The digital advertising ecosystem has become a prime target for cybercriminals, who are increasingly exploiting Adtech to distribute malware and conduct malicious campaigns.
Rather than simply exploiting legitimate platforms, malicious users are now acting as the platforms themselves, creating a complex web of deception that leverages the inherent complexity and fragmentation of the adtech supply chain to evade detection.
See also: GPUGate malware: Exploiting GitHub and Google Ads for attacks

Recent investigations have uncovered a massive operation involving Vane Viper, a malicious user that has appeared on about half of the customer networks monitored by security researchers, generating about a trillion DNS queries in the last year. The user's infrastructure spans about 60,000 domains, representing only a small part of the broader malicious ecosystem they control.
The sophistication of this campaign lies in the carefully crafted corporate structure designed to potentially negate liability. Corporate filings trace Vane Viper to AdTech Holding, a Cyprus-based company whose primary subsidiary, PropellerAds, operates as both an ad network and a traffic broker. Infoblox researchers found compelling evidence that PropellerAds has gone beyond simply ignoring the criminal exploitation of its platform, with evidence pointing to several ad fraud campaigns originating directly from infrastructure attributed to the company.
See also: Google Ads spread malware via fake Homebrew Site

The malicious ad operation uses a sophisticated traffic distribution system (TDS) that routes users through multiple layers of redirection before delivering malicious payloads. This approach allows malicious users to serve legitimate content to automated security tools while directing human users to malicious destinations.
The most insidious element of Vane Viper's operation involves exploiting browser push notifications to gain persistent access to victims' devices. The campaign uses malicious service workers, JavaScript files that intercept network requests between web applications and servers, to manipulate browser behavior and maintain long-term access to compromised systems.
These service workers use script chaining techniques to exploit push notifications, with the most concerning element being the use of the eval() to execute arbitrary content retrieved from remote URLs. The remote URL is specified by hardcoded domains within the service worker, creating a dynamic command and control mechanism that can adapt to changing business requirements.
See also: Hackers exploited flaw in Krpano framework for Spam Ads

The business demonstrates remarkable resilience through its domain management strategy, cycling thousands of newly registered domains each month while maintaining key push notification domains for years. The analysis reveals that most operational domains remain active for less than a month, with registrations reaching 3,500 domains in peak months, while key infrastructure domains such as omnatuor.com, propeller-tracking.com , and various push notification services, including in-page-push.com and puissanceg.com, have remained operational for over 1,200 days, ensuring continuity of operation despite removal attempts.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
