Skip to content

Balada

Balada is a website injection campaign observed on compromised WordPress sites.

Profile source: Mallory opens in a new tab

Balada

Family profile

Balada is a website injection campaign observed on compromised WordPress sites. It is referenced alongside DollyWay and Sign1 as one of several malicious injections used to redirect victim traffic through the VexTrio traffic distribution system (TDS) ecosystem. High-confidence reporting indicates these compromises involved injected malicious scripts and, in related WordPress compromise activity, DNS TXT record-based command-and-control mechanisms that encoded redirect URLs. Balada-linked redirections were associated first with VexTrio infrastructure, including Los Pollos smartlinks, and later with Help TDS after disruption to Los Pollos in November 2024. The broader ecosystem uses compromised websites at scale, fake CAPTCHA and push-notification lures, server-side redirects, and malicious adtech infrastructure to deliver scams and malware. Balada is therefore associated with large-scale website compromise and traffic monetization operations tied to the VexTrio ecosystem, which has strong Russian-connected hosting and domain-registration links. The provided content does not include family-specific file-based IOCs for Balada beyond its identification as a named website injection campaign used in these redirection chains.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 9, 2026
Last activity
Aug 9, 2026
Feed role
C2
Host form
0 IP / 184 hostnames

Leading locations

  • US180

Leading providers

  • DigitalOcean, LLC180

Infrastructure traits

  • Hosting 180

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.