NEWS

Russian Organized Crime Controls Malicious Adtech

Russian organized crime controls a vast network of malicious adtech, used to spread scams, malware, and state-backed disinformation. This sophisticated infrastructure is deeply integrated and constantly evolving.

By
LNGFRM Team
Published June 13, 2025
A stylized browser window displaying a network diagram of interconnected nodes, surrounded by placeholder text and content blocks.
Illustration by Addison Smith for LNGFRM

The murky world of online advertising has long been a haven for the unscrupulous, a digital wild west where the line between legitimate marketing and outright fraud blurs with alarming frequency.

But a recent, startling discovery has pulled back the curtain on an even darker truth: this sprawling ecosystem of online hucksters and website hackers is not merely a nuisance, but a sophisticated, resilient machine actively leveraged by state-backed disinformation campaigns.

This isn’t just about pop-ups and spam; it’s about the weaponization of adtech, and the implications are chilling.

Late last year, security researchers at Qurium stumbled upon a disconcerting connection.

They were investigating “Doppelganger,” a Kremlin-backed disinformation network notorious for infiltrating European media landscapes by pushing fake news through cloned websites.

What they found was a disturbing convergence: Doppelganger wasn’t just using clever cloaking techniques to hide its tracks from search engines, it was tapping into the very same malicious advertising infrastructure that fuels a vast, shadowy industry of scams and malware.

This dark adtech, it turns out, is far more deeply entrenched and interconnected than previously imagined, operating with an almost incestuous efficiency.

The threads of this digital tapestry led Qurium to VexTrio, widely considered the oldest malicious traffic distribution system (TDS) in existence.

While TDSs can be legitimate tools for managing ad traffic, VexTrio’s purpose is far more sinister, primarily funnelling victims of phishing, malware, and social engineering scams.

Digging deeper, the researchers traced Doppelganger’s cloaking service to an Internet provider in Switzerland, and from there, to a pair of affiliate marketing services that read like something out of a crime drama: LosPollos.com and TacoLoco.co.

The “Breaking Bad” homage in LosPollos is no accident.

Its logo features Gustavo Fring, the fictional chicken restaurant owner who fronted a methamphetamine cartel.

This nod to a criminal empire is disturbingly apt.

LosPollos affiliates, often leveraging hacked WordPress sites, are armed with “smartlinks” that shunt unsuspecting users directly into the VexTrio TDS.

From there, traffic is distributed to a rogue’s gallery of online misdeeds: dating services, sweepstakes, bait-and-switch apps, financial scams, and outright malware downloads.

Each click, each unwitting victim, earns the affiliate a small commission, fueling the illicit engine.

TacoLoco, meanwhile, perfected a particularly insidious trick: deceiving users into enabling browser push notifications.

Their method is a masterclass in psychological manipulation, disguising notification requests as CAPTCHA challenges – those ubiquitous tests designed to distinguish humans from bots.

For years, VexTrio and its partners have successfully tricked countless users into opting in, transforming their devices into conduits for a relentless barrage of phony virus alerts and misleading pop-up messages.

The sheer scale of this deception is staggering: GoDaddy’s 2024 annual report revealed that nearly 40 percent of compromised websites redirected visitors to VexTrio via LosPollos smartlinks.

The corporate veil behind these operations began to fray.

Qurium’s research pointed to Adspro Group, a company registered in the Czech Republic and Russia, operating LosPollos and TacoLoco’s infrastructure through Swiss hosting providers C41 and Teknology SA.

Further investigation peeled back the layers to reveal Giulio Vitorrio Leonardo Cerutti, the owner of Teknology SA, and the CEO of Holacode, the company that developed LosPollos and TacoLoco.

Holacode even marketed a VPN service called “Spamshield,” ironically claiming to block unwanted push notifications.

Infoblox, another security firm, tested “Spamshield” only to find it hid notifications for 24 hours before demanding payment – a cynical twist that underscores the pervasive deception.

When confronted with these findings, Cerutti vehemently denied any association with VexTrio, claiming his companies operate strictly within regulations and are transparent.

“We are a group operating in the advertising and marketing space, with an affiliate network program,” he stated, adding, “I strongly declare we have no connection with VexTrio at all.”

He even suggested his companies were victims of “publisher fraud” and “sketchy traffic.”

Such a defense, coming from the nexus of an operation implicated in widespread deception and disinformation, rings hollow, especially given Cerutti’s pre-emptive legal threat to one journalist who had merely been tagged in an industry post about VexTrio.

This aggressive posture speaks volumes about the lengths to which these entities will go to protect their lucrative, illicit enterprises.

The exposure, however, did have an immediate, if temporary, impact.

Just four days after Qurium published its findings, LosPollos announced the suspension of its push monetization service.

Less than a month later, Adspro rebranded itself as Aimed Global.

But this is the nature of the beast: a constant game of whack-a-mole.

Malware strains like DollyWay, which had consistently directed victims to VexTrio for eight years, simply pivoted overnight to another TDS called Help TDS.

This suggests a deep, symbiotic relationship, with Infoblox’s analysis revealing Help TDS’s long-standing, exclusive ties to VexTrio and its connections to at least four other Russian-based push monetization programs like Partners House, BroPush, RichAds, and RexPush.

While overt common ownership remains elusive, the pattern of traffic redirection and the shared Russian nexus paint a clear picture of a tightly knit, if decentralized, criminal ecosystem.

Renee Burton, vice president of threat intelligence at Infoblox, argues forcefully against the prevailing industry view that these deceptive adtech methods occupy a “legally grey area” and pose only minor threats like adware.

“These TDSs are a nefarious threat,” Burton insists, “because they’re the ones you can connect to the delivery of things like information stealers and scams that cost consumers billions of dollars a year.”

Her stark conclusion leaves little room for ambiguity: “From a larger strategic perspective, my takeaway is that Russian organized crime has control of malicious adtech, and these are just some of the many groups involved.”

This is not merely a nuisance; it is a critical component of a global criminal enterprise, with tentacles reaching into state-sponsored influence operations.

For the average internet user, the takeaway is clear: vigilance is paramount.

Be exceedingly sparing in approving website notifications.

While many are benign, countless dodgy firms are paying site owners to install their notification scripts, then reselling that communication pathway to an endless stream of scammers and online hucksters.

Major browsers offer robust controls to manage or block these requests entirely, either across the board or on a per-website basis.

Taking a few minutes to adjust these settings in Firefox, Chrome, or Safari can save untold headaches down the road, acting as a small but crucial defense against a sophisticated, shadowy empire that thrives on deception and thrives on the unwitting clicks of millions.

The digital underworld is more integrated and dangerous than ever, and understanding its hidden mechanisms is the first step toward self-preservation.

Author

  • LNGFRM Team

    Frank DiBernardo handles LNGFRM's Foodie and Miscellaneous writing tasks. He's always getting ideas from users, so don't be afraid to send an email to the editor.

Daily Newsletter
Subscribe to our Newletter!
You May Also Like

Mohit Bansal: On Zero-Headcount Security Scaling

Mohit Bansal’s approach to security engineering at Webflow rests on a deceptively simple reframe: treating fixed headcount not as a limitation to work around but as a firm design constraint that shapes every architectural decision, from how vulnerabilities get prioritized to how vendor risk gets automated away. His core discipline is pragmatic sequencing over theoretical perfection—getting 80 percent coverage on five critical risks rather than chasing 100 percent on two—paired with a relentless drive to automate repetitive data-gathering so a fixed team can spend its limited human judgment on the problems that actually require it.

By Mike Malone
Published June 30, 2026
© 2026 LNGFRM. All rights reserved.