Inside the Robot: Deconstructing VexTrio’s Affiliate Advertising Platform
ID: 9f1f3791-3b9c-5fe3-ad82-9591ed1ba0be
STIX ID: report--9f1f3791-3b9c-5fe3-ad82-9591ed1ba0be
Feed Name: Infoblox Threat Intel Blog
This report exposes VexTrio as a global malicious adtech enterprise that operates resilient TDS infrastructure, self-hosted trackers (e.g., Binom), cloakers (IM KLO), and CDN resources to deliver large-scale scam and malware campaigns (push-notification scareware, dating and antivirus scams). It maps domains, IP ranges, hosting providers, DevOps components, and choke points (popular CDN domains) and demonstrates active abuse with concrete evidence from passive DNS, BGP, and a tracked push-notification redirect that led to a Binom server and scareware landing page.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
