VexTrio Viper Adds a New DNS TDS Domain
ID: 2a76e88b-def6-58c8-bf5f-2044ad286a0c
STIX ID: report--2a76e88b-def6-58c8-bf5f-2044ad286a0c
Feed Name: Infoblox Threat Intel Blog
Infoblox Threat Intel observed a VexTrio Viper DNS-based TDS using the domain airlogs.net (registered 2024-04-23) to serve base64-encoded TXT responses that direct visitors to malicious payload hosts; the actor shifted to server-side DNS checks and hid queries in a compromised WordPress plugin, complicating detection. Query volume spiked shortly after registration and name servers pointed to Russian IPs previously associated with VexTrio, underscoring active use and the need for DNS-layer defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
