A malware campaign dubbed 'DollyWay' has been ongoing since 2016, affecting more than 20,000 WordPress websites worldwide, with the aim of redirecting users to malicious websites.
See also: Arcane: New info-stealer malware targets users through game cheats

The campaign has evolved significantly over the past eight years, leveraging advanced evasion, re-infection, and profitability strategies.
According to GoDaddy researcher Denis Sinegubko , the DollyWay malware operates as a large-scale fraud redirection system in its latest version (v3). However, in the past, it has distributed more malicious payloads such as ransomware and banking trojans . DollyWay v3 is an advanced redirection operation that targets vulnerable WordPress websites, exploiting n-day vulnerabilities in plugins and themes to compromise them.
As of February 2025, DollyWay is generating 10 million false impressions per month, redirecting WordPress website visitors to fake dating , gambling, cryptocurrency, and contest websites
The campaign is funded through the partner networks VexTrio and LosPollos, after visitors have gone through a Traffic Distribution System (TDS).
A Traffic Distribution System analyzes and redirects traffic based on various visitor parameters, such as their location, device type, and referral source. Cybercriminals often use malicious TDS systems to redirect users to phishing websites or malware downloads.
See also: Microsoft warns of new StilachiRAT malware
Web pages are compromised via script injection using 'wp_enqueue_script,' which dynamically loads a second script from the compromised website.

The second phase gathers visitor referral data to categorize redirect traffic and then loads the TDS script that determines the validity of the goals.
Website visitors who are not referred, are not robots, and are not logged in WordPress users (including administrators), are considered invalid and are not redirected.
The third phase selects three random infected websites to act as TDS nodes and then loads hidden JavaScript from one of them to perform the final redirect to the VexTrio or LosPollos scam pages. The DollyWay malware uses affiliate tracking parameters to ensure that attackers are rewarded for each redirect.
It is worth noting that the final redirect only occurs when the visitor interacts with some element of the page (by clicking), thus avoiding passive crawling tools that only look at page loads.
See also: Phishing emails imitate Booking.com and distribute malware
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
To protect yourself from malware, you can follow various ways and best practices. Some of the most important are:
- Use of Antivirus
- Software Update
- Avoiding Malicious Links and Attachments
- Using Strong Passwords
- Enabling Firewall
- Countering Phishing Attacks
- Creating Backups
- Beware of Applications and Software
- Using VPN
By following these practices, you can significantly reduce the risk of infection by malware, such as DollyWay, and protect system .
Source: bleepingcomputer
