{"id":169775,"date":"2025-04-03T21:17:53","date_gmt":"2025-04-03T21:17:53","guid":{"rendered":"https:\/\/peraltafinancing.com\/business\/internet-business\/dollyways-eight-year-evolution-from-master134-to-modern-malware-infrastructure\/"},"modified":"2025-04-03T21:17:53","modified_gmt":"2025-04-03T21:17:53","slug":"dollyways-eight-year-evolution-from-master134-to-modern-malware-infrastructure","status":"publish","type":"post","link":"https:\/\/fivemor.com\/?p=169775","title":{"rendered":"DollyWay&#8217;s Eight-Year Evolution: From Master134 to Modern Malware Infrastructure"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<div class=\"wp-block-group article__contained\" style=\"padding-top:var(--wp-spacing-s);padding-bottom:var(--wp-spacing-s);padding-left:var(--wp-spacing-s);padding-right:var(--wp-spacing-s);background-color:var(--c-bg-green-100)\">\n<div class=\"group-content content has-layout-constrained\">\n<h2 id=\"h-key-findings-nbsp\">Key findings\u00a0<\/h2>\n<ul class=\"wp-block-list\">\n<li>The DollyWay World Domination operation evolved through multiple distinct campaign phases since 2016, showing increasing sophistication in both technical capabilities and infrastructure.\u00a0<\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li>Campaign maintained consistent monetization partnerships while advancing evasion and persistence techniques.\u00a0<\/li>\n<\/ul>\n<ul class=\"wp-block-list\">\n<li>Infrastructure evolution demonstrates clear learning patterns, with each iteration building upon previous successful elements.\u00a0\u00a0<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<p>The DollyWay World Domination\u2019s eight-year evolution from simple script injections to sophisticated multi-stage malware provides unique insights into how threat actors adapt and mature their techniques over time. This analysis follows the DollyWay operation&#8217;s development through seven distinct campaigns, revealing how each iteration built upon previous successes while introducing new capabilities.\u00a0<\/p>\n<p>By examining technical artifacts, shared infrastructure components, and consistent monetization patterns across multiple campaign phases, we&#8217;ve reconstructed the DollyWay malware&#8217;s complete operational history \u2014 from its earliest days as Master134 through its current more sophisticated form. This timeline demonstrates how threat actors learn from both successes and failures while maintaining core operational elements that enable long-term campaign tracking.\u00a0<\/p>\n<p><strong>Related posts:<\/strong><\/p>\n<h2 id=\"h-dollyway-world-domination-timeline-nbsp\">DollyWay World Domination timeline\u00a0<\/h2>\n<p>Initially, some of the malware campaigns may seem unrelated, but we managed to link them to the same operators by observing the same ad network affiliate ids in their redirect links, common techniques and shared malware codebase.\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"\" loading=\"lazy\" width=\"1114\" height=\"1322\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-27.png?size=3840x0\"\/><\/figure>\n<\/div>\n<h3 id=\"h-master134-november-2016-2020-nbsp\">Master134 (November 2016 &#8211; 2020)\u00a0<\/h3>\n<p>The earliest identified campaign in this operation was named Master134 after the IP address used in its injections: 134.249.116[.]78 \u00a0<\/p>\n<p>According to CheckPoint research, this campaign compromised over 10,000 sites and redirected visitors through various ad networks including AdsTerra and PropellerAds. \u00a0<\/p>\n<p>While normal ads served by these ad networks are usually legitimate, many ads served to the visitors redirected by the Master134 malware proved to be malicious. <\/p>\n<p>According to the CheckPoint research:\u00a0<\/p>\n<figure class=\"wp-block-pullquote\">\n<blockquote class=\"wp-block-pullquote__blockquote\">\n<p><em>The list of redirection chains includes major players in the Exploit Kit landscape, along with some other malicious sites: Fobos, HookAds, Seamless, BowMan, TorchLie, BlackTDS and Slyip, all redirect to the Rig Exploit Kit. In addition, redirections to Magnitude Exploit Kit, GrandSoft Exploit Kit, FakeFlash and Technical Support Scams can also be found in the list.<\/em>\u00a0<\/p>\n<\/blockquote>\n<p><svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" fill=\"none\" viewbox=\"0 0 32 32\" aria-hidden=\"true\" focusable=\"false\"><path fill=\"currentColor\" d=\"M0 19.987C0 25.744 3.786 29 7.573 29c3.694 0 6.695-3.02 6.695-6.89 0-3.869-2.724-6.983-6.649-6.983h-.23c.6-1.982 2.631-3.964 6.002-5.096V3C6.741 5.407 0 10.503 0 19.987Zm17.732 0c0 5.757 3.786 9.013 7.573 9.013C28.998 29 32 25.98 32 22.11c0-3.869-2.724-6.983-6.65-6.983h-.23c.6-1.982 2.632-3.964 6.003-5.096V3c-6.65 2.407-13.391 7.503-13.391 16.987Z\"\/><\/svg><\/figure>\n<p>We were able to link Master134 to DollyWay when we noticed that in late 2019, started using what we call DisposableTDS (the TDS that used new disposable domains on .tk, .ga, .ml, .cf TLDs every day) that ultimately redirected to LosPollos links using the affiliate ID u=h2xkd0x, which is associated with DollyWay v1 and v2.\u00a0<\/p>\n<p>First seen:<a data-eid=\"publishing.library.dollyway-malware-history.external.link.click\" rel=\"nofollow noopener noreferrer\" data-wpel-link=\"external\" href=\"https:\/\/urlscan.io\/result\/e2e0255a-dc38-41e2-9ad8-166d91c83e97\/#transactions\"> November 30th 2016<\/a> \u00a0<\/p>\n<p>References:\u00a0<\/p>\n<p>Key features:\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li><span>Injected scripts:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li><strong>134.249.116[.]78\/jquery.js<\/strong>\u00a0<\/li>\n<li><strong>134.249.116.78\/index.php<\/strong>\u00a0<\/li>\n<li><strong>134.249.116.78\/?key=<\/strong>\u00a0<\/li>\n<li><strong>134.249.116.78\/cloud.php<\/strong>\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Injection pattern\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>inside legitimate .html, .js and .php files.\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Redirect destinations (changed multiple times):\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li><span>Before November 2019: AdsTerra and PropellerAds links\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>hxxps:\/\/www.hibids10[.]com\/watch?key=7d54252789920db9b4985c857ac11077\u00a0<\/li>\n<li>hxxps:\/\/www.cpm20[.]com\/watch?key=789a4129e78c00008a47b36e23d65ea7\u00a0<\/li>\n<li><a data-eid=\"publishing.library.dollyway-malware-history.external.link.click\" rel=\"nofollow noopener noreferrer\" data-wpel-link=\"external\" href=\"http:\/\/www.cpm10.com\/watch?key=fe0a93971e993f059d7a78bf2fa5117a\">http:\/\/www.cpm10<\/a>[.]com\/watch?key=fe0a93971e993f059d7a78bf2fa5117a\u00a0<\/li>\n<li>hxxps:\/\/onclkds[.]com\/afu.php?zoneid=1157984\u00a0<\/li>\n<li>hxxp:\/\/bestadbid[.]com\/afu.php?zoneid=1462665&amp;var=\u00a0<\/li>\n<li>hxxps:\/\/go.ad2up[.]com\/afu.php?id=979282\u00a0<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li>In 2018, for a short period used the <strong>DisposableTDS<\/strong> URLs with the ?<strong>601491161591<\/strong> parameter that<a data-eid=\"publishing.library.dollyway-malware-history.external.link.click\" rel=\"nofollow noopener noreferrer\" data-wpel-link=\"external\" href=\"https:\/\/urlscan.io\/result\/cf6ca983-17c7-494a-beab-7a33cef96143\/\"> redirected to tech support scam<\/a> pages. It also<a data-eid=\"publishing.library.dollyway-malware-history.external.link.click\" rel=\"nofollow noopener noreferrer\" data-wpel-link=\"external\" href=\"https:\/\/urlscan.io\/result\/a64e1a6f-f1ec-42e3-aca0-31e62c1d15be\/\"> redirected to Gift scam<\/a> pages similar to what LosPollos offers in the Mainstream category.\u00a0<\/li>\n<li><span>After November 2019: <strong>DisposableTDS <\/strong>with the<strong> <\/strong>?<strong>6871568466678<\/strong> redirecting to LosPollos links with the <strong>u=h2xkd0x<\/strong> affiliate id parameter parameter Typical redirect chain:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Infected site\u00a0<\/li>\n<li>\u2192 hxxp:\/\/134.249.116[.]78\/?key=\u00a0<\/li>\n<li>\u2192 hxxp:\/\/134.249.116[.]78\/cloud.php\u00a0<\/li>\n<li>\u2192 hxxp:\/\/<disposable-domain>.tk\/index\/?6871568466678\u00a0<\/disposable-domain><\/li>\n<li>\u2192 hxxp:\/\/<lospollos-domain>\/?u=h2xkd0x<\/lospollos-domain><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3 id=\"h-fake-browser-updates-september-2018-2019-nbsp\">Fake Browser Updates (September 2018 &#8211; 2019)\u00a0<\/h3>\n<p>This campaign marked a tactical shift, focusing on malicious downloads disguised as browser updates. The malware was distributed through compromised third-party sites, typically injecting update.js scripts into various website directories.\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"\" loading=\"lazy\" width=\"1429\" height=\"666\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-30.png?size=3840x0\"\/><\/figure>\n<\/div>\n<p><strong>First seen:<\/strong><a data-eid=\"publishing.library.dollyway-malware-history.external.link.click\" rel=\"nofollow noopener noreferrer\" data-wpel-link=\"external\" href=\"https:\/\/urlscan.io\/result\/399e2a9b-687f-496e-b0ed-b663fff67272\/\"> September 14th 2018<\/a>\u00a0<\/p>\n<p><strong>References:<\/strong>\u00a0<\/p>\n<p><strong>Key features:<\/strong>\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li>Malware distribution via compromised third-party sites\u00a0<\/li>\n<li><span>Injection patterns:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Malware added into local .js files \u00a0<\/li>\n<li><span>Injected as an external <strong>update.js<\/strong> script hosted on compromised third-party sites\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>hxxps:\/\/[redacted]\/wp-content\/themes\/wibeee\/assets\/css\/update.js\u00a0<\/li>\n<li>hxxp:\/\/[redacted]\/wp-admin\/css\/colors\/blue\/update.js\u00a0<\/li>\n<li>hxxp:\/\/[redacted]\/templates\/shaper_newsplus\/js\/update.js\u00a0<\/li>\n<li>hxxp:\/\/[redacted]\/images\/stories\/virtuemart\/product\/resized\/thumb_01\/update.js\u00a0<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li><span>Malicious downloads hosted on compromised third-party sites\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>hxxp:\/\/[redacted]\/.well-known\/acme-challenge\/update_2018_02.browser-components.zip\u00a0<\/li>\n<li>hxxp:\/\/[redacted]\/templates\/shaper_newsplus\/js\/update_2018_01.exe\u00a0<\/li>\n<li>hxxp:\/\/[redacted]\/templates\/ja_edenite\/admin\/update_2018_02.browser-components.zip\u00a0<\/li>\n<li>hxxp:\/\/[redacted]\/templates\/beez_20\/images\/_notes\/update_2019_02.browser-components.zip\u00a0<\/li>\n<li>hxxp:\/\/[redacted]\/templates\/beez_20\/images\/_notes\/update_2019_02.apk\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Tracked via HiStats counters:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>ID: 4209412\u00a0<\/li>\n<li>ID: 4214393\u00a0<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3 id=\"h-adsurl-campaign-2019-nbsp\">AdsUrl Campaign (2019)\u00a0<\/h3>\n<p>In 2019 the Fake Browser Update campaign evolved to first add Android downloads, then complemented the code with redirects to scam sites, and finally malicious downloads were dropped completely in favor of scam redirects. This later iteration of this campaign is referred to as AdsUrl. It can be considered as a direct predecessor to the <strong>DollyWay<\/strong> campaign.\u00a0<\/p>\n<p>At its peak, PublicWWW detected over 1,500 infected sites using this infrastructure model. The campaign maintained connections to previous operations through shared tracking IDs and similar monetization methods.\u00a0<\/p>\n<p><strong>First seen:<\/strong><a data-eid=\"publishing.library.dollyway-malware-history.external.link.click\" rel=\"nofollow noopener noreferrer\" data-wpel-link=\"external\" href=\"https:\/\/urlscan.io\/result\/fc1785f4-03d0-4c36-b5d1-3412ccad2576\/#transactions\"> February 22, 2019<\/a>\u00a0<\/p>\n<p><strong>Key Features:<\/strong>\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li><span>Injection pattern:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Obfuscated JavaScript and HiStats tracker injected into footer.php files of WordPress themes.\u00a0<\/li>\n<li>The injection uses a basic \u201c<strong>eval(function(p,a,c,k,e,d){&#8230;<\/strong>\u201d obfuscation\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Distributed TDS hosted on compromised sites\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>The redirect URLs are obtained from two random TDS nodes ((defined as sAdsUrl1 and sAdsUrl2 \u2014 hence the name of the campaign) \u00a0<\/li>\n<li><span>The TDS node script is always named <strong>r.php and <\/strong> is placed in various subdirectories on compromised sites:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>hxxps:\/\/[redacted]\/wp-admin\/css\/colors\/blue\/r.php\u00a0<\/li>\n<li>hxxps:\/\/[redacted]\/wp-content\/themes\/basis\/css\/r.php\u00a0<\/li>\n<li>hxxps:\/\/[redacted]\/wp-content\/themes\/dt-the7\/woocommerce\/cart\/r.php\u00a0<\/li>\n<li>hxxps:\/\/[redacted]\/wp-content\/themes\/envision\/bbpress\/r.php\u00a0<\/li>\n<li>hxxps:\/\/[redacted]\/wp-content\/themes\/flatsome\/inc\/admin\/advanced\/assets\/css\/r.php\u00a0<\/li>\n<li>hxxps:\/\/[redacted]\/wp-content\/themes\/outliner\/admin\/css\/r.php\u00a0<\/li>\n<li>hxxps:\/\/[redacted]\/wp-content\/themes\/symetrio-theme\/.idea\/r.php\u00a0<\/li>\n<li>hxxps:\/\/[redacted]\/wp-includes\/ID3\/r.php\u00a0<\/li>\n<li>hxxps:\/\/[redacted]\/scanshell\/r.php\u00a0<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li><span>Redirect destinations:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Before April 2019: DisposableTDS with the 5731550755135 parameter, redirecting to some ad network links with the <strong>?utm_medium=4c23b9fecf7dfd895dfe0da99e857f3bee8e9d42&amp;utm_campaign=808<\/strong> parameters.\u00a0<\/li>\n<li>After April 2019: DisposableTDS with the 5731550755135 parameter, redirecting to LosPollos links with the <strong>u=h2xkd0x<\/strong> affiliate id parameter parameter\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Typical Redirect chain example:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Infected site\u00a0<\/li>\n<li>\u2192 hxxp:\/\/sikopersimoasho[.]ml\/index\/?5731550755135\u00a0<\/li>\n<li>\u2192 hxxp:\/\/co34[.]space\/?u=h2xkd0x&amp;o=lxkgnum\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Maintained same HiStats counter IDs as Fake Browser Update campaign:\u00a0<\/span><\/li>\n<li>Decoded malware example:<\/li>\n<\/ul>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"\" loading=\"lazy\" width=\"1484\" height=\"948\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-28.png?size=3840x0\"\/><\/figure>\n<\/div>\n<h3 id=\"h-dollyway-v1-june-2020-nbsp\">DollyWay v1 (June 2020)\u00a0<\/h3>\n<p>The first known version of DollyWay introduced several core features that would define later iterations. It started using \u201cdolly\u201d in names of variables and settings, utilized a distributed network of TDS scripts hosted on compromised sites <s> <\/s>establishing the foundation for future versions&#8217; infrastructure.\u00a0<\/p>\n<p><strong>First seen:<\/strong><a data-eid=\"publishing.library.dollyway-malware-history.external.link.click\" rel=\"nofollow noopener noreferrer\" data-wpel-link=\"external\" href=\"https:\/\/urlscan.io\/result\/e23b9ed7-58eb-4648-a9b9-f99ad598d21d\/\"><strong> <\/strong>June 16th 2020<\/a>\u00a0<\/p>\n<p><strong>References:<\/strong>\u00a0<\/p>\n<p><strong>Key features:<\/strong>\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li><span>Injection pattern:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Installs a fake Hello Dolly plugin <strong>wp-content\/plugins\/hello\/hello.php<\/strong>\u00a0<\/li>\n<li>Stores settings in WordPress database.\u00a0<\/li>\n<li>Removes the real Hello Dolly plugin and other fake Hello Dolly plugins<\/li>\n<\/ul>\n<\/li>\n<li><span>Distributed TDS hosted on compromised sites\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li><span>The redirect scripts are obtained from 4-5 TDS nodes named <strong>i.php <\/strong>and placed in various WordPress directories:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>\/pwa\/i.php\u00a0<\/li>\n<li>\/images\/i.php\u00a0<\/li>\n<li>\/fileadmin\/i.php\u00a0<\/li>\n<li>\/chamber\/i.php\u00a0<\/li>\n<li>\/extract\/i.php\u00a0<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<li><span>Redirect destinations:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>TDS redirects to DisposableTDS with the <strong>7961591006225<\/strong> parameter, redirecting to LosPollos links with the <strong>u=h2xkd0x<\/strong> affiliate id parameter \u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>VexTrio\/LosPollos integration:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Initial affiliate ID: <strong>u=h2xkd0x<\/strong>\u00a0<\/li>\n<li>Later switched to: <strong>u=7mkpd0d<\/strong>\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Introduction of \u201cDolly Tools\u201d (cpl.php):\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Custom web shell with all typical File Manager features.\u00a0<\/li>\n<li>DollyWay injections\u00a0<\/li>\n<li>WordPress update and maintenance capabilities\u00a0<\/li>\n<li>Removal of 150+ different strains of competing malware.<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3 id=\"h-777traffget-october-2020-nbsp\">777traffget (October 2020)\u00a0<\/h3>\n<p>This campaign shows the evolution of the Master134 campaign when it stopped using the 134.249.116[.]78 server and switched to the 777traffget[.]site instead.. It still used similar injection techniques and the same DisposableTDS with the <strong>6871568466678<\/strong> parameter redirecting to LosPollos links as the late Master134.\u00a0<\/p>\n<p><strong>First seen:<\/strong><a data-eid=\"publishing.library.dollyway-malware-history.external.link.click\" rel=\"nofollow noopener noreferrer\" data-wpel-link=\"external\" href=\"https:\/\/urlscan.io\/result\/70512162-e299-4086-88a1-e486ebffd53c\/#transactions\"> October 8, 2020<\/a>\u00a0<\/p>\n<p><strong>Key Features:<\/strong>\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li><span>Injection pattern:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Injects obfuscated script into JS, HTML and PHP files<\/li>\n<\/ul>\n<\/li>\n<li><span>Redirect destinations:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>TDS redirects to DisposableTDS with the <strong>6871568466678<\/strong> parameter, redirecting to LosPollos links with the <strong>u=h2xkd0x<\/strong> affiliate id parameter \u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Typical redirect chain:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Infected site\u00a0<\/li>\n<li>\u2192 hxxps:\/\/777traffget[.]site\/get.php?key=738dd3a8d3649a9131aafdde64b25464\u00a0<\/li>\n<li>\u2192 hxxps:\/\/diathophyltetigid[.]ga\/index\/?6871568466678\u00a0<\/li>\n<li>\u2192 hxxp:\/\/compensationsa[.]xyz\/?u=h2xkd0x&amp;o=lxkgnum&amp;t=cid:1316\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Performs site \u201cmaintenance\u201d on target websites:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Removes wp-admin\/update-core.php (probably to prevent automatic WordPress updates that may replace infected files)\u00a0<\/li>\n<li>Removes all non-default rules from WordPress .htaccess files (probably to prevent security related features)<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3 id=\"h-dollyway-v2-october-2020-nbsp\">DollyWay v2 (October 2020)\u00a0<\/h3>\n<p>The signature of DollyWay v2 is the \/<strong>wp-content\/count.php<\/strong> URLs of the TDS nodes. Version 2 marked significant technical improvements, introducing new heterogenous injections and a more structured TDS approach. This version established the foundational infrastructure that would be enhanced in v3. \u00a0<\/p>\n<p>The campaign maintained consistent branding \u201cDolly\u201d elements while expanding its technical capabilities, particularly in terms of maintaining persistence and verifying payload integrity.\u00a0<\/p>\n<p>First seen: <a data-eid=\"publishing.library.dollyway-malware-history.external.link.click\" data-wpel-link=\"external\" rel=\"noreferrer noopener nofollow\" target=\"_blank\" href=\"https:\/\/urlscan.io\/result\/43a8afd4-b80e-4753-90f5-38d1bc763be6\/\">October 1st 2020<\/a>\u00a0<\/p>\n<p><strong>References:<\/strong>\u00a0<\/p>\n<p><strong>Key features:<\/strong>\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li><span>Injection pattern:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Heterogenous server-side malware that includes fake plugins compiled from pieces of legitimate plugins and themes with random sprinkles of code that restores and executes the DollyWay PHP code from multiple WordPress options.\u00a0<\/li>\n<li>Stores settings in encoded WordPress options.\u00a0<\/li>\n<li>Creates malicious WordPress admin users\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Distributed C2\/TDS hosted on compromised sites\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Injects 3 externals <strong>\/wp-content\/count.php<\/strong> scripts from random TDS nodes.\u00a0<\/li>\n<li><span>Uses five 13 digit \u201csubs\u201d numbers to pass to the TDS URLs. However, in the current version of the <strong>count.php<\/strong> script this parameter is ignored and the TDS always chooses the \u201cMainstream\u201d category for LosPollos links\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>7911586164333\u00a0<\/li>\n<li>7961591006225\u00a0<\/li>\n<li>8001593090904\u00a0<\/li>\n<li>8131599557550\u00a0<\/li>\n<li>7531575880767\u00a0<\/li>\n<\/ul>\n<\/li>\n<li>Infected sites regularly update the list of TDS nodes from <strong>wp-contents\/data.txt<\/strong>. This file is shared with Dolly Way v3.\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Redirect destinations:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Before September 2021: TDS redirects to DisposableTDS with the parameters that match DollyWay subs, passed to the TDS scripts. They redirect to LosPollos links with the <strong>u=h2xkd0x<\/strong> affiliate id parameter.\u00a0<\/li>\n<li>After September 2021: LosPollos links with the affiliate <strong>u=7mkpd0d<\/strong> id parameter\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>VexTrio\/LosPollos integration:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Initial affiliate ID: <strong>u=h2xkd0x<\/strong>\u00a0<\/li>\n<li>Later switched to: <strong>u=7mkpd0d<\/strong>\u00a0<\/li>\n<li>LosPollos API key: <strong>ea6ff61a45e946c287ea5f121c4f2e4b<\/strong>\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>\u201cDolly Tools\u201d (cpl.php):\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Custom web shell with all typical File Manager features.\u00a0<\/li>\n<li>DollyWay injections\u00a0<\/li>\n<li>WordPress update and maintenance capabilities\u00a0<\/li>\n<li>Removal of competing malware.\u00a0<\/li>\n<\/ul>\n<\/li>\n<li>Cryptographic verification using public key (same as v3)\u00a0<\/li>\n<\/ul>\n<h3 id=\"h-yuy-redirects-november-2021-nbsp\">_yuy Redirects (November 2021)\u00a0<\/h3>\n<p>Building on techniques from both <strong>Master134<\/strong> and <strong>777traffget<\/strong>, this malware does not use the DisposableTDS, incorporating AdsTerra links directly in the injected code. When deobfuscated, this malware consistently features the <strong>_yuy<\/strong> function to set cookies, which gave the name to the campaign.\u00a0<\/p>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"\" loading=\"lazy\" width=\"1308\" height=\"1190\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/03\/image-26.png?size=3840x0\"\/><figcaption class=\"wp-block-image__caption\">Examples of similarities found in _yuy redirect injections.\u00a0<\/figcaption><\/figure>\n<\/div>\n<p><strong>First seen:<\/strong> <a data-eid=\"publishing.library.dollyway-malware-history.external.link.click\" data-wpel-link=\"external\" rel=\"noreferrer noopener nofollow\" target=\"_blank\" href=\"https:\/\/urlscan.io\/result\/4f9472ef-8b9c-451c-8f44-8d037deffa60\/#transactions\">November 28, 2021<\/a>\u00a0<\/p>\n<p><strong>Key features:<\/strong>\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li><span>Infection pattern: \u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Injects obfuscated code into legitimate .js and .php files\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Redirect destinations:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li><span>AdsTerra links\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>hxxps:\/\/www.effectivecpmgate[.]com\/ciandu5h?key=51cd90fcb960fabc605cb3c5aa8b2f72\u00a0<\/li>\n<li>hxxps:\/\/www.effectivecpmcontent[.]com\/ciandu5h?key=51cd90fcb960fabc605cb3c5aa8b2f72\u00a0<\/li>\n<li>hxxps:\/\/www.trustedcpmrevenue[.]com\/i67ipuic95?key=3349d3171349d37ef88a5515968a0e17\u00a0<\/li>\n<li><span>hxxp:\/\/176.113.115[.]10\/set.php TDS\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>This IP is associated with malicious downloads and<a data-eid=\"publishing.library.dollyway-malware-history.external.link.click\" rel=\"nofollow noopener noreferrer\" data-wpel-link=\"external\" href=\"https:\/\/www.esentire.com\/blog\/esentire-threat-intelligence-malware-analysis-batloader\"> Redline C2<\/a>\u00a0<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3 id=\"h-dollyway-v3-may-2022-present-nbsp\">DollyWay v3 (May 2022 &#8211; Present)\u00a0<\/h3>\n<p>The signature of <a data-eid=\"publishing.library.dollyway-malware-history.internalblog.link.click\" data-wpel-link=\"internal\" rel=\"noreferrer noopener follow\" target=\"_blank\" href=\"https:\/\/www.godaddy.com\/resources\/news\/dollyway-world-domination\">DollyWay v3<\/a> is the \/<strong>wp-content\/counts.php<\/strong> URLs of the TDS nodes. This current iteration represents the most sophisticated version, implementing a four-stage injection process and enhanced evasion techniques. It maintains the core infrastructure elements of v2 while adding significant improvements to persistence and evasion capabilities. <\/p>\n<p>This version demonstrates sophistication in its reinfection mechanisms and its ability to maintain persistence across WordPress installations. The malware operators added injection of WPCode snippets and a never-ending reinfection cycle, while maintaining previously successful techniques.\u00a0<\/p>\n<p>The earlier iterations of Dolly Way v3 resembled Dolly Way v2 in the way that the malicious server-side code worked. A thorough description of that earlier iteration can be found in Martin Haunschmid\u2019s post from 2022: <a data-eid=\"publishing.library.dollyway-malware-history.external.link.click\" data-wpel-link=\"external\" rel=\"noreferrer noopener nofollow\" target=\"_blank\" href=\"https:\/\/martinhaunschmid.com\/dollyrat-sophisticated-wordpress-malware\">DollyRAT: Sophisticated WordPress RAT<\/a>\u00a0<\/p>\n<p><strong>First seen:<\/strong><a data-eid=\"publishing.library.dollyway-malware-history.external.link.click\" rel=\"nofollow noopener noreferrer\" data-wpel-link=\"external\" href=\"https:\/\/urlscan.io\/result\/aac080dc-f7c0-4a11-87ea-3f52fae6e702\/\"><strong> <\/strong>May 23rd 2022 <\/a>\u00a0<\/p>\n<p><strong>Key features:<\/strong>\u00a0<\/p>\n<ul class=\"wp-block-list\">\n<li><span>Infection pattern:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Infects all active plugins\u00a0<\/li>\n<li>Creates malicious WPCode PHP snippets\u00a0<\/li>\n<li>Automatically reofbuscates malware and reinfects all active plugins and WPCode snippets on every WordPress page load.\u00a0<\/li>\n<li>Stores settings in encoded WordPress options.\u00a0<\/li>\n<li><span>Earlier variations:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Use the same pseudo-legitimate WordPress plugins as DollyWay v2.\u00a0<\/li>\n<li>Store pieces of malicious code in WordPress options.\u00a0<\/li>\n<li>In 2023, pseudo-legitimate plugins were replaced by small fake plugins in the wp-content\/mu-plugins\/ directory that contained condensed malicious code similar to the pseudo-legitimate WordPress plugins of the previous iteration.\u00a0<\/li>\n<\/ul>\n<\/li>\n<li>Creates malicious WordPress admin users\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Four-stage malicious script injection chain for enhanced evasion. \u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>The third stage of the injection dynamically loads scripts from 3 random TDS nodes.\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Distributed C2\/TDS hosted on compromised sites\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>All TDS node scripts share the <strong>\/wp-content\/counts.php<\/strong> path.\u00a0<\/li>\n<li>V3 TDS URLs contain the <strong>?cat<\/strong> parameter to choose a LosPollos category and the <strong>&amp;t <\/strong>parameter that reports the encrypted domain of the infected site.\u00a0<\/li>\n<li>Infected sites regularly update the list of TDS nodes from <strong>wp-contents\/data.txt<\/strong>. This file is shared with Dolly Way v2.\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Redirect destination:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Before November 19, 2024: LosPollos links with the affiliate <strong>u=7mkpd0d<\/strong> id parameter\u00a0<\/li>\n<li>After November 19, 2024: New TDS with a URL structure and choice of TLDs resembling the DisposalTDS, but with less frequent rotation of the second level domains. hxxps:\/\/<subdomain>.participates[.]cfd\/help\/?<strong>11341608982415<\/strong>&amp;sub_id_1\u00a0<\/subdomain><\/li>\n<\/ul>\n<\/li>\n<li><span>VexTrio\/LosPollos integration:\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>Affiliate ID: <strong>u=7mkpd0d<\/strong>\u00a0<\/li>\n<li>LosPollos API key: <strong>ea6ff61a45e946c287ea5f121c4f2e4b<\/strong>\u00a0<\/li>\n<\/ul>\n<\/li>\n<li><span>Cryptographic verification using public key (same as v2)\u00a0<\/span>\n<ul class=\"wp-block-list\">\n<li>\u201cDolly Tools\u201d (cpl.php):\u00a0<\/li>\n<li>Custom web shell with all typical File Manager features.\u00a0<\/li>\n<li>DollyWay injections\u00a0<\/li>\n<li>WordPress update and maintenance capabilities\u00a0<\/li>\n<li>Removal of competing malware\u00a0<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2 id=\"h-dollyway-world-domination-links-between-campaigns\">DollyWay World Domination: Links between campaigns<\/h2>\n<div class=\"wp-block-image__wrapper\">\n<figure class=\"wp-block-image size-full\"><img alt=\"DollyWay World Domination: Links between campaigns\" loading=\"lazy\" width=\"1414\" height=\"929\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" sizes=\"auto, (min-width: 1256px) 1200px, calc(100vw - 2.5rem)\" srcset=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=16x0 16w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=32x0 32w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=48x0 48w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=64x0 64w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=96x0 96w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=128x0 128w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=256x0 256w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=392x0 392w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=640x0 640w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=750x0 750w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=828x0 828w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=1080x0 1080w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=1248x0 1248w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=1920x0 1920w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=2048x0 2048w, https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=3840x0 3840w\" src=\"https:\/\/www.godaddy.com\/resources\/wp-content\/uploads\/2025\/04\/dollyway_links_between_campaigns-1.jpg?size=3840x0\"\/><\/figure>\n<\/div>\n<h2 id=\"h-conclusion-nbsp\">Conclusion\u00a0<\/h2>\n<p>DollyWay&#8217;s evolution from Master134 to its current form demonstrates a consistent pattern of technical advancement. Each iteration introduced new capabilities while preserving proven techniques, resulting in increasingly sophisticated and resilient malware infrastructure.\u00a0<\/p>\n<p>The operation&#8217;s ability to maintain monetization partnerships while advancing their technical capabilities suggests a well-organized team with clear strategic objectives. Their recent forced transition away from LosPollos represents just the latest adaptation in an eight-year pattern of tactical shifts in response to changing circumstances.\u00a0<\/p>\n<p>As the operation continues to adapt, we expect to see further innovations building upon their established pattern of incorporating successful elements from previous campaigns while introducing new evasion and persistence techniques.\u00a0<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Key findings\u00a0 The DollyWay World Domination operation evolved through multiple distinct campaign phases since 2016, showing increasing sophistication in both technical capabilities and infrastructure.\u00a0 Campaign maintained consistent monetization partnerships while advancing evasion and persistence techniques.\u00a0 Infrastructure evolution demonstrates clear learning patterns, with each iteration building upon previous successful elements.\u00a0\u00a0 The DollyWay World Domination\u2019s eight-year evolution [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":169776,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[95],"tags":[68063,68064,7471,59739,13439,22198,68065,1434],"dealstore":[],"offerexpiration":[],"class_list":["post-169775","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-internet-business","tag-dollyways","tag-eightyear","tag-evolution","tag-infosec","tag-infrastructure","tag-malware","tag-master134","tag-modern"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>DollyWay&#039;s Eight-Year Evolution: From Master134 to Modern Malware Infrastructure - Som2ny Network<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/fivemor.com\/?p=169775\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DollyWay&#039;s Eight-Year Evolution: From Master134 to Modern Malware Infrastructure - Som2ny Network\" \/>\n<meta property=\"og:description\" content=\"Key findings\u00a0 The DollyWay World Domination operation evolved through multiple distinct campaign phases since 2016, showing increasing sophistication in both technical capabilities and infrastructure.\u00a0 Campaign maintained consistent monetization partnerships while advancing evasion and persistence techniques.\u00a0 Infrastructure evolution demonstrates clear learning patterns, with each iteration building upon previous successful elements.\u00a0\u00a0 The DollyWay World Domination\u2019s eight-year evolution [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/fivemor.com\/?p=169775\" \/>\n<meta property=\"og:site_name\" content=\"Som2ny Network\" \/>\n<meta property=\"article:published_time\" content=\"2025-04-03T21:17:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/04\/dollyway.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1737\" \/>\n\t<meta property=\"og:image:height\" content=\"1327\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"admin\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"admin\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"12 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/fivemor.com\/?p=169775#article\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/?p=169775\"},\"author\":{\"name\":\"admin\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\"},\"headline\":\"DollyWay&#8217;s Eight-Year Evolution: From Master134 to Modern Malware Infrastructure\",\"datePublished\":\"2025-04-03T21:17:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=169775\"},\"wordCount\":2345,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=169775#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/04\/dollyway.jpg\",\"keywords\":[\"DollyWays\",\"EightYear\",\"evolution\",\"InfoSec\",\"Infrastructure\",\"Malware\",\"Master134\",\"Modern\"],\"articleSection\":[\"Internet Business\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/fivemor.com\/?p=169775#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/fivemor.com\/?p=169775\",\"url\":\"https:\/\/fivemor.com\/?p=169775\",\"name\":\"DollyWay's Eight-Year Evolution: From Master134 to Modern Malware Infrastructure - Som2ny Network\",\"isPartOf\":{\"@id\":\"https:\/\/fivemor.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/fivemor.com\/?p=169775#primaryimage\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/?p=169775#primaryimage\"},\"thumbnailUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/04\/dollyway.jpg\",\"datePublished\":\"2025-04-03T21:17:53+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/fivemor.com\/?p=169775#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/fivemor.com\/?p=169775\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/?p=169775#primaryimage\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/04\/dollyway.jpg\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/04\/dollyway.jpg\",\"width\":1737,\"height\":1327},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/fivemor.com\/?p=169775#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/fivemor.com\/?bp_activities=1\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DollyWay&#8217;s Eight-Year Evolution: From Master134 to Modern Malware Infrastructure\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/fivemor.com\/#website\",\"url\":\"https:\/\/fivemor.com\/\",\"name\":\"Som2ny Network\",\"description\":\"Daily Deals\",\"publisher\":{\"@id\":\"https:\/\/fivemor.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/fivemor.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/fivemor.com\/#organization\",\"name\":\"Som2ny Network\",\"url\":\"https:\/\/fivemor.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"contentUrl\":\"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png\",\"width\":300,\"height\":86,\"caption\":\"Som2ny Network\"},\"image\":{\"@id\":\"https:\/\/fivemor.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371\",\"name\":\"admin\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/fivemor.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png\",\"caption\":\"admin\"},\"sameAs\":[\"https:\/\/fivemor.com\"],\"url\":\"https:\/\/fivemor.com\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DollyWay's Eight-Year Evolution: From Master134 to Modern Malware Infrastructure - Som2ny Network","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/fivemor.com\/?p=169775","og_locale":"en_US","og_type":"article","og_title":"DollyWay's Eight-Year Evolution: From Master134 to Modern Malware Infrastructure - Som2ny Network","og_description":"Key findings\u00a0 The DollyWay World Domination operation evolved through multiple distinct campaign phases since 2016, showing increasing sophistication in both technical capabilities and infrastructure.\u00a0 Campaign maintained consistent monetization partnerships while advancing evasion and persistence techniques.\u00a0 Infrastructure evolution demonstrates clear learning patterns, with each iteration building upon previous successful elements.\u00a0\u00a0 The DollyWay World Domination\u2019s eight-year evolution [&hellip;]","og_url":"https:\/\/fivemor.com\/?p=169775","og_site_name":"Som2ny Network","article_published_time":"2025-04-03T21:17:53+00:00","og_image":[{"width":1737,"height":1327,"url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/04\/dollyway.jpg","type":"image\/jpeg"}],"author":"admin","twitter_card":"summary_large_image","twitter_misc":{"Written by":"admin","Est. reading time":"12 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/fivemor.com\/?p=169775#article","isPartOf":{"@id":"https:\/\/fivemor.com\/?p=169775"},"author":{"name":"admin","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371"},"headline":"DollyWay&#8217;s Eight-Year Evolution: From Master134 to Modern Malware Infrastructure","datePublished":"2025-04-03T21:17:53+00:00","mainEntityOfPage":{"@id":"https:\/\/fivemor.com\/?p=169775"},"wordCount":2345,"commentCount":0,"publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"image":{"@id":"https:\/\/fivemor.com\/?p=169775#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/04\/dollyway.jpg","keywords":["DollyWays","EightYear","evolution","InfoSec","Infrastructure","Malware","Master134","Modern"],"articleSection":["Internet Business"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/fivemor.com\/?p=169775#respond"]}]},{"@type":"WebPage","@id":"https:\/\/fivemor.com\/?p=169775","url":"https:\/\/fivemor.com\/?p=169775","name":"DollyWay's Eight-Year Evolution: From Master134 to Modern Malware Infrastructure - Som2ny Network","isPartOf":{"@id":"https:\/\/fivemor.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/fivemor.com\/?p=169775#primaryimage"},"image":{"@id":"https:\/\/fivemor.com\/?p=169775#primaryimage"},"thumbnailUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/04\/dollyway.jpg","datePublished":"2025-04-03T21:17:53+00:00","breadcrumb":{"@id":"https:\/\/fivemor.com\/?p=169775#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/fivemor.com\/?p=169775"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/?p=169775#primaryimage","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/04\/dollyway.jpg","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2025\/04\/dollyway.jpg","width":1737,"height":1327},{"@type":"BreadcrumbList","@id":"https:\/\/fivemor.com\/?p=169775#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/fivemor.com\/?bp_activities=1"},{"@type":"ListItem","position":2,"name":"DollyWay&#8217;s Eight-Year Evolution: From Master134 to Modern Malware Infrastructure"}]},{"@type":"WebSite","@id":"https:\/\/fivemor.com\/#website","url":"https:\/\/fivemor.com\/","name":"Som2ny Network","description":"Daily Deals","publisher":{"@id":"https:\/\/fivemor.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/fivemor.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/fivemor.com\/#organization","name":"Som2ny Network","url":"https:\/\/fivemor.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/","url":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","contentUrl":"https:\/\/fivemor.com\/wp-content\/uploads\/2026\/07\/4a0953c4-logo-300x86-1.png","width":300,"height":86,"caption":"Som2ny Network"},"image":{"@id":"https:\/\/fivemor.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/fivemor.com\/#\/schema\/person\/b85e3c3dc0e1daea076524dc8810c371","name":"admin","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/fivemor.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/729ae85bf62b9917e93538db2f2688ca?s=96&r=g&default=https%3A%2F%2Ffivemor.com%2Fwp-content%2Fplugins%2Fbuddypress-first-letter-avatar%2Fimages%2Fdefault%2F96%2Flatin_a.png","caption":"admin"},"sameAs":["https:\/\/fivemor.com"],"url":"https:\/\/fivemor.com\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/169775","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=169775"}],"version-history":[{"count":0,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/posts\/169775\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=\/wp\/v2\/media\/169776"}],"wp:attachment":[{"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=169775"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=169775"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=169775"},{"taxonomy":"dealstore","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fdealstore&post=169775"},{"taxonomy":"offerexpiration","embeddable":true,"href":"https:\/\/fivemor.com\/index.php?rest_route=%2Fwp%2Fv2%2Fofferexpiration&post=169775"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}