{"id":181259,"date":"2024-01-24T06:22:22","date_gmt":"2024-01-24T12:22:22","guid":{"rendered":"https:\/\/lifeboat.com\/blog\/2024\/01\/vextrio-the-uber-of-cybercrime-brokering-malware-for-60-affiliates"},"modified":"2024-01-24T06:22:22","modified_gmt":"2024-01-24T12:22:22","slug":"vextrio-the-uber-of-cybercrime-brokering-malware-for-60-affiliates","status":"publish","type":"post","link":"https:\/\/lifeboat.com\/blog\/2024\/01\/vextrio-the-uber-of-cybercrime-brokering-malware-for-60-affiliates","title":{"rendered":"VexTrio: The Uber of Cybercrime \u2014 Brokering Malware for 60+ Affiliates"},"content":{"rendered":"<p><a class=\"aligncenter blog-photo\" href=\"https:\/\/lifeboat.com\/blog.images\/vextrio-the-uber-of-cybercrime-brokering-malware-for-60-affiliates2.jpg\"><\/a><\/p>\n<p>VexTrio, the shadowy entity controlling a massive network of 70,000+ domains, is finally in the spotlight. This \u201ctraffic broker\u201d fuels countless scams &amp; malware campaigns, including ClearFake, SocGholish, &amp; more. Read:<\/p>\n<hr>\n<p>The threat actors behind ClearFake, SocGholish, and dozens of other actors have established partnerships with another entity known as <strong>VexTrio<\/strong> as part of a massive \u201ccriminal affiliate program,\u201d new findings from Infoblox reveal.<\/p>\n<p>The latest development demonstrates the \u201cbreadth of their activities and depth of their connections within the cybercrime industry,\u201d the company <a href=\"https:\/\/blogs.infoblox.com\/cyber-threat-intelligence\/cybercrime-central-vextrio-operates-massive-criminal-affiliate-program\/\" target=\"_blank\">said<\/a>, describing VexTrio as the \u201csingle largest malicious traffic broker described in security literature.\u201d<\/p>\n<p>VexTrio, which is believed to be have been active since at least 2017, has been attributed to <a href=\"https:\/\/blogs.infoblox.com\/cyber-threat-intelligence\/cyber-threat-advisory\/vextrio-ddga-domains-spread-adware-spyware-and-scam-web-forms\/\" rel=\"noopener\" target=\"_blank\">malicious campaigns<\/a> that use domains generated by a dictionary domain generation algorithm (<a href=\"https:\/\/www.splunk.com\/en_us\/blog\/security\/threat-hunting-for-dictionary-dga-with-peak.html\" rel=\"noopener\" target=\"_blank\">DDGA<\/a>) to propagate scams, riskware, spyware, adware, potentially unwanted programs (PUPs), and pornographic content.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>VexTrio, the shadowy entity controlling a massive network of 70,000+ domains, is finally in the spotlight. This \u201ctraffic broker\u201d fuels countless scams &amp; malware campaigns, including ClearFake, SocGholish, &amp; more. Read: The threat actors behind ClearFake, SocGholish, and dozens of other actors have established partnerships with another entity known as VexTrio as part of a [\u2026]<\/p>\n","protected":false},"author":662,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34,1497,41],"tags":[],"class_list":["post-181259","post","type-post","status-publish","format-standard","hentry","category-cybercrime-malcode","category-energy","category-information-science"],"_links":{"self":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/181259","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/users\/662"}],"replies":[{"embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/comments?post=181259"}],"version-history":[{"count":0,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/posts\/181259\/revisions"}],"wp:attachment":[{"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/media?parent=181259"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/categories?post=181259"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lifeboat.com\/blog\/wp-json\/wp\/v2\/tags?post=181259"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}