BlackTDS, Sutra, and the Drive-by Service Model
Use historical criminal services to understand how today's specialized traffic markets developed.
In this lesson, you will learn to:
- Explain the drive-by-as-a-service model.
- Extract durable service features without treating historical indicators as current.
BlackTDS, Sutra, and the Drive-by Service Model
Reviews BlackTDS’s drive-by-as-a-service reporting, malvertising and exploit-kit chains, and older Sutra research while clearly marking historical observation windows.
BlackTDS sold delivery as a service
Proofpoint reported BlackTDS in 2017 as a traffic distribution and drive-by service advertised to criminals. Customers could direct traffic through filtering toward exploit kits or malware while the service handled parts of hosting and delivery. One observed malvertising pass led into BlackTDS, then Keitaro TDS, and then the GrandSoft exploit kit. Other reporting described fake Microsoft font-pack lures and spam-linked campaigns.
The important lesson is specialization: traffic source, TDS service, exploit kit, payload, and customer can be different roles. BlackTDS was described as a criminal service rather than a legitimate product merely found in a bad chain. Keep the 2017–2018 date attached; this course does not claim that the same infrastructure remains active in 2026.
Sutra represents an older off-the-shelf generation
Academic and security research from the exploit-kit era documented off-the-shelf systems such as Sutra TDS, Simple TDS, and Advanced TDS. Sutra could route visitors based on IP geolocation, operating system, browser, and other metadata, helping customers direct compatible victims toward drive-by infrastructure and hide final hosting behind redirects.
Historical tools show that modern visitor qualification is not new. What changed is scale, cloud and shared-service abuse, affiliate specialization, scripting, and the range of monetization. Use historical code or URL patterns only within their observation period. A modern site with a similar filter is not automatically Sutra. Naming requires distinctive evidence, not resemblance to a decade-old design.
Compare services along stable dimensions
For each service or platform, compare who could obtain it, whether it was legitimate or criminally marketed, where it ran, how customers supplied traffic, which visitor features it used, how it maintained state, what destinations it supported, which telemetry it exposed, and how it resisted analysis. This produces a useful comparison without forcing unlike names into one category.
Historical reporting may use “TDS,” “traffic direction,” “traffic broker,” “drive-by service,” and “malware distribution network” with overlapping meanings. Quote the source’s term where precision matters, then explain the functional role. The stable question is: who controlled the decision that sent this visitor from this source to this destination at this time?
Resources
- Proofpoint: BlackTDS Drive-by as a Service — Study the 2017 criminal service, filtering, malvertising, Keitaro, and GrandSoft chain.
- Microsoft Research: Malicious Web Infrastructure — Use the academic history for Sutra and other off-the-shelf TDS kits.