The US Federal Bureau of Investigation (FBI) has issued a new warning about the increasing use of so-called Traffic Distribution Systems (TDS) by cybercriminals, noting that this technology has evolved into one of the most effective tools for distributing malware, conducting phishing attacks and implementing online financial fraud.

Although TDS systems were originally developed for legitimate uses in digital marketing and online advertising, attackers have found ways to exploit them, creating complex redirection chains that can bypass traditional security mechanisms.
FBI: How Traffic Distribution Systems (TDS) Work
TDS are essentially web traffic routing mechanisms. When a user visits a website, clicks on an ad , or downloads an app, the system can automatically direct them to different web pages based on specific criteria.
See also: Hackers sell advanced HiddenMiner on Dark Web forum
Cybercriminals use this capability to selectively redirect their victims to compromised websites, fake login pages, or servers distributing malware. The process is often invisible to the user, who may believe they are visiting a perfectly legitimate destination.
The techniques used by attackers
According to the FBI, victims are accessing malicious TDS through multiple deception techniques. Phishing remains the most common method, but malicious ads, fake search results, and compromised websites are also proving particularly effective.
One of the most worrying practices is SEO Poisoning, where attackers create pages that mimic trusted services and manage to appear high in search engine results. The user, without suspecting the danger, is led into a chain of redirects that are fully controlled by the perpetrators.
See also: Warning from Google and FBI: Ransomware group sends fake IT workers for attacks
At the same time, cybercriminals exploit weak passwords, outdated plugins, and vulnerable content management systems to gain access to legitimate websites and embed malicious code.

Why TDS makes it difficult to detect attacks
The big challenge for cybersecurity experts is that Traffic Distribution Systems use multiple intermediate stages before leading the victim to the final destination.
This technique makes it extremely difficult to detect the real source of the attack and allows attackers to bypass security filters, firewalls and threat detection systems.
At the same time, TDS platforms collect information about each visitor, such as IP address, operating system, device type, geographic location, and browser details. With this data, attackers can decide whether a user is an attractive target or a security analyst who will be shown innocent content.
From a simple click to ransomware
The FBI is warning that a seemingly innocent visit to a website can escalate into a serious cybersecurity incident.
Users may be redirected to phishing pages that steal passwords and banking information, or unknowingly install malware. In many cases, access gained through a TDS is later sold to ransomware groups, which encrypt data and demand millions of dollars in ransom.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Hidden Risk: North Korean hackers BlueNoroff target crypto companies
This development proves that cyberattacks now operate as an organized ecosystem, where different criminal groups cooperate and exchange access to infected systems.

The protection measures recommended by the FBI
The US agency is urging individuals and businesses to adopt stricter protection measures. Key recommendations include using strong and unique passwords, enabling two-factor authentication (2FA), regularly updating software and plugins, and installing reliable security solutions.
For businesses, special emphasis is placed on training staff to detect phishing attacks, continuous monitoring of suspicious activity, and regular auditing of management accounts.
As criminal groups constantly evolve their techniques, the FBI emphasizes that vigilance and proactive cybersecurity are now necessary prerequisites for safe use of the internet.
