logo

Traffic Distribution System (TDS) abuse - What’s hiding behind the veil?

ID: 34801fed-c9a5-5d0d-8454-f19761f43294

STIX ID: report--34801fed-c9a5-5d0d-8454-f19761f43294

Feed Name: The Spamhaus Project

Threat Score
70/100

Date Published: 2025-11-05

Date Updated: 2026-04-30

Author: The Spamhaus Team

...
...

Infoblox provided Spamhaus with a list of 100,000 domains attributed to the Vextrio threat actor, many of which are low-cost TLD registrations (.life, .com, .club, .top) acquired in bulk (about 66,000 at Namesilo and 17,000 at Namecheap). Researchers link these domains to TDS activity; Spamhaus has added them to its Domain Blocklist and is tracking the infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.