logo

VexTrio: The Uber of Cybercrime - Brokering Malware for 60+ Affiliates

ID: 642886dd-121f-5fe2-a8ca-5d8f1f5a0185

STIX ID: report--642886dd-121f-5fe2-a8ca-5d8f1f5a0185

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-01-23

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Infoblox analysis reveals VexTrio as a long-running, large-scale criminal traffic broker operating HTTP- and DNS-based TDS clusters that leverage DDGA domains and compromised websites (often via vulnerable WordPress/Joomla instances) to route millions of visitors to scams, PUPs, adware/spyware, and malware (notably Glupteba). The network brokers traffic for dozens of affiliates (including SocGholish and ClearFake), runs tens of thousands of domains, and uses profiling-based redirects to maximize malicious monetization while evading takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.