A ad fraud operation , called “Scallywag,” is generating revenue from pirated and URL shortening websites through specially crafted WordPress plugins that generate billions of fraudulent ad requests daily.

The Scallywag campaign was uncovered by the company HUMAN, which mapped a network of 407 domains supporting the scam. According to the company, the malicious operation reached up to 1.4 billion fraudulent ad requests per day.
HUMAN's efforts to block and report Scallywag's traffic resulted in a 95% reduction in traffic. However, the attackers continued, changing domains and choosing other revenue models.
See also: Google suspended 39 million suspected fraud ad accounts
Using WordPress plugins for the new ad fraud business
Legitimate ad providers avoid piracy and URL shortening sites due to legal risks, brand safety concerns , and lack of quality content
Scallywag is a fraud-as-a-service, based on four WordPress plugins, which help cybercriminals generate money from dangerous and low-quality websites.
These WordPress plugins are: Soralink (released in 2016), Yu Idea (2017), WPSafeLink (2020) and Droplink (2022).
Human says that many independent threat actors purchase and use the above WordPress plugins to create their own ad fraud programs.
“These extensions lower the barrier to entry for an aspiring threat actor looking to monetize content that generally wouldn’t be able to monetize through advertising. In fact, several threat actors have published videos to guide others in creating their own scams,” HUMAN explains.
The Droplink plugin is the only exception to the sales model, as it is available for free while performing various money-making steps for sellers.
See also: Arrests of people for crypto investment fraud via AI
Users who visit pirated catalog sites to find premium movies or software click on embedded URL-shortened links and are redirected through the company's cashout infrastructure.
Pirate catalog sites that cannot host ads directly are not necessarily run by the operators of the Scallywag ad fraud campaign. Instead, their operators form a “gray partnership” with ad fraudsters to outsource revenue.
The redirection process takes the visitor through intermediate, ad-heavy pages and ends up on a page that hosts the promised content (software or movie).
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Intermediate sites are WordPress sites running Scallywag plugins. These handle redirection, ad loading, CAPTCHA, timer, and the cloaking mechanism, which displays a clean blog on ad platform checks.
Scallywag operation targeting
HUMAN detected Scallywag activity by analyzing traffic patterns across its partner network (e.g., high volume of ad impressions from seemingly benign WordPress blogs, CAPTCHA interaction before redirection, and more).
It then labeled the network as fraudulent and worked with ad providers to stop bidding on ad requests and reduce Scallywag's revenue stream.
For their part, the Scallywag campaign operators attempted to evade detection by using new cashout domains and open redirect chains to hide the real referral link. However, HUMAN says it detected and blocked them. As a result, daily traffic dropped sharply from 1.4 billion requests to almost zero. It is likely that the operators will continue their efforts by implementing new methods to evade detection.
See also: US seizes $8.2 million linked to 'Romance Baiting' scams

Protection methods (for users, administrators and advertisers)
👤 For regular users:
• Avoid pirated sites & URL shorteners that you don't trust.
• Use ad blockers with anti-malvertising capabilities.
• Update your browser and extensions regularly.
• Avoid clickbait – it often leads to these types of domains.
🧑💻 For WordPress administrators:
• Choose only reliable plugins, with positive reviews and active updates.
• Use security plugins like Wordfence.
• Enable Web Application Firewall (WAF).
• Scan frequently for malicious code on the server or database.
• Disable file editing via WP admin (define('DISALLOW_FILE_EDIT', true); in wp-config.php).
🧠 For advertising networks and brands:
• Use ad verification services to detect fake impressions.
• Adopt ads.txt and app-ads.txt in collaboration with publishers.
• Monitor for suspicious increases in traffic or ad requests.
• Invest in fraud detection AI.
Source: www.bleepingcomputer.com
