{"id":10640,"date":"2025-04-22T11:01:42","date_gmt":"2025-04-22T11:01:42","guid":{"rendered":"https:\/\/usaontheweb.com\/clone1\/wordpress-ad-fraud-plugins-generated-1-4-billion-ad-requests-per-day\/"},"modified":"2025-04-22T11:01:42","modified_gmt":"2025-04-22T11:01:42","slug":"wordpress-ad-fraud-plugins-generated-1-4-billion-ad-requests-per-day","status":"publish","type":"post","link":"https:\/\/usaontheweb.com\/clone1\/wordpress-ad-fraud-plugins-generated-1-4-billion-ad-requests-per-day\/","title":{"rendered":"WordPress ad-fraud plugins generated 1.4 billion ad requests per day"},"content":{"rendered":"<p>WordPress <\/p>\n<div>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"Wordpress Monitors\" height=\"900\" src=\"https:\/\/www.bleepstatic.com\/content\/hl-images\/2022\/11\/11\/surveillance-monitors.jpg\" width=\"1600\"><\/p>\n<p>A large-scale ad fraud operation called &#8216;Scallywag&#8217; is monetizing pirating and URL shortening sites through specially crafted WordPress plugins that generate billions of daily fraudulent requests.<\/p>\n<p>Scallywag was uncovered by bot and fraud detection firm HUMAN, which mapped a network of 407 domains supporting the operation that peaked at 1.4 billion fraudulent ad requests per day.<\/p>\n<p>HUMAN&#8217;s efforts to block and report Scallywag traffic have resulted in its\u00a0shrinking by 95%, although the threat actors have shown\u00a0resilience by rotating domains and moving to other monetization models.<\/p>\n<h2>WordPress Built around WordPress ad fraud plugins<\/h2>\n<p>Legitimate ad providers avoid pirating and URL shortening sites due to legal risks, brand safety concerns, ad fraud, and lack of quality content.<\/p>\n<p>Scallywag is a fraud-as-a-service operation built around four WordPress plugins\u00a0that help cybercriminals generate money from risky and low-quality sites.<\/p>\n<p>The WordPress plugins created by the operation are Soralink (released in 2016), Yu Idea (2017), WPSafeLink (2020), and Droplink (2022).<\/p>\n<p>Human says multiple independent threat actors buy and use these WordPress plugins to set up their own ad fraud schemes, with some even posting tutorials on YouTube on how exactly to do it.<\/p>\n<p>&#8220;These extensions lower the barrier to entry for a would-be threat actor who wants to monetize content that wouldn&#8217;t generally be monetizable with advertising; indeed, several threat actors have published videos to coach others on setting up their own schemes,&#8221; explains HUMAN.<\/p>\n<p>Droplink is the only exception to the sales model, as it&#8217;s available for free by performing various money-making steps for the sellers.<\/p>\n<p>Users visiting piracy catalog sites to find movies or premium software click on embedded URL-shortened\u00a0links and are redirected through the operation&#8217;s cashout infrastructure.<\/p>\n<p>Piracy catalog sites that can&#8217;t directly host ads aren&#8217;t necessarily run by Scallywag actors. Instead, their operators form a &#8216;gray partnership&#8217; with ad fraudsters to outsource monetization.<\/p>\n<div>\n<figure><img loading=\"lazy\" decoding=\"async\" alt=\"Wordpress Piracy site (left) linking to Scallywag site (right)\" height=\"600\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2025\/April\/pirate-site.jpg\" width=\"1110\"><figcaption><strong>Piracy site (left) linking to Scallywag site (right)<\/strong><br \/><em>Source: HUMAN<\/em><\/figcaption><\/figure>\n<\/div>\n<p>The redirection process takes the visitor\u00a0through intermediary, ad-heavy pages that generate fraudulent impressions for the Scallywag operators, and end up on a page hosting the promised content (software or movie).<\/p>\n<p>The intermediary sites are WordPress sites running the Scallywag add-ons. Those handle the redirect logic, loading of ads, CAPTCHA, timer, and the cloaking mechanism, which shows a clean blog on ad platform checks.\u200b<\/p>\n<div>\n<figure><img loading=\"lazy\" decoding=\"async\" alt=\"Wordpress Scallywag's operational overview\" height=\"575\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2025\/April\/diagram.jpg\" width=\"1003\"><figcaption><strong>Scallywag&#8217;s operational overview<\/strong><br \/><em>Source: HUMAN<\/em><\/figcaption><\/figure>\n<\/div>\n<h2>WordPress Disrupting Scallywag<\/h2>\n<p>HUMAN detected Scallywag activity by analyzing traffic patterns across their partner network, such as high ad impression volume from seemingly benign WordPress blogs, cloaking behavior, and forced wait times or CAPTCHA interaction before redirection.<\/p>\n<div>\n<figure><img loading=\"lazy\" decoding=\"async\" alt=\"Wordpress Site visited directly (left) and visited through URL-shortener (right)\" height=\"600\" width=\"1020\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2025\/April\/cloaking.jpg\" previous-src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2025\/April\/cloaking.jpg\"><figcaption><strong>Same site visited directly (left) and visited through URL-shortener (right)<\/strong><br \/><em>Source: HUMAN<\/em><\/figcaption><\/figure>\n<\/div>\n<p>Subsequently, it classified the network as fraudulent, working with ad providers to stop the bidding\u00a0on ad requests and cutting Scallywag&#8217;s revenue stream.<\/p>\n<p>In rsponse, the Scallywag actors tried to evade detection using new cashout domains and open redirect chains to hide the real referrer, but HUMAN says they detected and blocked those, too.<\/p>\n<div>\n<figure><img loading=\"lazy\" decoding=\"async\" alt=\"Wordpress Scallywag ad requests over time\" height=\"560\" width=\"1086\" src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2025\/April\/block.jpg\" previous-src=\"https:\/\/www.bleepstatic.com\/images\/news\/u\/1220909\/2025\/April\/block.jpg\"><figcaption><strong>Scallywag ad requests over time<\/strong><br \/><em>Source: HUMAN<\/em><\/figcaption><\/figure>\n<\/div>\n<p>As a result, Scallywag&#8217;s daily ad fraud traffic dropped sharply from 1.4 billion to nearly zero, with many affiliates abandoning the method and moving on to other scams.<\/p>\n<p>Although the Scallywag ecosystem has economically collapsed, its operators will likely continue trying to evade the mitigations and return to profits.<\/p>\n<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>WordPress A large-scale ad fraud operation called &#8216;Scallywag&#8217; is monetizing pirating and URL shortening sites through specially crafted WordPress plugins<\/p>\n","protected":false},"author":7282,"featured_media":10641,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1166],"tags":[],"class_list":["post-10640","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-website"],"_links":{"self":[{"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/posts\/10640","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/users\/7282"}],"replies":[{"embeddable":true,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/comments?post=10640"}],"version-history":[{"count":0,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/posts\/10640\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/media\/10641"}],"wp:attachment":[{"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/media?parent=10640"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/categories?post=10640"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usaontheweb.com\/clone1\/wp-json\/wp\/v2\/tags?post=10640"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}