Infoblox Threat Intel
Vane Viper
Vane Viper is a malicious adtech ecosystem built around Cyprus-based, Russian nexus AdTech Holdings and its subsidiaries, including its flagship platform PropellerAds.
The group leverages push notifications to maintain persistence on devices and uses a TDS as a malvertising funnel to deliver a range of threats.
Its operations rely on tactics such as back-button hijacking, distribution of malicious Android Package Kit (APK) files, and bulk domain registrations that enable rapid domain churn. Vane Viper’s infrastructure is consistently hosted on networks that are perpetually abused.
Vane Viper
- Operating since: At least 2013
- Infoblox discovered: March 2022
- Infoblox published: September 2025
- Prevalence: Very common
