logo

Vault Viper: High Stakes, Hidden Threats

ID: 3a3b252f-048a-5c0c-a6a0-0ef83503e34d

STIX ID: report--3a3b252f-048a-5c0c-a6a0-0ef83503e34d

Feed Name: Infoblox Threat Intel Blog

Threat Score
88/100

Date Published: 2025-10-23

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

Infoblox Threat Intel (with UNODC collaboration) exposes "Vault Viper" (Baoying Group / BBIN), a sprawling criminal iGaming white-label and transnational infrastructure that distributes a custom Chromium-based "Universe Browser"—marketed as a privacy/circumvention tool but containing persistent, anti-analysis, and covert network/DNS manipulation components consistent with RATs and information-stealing malware; the report maps extensive DNS/ASN footprints, C2 domains and IPs, provides technical analysis of Windows and mobile binaries and extensions, lists IoCs, and ties the operation to organized crime networks (including links to Suncity and convicted actors), concluding the browser functions as a high-risk collection and exploitation platform enabling credential/device takeover and large-scale monetization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.