A sophisticated cybercrime operation, known as the “DollyWay World Domination,” has successfully infiltrated more than 20,000 WordPress websites since 2016, redirecting unsuspecting users to malicious destinations.
See also: Fake DocuSign pages distribute NetSupport RAT malware

The attack takes its name from the signature code snippet define('DOLLY_WAY', 'World Domination') found within the malware and continues to evolve, adopting advanced evasion techniques that make traditional security measures difficult. Kaspersky says the DollyWay World Domination campaign primarily targets WordPress installations via vulnerable plugins and themes, taking advantage of the platform's massive global presence, which powers nearly half of all websites worldwide.
GoDaddy security researchers first documented this massive operation in March 2025, revealing that attackers have been maintaining persistent access to compromised websites for nearly a decade. The attack methodology involves a multi-stage approach that begins with the injection of seemingly innocent scripts that bypass static HTML parsing.
These initial payloads act as digital “Trojan Horses,” creating permanent backdoors before downloading additional malicious elements, which are designed to profile victims, communicate with control centers, and redirect online traffic.
See also: The North Face: Credential stuffing attacks allowed data breach
The malware exhibits impressive resilience through a sophisticated re-infection mechanism, which is activated every time it loads any page of the compromised website, making full recovery extremely difficult.

The managers of the DollyWay World Domination campaign have developed a complex merchandising strategy, leveraging two main networks : VexTrio and LosPollos.
VexTrio, described by cybersecurity experts as the “Uber of cybercrime,” acts as the primary online traffic broker, directing victims to various fraudulent websites, such as fake dating platforms, cryptocurrency scams, and illegal gambling sites, based on detailed user profile data.
The campaign's partnership with the LosPollos network lends a sense of legitimacy to some redirects, as in some cases traffic is directed to genuine apps, such as Tinder or TikTok on Google Play.
This dual strategic approach not only generates revenue through both legal and illegal channels, but also helps to conceal the malicious nature of the overall operation by mixing deceptive redirects with promotions of genuine applications.
See also: Czech Republic accuses Chinese hackers of attack on Foreign Ministry
Based on the above, the DollyWay World Domination campaign is a prime example of how modern cyberattacks have evolved from simple security breaches to fully organized, long-term ecosystems of digital crime. Another critical point is the collaboration with platforms such as VexTrio and LosPollos , which are hubs in the underground digital ecosystem, providing cybercriminals with tools to target specific victims and generate revenue on a global scale.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
