logo

Inside the Robot: Deconstructing VexTrio’s Affiliate Advertising Platform

ID: 9f1f3791-3b9c-5fe3-ad82-9591ed1ba0be

STIX ID: report--9f1f3791-3b9c-5fe3-ad82-9591ed1ba0be

Feed Name: Infoblox Threat Intel Blog

Threat Score
75/100

Date Published: 2025-08-14

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

This report exposes VexTrio as a global malicious adtech enterprise that operates resilient TDS infrastructure, self-hosted trackers (e.g., Binom), cloakers (IM KLO), and CDN resources to deliver large-scale scam and malware campaigns (push-notification scareware, dating and antivirus scams). It maps domains, IP ranges, hosting providers, DevOps components, and choke points (popular CDN domains) and demonstrates active abuse with concrete evidence from passive DNS, BGP, and a tracked push-notification redirect that led to a Binom server and scareware landing page.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.