The Hidden Infrastructure Behind VexTrio's TDS
Essential information
- Published
- 15/08/2025 12:28
- Modified
- 15/08/2025 13:07
- Tags
- 2025-08-15 adtech binom cloaking content delivery network devops infrastructure tracking traffic distribution system
- Related entities
- 1 intrusion sets (apt), 2 techniques (mitre)
Description
This report provides an in-depth analysis of VexTrio's traffic distribution system (TDS) infrastructure. It reveals their use of resilient, fault-tolerant systems spread across multiple hosting providers and data centers. Key components include DevOps tools like Terraform and Kubernetes, tracking software such as Binom, and cloaking capabilities. The analysis exposes VexTrio's reliance on content delivery networks (CDNs) as potential vulnerabilities. Their CDN domains rank among the top 10,000 most popular websites globally, highlighting the massive scale of their operations. The research aims to shed light on the inner workings of malicious adtech networks to spur further investigation into the industry.