HomeSecurityVexTrio TDS: Massive criminal operation with 70,000 domains

VexTrio TDS: Massive criminal operation with 70,000 domains

A previously unknown System (TDS) named 'VexTrio' has been active since at least 2017, assisting 60 partners in their criminal operations through a vast network of 70,000 websites.

See also: US Department of Justice focuses on hunting DeFi hackers

VexTrio

Traffic Distribution Systems (TDS) are services that redirect incoming traffic and redirect the user to another website depending on the visitor's operating system, IP address, device, geographic region, and other criteria.

For legitimate reasons, a TDS is often used in the affiliate marketing sector. However, in the cybercrime space, they redirect unwary users to malicious destinations such as phishing, exploit kits, and websites that distribute malware.

One such incident is Parrot TDS, which was recently featured in a Unit 42 report that presented evidence of its active and growing operation .

A new report from Infoblox focuses on a much larger TDS operation called VexTrio, which works with well-known criminal campaigns and actors like ClearFake and SocGholish, among others.

Infoblox identified VexTrio as a highly influential entity in the cybercrime space, with a vast network that plays a central role in the distribution of malicious content.

VexTrio controls over 70,000 compromised websites, a testament to its widespread influence, allowing the platform to distribute malicious content to visitors across a wide range of websites and services.

Typically, websites are hijacked to embed malicious redirect scripts into the HTML code of vulnerable websites. In other cases, threat actors simply create their own websites and use blackhat SEO to generate traffic.

The platform acts as a traffic broker, receiving payment from cybercriminal groups and redirecting visitors to websites under its control to its clients' malicious destinations.

See also: Twitter hack: Joseph James O'Connor sentenced to five years in prison

VexTrio also extends its influence by partnering with at least 60 companies or partners, who send traffic from their resources, such as compromised websites, to VexTrio's TDS servers.

Infoblox notes that these partnerships do not appear to be temporary, as they have observed cases that have lasted up to four years, demonstrating a high level of trust and mutual benefit.

criminal operation

One of VexTrio's partners is ClearFake, a malicious campaign that displays prompts on hacked websites, urging visitors to install fake browser updates, which install malware on the device.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

ClearFake has been a partner with VexTrio for five months, but instead of directly routing traffic to the platform's TDS servers, it uses the Keitaro as an intermediate redirection point.

The SocGholish malware campaign has also been working with VexTrio since at least April 2022, according to Infoblox. Historically, SocGholish has been used by ransomware to gain initial access to corporate networks.

The variety and complexity of attack chains, which involve multiple threat actors, make VexTrio activity difficult to detect, record, and counter.

See also: Ransomware attacks are becoming more frequent and sophisticated

Ransomware as a Service (RaaS) is a type of cybercrime activity wherecriminals offer their services to other criminals as a service. This means that criminals do not need to have technical knowledge to carry out a ransomware attack, as they can simply purchase the service from a RaaS provider.

RaaS providers create and maintain the ransomware, while also providing support to their clients in carrying out the attack. This can include providing training, technical support, and even managing the ransom demanded from victims.

RaaS attacks typically follow the same process. First, the ransomware is introduced to the victim's system, usually via a seemingly harmless file or link. Once installed, the ransomware encrypts the victim's data, making it inaccessible.

The ransomware then displays a message to the victim, demanding a ransom, usually in the form of cryptocurrency, to regain access to their data. If the victim pays, the criminal then provides the decryption code. However, there is no guarantee that the criminal will keep their promise.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS