VexTrio Cybercrime Network Redirects Traffic via 20,000 Hacked WordPress Sites

Listen to this Post

The growing scale of cyberattacks, including data breaches and identity theft, highlights the increasing complexity of online security threats. In one of the latest examples, a cybercrime group called “VexTrio” has been using thousands of compromised WordPress websites to funnel traffic through a redirection scheme. This operation has been ongoing for nearly a decade, impacting over 20,000 sites and targeting millions of visitors globally. The scheme operates under the alias “DollyWay World Domination,” a name coined after a particular code string found in the malware, and involves various malicious tactics such as cryptographically signed data transfers and reinfections that make it difficult to eliminate. In this article, we break down the scale of the threat, its operation methods, and best practices for WordPress site owners and users.

The Rise of VexTrio: A Decade-Long Malware Campaign

VexTrio is not a new name in the cybercrime world. This group has been running what is known as the “DollyWay World Domination” campaign for nearly eight years. A recent report by GoDaddy reveals the extent of their operation, which has now compromised over 20,000 WordPress sites worldwide. What started as multiple smaller campaigns is now recognized as one unified operation utilizing Traffic Distribution Systems (TDS) and lookalike domains to redirect traffic and deliver scams.

Denis Sinegubko, from GoDaddy, highlighted that the

How DollyWay Infects WordPress Sites

DollyWay v3, the latest iteration of this malware, uses sophisticated tactics to infect WordPress sites. These include injecting malicious redirect scripts that utilize compromised Traffic Direction System (TDS) nodes. Once a visitor lands on a compromised site, the redirect chain begins. First, the user is sent to a scam page, which may involve topics such as cryptocurrency investments, before being forwarded to malware or phishing websites.

What’s particularly alarming about DollyWay is its ability to reinfect sites automatically. Each time a user accesses an infected page, the malware disables security plug-ins, injects new code, and re-obfuscates itself. This cyclical process ensures that WordPress sites remain infected, sometimes even after an attempt at malware removal. This mechanism significantly complicates the removal process, especially for high-traffic sites.

The scale of this attack is staggering. As of February 2025, it was reported that over 10,000 WordPress sites were compromised every month, generating millions of malicious impressions and redirecting visitors to these scam sites.

VexTrio’s Monetization Strategy

VexTrio’s operations are not just about causing harm; they’re also a means to make money. The group monetizes its malicious redirection schemes by leveraging commercial ad networks, such as AdsTerra and PropellorAds, to gain affiliate ad revenue. These ad networks often pay out through traditional means, making it more difficult to trace the source of these scams. Historically, however, VexTrio has used more aggressive tactics, including deploying ransomware and banking trojans.

Key Defender Takeaways

The VexTrio operation demonstrates the diverse tactics used by cybercriminals to generate revenue through online scams. What stands out is the group’s ability to blend complex redirection systems with legitimate advertising networks, allowing them to profit while camouflaging their malicious activity. This type of attack highlights the need for better cybersecurity practices, particularly for WordPress site administrators, who should prioritize updating WordPress themes, plugins, and core systems.

For WordPress administrators, Sinegubko recommends several measures to prevent infection or mitigate further damage, including:

  • Temporarily taking down compromised sites or disabling all plugins to stop the malware from spreading.

– Keeping WordPress core, themes, and plugins updated.

  • Implementing strong admin password policies and multi-factor authentication (MFA).
  • Using tools to detect malicious code and considering the use of a Web Application Firewall (WAF).

What Undercode Says: An Analysis of the VexTrio Attack

VexTrio’s operation is a perfect example of the shifting landscape of cybercrime. In contrast to more overt forms of malware attacks, VexTrio has adopted a low-key yet highly effective method of attack: redirecting traffic through seemingly innocuous WordPress sites. The real genius of this scheme lies in its subtlety—by using common tools like TDS and relying on monetizing legitimate ad networks, the cybercriminals have crafted a system that is difficult to detect and mitigate.

The continuous reinfection of websites and the use of commercial ad networks as part of the scam make it harder for victims to understand the full scope of the threat. Many site administrators may notice abnormal traffic or a drop in website performance, but often fail to associate it with malware. Moreover, the complexity of removing the malware is an ongoing challenge for WordPress administrators. The constant cycle of obfuscation and reinfection ensures that these sites remain compromised for extended periods.

The fact that this operation has been running for nearly a decade also points to the shortcomings of traditional security measures. Even with regular updates to WordPress core and plugins, many administrators fail to adopt the best practices required to thwart attacks like this. The integration of malware with ad networks further blurs the lines between legitimate advertising and cybercrime.

It is clear that website administrators need to reassess their security policies and adopt more robust preventive measures. The rise of sophisticated malware like DollyWay demands a deeper commitment to cybersecurity, from using advanced detection tools to adopting stricter access management protocols.

Fact Checker Results

  • The malware known as DollyWay has indeed been active for nearly a decade, targeting WordPress websites globally.
  • VexTrio’s use of commercial ad networks like AdsTerra for monetization is a documented strategy.
  • GoDaddy’s research indicates the campaign continues to infect thousands of WordPress sites, redirecting millions of users to malicious content.

References:

Reported By: https://www.darkreading.com/cyberattacks-data-breaches/vextrio-20000-hacked-wordpress-sites-traffic-redirect-scheme
Extra Source Hub:
https://www.twitter.com
Wikipedia
Undercode AI

Image Source:

Pexels
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp | 💬 TelegramFeatured Image