech Holding claims to offer advertisers reach and monetization at scale, but what it actually delivers is risk.”

“Vane Viper hides behind the plausible deniability of operating as an advertising network, while using their TDS [traffic distribution system] to deliver multiple kinds of threats.”

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Xiaomi 17, Xiaomi 17 Pro, Xiaomi 17 Pro max, characteristics, price and technical file
Next Article Microsoft cuts cloud services to Israeli military unit over Palestinian surveillance | News
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

DeepSeek upgrades V3 model with more parameters, open-source shift · TechNode
Computing
Microsoft blocks Israeli military’s access to some cloud services to prevent mass surveillance – News
News
We finally have pricing for the Asus ROG Xbox Ally, and it’s an expensive handheld
News
7 Ways to Protect Your Mental Health When You Work in Social Media
Computing

You Might also Like

Computing

DeepSeek upgrades V3 model with more parameters, open-source shift · TechNode

1 Min Read
Computing

7 Ways to Protect Your Mental Health When You Work in Social Media

9 Min Read
Computing

Solana Price Prediction: Can SOL Surpass $300 Soon? | HackerNoon

0 Min Read
Computing

Inside Recompose, where the human composting startup is ready to grow its formula beyond Seattle

8 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?