Threat Advisory

VexTrio APT Navigating the Complex Ecosystem of a Sophisticated Cyber Threat

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

A sophisticated threat actor group known as VexTrio has been identified, demonstrating advanced tactics in carrying out cyber-attacks. This group employs a complex business model, utilizing DNS-based Traffic Distribution Systems (TDS) and Dynamically Defined Global Arrays (DDGA) domains to establish a resilient and challenging-to-dismantle ecosystem. VexTrio has developed a resilient and intricate ecosystem through a network of affiliates, making attribution and classification challenging.[/subscribe_to_unlock_form]

Summary:

A sophisticated threat actor group known as VexTrio has been identified, demonstrating advanced tactics in carrying out cyber-attacks. This group employs a complex business model, utilizing DNS-based Traffic Distribution Systems (TDS) and Dynamically Defined Global Arrays (DDGA) domains to establish a resilient and challenging-to-dismantle ecosystem. VexTrio has developed a resilient and intricate ecosystem through a network of affiliates, making attribution and classification challenging.[emaillocker id="1283"]

VexTrio's modus operandi involves the utilization of DNS-based Traffic Distribution Systems (TDS) and Dynamically Defined Global Arrays (DDGA) domains. The TDS serves as an intermediary redirect mechanism, leading to various attack campaigns. One notable campaign is the robot CAPTCHA scheme, initiated through compromised websites injected with malicious JavaScript. Upon passing TDS checks, victims encounter a deceptive CAPTCHA page, urging them to click 'Allow' for supposed robot verification. However, this action alters browser permissions, enabling VexTrio to push notifications to victims. This method is employed to redirect users to benign websites, exploiting referral programs or adding a seemingly harmless facade. Another noteworthy campaign involves SMS scams, where VexTrio TDS servers receive web traffic from affiliates and redirect victims to a landing page prompting them to send premium-rate SMS messages.

VexTrio poses a significant and persistent threat in the cybersecurity landscape. Their intricate network, coupled with dynamic techniques, presents challenges for accurate classification and attribution. Organizations are urged to implement preventive measures, including limiting web activity to secure websites, avoiding interactions with untrusted domains, and leveraging security solutions that offer real-time protection against malicious hostnames. Awareness of VexTrio's evolving tactics and infrastructure is crucial for enhancing the resilience of organizations against this persistent threat actor.

Threat Profile:

 

References:

The following reports contain further technical details:

https://thehackernews.com/2024/01/vextrio-uber-of-cybercrime-brokering.html

[/emaillocker]
crossmenu