No Hoodies Here: Organized Crime in AdTech
Black Hat USA 2025 · Day 1 · Briefings
Overview
Infoblox researchers unmasked Vextrio — the internet's most prolific malicious traffic distribution network — as a multi-year organized crime operation run by Italian and Eastern European principals operating out of Lugano, Switzerland. Using only open-source intelligence, they traced roughly a hundred shell companies across multiple continents to a handful of identifiable individuals who own professional race teams, fly private jets to Coldplay concerts, and take stratosphere flights — all funded by a trillion-dollar scam-as-a-service ecosystem hiding in plain sight inside the legitimate advertising industry. ---

Key moments
- 4:00 Vextrio TDS: 40% of all compromised WordPress sites redirected through it in 2024
- 4:29 Vextrio now reaches top 10,000 domains in 30-45 days, down from 6 months previously
- 5:59 Los Pollos affiliate platform found via single video frame with tracked URL pattern
- 7:59 Breaking Bad-themed Los Pollos openly advertised malicious affiliate marketing on YouTube
- 12:00 Investigators linked Vextrio, Los Pollos, and related firms via passive DNS to Swiss /24
- 15:59 Italian organized crime connection: key figures traceable through Lugano holding companies
- 22:00 Eastern European operation: Russian/Belarusian principals tracked via LinkedIn boasting
- 28:00 Monetization: victims enrolled in subscriptions paying up to $120/lead to the criminals
No Hoodies Here: Organized Crime in AdTech
Speakers: Dave Mitchell, VP of Security Research, Infoblox; Renee Burton, VP of Threat Intelligence, Infoblox (Chris Kim, Infoblox, contributed to the research)
Conference: Black Hat USA 2025 — August 6-7, 2025, Mandalay Bay, Las Vegas
YouTube: https://www.youtube.com/watch?v=o7jlWJ8_Xuc
Reading time: ~10 minutes
Type: Briefing
TL;DR
Infoblox researchers unmasked Vextrio — the internet's most prolific malicious traffic distribution network — as a multi-year organized crime operation run by Italian and Eastern European principals operating out of Lugano, Switzerland. Using only open-source intelligence, they traced roughly a hundred shell companies across multiple continents to a handful of identifiable individuals who own professional race teams, fly private jets to Coldplay concerts, and take stratosphere flights — all funded by a trillion-dollar scam-as-a-service ecosystem hiding in plain sight inside the legitimate advertising industry.
Introduction
The cybersecurity industry loves a hacker in a hoodie. But the most prolific cybercrime infrastructure operation on the internet turns out to look more like a holding company in Lugano than a basement in Eastern Europe. Infoblox researchers Dave Mitchell and Renee Burton spent years pulling the threads of a network known as Vextrio — a traffic distribution system (TDS) that, in 2024 alone, was responsible for redirecting 40 percent of all compromised websites, particularly WordPress sites, into its infrastructure. Their findings, presented at Black Hat USA 2025 alongside research by colleague Chris Kim, reveal a sprawling, professionally run criminal enterprise that has learned to hide in the chaos of legitimate ad tech.
The talk matters because the security industry has systematically under-investigated this class of threat. When analysts follow a compromised website redirect to a scam page or a malware drop, they typically focus on the payload. Vextrio and its associated network represent the invisible middle layer — the commercial-grade ad routing infrastructure that delivers those payloads to hundreds of millions of users while maintaining plausible deniability as an advertising network.
The Vextrio TDS: Infrastructure as a Criminal Service
Vextrio operates on the same basic model as legitimate ad technology. It profiles incoming users — checking IP address, user agent, country of origin, and prior visit history — and routes them to content accordingly. The difference is what that content is: fake antivirus downloads, phishing pages, subscription scams, and investment fraud.
▶ Watch: How Vextrio TDS Works (04:00)
The scale is staggering. Vextrio appears in more than half of Infoblox's customer networks through its Protective DNS platform, and the organization has reached the top 10,000 most popular domains on the internet in under 30 to 45 days — a process that previously took six months. It has established peering relationships with other TDS operations (the researchers draw an explicit analogy to network peering), interoperating with entities like Sokaolish, ClearFake, and Dolly Way. The Dolly Way connection is particularly notable: GoDaddy researcher Dennis has separately documented it as one of the primary malware strains that infects WordPress sites and feeds traffic into Vextrio's system.
The breakthrough that began unraveling the true identity of the organization came from an unexpected source: a YouTube video. An investigative journalist named Tord, working with Infoblox in Europe, found a video from a Russian-speaking man promoting an affiliate marketing program. A single frame containing a domain name — and crucially, a URL format using the pattern ?u= and o= query parameters — matched patterns the team had tracked for years.
Los Pollos, AdsPro, and the Web of Shell Companies
That YouTube video pointed to an affiliate network called Los Pollos — named, apparently without irony, after the front business in Breaking Bad. Los Pollos pushed "smart links" (short links for ad delivery) and had partnerships with entities including Ashley Madison and Propeller Ads, plus several others that turned out to be related companies.
▶ Watch: Unmasking Los Pollos and AdsPro (08:00)
Among those related entities was a push notification platform called Taco Loco, and a company called AdsPro — a rebranded entity that Infoblox believes has changed names two or three times since the researchers first identified it. Each rebranding follows a publication from Infoblox. The company maintains the same webpage template and tends to use the same data centers, making it easy to track despite the name changes. IP address analysis of the Los Pollos ecosystem revealed that a single IP served as the mail server for all related domains, including some not listed publicly — and all roads led to AdsPro.
Underneath AdsPro sits a web of approximately a hundred companies that Infoblox has catalogued. These include energy companies, crypto companies, payment processors, mail systems, a ski resort, a restaurant, a cosmetic shop, and a construction firm — all operating from the same autonomous system numbers that are 98 percent Vextrio traffic. The researchers discovered these ostensibly unrelated businesses are all owned by the same principals.
Doxing an Organized Crime Syndicate
The bulk of the presentation belongs to Renee Burton, who describes what she calls "the doxing part" — the process of identifying the actual human beings behind the operation using entirely open-source methods: social media, business transparency records, App Store terms and conditions, and "a lot of clever searching."
▶ Watch: The Origin Story — Italian and Eastern European Groups (12:00)
The enterprise splits into two groups. The Italian contingent traces back to the Turin region and can be dated to approximately 2004, when they were running dating scams and spam operations that generated lawsuits in the mid-2000s, 2010, and 2012. Key figures include Marco Ruffo, whose name appears on domain registrations that were subjects of those lawsuits, and two others — Julio Cerutti, a finance-trained executive from the London School of Economics who joined around 2015, and another Julio who remained in Turin. Two of the original Italians formed a company called Tecca around 2012, positioning themselves as leaders in mobile development. Around 2015, the Lugano, Switzerland migration began, bringing a sudden proliferation of new micro-businesses expanding into South America and the Middle East.
The Eastern European group consists of four to five key figures: primarily Russians and Belarusians, plus one Bulgarian-Canadian who serves as the public face. The Bulgarian-Canadian is the declared co-founder and CEO of Los Pollos and AdsPro and is conspicuously active on social media. The actual leadership, however, appears to be Russian and Belarusian. One individual — Igor — is described as a sophisticated computer engineer. The convergence of the Italian and Eastern European groups happens around 2020, when multiple company headquarters relocated to Lugano, effectively merging the two operations.
▶ Watch: The Merger — How the Groups Converged in Lugano (14:01)
A key OSINT technique the team used was cross-referencing social media posts: the same car appeared in posts by different individuals just days apart, with one post explicitly tagging the others by name. That confirmed a personal relationship between the Bulgarian frontman and the Russian technical operators. License plate analysis of a car belonging to a Belarusian individual named Kunitsa provided additional confirmation.
Blank Credit Card Offers, Fake VPNs, and the Full Scam Stack
Beyond the traffic distribution infrastructure, Infoblox's ten months of additional research uncovered two major revenue streams previously unknown:
Blank credit card submit offers. Referenced on Black Hat World forums as a top offering from Ad Trafico — a Vextrio company owned by the Eastern Europeans and Cerutti — "blank CC offers" provide affiliates with fake credit card templates. A publisher places an ad promising a free iPhone for $1.99 shipping. The user submits their real credit card number. The payment processor, also controlled by the same group, automatically enrolls the victim in a subscription model. Payouts to publishers run up to $120 per "lead." One Russian-language blog advertising Ad Trafico for this purpose was cleaned of all mentions immediately after Infoblox published on the topic.
▶ Watch: Blank CC Offers and Fake Apps (28:02)
Fake apps. Running for at least seven to eight years across Google Play and the Apple App Store, the group publishes fake VPNs (actually residential proxies) and fake ad-blocking apps. One particularly elegant scheme involves an app that requests device permissions, disables browser notifications, then shows users a fake screen of "blocked" notifications. After 24 hours, it reverts to displaying all notifications again and charges $6.99 per week to maintain the blocked state.
The lifestyle evidence the researchers accumulated is equally striking: private jet flights to concerts, stratosphere flights in Russian military aircraft (Crown Vasiliev's YouTube channel documents this), Alpine ski trips, and a professional racing team. Ski Fry, a ski resort, is attributed to Cerutti.
Notable Quotes
"We have not yet found a non-Russian-speaking commercial traffic distribution system. Not one. And we've studied a lot." — Renee Burton ▶ 32:02
"Scamming is a trillion-dollar business, and this kind of business is paying for private jets to Coldplay concerts." — Renee Burton ▶ 32:02
"Is it legal? Absolutely fucking not. That's not from me. That's from the blog advertising Ad Trafico." — Renee Burton ▶ 28:02
"Pretty much everything we dig into that we thought before was hackers in hoodies is actually commercial ad tech, and it's actually Russian." — Renee Burton ▶ 32:02
Key Takeaways
- Malicious ad tech is a structured criminal industry, not a hacker operation. Vextrio and its related companies operate with HR departments, public LinkedIn profiles, business transparency filings, and corporate structures across multiple jurisdictions.
- Don't trust the Internet Archive as an evidence repository. Domain owners can force takedowns. Use Archive.today for preservation; always screenshot with the URL visible. Brian Krebs confirmed this lesson.
- The CVSS of scam infrastructure is your own attention. Security practitioners focus disproportionately on malware and reverse engineering while scam-as-a-service operations generating more economic damage go under-examined.
- Traffic distribution systems are the invisible layer. When following a redirect chain, the TDS sitting between the compromised site and the final payload deserves its own investigation — it may reveal a sophisticated criminal organization.
- OSINT from publicly available records can unmask major criminal operations. Business transparency registries, App Store terms and conditions, social media cross-referencing, and domain/IP relationship mapping produced enough evidence to identify approximately a hundred companies and their key principals.
No slides PDF was listed for this talk.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Infoblox spent years tracing a trillion-dollar scam-as-a-service empire — Vextrio, 40% of compromised WordPress redirects in 2024 — back to Italian dating scammers from 2004, Eastern European technical operators, and a Lugano holding company where everyone apparently owns race teams and takes stratosphere flights. The OSINT methodology is rigorous, the narrative is gripping, and it forces a category reclassification that most of the security industry has been avoiding.
Heather Calloway (CISO) — MUST SEE
Infoblox pulled the thread on what looked like malware infrastructure and found a professionally organized criminal enterprise with shell companies, a ski resort, and a private jet to a Coldplay concert. The governance failure here isn't that the scam exists — it's that the advertising industry's architecture makes it invisible. Every CISO who thinks scam-as-a-service is someone else's problem should watch this.