VexTrio
· Published 21/12/2025 02:40 · Modified 21/12/2025 02:54
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 02:40
- Modified
- 21/12/2025 02:54
- Updated at
- 21/12/2025 02:54
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 3 reports, 25 attack patterns (mitre), 5 malware, 3 countries, 25 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (3)
-
2 MITREs 1 APTPublished 15/08/2025 12:28 · Modified 15/08/2025 13:07
-
10 MITREs 28 Observables 1 APTPublished 12/08/2025 18:54 · Modified 12/08/2025 19:55
-
8 MITREs 3 Malwares 83 Observables 1 APTPublished 13/06/2025 07:59 · Modified 13/06/2025 08:28
Attack patterns (MITRE) (25 / 28)
-
T1036 usesMasquerading
-
T1586 usesCompromise Accounts
-
T1204 usesUser Execution
-
T1064 usesScripting
-
T1457 uses
-
T1589 usesGather Victim Identity Information
-
T1213 usesData from Information Repositories
-
T1046 usesNetwork Service Discovery
-
T1592 usesGather Victim Host Information
-
T1071 usesApplication Layer Protocol
-
T1566 usesPhishing
-
T1588 usesObtain Capabilities
-
T1584 usesCompromise Infrastructure
-
T1557 usesAdversary-in-the-Middle
-
T1190 usesExploit Public-Facing Application
-
T1189 usesDrive-by Compromise
-
T1585 usesEstablish Accounts
-
T1027 usesObfuscated Files or Information
-
T1606 usesForge Web Credentials
-
T1056 usesInput Capture
-
T1608 usesStage Capabilities
-
T1590 usesGather Victim Network Information
-
T1199 usesTrusted Relationship
-
T1598 usesPhishing for Information
-
T1102 usesWeb Service
Malware (5)
-
Sign1 usesFamilyPublished 13/06/2025 07:59 · Modified 13/06/2025 07:59
- SocGhoulish
-
ClearFake usesFamilyPublished 04/02/2025 03:00 · Modified 04/02/2025 03:00
-
DollyWay usesFamilyPublished 13/06/2025 07:59 · Modified 13/06/2025 07:59
-
Balada usesFamilyPublished 13/06/2025 07:59 · Modified 13/06/2025 07:59
Countries (3)
- Czechia targets
- Switzerland targets
- Russian Federation targets
Indicators (25 / 164)
-
rpn-news3.clubindicates -
tiktok.supersbows.usindicates -
trafficiq.comindicates -
cdn-routing.comindicates -
allowthoughtpush.xyzindicates -
airpathinch.xyzindicates -
fastminingpro.comindicates -
702942e07c.hotbkebani.ccindicates -
vm-technitrade.holacode.techindicates -
universalrock-storage.comindicates -
cryptoprofit.lifeindicates -
tiktok.superbowsm.topindicates -
winner-g5sf.liveindicates -
anroadship.xyzindicates -
aloneflybox.xyzindicates -
http://pushtorm.net/System/AddSubscriberindicates -
prize-of-5win.liveindicates -
https://tinyurl.com/2ykfey8vindicates -
get-the-prize-ht7.liveindicates -
againstsegmentyellow.xyzindicates -
bonustop-price.lifeindicates -
amongcitylearn.xyzindicates -
arevowelwire.xyzindicates -
defendyourpc.comindicates -
b9ab1.rpbuildit.xyzindicates