VexTrio: Cybercrime Uber – Malware Brokers for 60+ Affiliates

January 23, 2024
1 min read

VexTrio, a cybercrime entity, has been identified as the largest malicious traffic broker in the cybersecurity industry. The group has been active since at least 2017 and has partnerships with over 60 affiliates, including ClearFake and SocGholish. VexTrio has been involved in various types of malicious campaigns, distributing malware, riskware, spyware, and potentially unwanted programs. The group operates a vast network of more than 70,000 domains and uses a traffic distribution system (TDS) to monetize its activities. It is estimated that VexTrio controls multiple TDS networks, including those of its affiliates. The group recruits affiliates through an unknown process but is suspected of advertising its services in dark web forums. VexTrio’s TDS is sophisticated and complex, and it leverages domains generated by a dictionary domain generation algorithm (DDGA) to manage the traffic passing through it. The group also exploits vulnerabilities in content management systems like WordPress to inject rogue JavaScript into compromised websites. It is suspected that VexTrio carries out its own web traffic campaigns by abusing referral programs and reselling the traffic to other actors. The intricate and entangled nature of VexTrio’s affiliate network makes attribution and classification challenging, allowing the group to remain nameless and undetected for more than six years. Researchers recommend blocking VexTrio traffic in DNS to mitigate the group’s activities.

Latest from Blog

Bridging the cyber talent gap: tips for CISOs

TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat