Information about Fast VPN shows that it was developed by LocoMind, a VexTrio entity | Image: Infoblox
In a detailed investigation, Infoblox Threat Intel has unmasked VexTrio as a sprawling cybercriminal network whose operations have infiltrated multiple corners of the internetβranging from fake dating sites and cryptocurrency scams to fraudulent mobile apps and large-scale spam campaigns. The report emphasizes that while their name is well-known in the security community, βit is not widely known that most of the time VexTrio is delivering their own scam content, rather than that of independent advertisers.β
At the heart of VexTrioβs operation is a self-reinforcing ecosystem: βVexTrioβs scams feed their spam, and their spam feeds their scams.β Their so-called βsmartlinksβ hide malicious landing pages across compromised websites, social media platforms, and even email security tools. Victims are funneled into fraudulent dating, cryptocurrency, sweepstakes, and antivirus schemesβeach carefully designed to extract money or personal data.
The affiliate networks they operateβLos Pollos, Adtrafico, and TacoLocoβare used to control what content is delivered to end users, ensuring maximum profitability while masking ownership. DNS analysis shows that in many cases, βthe VexTrio TDS delivers content more often from their own hostingβ¦ than external partners.β
Beyond web-based fraud, VexTrio has expanded aggressively into mobile app distribution. Infoblox notes that they have released VPNs, spam blockers, and dating apps under various developer names like HolaCode, LocoMind, Hugmi, and AlphaScale Mediaβoften achieving millions of downloads. The apps are deceptively marketed, hiding their fraudulent nature behind inflated ratings, while user reviews tell the real story.
One example is Spam Shield, which promised to protect users from unwanted notifications but instead simply disabled browser alerts while locking victims into paid subscriptions. As the report explains: βWhile it claims to eliminate threats, this app simply turns off browser notifications.β
Similarly, their VPN products often operate as residential proxiesβraising serious privacy concerns. Names and branding are deliberately chosen to mimic legitimate services, sowing confusion among users.
VexTrioβs scam landing pages have appropriated the likenesses of public figures and brands including MrBeast, Elon Musk, President Donald Trump, and even the U.S. Cybersecurity and Infrastructure Security Agency (CISA). As Infoblox highlights, this tactic is used to βdeceive users into participating in its cryptocurrency scams.β
The investigation reveals deep interconnections between VexTrio and ostensibly legitimate companies, particularly in Prague and Cyprus. Entities such as Techintrade and OILIMPEX share software, hosting, and even corporate leadership ties with VexTrio. DNS records have directly linked these companies to VexTrio infrastructure, raising questions about the true size of their enterprise.
Perhaps the most alarming aspect is how long VexTrio has operated without facing significant legal repercussions. Infoblox bluntly states: βWe are astonished that VexTrio has operatedβand thrivedβfor 15 years without facing legal consequences.β Despite numerous takedown attempts, the group adapts and re-emergesβits tactics evolving, but its core mission unchanged.
The report closes with a warning to the cybersecurity community, quoting Publilius Syrus: βFraus est celare fraudemβto conceal fraud is itself a fraud.β
Related Posts:
- Infoblox Uncovers Malicious Wave in .US Domain Registrations
- 13,000 MikroTik Routers Hijacked for Global Malspam Operation
- Infoblox Exposes $5.7B Investment Scam Surge Fueled by RDGAs and DNS Abuse
- Morphing Meerkat’s Phishing Tactics: Abusing DNS MX Records
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.