{"id":12088,"date":"2025-08-06T12:55:34","date_gmt":"2025-08-06T19:55:34","guid":{"rendered":"https:\/\/blogs.infoblox.com\/?p=12088"},"modified":"2025-08-12T11:43:59","modified_gmt":"2025-08-12T18:43:59","slug":"vextrios-origin-story-from-spam-to-scam-to-adtech","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/","title":{"rendered":"VexTrio\u2019s Origin Story: From Spam to Scam to Adtech"},"content":{"rendered":"<blockquote>\n<p>\u201cEveryone knows that eliminating spam is impossible to achieve, <em>until an ignorant person who doesn\u2019t know this comes along and starts sending some (Italian) spammer to jail<\/em>. <em>&lt;beg&gt;\u201d<\/em> \u2014Lex Tutor, 2011<\/p>\n<\/blockquote>\n<p>This quote is powerful when you realize that it is <a href=\"https:\/\/groups.google.com\/g\/it.news.net-abuse\/c\/Jyd5cZy2Nnc\/m\/0bmio7YJMSsJ\" target=\"_blank\" rel=\"noopener\"><strong>referring to progenitors<\/strong><\/a> of the notorious <a href=\"https:\/\/blogs.infoblox.com\/threat-intelligence\/cybercrime-central-vextrio-operates-massive-criminal-affiliate-program\/\"><strong>VexTrio<\/strong><\/a> traffic distribution system (TDS). \u201c<a href=\"https:\/\/groups.google.com\/g\/it.news.net-abuse\/search?q=lex%20tutor\" target=\"_blank\" rel=\"noopener\"><strong>Lex Tutor<\/strong><\/a>\u201d was an online moniker active in anti-spam communities for at least a decade. He not only complained about the endless torrent of spam plaguing internet users, but actively battled spammers in the courts as well. Through forum posts, Tutor documented a series of micro-companies he claimed were connected to persistent spam operations, referencing their \u201chideouts\u201d in Lugano (Switzerland), fake identities, their practice of using abuse reports to clean email lists, and their alleged theft of personal data from various partner services to fuel more spam.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11741\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-1.jpg\" alt=\"\" width=\"906\" height=\"573\" \/><\/p>\n<p>Although Tutor complained about spam, VexTrio is more widely known for their traffic distribution system (TDS). The TDS helps disguise digital fraud, the cost of which, according to the <a href=\"https:\/\/www.ana.net\/miccontent\/show\/id\/ii-2025-02-ai-ad-fraud\" target=\"_blank\" rel=\"noopener\"><strong>Association of National Advertisers (ANA)<\/strong><\/a>, will grow to US$172 billion by 2028. Investment fraud scams alone reportedly brought in US$16.6 billion from U.S. victims in 2024, according to <a href=\"https:\/\/www.ic3.gov\/AnnualReport\/Reports\/2024_IC3Report.pdf\" target=\"_blank\" rel=\"noopener\">FBI reporting<\/a>. VexTrio delivers scareware, dating scams, cryptocurrency scams, fake VPNs and ad blockers, among other types of fraud.<\/p>\n<p>VexTrio gained our attention because of their affiliation with <a href=\"https:\/\/blog.sucuri.net\/2024\/06\/socgholish-malware.html\" target=\"_blank\" rel=\"noopener\">major malware actors<\/a> and the seemingly ubiquitous presence of their TDS in the threat landscape. When <a href=\"https:\/\/blogs.infoblox.com\/threat-intelligence\/cyber-threat-advisory\/vextrio-ddga-domains-spread-adware-spyware-and-scam-web-forms\/\">we first reported<\/a> on the actor in 2022, their domains were seen in over 50% of our customer networks. In 2024, nearly <a href=\"https:\/\/www.godaddy.com\/resources\/news\/godaddy-annual-cybersecurity-report\" target=\"_blank\" rel=\"noopener\">40 percent of all compromised websites<\/a> worldwide redirected to VexTrio\u2019s TDS and led victims to a wide array of scams. Hundreds of sites hosted in a single WordPress provider have been hacked simultaneously to route visitors to VexTrio. As of July 2025, domains that support their core infrastructure rank in the top 10,000 most popular in the world, despite concerted security industry efforts to hobble their operations.<\/p>\n<p>The Italian spammers that Tutor hoped would be sent to jail became part of what we know as VexTrio today. But the TDS technology was developed by a group from Eastern Europe. Until 2020, the Italians and Eastern Europeans appear to operate independently but then join forces and establish their headquarters in Lugano, Switzerland. The merger created a formidable suite of commercial entities that touch every part of the adtech industry. <a href=\"https:\/\/blogs.infoblox.com\/threat-intelligence\/vexing-and-vicious-the-eerie-relationship-between-wordpress-hackers-and-an-adtech-cabal\/\" target=\"_blank\" rel=\"noopener\">Relationships with black hats<\/a> cemented their dominance in malicious traffic distribution. In the last few years, many of the original Italians appear to have moved on to other ventures.<\/p>\n<p>So how did a few friends from Turin, Italy find themselves embroiled in a Russian-nexus cybercriminal organization with close ties to some of the most prolific website hackers in the world? It\u2019s a complicated and murky story. But internet history shows the Italian group wasn\u2019t innocent to start with: they were accused of spamming and scamming early on, using shell companies for cover and embroiled in lawsuits stemming from their spam. The group emerged around 2004 and was heavily invested in dating websites by 2009. They grew numerous adult brands, profiting from the growth of Facebook. Despite the accusations, their sites were enormously popular, and they garnered partnerships with multiple mobile providers. By 2015, this group\u2019s primary company, <a href=\"https:\/\/web.archive.org\/web\/20150313013854\/http:\/tekka.it\/\" target=\"_blank\" rel=\"noopener\">Tekka<\/a>, part of their holding company, <a href=\"https:\/\/web.archive.org\/web\/20121014150606\/http:\/www.tekkagroup.com\/\" target=\"_blank\" rel=\"noopener\">Tekka Group<\/a>, was led by two childhood friends and projected an image of leaders in website innovation: \u201c<em><a href=\"https:\/\/www.linkedin.com\/company\/tekka-group\" target=\"_blank\" rel=\"noopener\">Tekka is young, Tekka is fast, Tekka is digital<\/a><\/em>.\u201d A move to Lugano and the addition of another Italian, <a href=\"https:\/\/www.linkedin.com\/in\/giulio-cerutti-1472611\/?originalSubdomain=ch\" target=\"_blank\" rel=\"noopener\">Guilio Cerutti<\/a>, marked the kickoff of a <a href=\"https:\/\/web.archive.org\/web\/20170830003222\/http:\/www.tekka.it\/\" target=\"_blank\" rel=\"noopener\">new phase in their business<\/a>, as they rebranded and began creating a series of new micro-companies.<\/p>\n<p>The Eastern Europeans, many originally from Belarus and Russia, developed the TDS and related technology stack. They established companies in several countries, including Bulgaria, Moldova, Romania, and Estonia, before ending up in Prague, Czechia in 2015. Like the Italians, there are numerous micro-companies with complex relationships. Their affiliate advertising firm Los Pollos, part of AdsPro Group, was <a href=\"https:\/\/www.qurium.org\/forensics\/when-kehr-meets-vextrio\/\" target=\"_blank\" rel=\"noopener\">identified by Qurium<\/a> as the source of links distributed by the Russian disinformation actor Doppleganger. That discovery was made through analysis of a <a href=\"https:\/\/www.youtube.com\/watch?v=8rLIx_wKrto\" target=\"_blank\" rel=\"noopener\">revealing YouTube video<\/a>. While AdsPro claims headquarters in Switzerland, many of its employees work in Eastern Europe, including Czechia, Bulgaria, Montenegro, and Moldova; see Figure 1. In addition to AdsPro and Los Pollos, several other adtech firms are central to VexTrio\u2019s operations, including Taco Loco and HolaCode.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11742\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-1.jpg\" alt=\"\" width=\"858\" height=\"622\" \/><\/p>\n<p class=\"image-caption\">Figure 1. AdsPro office locations in July 2024 according to their website. Following public disclosure of AdsPro as part of VexTrio in December 2024, someone successfully had the company domains excluded from the Internet Archive project. Captured December 2024.<\/p>\n<p>Over the last decade, VexTrio became the darling of many famous, and many other not so famous, malicious actors who used Los Pollos so-called smartlinks to funnel victims to scams from compromised websites, spam, and poisoned search engine optimization (SEO) results. Surprisingly, in affiliate marketing forums, Los Pollos acknowledged that some of their traffic came from black (illegal) sources. In our research, we also found self-described black hat hackers who claimed to work for Los Pollos. This online material supports the results of <a href=\"https:\/\/blogs.infoblox.com\/threat-intelligence\/vexing-and-vicious-the-eerie-relationship-between-wordpress-hackers-and-an-adtech-cabal\/\">our previous research<\/a>, showing that VexTrio has a long-term relationship with malware actors that drives their success in digital fraud.<\/p>\n<p>In 2024, Los Pollos claimed 200,000 affiliates and over 2 billion unique users every month. VexTrio, as a parent enterprise, maintained an infrastructure across the globe, some of it hidden in bulletproof hosting providers and other elements in cloud providers. They still used the hosting originally established by the Italians, leasing IP addresses for multiple autonomous systems (ASs) from the Lugano-based ISP <a href=\"https:\/\/platform.inflect.com\/building\/12-via-soldini-chiasso\/c41-ch\/datacenter\/chiasso\" target=\"_blank\" rel=\"noopener\">C41<\/a> (InternetOne) (AS203639, AS5398 and AS6898). These Swiss IP ranges are still used for dating scam landing pages, while the TDS and spam operations are run from several other hosting providers around the world, often with bulletproof hosting providers. The crypto scams are run out of ISPs in Eastern Europe.<\/p>\n<p>Their many commercial entities are intertwined in ways that make traditional analysis difficult. For example, in Figure 2, Teknology, a VexTrio company created by the Italians, acts as a reference for Los Pollos, while several of the others listed as trusted brands are also owned by the actors. In some cases, they will present two companies as distinct, such as AdsPro and Apperito, but will have identical staff and claim ownership of the same \u201cprojects.\u201d They register companies with names that are difficult to distinguish from other legitimate entities. The business relationships are so convoluted that separating VexTrio from their independent partners is a daunting task. While we\u2019ve uncovered nearly a hundred firms created, and often dissolved, over the last two decades, we\u2019re certain we\u2019ve missed many.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11743\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-2.jpg\" alt=\"\" width=\"854\" height=\"596\" \/><\/p>\n<p class=\"image-caption\">Figure 2. The Los Pollos website in May 2024, as recorded by archive.org, claimed 2 billion unique users. Several of the testimonial brands listed on the site, including Teknology, tacolo[.]co, and Adtrafico are part of VexTrio.<\/p>\n<p>That\u2019s the short version. What we know about VexTrio could cover hundreds of pages.<\/p>\n<p>But VexTrio is only one player in malicious adtech. From a strategic perspective, this industry facilitates a vast array of cybercrime and has taken root, largely unnoticed, in the last decade. This corner of the advertising world has relied on plausible deniability while raking in vast sums from scams, phishing, and malware. They advertise openly and have convoluted relationships with each other that make it difficult to find where one company, or group, ends and a partner begins. Hopefully, this work will inspire others to join in the hunt.<\/p>\n<p><em>For readability\u2019s sake, we have split this research into three parts. This first segment describes the VexTrio enterprise and key figures, the second will discuss their cybercrime activities, and the third investigates their technology stack and infrastructure. <\/em><\/p>\n<p>We have included numerous links to supporting evidence throughout this paper. All these hyperlinks were active in early July 2025. Names, domains, and companies may appear in this report only because of technical or business link to VexTrio; their mention alone does not mean they knew of or took part in any wrongdoing. Specific illegal activity claims are explicit and backed by cited evidence.<\/p>\n<h3>Defining VexTrio<\/h3>\n<p>Before we get started, let\u2019s explain briefly how we got here. Infoblox Threat Intel has been tracking and chasing VexTrio since 2022. We\u2019ve published multiple papers on the threat actor and collaborated with various folks in the industry along the way to better understand how they fit into the threat landscape. In the fall of 2024, researchers at Qurium and Sucuri\/GoDaddy independently discovered that URL links that led to scams from the VexTrio TDS were owned by the commercial affiliate advertising company, Los Pollos. <a href=\"https:\/\/www.qurium.org\/forensics\/when-kehr-meets-vextrio\/\" target=\"_blank\" rel=\"noopener\">Qurium further connected<\/a> AdsPro, Teknology, TacoLoco, and Guilio Cerutti. Qurium further identified, but did not publish, several key individuals, and we started collaborating.<\/p>\n<p>Puzzle pieces began to fall into place. When we pulled the thread on the Los Pollos lead, we were able to unravel a complex network of companies and individuals that spanned many countries and years. We reported their domains to several providers and watched as tens of thousands of compromised websites that once directed traffic to VexTrio directed it elsewhere. We hinted at their misdeeds on LinkedIn, and they responded by pulling down material from websites and the Web Archive (archive.org), including that shown in Figure 1.<\/p>\n<p>Using material found on the open internet dating back over two decades, we\u2019ve spent thousands of hours assembling a picture that goes well beyond anything previously published. In total, the VexTrio enterprise includes nearly a hundred companies and brands. The scope of their activities includes malicious apps and large-scale spamming operations, and as we published a few months ago, they have a special relationship with numerous website hackers.<\/p>\n<p>In this three-part report, we\u2019ll introduce the people, the enabling technology, the companies, the hosting, and the activities of VexTrio, a name we use for both the actor and the TDS operations. VexTrio is the union of two independent groups; we use the term to encompass all the entities that the key figures are involved in because, as you\u2019ll learn, finding the dividing line between what is and isn\u2019t VexTrio is complicated. It is much cleaner to include all commercial links and all shared infrastructure into the name.<\/p>\n<p>VexTrio was first recognized as a distinct actor in 2022 but has been delivering scams through their advertising networks since 2015. We assume the reader knows something about the threat actor and their affiliation with other malicious actors of various sorts, particularly WordPress hackers. If you want more background, there are many publications available including:<\/p>\n<ul>\n<li><a href=\"https:\/\/blogs.infoblox.com\/threat-intelligence\/cyber-threat-advisory\/vextrio-ddga-domains-spread-adware-spyware-and-scam-web-forms\/\">VexTrio DDGA Domains Spread Adware, Spyware, and Scam Web Forms<\/a><\/li>\n<li><a href=\"https:\/\/blogs.infoblox.com\/threat-intelligence\/cyber-threat-advisory\/vextrio-deploys-dns-based-tds-server\/\">VexTrio Deployes DNS-Based TDS Server<\/a><\/li>\n<li><a href=\"https:\/\/blog.sucuri.net\/2024\/03\/sign1-malware-analysis-campaign-history-indicators-of-compromise.html\" target=\"_blank\" rel=\"noopener\">Sign1 Malware: Analysis, Campaign Highlights, and Indicators of Compromise<\/a><\/li>\n<li><a href=\"https:\/\/blog.sucuri.net\/2023\/08\/from-google-dns-to-tech-support-scam-sites-unmasking-the-malware-trail.html\" target=\"_blank\" rel=\"noopener\">From Google DNS to Tech Support Scams Unmasking the Malware Trail<\/a><\/li>\n<li><a href=\"https:\/\/blog.sucuri.net\/2024\/11\/php-reinfector-and-backdoor-malware-target-wordpress-sites.html\" target=\"_blank\" rel=\"noopener\">PFP Reinfector and Backdoor Malware Target WordPress Sites<\/a><\/li>\n<li><a href=\"https:\/\/insights.infoblox.com\/resources-whitepaper\/infoblox-whitepaper-cybercrime-central-vextrio-operates-massive-criminal-affiliate-program\/\" target=\"_blank\" rel=\"noopener\">VexTrio Operates Massive Criminal Affiliate Program<\/a><\/li>\n<\/ul>\n<p>We initially tracked VexTrio as a malicious TDS that led to a range of dating and adult content scams. The VexTrio TDS would redirect to legitimate decoy pages, like Amazon\u2019s shopping website, when their links were visited from places or devices that didn\u2019t match their desired victim profile. Over the years, and particularly over the last nine months, our understanding of the scope of VexTrio has dramatically changed. While we initially assumed they were \u201chackers in hoodies,\u201d we now know they own commercial enterprises that extend well beyond those that support the TDS operations, including construction, energy, and even ski resorts.<\/p>\n<p>When we say VexTrio now, we mean the controlling individuals and all the businesses they own. To determine what is VexTrio and what is not, we\u2019ve used business and court records, trademark filings, social media and online archives, historical domain name system (DNS) records, software and infrastructure details, and more.<\/p>\n<h3>The People<\/h3>\n<p>The people are the heart of every successful operation, and VexTrio, is no exception. The people involved in VexTrio, if we consider consolidated enterprises, fall into three primary groups: the Italians, the Eastern Europeans, and the assorted frontmen. Unlike Chinese organized crime groups, VexTrio uses true identities in their commercial filings, which made it easier to tie people and companies together. Figure 3 shows connectivity between key figures and firms over the past two decades.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11744\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-3.jpg\" alt=\"\" width=\"816\" height=\"676\" \/><\/p>\n<p class=\"image-caption\">Figure 3. The relationship between key figures and select commercial entities that evolved into what is known as VexTrio today. Not all named businesses are currently operating and some listed individuals may not be involved in the core VexTrio businesses (e.g., Teknology, Los Pollos, AdsPro \/ Aimed Global, Adtrafico, Taco Loco, HolaCode).<\/p>\n<p>Let\u2019s start with the Italians. Not because they hold the power in VexTrio (they don\u2019t), but because we can track their lineage back to 2004. The Italian crew, hailing predominantly from Turin, are the spammers that Lex Tutor so badly wanted jailed. They hold business degrees from the London School of Economics, Bocconi University, and elsewhere. Several of them hold tight friendships dating back decades, and they began working in the spam industry through a U.S. shell company, <a href=\"https:\/\/web.archive.org\/web\/20100429075420\/http:\/crownstone.net\/\" target=\"_blank\" rel=\"noopener\">Crownstone LLC<\/a>. Although the key players in Crownstone LLC are Italian, they had a \u201cheadquarters\u201d in New York and established operations in Lugano very early on, which Lex Tutor referred to as the \u201chideout\u201d that allowed them to skirt Italian law. See Figure 4.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11745\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-4.jpg\" alt=\"\" width=\"889\" height=\"592\" \/><\/p>\n<p class=\"image-caption\">Figure 4. A historical record of the Crownstone LLC website, showing locations in New York City and Lugano. This site also identifies several of their key brands: Onedate, Lifeintwo, Oneklub, Niik, and DirectCro.<\/p>\n<p>Crownstone dove deep into dating apps as Facebook took off and at one point had one of the fastest growing apps on the platform; see Figure 5. The primary brand Onedate took off in the mainstream, <a href=\"https:\/\/bibliotecadelconsumidor.profeco.gob.mx\/media\/revistas\/RC-385%20Marzo%202009.pdf\" target=\"_blank\" rel=\"noopener\">charging nearly twice what match[.]com did<\/a> for membership in 2009, and they established several variants. Marketing reports indicate that <a href=\"https:\/\/www.adweek.com\/performance-marketing\/zoosk-badoo-topface-onedate-and-more-on-the-top-20-facebook-dating-apps-by-mau\/\" target=\"_blank\" rel=\"noopener\">Ondate was a top 20 Facebook app<\/a> in 2012 by monthly active users.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11746\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-5.jpg\" alt=\"\" width=\"1033\" height=\"258\" \/><\/p>\n<p class=\"image-caption\">Figure 5. A Google archive preview indicating that Onedate was one of the most explosive Facebook applications. The contents of this page are restricted to subscribers.<\/p>\n<p>At first glance, none of their activities during these years seem suspicious. They appear to be young men off to make their fortune at a time when dating sites were booming. But when you dig a bit, there is a long history of scam and spam <a href=\"https:\/\/datingspot24.com\/reviews\/onedate.com-experience\/\" target=\"_blank\" rel=\"noopener\">complaints<\/a> about their fake dating websites. Their DNS records and WHOIS registration history show a pattern of sketchy domain names. We found multiple court records <a href=\"https:\/\/www.aepd.es\/documento\/e-00900-2011.pdf\" target=\"_blank\" rel=\"noopener\">implicating Crownstone in spam<\/a> operations. <a href=\"https:\/\/trademarks.justia.com\/772\/30\/onedate-77230697.html\" target=\"_blank\" rel=\"noopener\">Trademarks for Onedate<\/a> were shared with a now-defunct Italian nightclub in Sharm El Sheikh, Egypt. These are later <a href=\"https:\/\/assignments.uspto.gov\/assignments\/assignment-tm-4810-0406.pdf\" target=\"_blank\" rel=\"noopener\">conveyed to Tekka Digital<\/a>, founded by Guilio Lingua and Matteo Costa. According to 2011 <a href=\"https:\/\/web.archive.org\/web\/20111105025930\/http:\/www.tekkaweb.com:80\/customers.html\" target=\"_blank\" rel=\"noopener\">website archives<\/a>, Tekka serves to acquire customers for Crownstone, but they also have <a href=\"https:\/\/web.archive.org\/web\/20111005171901\/http:\/www.tekkaweb.com\/\" target=\"_blank\" rel=\"noopener\">relationships with major mobile carriers<\/a> like Vodafone and Orange.<\/p>\n<p>In 2015, there is a shift in their businesses. In what appears to be a time of great success for the pair (see Figure 6) they joined forces with another Italian businessman, Guilio Cerutti, who had traveled the world learning finance from CNH Industrial Capital. It\u2019s unclear to us how they initially met Cerutti. They set up shop in Lugano (surprised?) and established a dizzying array of micro-companies, including <a href=\"https:\/\/www.linkedin.com\/company\/teknology-sa\/about\/\" target=\"_blank\" rel=\"noopener\">Teknology SA<\/a>, <a href=\"https:\/\/annuaire-entreprises.data.gouv.fr\/entreprise\/tekka-next-812083806\" target=\"_blank\" rel=\"noopener\">Tekka Next<\/a>, <a href=\"https:\/\/business-monitor.ch\/en\/companies\/1024817-bidok-sagl\" target=\"_blank\" rel=\"noopener\">Bidok SA<\/a>, and <a href=\"https:\/\/www.moneyhouse.ch\/en\/company\/gl-holding-sa-14023417831\" target=\"_blank\" rel=\"noopener\">GL Holding<\/a>. A <a href=\"https:\/\/www.shab.ch\/shabforms\/servlet\/Search?EID=7&amp;DOCID=5755294\" target=\"_blank\" rel=\"noopener\">key figure from Crownstone<\/a>, <a href=\"https:\/\/business-monitor.ch\/en\/p\/marco-rufa-3689695\" target=\"_blank\" rel=\"noopener\">Marco Rufa<\/a>, remained in the mix, as well; while he doesn\u2019t seem involved in daily operations in 2025, he is named as a <a href=\"https:\/\/www.zefix.ch\/de\/search\/entity\/list\/firm\/1183617\" target=\"_blank\" rel=\"noopener\">director<\/a> on several of the entities. Marco Rufa is the signatory for Crownstone LLC in the transfer of <a href=\"https:\/\/trademarks.justia.com\/772\/30\/onedate-77230697.html\" target=\"_blank\" rel=\"noopener\">trademark<\/a> assets to Tekka and his name is on domain registration data for Crownstone domains.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11747\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-6.jpg\" alt=\"\" width=\"387\" height=\"658\" \/><\/p>\n<p class=\"image-caption\">Figure 6. December 2015 <a href=\"https:\/\/www.tekkadigital.com\/press\/new-services\" target=\"_blank\" rel=\"noopener\">article<\/a> about <a href=\"https:\/\/www.northdata.com\/TEKKA%20DIGITAL%20SA,%20Canobbio\/CHE-303.540.263\" target=\"_blank\" rel=\"noopener\">Tekka Digital<\/a> and their founders. Captured November 2024.<\/p>\n<p>From public records, Teknology attempts to grow their global presence in the years that follow. They create entities in multiple countries. A <a href=\"https:\/\/www.slideshare.net\/slideshow\/tekka-the-new-mobile-enterteinment-era-for-mobile-users\/65543986#1\" target=\"_blank\" rel=\"noopener\">2016 slide deck<\/a> posted to SlideShare by a Tekka Digital employee claims that the company was created in 2007 and served over 80 million customers. They venture out into other areas, including a shopping club service they call <a href=\"https:\/\/web.archive.org\/web\/20190712114913\/https:\/www.tekkadigital.com\/press\/beseev\" target=\"_blank\" rel=\"noopener\">Beseev<\/a>, but the primary money maker for the next several years still seems to be the legacy from Crownstone: the <a href=\"https:\/\/datingspot24.com\/reviews\/onedate.com-experience\/\" target=\"_blank\" rel=\"noopener\">scam dating<\/a> websites like <a href=\"https:\/\/nuraka.com\/onedatecom-review-scam\/\" target=\"_blank\" rel=\"noopener\">OneDate<\/a>.<\/p>\n<p>Things become very interesting when they join forces with Los Pollos sometime in 2020.<\/p>\n<p>Los Pollos is a project that was created under the entity <a href=\"https:\/\/web.archive.org\/web\/20230608204402\/https:\/www.adspro.eu\/about\" target=\"_blank\" rel=\"noopener\">AdsPro<\/a> (now <a href=\"https:\/\/www.facebook.com\/aimedteam\/\" target=\"_blank\" rel=\"noopener\">Aimed Global<\/a>) and, according to North Data (northdata[.]com), was controlled by three key individuals in 2024: <a href=\"https:\/\/rocketreach.co\/igor-voronin-email_121279938\" target=\"_blank\" rel=\"noopener\">Igor Voronin<\/a>, <a href=\"https:\/\/business-monitor.ch\/de\/companies\/1063876-apexview-gmbh\/management\" target=\"_blank\" rel=\"noopener\">Andrew Kunitsa<\/a>, and <a href=\"https:\/\/www.northdata.de\/Laptsevich,%20Dzmitry,%20Praha\/sz3\" target=\"_blank\" rel=\"noopener\">Dzmitry Laptsevich<\/a> (see Figure 7). While the Italians created numerous companies all over the world, this group of Russian speakers are connected to far more. To uncover and connect the entities, we have used open business records, DNS records, domain registration information, social media, and other public records. Their wives and others who appear to be \u201cfrontmen\u201d are also found as directors or executive officers of many connected companies. There are also numerous variants of a single entity: AdsPro has AdsPro Group, AdsPro Europe, AdsPro Digital, AdsPro Web Services, and AdsPro Limited. They cleverly choose company names that are similar to legitimate services; for example, the name of their development group HolaCode is the same name as a nonprofit organization. They also use names, like Los Pollos, that will get lost in a sea of search results.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11748\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-7.jpg\" alt=\"\" width=\"1032\" height=\"421\" \/><\/p>\n<p class=\"image-caption\">Figure 7. Chart from North Data showing the relationship between AdsPro Group, other entities, and individuals. Voronin, Kunitsa, and Laptsevich were listed as directors when this image was captured in November 2024. This chart also shows K. Toropova, who is connected to a VexTrio advertiser, <a href=\"https:\/\/or.justice.cz\/ias\/ui\/vypis-sl-detail?dokument=14213501&amp;subjektId=525992&amp;spis=161924\" target=\"_blank\" rel=\"noopener\">Techintrade<\/a>. Voronin and Kunitsa are named in <a href=\"https:\/\/or.justice.cz\/ias\/content\/download?id=db3de979e044479fb6d52515dd9942bc\" target=\"_blank\" rel=\"noopener\">official records<\/a> for AdsPro.<\/p>\n<p>This group has a much smaller public footprint than the Italians. Instead of rich LinkedIn profiles, for example, in November 2024, Igor\u2019s simply said <a href=\"https:\/\/www.linkedin.com\/in\/igor-voronin-681b2317\" target=\"_blank\" rel=\"noopener\">Igor Holacode<\/a>; see Figure 8. We have found various pieces of evidence that tie each of the AdsPro founders to Russian or Belarussian backgrounds, but online information also indicates that they have all spent most of their lives in other countries, including Romania and Czechia (Prague).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11752\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-8.jpg\" alt=\"\" width=\"982\" height=\"539\" \/><\/p>\n<p class=\"image-caption\">Figure 8. The LinkedIn profile believed to be Igor Voronin, general director of HolaCode. Captured November 2024.<\/p>\n<p>Much of what we know about the key figures in AdsPro comes from business transparency records in various European countries. For example, North Data searches on the CEO of Teknology, <a href=\"https:\/\/www.northdata.de\/Cerutti,+Giulio+Vittorio+Leonardo,+London\/1b2e\" target=\"_blank\" rel=\"noopener\">Giulio Cerutti<\/a>, demonstrate a variety of connections with the AdsPro trio; see Figures 9 and 10. We found additional supporting information in social media accounts and other online records that were available in fall 2024. Records from hlidacstatu[.]cz indicate not only Kunita\u2019s relationships with Voronin and Laptsevich, but also the receipt of <a href=\"https:\/\/www.hlidacstatu.cz\/Osoba\/DalsiDatabaze\/andrew-kunitsa\" target=\"_blank\" rel=\"noopener\">COVID-19 relief funding<\/a> from the government.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11753\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-9.jpg\" alt=\"\" width=\"978\" height=\"394\" \/><\/p>\n<p class=\"image-caption\">Figure 9. Guilio Cerutti business connections, according to North Data, December 2024.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11754\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-10.jpg\" alt=\"\" width=\"977\" height=\"389\" \/><\/p>\n<p class=\"image-caption\">Figure 10. Business connections of Giulio Cerutti according to North Data in July 2025; Cerutti is connected to Andrew Kunitsa via Apexview GmbH, Igor Voronin via Malthael GmbH, and Dzmitry Laptsevich via Falkenzer GmbH.<\/p>\n<p>Besides the directors of AdsPro, there are a handful of other key figures in this branch of the VexTrio family. Most notable is <a href=\"https:\/\/www.crunchbase.com\/person\/kroum-vassilev\" target=\"_blank\" rel=\"noopener\">Kroum Vassilev<\/a>, a Bulgarian-Canadian. According to his <a href=\"https:\/\/ca.linkedin.com\/in\/kroum\" target=\"_blank\" rel=\"noopener\">LinkedIn profile<\/a>, Kroum was the co-founder and chief operating officer (COO) of AdsPro (now <a href=\"https:\/\/www.linkedin.com\/company\/aimedglobal\/\" target=\"_blank\" rel=\"noopener\">Aimed Global<\/a>). He also claims to be the co-founder of Los Pollos.<\/p>\n<p>Besides AdsPro and Los Pollos, Vassilev claims to be a founder or managing partner at several other firms. This includes <a href=\"https:\/\/www.profine-group.com\/en\/news-and-media\/#!\/press-releases\/profine-energy-wants-to-invest-one-billion-in-bulgaria\" target=\"_blank\" rel=\"noopener\">Profine Energy<\/a>, <a href=\"https:\/\/bg.linkedin.com\/company\/immovlo\" target=\"_blank\" rel=\"noopener\">Immovlo<\/a>, <a href=\"https:\/\/bg.linkedin.com\/company\/enevlo\" target=\"_blank\" rel=\"noopener\">Enevlo<\/a>, <a href=\"https:\/\/bg.linkedin.com\/company\/kayabrands\" target=\"_blank\" rel=\"noopener\">Kaya Brands<\/a>, <a href=\"https:\/\/adtailor.com\/aboutus.jsp\" target=\"_blank\" rel=\"noopener\">Adtailor<\/a>, and <a href=\"https:\/\/www.advage.com\/\" target=\"_blank\" rel=\"noopener\">Advage<\/a>, with locations in Bulgaria, Czechia, and Canada. He lists the London School of Economics as his education.<\/p>\n<p>Vassilev has a long history in the adult advertising industry. His LinkedIn profile claims he was the COO of <a href=\"https:\/\/smartbranding.com\/names-with-stories-the-story-behind-bookmark-com\/\" target=\"_blank\" rel=\"noopener\">bookmark[.]com<\/a> from 2009-2012, during which time it was a pornography site, and his earlier firm, Marketing Extensions, also appears to have been in the same line of business. Like many of the individuals involved in VexTrio, Vassilev tries to balance a professional appearance with an adrenaline-filled lifestyle. He\u2019s made appearances on Bulgarian TV for his energy company; see Figure 11. In contrast to the suit and tie, his <a href=\"https:\/\/www.instagram.com\/kroum\/\" target=\"_blank\" rel=\"noopener\">social media<\/a> shows his love of cars and the <a href=\"https:\/\/www.facebook.com\/kroum\/\" target=\"_blank\" rel=\"noopener\">fast life<\/a>. He posted <a href=\"https:\/\/www.youtube.com\/watch?v=f_jBRq7Gd_Y\" target=\"_blank\" rel=\"noopener\">video<\/a> of a supersonic stratospheric flight (55,000 feet) from a Russian airbase in 2017; see Figure 12. The love of the fast life is a common theme among the key figures of VexTrio. They all seem involved in racing or driving expensive cars, as well as other adrenaline-filled sports.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11755\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-11.jpg\" alt=\"\" width=\"970\" height=\"444\" \/><\/p>\n<p class=\"image-caption\">Figure 11. Kroum Vassilev <a href=\"https:\/\/www.linkedin.com\/posts\/kroum_%D0%BC%D0%B8%D0%BD%D0%B8%D0%BC%D1%83%D0%BC-3-%D0%B7%D0%B0%D0%BA%D0%BE%D0%BD%D0%B0-%D1%82%D1%80%D1%8F%D0%B1%D0%B2%D0%B0-%D0%B4%D0%B0-%D1%81%D0%B5-%D0%BF%D1%80%D0%BE%D0%BC%D0%B5%D0%BD%D1%8F%D1%82-%D0%B7%D0%B0-activity-7158786452871405568-4RgL\" target=\"_blank\" rel=\"noopener\">posted<\/a> on LinkedIn to announce a speaking slot on Bloomberg TV Bulgaria. Captured November 2024.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11756\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-12.jpg\" alt=\"\" width=\"895\" height=\"589\" \/><\/p>\n<p class=\"image-caption\">Figure 12. An Instagram <a href=\"https:\/\/www.instagram.com\/p\/Bb2HrBCj3XG\/?img_index=1\" target=\"_blank\" rel=\"noopener\">post<\/a> by Kroum Vassilev recapping adventures in planes. Captured June 2025.<\/p>\n<p>VexTrio employs a few hundred people globally. It\u2019s unclear how much the average VexTrio employee knows about the true business model. The companies tend to hire a lot of very young women for their public-facing roles and appear to hire development contractors from Eastern Europe. These employees often move between known VexTrio companies and partners, like iMonetizeIT. We know from the personal experience of one of our own researchers that employees of large scam operations may not be aware of the true nature of the business. While many employees move to other companies, some have been with VexTrio from the beginning. We suspect these longtime senior staff likely understand the scheme; still, we\u2019ve decided not to name those people here.<\/p>\n<h3>The Enterprise<\/h3>\n<p>Over a hundred companies and brands have direct public ties to the eight key VexTrio figures we have named. We expect there are many more. The vast majority of entities are holding companies with a few owners and no product or service. Others are in industries ranging from payment processors to energy to construction companies. It is unclear which, if any, of these are legitimate companies. In many cases, people listed as having control over a firm appear to be fronts for the real owners; they include wives, attorneys, and employees. VexTrio companies and brands often have names similar to existing brands so that they would be difficult to discern in search engine results.<\/p>\n<p>Los Pollos is part of a cluster of companies that pay homage to the popular television series Breaking Bad. The show centers on the drug trade and in the show Los Pollos is a chicken restaurant owned by drug runner Gus Fring. It is one of several businesses Gus used to launder money but ironically was also successful in its own right. Early images for VexTrio\u2019s Los Pollos lift imagery, including drug manufacturing, directly from the show (see Figure 13).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11757\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-13.jpg\" alt=\"\" width=\"983\" height=\"125\" \/><\/p>\n<p class=\"image-caption\">Figure 13. An August 2017 advertisement for Los Pollos uses an image of Walter White from the Breaking Bad television show, as well as an altered tagline. Captured March 2025.<\/p>\n<p>VexTrio has several Breaking Bad-themed entities under the AdsPro umbrella. <a href=\"https:\/\/web.archive.org\/web\/20241226171437\/https:\/www.portomontenegro.com\/shop-and-dine\/holacode\/\" target=\"_blank\" rel=\"noopener\">HolaCode<\/a> (holaco[.]de) is the <a href=\"https:\/\/www.holacode.dev\/\" target=\"_blank\" rel=\"noopener\">software development group<\/a> that is largely out of the public eye (Figure 14). According to online records, HolaCode DOO was <a href=\"http:\/\/www.podaci.net\/dodaci\/CGO\/OGLASI\/OGL-2022-17.pdf\" target=\"_blank\" rel=\"noopener\">registered in Montenegro<\/a> in March 2022 by Cerutti. This group appears to have developers in several countries and a physical location in Montenegro. According to a <a href=\"https:\/\/biznis.rs\/vesti\/region\/malim-firmama-je-tesko-da-dodju-do-dobrih-programera\/\" target=\"_blank\" rel=\"noopener\">Bosnian news article<\/a> from 2024, HolaCode was among the most profitable software engineering micro-enterprises in the region. It is unrelated to the nonprofit organization HolaCode. A third company is <a href=\"https:\/\/tacolo.co\/\" target=\"_blank\" rel=\"noopener\">TacoLoco<\/a>, which claims to process over 1 million requests per second, and is used for push monetization.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11758\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-14.jpg\" alt=\"\" width=\"918\" height=\"383\" \/><\/p>\n<p class=\"image-caption\">Figure 14. HolaCode location in Montenegro. Captured November 2024.<\/p>\n<p>The line between VexTrio partners and entities is blurry. For example, they will use <a href=\"https:\/\/web.archive.org\/web\/20240826003029\/https:\/www.lospollos.com\/\" target=\"_blank\" rel=\"noopener\">their own companies and employees as references<\/a> for services on websites. In Figure 15, an AdsPro website lists Los Pollos, TacoLoco, and <a href=\"https:\/\/web.archive.org\/web\/20241222190204\/http:\/adtrafico.com\/\" target=\"_blank\" rel=\"noopener\">Adtrafico<\/a> as \u201cpartners and solutions\u201d they rely on. After <a href=\"https:\/\/www.qurium.org\/press-releases\/when-kehr-meets-vextrio-2\/\" target=\"_blank\" rel=\"noopener\">AdsPro was exposed<\/a> they successfully lobbied the Internet Archive to <a href=\"https:\/\/www.linkedin.com\/posts\/ren%C3%A9e-burton-b7161110b_threatintel-cybercrime-cybersecurity-activity-7292203853901348864-MNlD\/\" target=\"_blank\" rel=\"noopener\">remove archived scans<\/a> from adspro[.]eu, as well as several other domains; the link shown in Figure 15 is no longer available. We know AdsPro is responsible for having the content removed because the Internet Archive <a href=\"https:\/\/help.archive.org\/help\/how-do-i-request-to-remove-something-from-archive-org\/\" target=\"_blank\" rel=\"noopener\">does not remove content<\/a> otherwise. They did forget some domains though, like <a href=\"https:\/\/web.archive.org\/web\/20240930220720\/https:\/adspro.group\/\" target=\"_blank\" rel=\"noopener\">adspro[.]group<\/a> and <a href=\"https:\/\/web.archive.org\/web\/20190205204834\/http:\/adsprodigital.com\/\" target=\"_blank\" rel=\"noopener\">adsprodigital[.]com<\/a>. In 2023, the AdsPro website claimed their companies had over 50 million monthly active users. We will discuss the three main AdsPro companies, Los Pollos, TacoLoco, and Adtrafico in more detail in the section titled Smartlinks and TDS.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11759\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-15.jpg\" alt=\"\" width=\"906\" height=\"666\" \/><\/p>\n<p class=\"image-caption\">Figure 15. The AdsPro website as it existed November 20, 2024, shows TacoLoco, LosPollos, and Adtrafico. While it says these are solutions and partners, AdsPro owns all three. These entries in the Internet Archive were deleted in December 2024, due to a complaint from the domain owner.<\/p>\n<p>The employees of AdsPro and another purportedly separate entity, <a href=\"https:\/\/web.archive.org\/web\/20240108235212\/https:\/apperito.com\/\" target=\"_blank\" rel=\"noopener\">Apperito<\/a>, are the same. They even posted social media images of their company outings in the same locations. Apperito also has multiple projects\u2014including an app development group, <a href=\"https:\/\/web.archive.org\/web\/20240421142126\/https:\/locomind.net\/\" target=\"_blank\" rel=\"noopener\">LocoMind<\/a> (see Figure 16).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11760\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-16.jpg\" alt=\"\" width=\"950\" height=\"614\" \/><\/p>\n<p class=\"image-caption\">Figure 16. Apperito.com projects as shown on their website in November 2024<\/p>\n<p>Part of their business model is developing fake apps, as we\u2019ll see later in the blog. With Apperito, we start to see a further reach of VexTrio into other parts of the advertising ecosystem; they list search engine optimization, creative development, and trackers. In 2024, LocoMind (locomind[.]net) claimed over 500,000 downloads and 50,000 active users for their apps. They claimed to provide user security for mobile phones. There are at least <a href=\"https:\/\/apkpure.net\/developer\/LocoMind#google_vignette\" target=\"_blank\" rel=\"noopener\">seven apps historically<\/a> associated with them, including a \u201c<a href=\"https:\/\/apkpure.net\/app-booster-lite-ram-cleaner\/com.app.booster.lite.phonecleaner.batterysaver.cleanmaster\" target=\"_blank\" rel=\"noopener\">RAM cleaner<\/a>\u201d and various VPNs, <a href=\"https:\/\/apkpure.net\/fast-vpn-super-proxy\/com.vpn.proxy.secure.wifi.turbovpn#google_vignette\" target=\"_blank\" rel=\"noopener\">like FastVPN<\/a>.<\/p>\n<p>AdsPro and their related businesses were previously very active on social media, including <a href=\"https:\/\/www.linkedin.com\/company\/aimedglobal\/\" target=\"_blank\" rel=\"noopener\">LinkedIn<\/a> and <a href=\"https:\/\/www.facebook.com\/aimedteam\/\" target=\"_blank\" rel=\"noopener\">Facebook<\/a>. They extensively marketed themselves and the quality of life for their employees. Following exposure by us in December 2024 on social media, they sanitized or deleted many of their accounts. Where possible, we archived those in various locations on the internet; in other cases, we kept screenshots as supporting evidence. For example, the AdsPro Facebook account actively promoted their services and people; they even had a series of posts on their cats (see Figure 17).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11761\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-17.jpg\" alt=\"\" width=\"881\" height=\"652\" \/><\/p>\n<p class=\"image-caption\">Figure 17. Image from the now-deleted AdsPro Facebook account in a series of posts about the cats of AdsPro. This image shows employee names logged into the RocketChat portal. Image captured November 2024.<\/p>\n<p>VexTrio also runs a wide range of spam-related services. For example, they operate mail[.]sendgrid[.]rest. It\u2019s somewhat surprising that they have gotten away with the use of a lookalike domain to the large email marketing company SendGrid since September 2021. They also control the domain, mailgun[.]fun. As far as we know, they have nothing to do with the company Mailgun. The sendgrid[.]rest and mailgun[.]fun mail servers run on the holaco[.]de infrastructure along with a wide range of related domains. According to shodan[.]io in June 2024, other domains include not only those related to Los Pollos, but fidelitymail[.]com, related to Fidelity Mail, an email marketing firm. See Figure 18 for these and other VexTrio service domains. Other domains on this IP address include fake apps they have developed and Pay Salsa, a payment processing service owned by VexTrio.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11762\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-18.jpg\" alt=\"\" width=\"755\" height=\"755\" \/><\/p>\n<p class=\"image-caption\">Figure 18. Shodan information for the IP address 78[.]47[.]103[.]187 shows several VexTrio company domains and app names. Image captured June 2025.<\/p>\n<p>In the Swiss networks associated to the firm Teknology, VexTrio hosts landing pages for the different scams, as well as some spam-related services. They offer email validation services through <a href=\"https:\/\/web.archive.org\/web\/20250623130935\/https:\/www.datasnap.ch\/en\/\" target=\"_blank\" rel=\"noopener\">DataSnap<\/a>, previously called Articheck (Figure 19). These examples highlight how they have attempted to hide their operations by blending into existing legitimate company names. While the email validation service was hosted under the name <a href=\"https:\/\/web.archive.org\/web\/20241226183020\/https:\/articheck.ch\/en\/chunk-7EF5A3DJ.js\" target=\"_blank\" rel=\"noopener\">articheck[.]ch<\/a>, a Google search on Articheck will give results about the art-related company, articheck[.]com. DataSnap claims to have a 99.9 percent accuracy in validating emails for direct email marketing. All VexTrio scams obtain email addresses for the victims, which likely makes email validation easier.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11763\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-19.jpg\" alt=\"\" width=\"943\" height=\"708\" \/><\/p>\n<p class=\"image-caption\">Figure 19. The DataSnap website. Captured July 2025.<\/p>\n<p>The key figures tied to VexTrio are involved in dozens of companies, many of them holding companies. Sometimes the line between a company and a brand is blurred and indistinguishable. We show a sample of the companies and brands that we uncovered in Table 1. These companies were found in open-source research through a combination of corporate record sites, information on known company websites or apps, social media postings, DNS records, and domain name registration history. We suspect there are many more entities than we have discovered.<\/p>\n<table>\n<tbody>\n<tr>\n<td>Adschain srl<br \/>\nAdsPro<br \/>\nAdsPro Digital<br \/>\nAdsPro Global<br \/>\nAdtailor<br \/>\nAdtrafico<br \/>\nAdvage<br \/>\nAdvxnet<br \/>\nAlcorvo<br \/>\nAlphascale Media GmbH<br \/>\nAlphaScale SA<br \/>\nAlpine Robe SA<br \/>\nAmgest SA<br \/>\nApexView GmbH<br \/>\nApLabz<br \/>\nApperito<br \/>\nApple Digital Srl<br \/>\nArticheck<br \/>\nBlueQuant AG<br \/>\nBright Media OOD<br \/>\nByteCore AG<br \/>\nCasualClub<br \/>\nCrownstone LLC<br \/>\nDigibility SRL<br \/>\nDigitarium SRL<br \/>\nEnerdigity SRL<br \/>\nFalkenzer SRL<br \/>\nFidelity Mail<br \/>\nGL Holding SA<br \/>\nGoalMobile SRI<br \/>\nGitronis SRO<br \/>\nHavran Investments SRL<br \/>\nHavran Media<br \/>\nHolaCode DOO<br \/>\nHostinec<\/td>\n<td>Idea Partners GmbH<br \/>\nIntelligent Supply sro<br \/>\nIridio SA<br \/>\nIronads srl<br \/>\nIronDeal FKT<br \/>\nKaya Brands<br \/>\nKlover Group<br \/>\nLocoMind<br \/>\nLoggaTI<br \/>\nLosPollos<br \/>\nMalthael GmbH<br \/>\nMarten Ivestment SRL<br \/>\nMedia Alliance sro<br \/>\nMobappo SAGL<br \/>\nNascor sro<br \/>\nNew Breeze OOD<br \/>\nPay Salsa<br \/>\nPrimerox sro<br \/>\nRaven Media<br \/>\nSionDev AG<br \/>\nSkib SA<br \/>\nSkyForge AG<br \/>\nSkyForge Digital AG<br \/>\nTacoLoco<br \/>\nTake OFF GmbH<br \/>\nTechtribe AG<br \/>\nTekka<br \/>\nTeknology SA<br \/>\nTekka Date<br \/>\nTekka Next SAGL<br \/>\nTekka Limited<br \/>\nTeknology Corp<br \/>\nYapple K Sro<br \/>\nYotaByte SA<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p class=\"image-caption\">Table 1. A sample of the entity names associated with the key historical figures of VexTrio: Guilio Lingua, Matteo Costa, Marco Rufa, Igor Voronin, Andrew Kunitsa, Dzmitry Laptsevich, and Kroum Vassilev.<\/p>\n<h3>Smartlinks and the VexTrio TDS<\/h3>\n<p>There are three companies in the VexTrio enterprise that are affiliate advertising networks: Los Pollos, Taco Loco, and Adtrafico. Each of these could be the subject of a paper in itself, but we will just do a short introduction of each and their connection to cybercrime.<\/p>\n<p>VexTrio is notorious because large numbers of compromised websites redirect users into their TDS; in 2024, nearly 40 percent of the compromises observed by GoDaddy led to VexTrio. This redirection is caused by links called <a href=\"https:\/\/youtu.be\/ardkiNptT1M?t=45\" target=\"_blank\" rel=\"noopener\">smartlinks<\/a> (or direct offers): a single URL that will always deliver content, regardless of the visitor\u2019s location or device. Adtech companies promise publishing affiliates, meaning the people who distribute the URLs, that these are an easy way to ensure they maximize their profits. Figure 20 shows how the company Adsbridge explains smartlinks, which they began <a href=\"https:\/\/web.archive.org\/web\/20200919052930\/https:\/www.adsbridge.com\/smartoffers\" target=\"_blank\" rel=\"noopener\">offering in 2020<\/a>. The diagram is taken from a <a href=\"https:\/\/web.archive.org\/web\/20240420070135\/https:\/www.adsbridge.com\/smartoffers\/\" target=\"_blank\" rel=\"noopener\">more recent versio<\/a>n of their website.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11765\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-20.jpg\" alt=\"\" width=\"976\" height=\"502\" \/><\/p>\n<p class=\"image-caption\">Figure 20. How smartlinks work according to the website of <a href=\"https:\/\/www.adsbridge.com\/smartoffers\/\" target=\"_blank\" rel=\"noopener\">Adsbridge<\/a>, which is <a href=\"https:\/\/www.adsbridge.com\/contact-us\/\" target=\"_blank\" rel=\"noopener\">part of iMonetizeIT<\/a>. Captured July 2025.<\/p>\n<p><a href=\"http:\/\/lospollos.com\/\" target=\"_blank\" rel=\"noopener\">Los Pollos<\/a> is a cost per action (CPA) network. In a CPA network, the publishing affiliate\u2014which in the case of compromised websites is a malware actor\u2014receives a commission if the site visitor performs an \u201caction\u201d at the landing page. An action in this context may be accepting website push notifications, <a href=\"https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-63\" target=\"_blank\" rel=\"noopener\">providing their name and email<\/a>, or purchasing a product with a credit card, for example. Los Pollos boasts that their advertisers are of high quality with a high conversion rate, meaning that users are likely to take the action. In return, the publishing affiliate only receives payment when the action specified by the advertiser is taken. We show a simplified example of this process in Figure 21.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11766\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-21.jpg\" alt=\"\" width=\"850\" height=\"718\" \/><\/p>\n<p class=\"image-caption\">Figure 21. How threat actors leverage compromised sites and smartlinks to earn money.<\/p>\n<p>Los Pollos smartlinks emerged on the security industries radar in 2017 but it was not clear that they were linked to the adtech firm until fall 2024. In October 2019, Los Pollos <a href=\"https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-32\" target=\"_blank\" rel=\"noopener\">introduced \u201cpush\u201d smartlinks<\/a> (Figure 22), which led to fake CAPTCHAs that tricked users into accepting push notifications from the site, creating a form of persistence. Until users turned off browser notifications, a task that is tricky for the average user, they would be inundated with notifications that their computer was hacked, they had won a gift card, or other clickbait. Opening a notification put them back into the TDS and a whole new cycle of exploitation would begin. This was the <a href=\"https:\/\/youtu.be\/1SV4PYo76OE\" target=\"_blank\" rel=\"noopener\">push monetization<\/a> option that Los Pollos closed in late November 2024.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11767\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-22.jpg\" alt=\"\" width=\"992\" height=\"350\" \/><\/p>\n<p class=\"image-caption\">Figure 22. Los Pollos announces their push monetization offering on their paid Black Hat World thread in October 2019. Captured June 2025.<\/p>\n<p>In 2020, <a href=\"https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-36\" target=\"_blank\" rel=\"noopener\">Los Pollos announced their sister company<\/a>, TacoLoco, which offered a new way for publishing affiliates to monetize their traffic. Los Pollos publishing affiliates who incorporated TacoLoco push monetization into their sites were promised a 90 percent revenue share for the life of the user\u2019s subscription. Los Pollos also encourages their affiliates to register as TacoLoco advertisers and use their smartlink as their ad. See Figure 23. We don\u2019t know how many people have <a href=\"https:\/\/www.youtube.com\/watch?v=ysPJdEykcZA\" target=\"_blank\" rel=\"noopener\">followed this advice<\/a>, but it creates a clever cycle in which these publishing affiliates are paying VexTrio for the potential of receiving a payment in return: what a deal!<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11768\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-23.jpg\" alt=\"\" width=\"1086\" height=\"453\" \/><\/p>\n<p class=\"image-caption\">Figure 23. Advertisement for and explanation of, TacoLoco, the VexTrio push monetization company. By combining LosPollos smartlinks with TacoLoco, they promised a 90 percent revenue share to affiliates.<\/p>\n<p>TacoLoco offers affiliates <a href=\"https:\/\/web.archive.org\/web\/20240810135147\/https:\/blog.tacolo.co\/how-to-monetize-traffic-with-tacoloco-a-complete-guide\/\" target=\"_blank\" rel=\"noopener\">two ways to monetize<\/a>: place <a href=\"https:\/\/web.archive.org\/web\/20240810130046\/https:\/blog.tacolo.co\/script-for-collecting-push-subscriptions-from-tacoloco-how-to-use-it-and-who-can-earn\/\" target=\"_blank\" rel=\"noopener\">special code on a website<\/a> that automatically offers push notifications to all visitors or get a special link and drive traffic to it. Figure 24 shows the script that is inserted into a website to ask users to accept notifications. The domain listed, nxt-psh[.]com, is a top 100,000 domain in global popularity by multiple sources as of July 2025. Some VexTrio domains have risen to the top 10,000 within a month, demonstrating their ability to reach large audiences worldwide.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11769\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-24.jpg\" alt=\"\" width=\"1086\" height=\"232\" \/><\/p>\n<p class=\"image-caption\">Figure 24. The push notification script that is inserted in a website header to lead visitors to a request to allow browser notifications, according to TacoLoco documentation. The domain nxt-psh[.]com is one of several domains used for push notifications.<\/p>\n<p>In their (now-deleted) \u201ccomplete guide\u201d blog, <a href=\"https:\/\/web.archive.org\/web\/20240810135147\/https:\/blog.tacolo.co\/how-to-monetize-traffic-with-tacoloco-a-complete-guide\/\" target=\"_blank\" rel=\"noopener\">TacoLoco showed several pre-made landing<\/a> pages that were available to affiliates. These landing pages are fake CAPTCHAs and considered within the security industry to be signature VexTrio images; see Figure 25. The blog also explains to affiliates how to set the \u201caggression\u201d parameter, which controls how many times a user will be asked to subscribe to notifications. The article states: \u201cSimply put, if a user opens a page, sees a push notification, but does not subscribe, then auto-update is triggered, and on another page, a pop-up window will offer to subscribe again.\u201d<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11770\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-25.jpg\" alt=\"\" width=\"1084\" height=\"483\" \/><\/p>\n<p class=\"image-caption\">Figure 25. Premade landing pages offered by TacoLoco in August 2022 according to their blog \u201cHow to Monetize Traffic with TacoLoco: A Complete Guide.\u201d Captured June 2025.<\/p>\n<p>The available evidence strongly suggests that VexTrio is complicit in cybercrime. They boast about the quality of their advertising affiliates. Unlike Facebook and other major advertising platforms, Los Pollos does not allow just anyone to advertise: they vet their advertisers. We, and many others, have followed hundreds of smartlinks and been willingly scammed time and time again. The million-dollar question is: Are they complicit in the scourge of WordPress malware that plagues sites globally? According to a message from their official account on Black Hat World in 2017, their platform is a little black, a little white. See Figure 26.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11771\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-26.jpg\" alt=\"\" width=\"1029\" height=\"464\" \/><\/p>\n<p class=\"image-caption\">Figure 26. Los Pollos official account reply to a question on Black Hat World forum. Captured June 2025.<\/p>\n<p>In the advertising world, black traffic refers to illegal sources. Senior AdsPro employees attended invite-only black hat SEO parties, according to photographs uncovered by Qurium researchers. So, what exactly do they know about the website hacking publishing affiliates? Minimally, they know enough to connect the compromises to the crypto wallets that they pay out every Tuesday. In other forum messages, the LosPollos official account suggests that affiliates who want to use their smartlinks on Facebook will <a href=\"https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-44\" target=\"_blank\" rel=\"noopener\">need to learn black hat methods<\/a>; see Figure 27.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11772\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-27.jpg\" alt=\"\" width=\"1035\" height=\"360\" \/><\/p>\n<p class=\"image-caption\">Figure 27. LosPollos official account suggesting the affiliate needed to learn black hat methods to advertise on Facebook and that their offers were not white hat. Captured June 2025.<\/p>\n<p>Not only has Los Pollos acknowledged they receive black hat traffic, but some black hat hackers have claimed direct ties to Los Pollos. Marius Gjura, who appears to be Albanian in origin, stated on LinkedIn (Figures 28 and 29) that he developed affiliate marketing cloaking software and further indicated he was connected to Los Pollos and iMonetizeIT (yes, the same iMonetizeIT that owns AdsBridge, whose smartlinks are described in Figure 20).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11773\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-28.jpg\" alt=\"\" width=\"797\" height=\"695\" \/><\/p>\n<p class=\"image-caption\">Figure 28. <a href=\"https:\/\/www.linkedin.com\/in\/marius-gjura\/?originalSubdomain=nl\" target=\"_blank\" rel=\"noopener\">LinkedIn profile<\/a> for self-described black hat hacker claims relationships with Los Pollos and iMonetizeIT. This same individual is linked to a different Albanian LinkedIn profile.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11774\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-29.jpg\" alt=\"\" width=\"846\" height=\"513\" \/><\/p>\n<p class=\"image-caption\">Figure 29. Albanian <a href=\"https:\/\/www.linkedin.com\/in\/marius-gjura-832388149\/?originalSubdomain=al\" target=\"_blank\" rel=\"noopener\">LinkedIn profile<\/a> describes role in developing affiliate link cloaking software. This same individual is linked to a Dutch profile that lists Los Pollos and describes themselves as a black hat hacker.<\/p>\n<p>Los Pollos not only vets their advertisers, but they also vet their publishing affiliates. In doing so, VexTrio may cause their own demise. User posts on forums such as Black Hat World indicate that the rejection level of publishing affiliate applicants is high, and there are no clear requirements for acceptance. On November 12, 2019, in response to an inquiry about what is needed, the official Los Pollos account replied \u201c<a href=\"https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-33\" target=\"_blank\" rel=\"noopener\">We don\u2019t have a list of requirements, we review each application<\/a>.\u201d They do not accept applicants with no history as a publishing affiliate (Figure 30) and they frequently reject applicants without a specific reason (Figure 31). <a href=\"https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-42\" target=\"_blank\" rel=\"noopener\">Los Pollos asks applicants<\/a> to provide them with marketing forum profiles, the names of other Los Pollos affiliates who could vouch for them, as well as traffic source information. According to forum posts, they routinely respond with \u201cUnfortunately, I am unable to accept your application at this time.\u201d And yet, they accepted the applications of prolific website hackers.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11775\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-30.jpg\" alt=\"\" width=\"938\" height=\"294\" \/><\/p>\n<p class=\"image-caption\">Figure 30. Los Pollos official account commentary on the rejection of a publishing affiliate application indicating they analyze their applicants. Captured June 2025.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11776\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-31.jpg\" alt=\"\" width=\"940\" height=\"471\" \/><\/p>\n<p class=\"image-caption\">Figure 31. Los Pollos vets their publishing affiliates before providing access to live smartlinks and does not accept first-timers. Captured June 2025.<\/p>\n<p>The third affiliate advertising company in their portfolio is Adtrafico. Instead of smartlinks, Adtrafico sells affiliates direct cost-per-action offers, meaning they know exactly what the end advertisement is and the action required for payment. Adtrafico emerged around the same time as Los Pollos, with a home page appearing around September 2016; see Figure 32. Early Adtrafico messaging promised \u201cthe freshest offers. Illegaly-high payouts\u201d for publishers. In April 2025, Adtrafico <a href=\"https:\/\/web.archive.org\/web\/20250418231441\/https:\/www.adtrafico.com\/\" target=\"_blank\" rel=\"noopener\">announced it was merging<\/a> with its parent company LosPollos, and as of July 2025 the domain adtrafico[.]com redirects to lospollos[.]com. According to their announcement, the merger doesn\u2019t change the Adtrafico business model, so for this discussion, we are keeping the present tense.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11777\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-32.jpg\" alt=\"\" width=\"926\" height=\"515\" \/><\/p>\n<p class=\"image-caption\">Figure 32. The Adtrafico website as of June 7, 2016, as well as the timeline of Wayback Machine archives for the domain adtrafico[.]com. Captured June 2025.<\/p>\n<p>As <a href=\"https:\/\/www.blackhatworld.com\/seo\/adtrafico-reliable-network-for-media-buyers-sweepstakes-dating-mobile-billing-and-more.1320953\/\" target=\"_blank\" rel=\"noopener\">Adtrafico explained<\/a> in their marketplace thread on Black Hat World, the publisher is paid for every successful lead, which is defined by some specific action. For example, on April 20, 2021, they detailed a \u201csweepstakes\u201d offer for an iPhone 12 Pro, targeting people in Czechia. The Adtrafico affiliate would somehow lead the user through to a link that gave an opportunity to win the new phone. To qualify, the targeted victim is led through a series of three quiz questions, and finally to a simple call button. Once the user makes the phone call, the affiliate is paid out \u20ac2.80. Not bad! This is called an interactive voice response (IVR) offer. In our experience, the quiz questions aren\u2019t real quizzes; they appear to buy time for the TDS to profile the potential victim.<\/p>\n<p>Most of the Adtrafico offers pay affiliates a few dollars for obtaining a user\u2019s email address, date of birth, physical address, and name. But some pay much more. These are typically what are called \u201cCC submit\u201d offers, meaning the fraud victim will need to submit a credit card number for the affiliate to be paid. As the Adtrafico official account announced on February 4, 2022, these offers have good payouts. In that example, a landing page offering the victim the ability to buy an iPad Air for US$3 would lead to a US$33.60 payment to the publishing affiliate if completed.<\/p>\n<p>How is that possible? Fraud. This type of ad steals the victim\u2019s money by charging them more than is shown on the screen. For example, they may be billed US$9.99 for that iPad Air that they will never receive. But they also get enrolled into automatically renewing subscriptions. The victim will need to realize the crime and then fight it through the credit card company as \u201cchargebacks.\u201d<\/p>\n<p>We\u2019ve had several people argue with us as to whether this is an effective scam mechanism; but if it weren\u2019t, they wouldn\u2019t do it. Threat actors like VexTrio can distribute massive numbers of such offers around the globe. They typically claim conversion rates for CC submit offers around 1.5 to 2 percent. At scale, that\u2019s a lot of money. We\u2019ve seen nutra industry vertical and anti-virus offers from Adtrafico that paid well over US$100 per lead.<\/p>\n<p>In 2024, Adtrafico was one of <a href=\"https:\/\/www.blackhatworld.com\/seo\/is-anyone-running-blank-checkout-offers.1572832\/\" target=\"_blank\" rel=\"noopener\">few advertising networks<\/a> that openly sold \u201cblank CC submit\u201d ads (Figure 33). In a typical CC submit offer like the iPad Air example, the advertiser provides the so-called creative. But with a blank offer, the publisher is given a template which they can adorn with the logo of their choice, like Amazon or Walmart, as well as the wording. According to advertising affiliate blog Partnerkin, <a href=\"https:\/\/partnerkin.com\/en\/blog\/publications\/ecom_blank_sweeps\" target=\"_blank\" rel=\"noopener\">blank CC offers were among the hottest in 2024<\/a>. Partnerkin states that some affiliates have \u201csix-figure days\u201d running blank CC offers, often getting 300+ percent return on investment (ROI). Another company, CheckItOut, <a href=\"https:\/\/imgur.com\/a\/1O31sdd\" target=\"_blank\" rel=\"noopener\">created slide decks for prospects<\/a> to explain the scheme.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11778\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-33.jpg\" alt=\"\" width=\"940\" height=\"758\" \/><\/p>\n<p class=\"image-caption\">Figure 33. Adtrafico blank credit card offer as of November 29, 2024. Adtrafico deleted these pages in mid-December 2024.<\/p>\n<p>In an effort to expose this type of activity, <a href=\"https:\/\/www.linkedin.com\/posts\/ren%C3%A9e-burton-b7161110b_infobloxthreatintel-threatintel-threatintelligence-activity-7279511581812531201-ipTp?\" target=\"_blank\" rel=\"noopener\">we outed Adtrafico<\/a> in late December 2024 on LinkedIn after they began removing content from their website. Adtrafico reacted within a few hours of the post, not by contacting us, but by scrubbing more material from the internet. They had the original Partnerkin <a href=\"https:\/\/partnerkin.com\/en\/blog\/publications\/ecom_blank_sweeps\" target=\"_blank\" rel=\"noopener\">article modified<\/a> to remove references to them and deleted numerous online posts. Before we release material, however, we make many copies. One <a href=\"https:\/\/web.archive.org\/web\/20241228001607\/https:\/partnerkin.com\/en\/blog\/publications\/ecom_blank_sweeps\" target=\"_blank\" rel=\"noopener\">copy of the original Partnerkin blog<\/a> is kept in the Internet Archive. Further archives of Adtrafico\u2019s website show that their <a href=\"https:\/\/web.archive.org\/web\/20241012212642\/https:\/www.adtrafico.com\/blog\/top-3-offers-of-the-week-102\/\" target=\"_blank\" rel=\"noopener\">top offer in October 2024<\/a>, was a blank CC offer targeting Slovenian residents and paying approximately US$38. The VexTrio team is always innovating: in August 2024, <a href=\"https:\/\/www.blackhatworld.com\/seo\/adtrafico-reliable-network-for-media-buyers-sweepstakes-dating-mobile-billing-and-more.1320953\/page-23\" target=\"_blank\" rel=\"noopener\">they announced \u201cSmartRotation\u201d<\/a> of blank CC offers, which allowed for more variety in landing pages to fool a broader audience.<\/p>\n<p>Plausible deniability is built into the paradigm of advertising networks. The adtech companies claim to act only as an intermediary between a publisher and an advertiser, with no way to control abuse of their platform. Indeed, this is <a href=\"https:\/\/krebsonsecurity.com\/2025\/06\/inside-a-dark-adtech-empire-fed-by-fake-captchas\/\" target=\"_blank\" rel=\"noopener\">what Guilio Cerutti claimed to Brian Krebs<\/a> in December 2024 following a <a href=\"https:\/\/www.linkedin.com\/posts\/ren%C3%A9e-burton-b7161110b_dns-threatintel-malware-activity-7275915939081019394-gNlP\/?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAButVkUBV1AlDCDv3gxOFHUy3uhLcxo4R2M\" target=\"_blank\" rel=\"noopener\">post we made on LinkedIn<\/a>. But in the case of VexTrio, they are not just the conduit, they are the connective tissue between two types of crime. They are not at arm\u2019s length from either the website hackers or the scam advertisers. Moreover, the evidence presented shows they likely run a large portion of the scams themselves.<\/p>\n<h3>The Ecosystem<\/h3>\n<p>VexTrio and their partners are successful in part because their businesses are obfuscated. But a larger part of their success is likely because they stick to fraud, where they know there is less risk of consequences.<\/p>\n<p>Michael Schwalbach, the CEO of <a href=\"https:\/\/advidi.com\/\" target=\"_blank\" rel=\"noopener\">Advidi<\/a>, a VexTrio advertiser, said in an <a href=\"https:\/\/mikeschwalbachadvidi.wordpress.com\/\" target=\"_blank\" rel=\"noopener\">online interview<\/a>:<\/p>\n<p style=\"text-align: center;\"><em>\u201c&#8230; some of the products can be aggressive \u2014<br \/>\nbut we\u2019ll never push products that cross the line.<br \/>\nFor example, we\u2019ll never push a cryptolocker or malware.\u201d<\/em><\/p>\n<p>VexTrio steals money by conning people. And as a result, they live a lavish lifestyle that most people only dream of; see Figure 33. If only Lex Tutor could have his wish come true. <\/p>\n<p><em>Since <a href=\"https:\/\/blogs.infoblox.com\/threat-intelligence\/vexing-and-vicious-the-eerie-relationship-between-wordpress-hackers-and-an-adtech-cabal\/\">our last publication<\/a>, VexTrio has registered thousands of domains and has changed their infrastructure, however we are still tracking them and the affiliated malware actors. Domains and references from this research can be found in our <a href=\"https:\/\/github.com\/infobloxopen\/threat-intelligence\/tree\/main\" target=\"_blank\">GitHub repository<\/a>. <\/em> <\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-fig-34.jpg\" alt=\"\" width=\"750\" height=\"746\" class=\"alignnone size-full wp-image-11786\" \/><\/p>\n<p class=\"image-caption\">One of the many <a href=\"https:\/\/www.facebook.com\/igor.itpark.7\" target=\"_blank\">social media posts<\/a> by key VexTrio figures showing off expensive cars and a lavish lifestyle. Captured July 2025.<\/p>\n<h3 style=\"font-size: 18px;\">References <\/h3>\n<ol style=\"font-size: 14px;\">\n<li><a href=\"https:\/\/groups.google.com\/g\/it.news.net-abuse\/c\/Jyd5cZy2Nnc\/m\/0bmio7YJMSsJ\" target=\"_blank\">https:\/\/groups.google.com\/g\/it.news.net-abuse\/c\/Jyd5cZy2Nnc\/m\/0bmio7YJMSsJ<\/a><\/li>\n<li><a href=\"https:\/\/blogs.infoblox.com\/threat-intelligence\/cybercrime-central-vextrio-operates-massive-criminal-affiliate-program\/\" target=\"_blank\">https:\/\/blogs.infoblox.com\/threat-intelligence\/cybercrime-central-vextrio-operates-massive-criminal-affiliate-program\/<\/a><\/li>\n<li><a href=\"https:\/\/groups.google.com\/g\/it.news.net-abuse\/search?q=lex%20tutor\" target=\"_blank\">https:\/\/groups.google.com\/g\/it.news.net-abuse\/search?q=lex%20tutor<\/a><\/li>\n<li><a href=\"https:\/\/www.ana.net\/miccontent\/show\/id\/ii-2025-02-ai-ad-fraud\" target=\"_blank\">https:\/\/www.ana.net\/miccontent\/show\/id\/ii-2025-02-ai-ad-fraud<\/a><\/li>\n<li><a href=\"https:\/\/www.ic3.gov\/AnnualReport\/Reports\/2024_IC3Report.pdf\" target=\"_blank\">https:\/\/www.ic3.gov\/AnnualReport\/Reports\/2024_IC3Report.pdf<\/a><\/li>\n<li><a href=\"https:\/\/blog.sucuri.net\/2024\/06\/socgholish-malware.html\" target=\"_blank\">https:\/\/blog.sucuri.net\/2024\/06\/socgholish-malware.html<\/a><\/li>\n<li><a href=\"https:\/\/blogs.infoblox.com\/threat-intelligence\/cyber-threat-advisory\/vextrio-ddga-domains-spread-adware-spyware-and-scam-web-forms\/\" target=\"_blank\">https:\/\/blogs.infoblox.com\/threat-intelligence\/cyber-threat-advisory\/vextrio-ddga-domains-spread-adware-spyware-and-scam-web-forms\/<\/a><\/li>\n<li><a href=\"https:\/\/www.godaddy.com\/resources\/news\/godaddy-annual-cybersecurity-report\" target=\"_blank\">https:\/\/www.godaddy.com\/resources\/news\/godaddy-annual-cybersecurity-report<\/a><\/li>\n<li><a href=\"https:\/\/blogs.infoblox.com\/threat-intelligence\/vexing-and-vicious-the-eerie-relationship-between-wordpress-hackers-and-an-adtech-cabal\/\" target=\"_blank\">https:\/\/blogs.infoblox.com\/threat-intelligence\/vexing-and-vicious-the-eerie-relationship-between-wordpress-hackers-and-an-adtech-cabal\/<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20150313013854\/http:\/tekka.it\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20150313013854\/http:\/tekka.it\/<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20121014150606\/http:\/www.tekkagroup.com\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20121014150606\/http:\/www.tekkagroup.com\/<\/a><\/li>\n<li><a href=\"https:\/\/www.linkedin.com\/company\/tekka-group\" target=\"_blank\">https:\/\/www.linkedin.com\/company\/tekka-group<\/a><\/li>\n<li><a href=\"https:\/\/www.linkedin.com\/in\/giulio-cerutti-1472611\/?originalSubdomain=ch\" target=\"_blank\">https:\/\/www.linkedin.com\/in\/giulio-cerutti-1472611\/?originalSubdomain=ch<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20170830003222\/http:\/www.tekka.it\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20170830003222\/http:\/www.tekka.it\/<\/a><\/li>\n<li><a href=\"https:\/\/www.qurium.org\/forensics\/when-kehr-meets-vextrio\/\" target=\"_blank\">https:\/\/www.qurium.org\/forensics\/when-kehr-meets-vextrio\/<\/a><\/li>\n<li><a href=\"https:\/\/www.youtube.com\/watch?v=8rLIx_wKrto\" target=\"_blank\">https:\/\/www.youtube.com\/watch?v=8rLIx_wKrto<\/a><\/li>\n<li><a href=\"https:\/\/platform.inflect.com\/building\/12-via-soldini-chiasso\/c41-ch\/datacenter\/chiasso\" target=\"_blank\">https:\/\/platform.inflect.com\/building\/12-via-soldini-chiasso\/c41-ch\/datacenter\/chiasso<\/a><\/li>\n<li><a href=\"https:\/\/blogs.infoblox.com\/threat-intelligence\/cyber-threat-advisory\/vextrio-deploys-dns-based-tds-server\/\" target=\"_blank\">https:\/\/blogs.infoblox.com\/threat-intelligence\/cyber-threat-advisory\/vextrio-deploys-dns-based-tds-server\/<\/a><\/li>\n<li><a href=\"https:\/\/blog.sucuri.net\/2024\/03\/sign1-malware-analysis-campaign-history-indicators-of-compromise.html\" target=\"_blank\">https:\/\/blog.sucuri.net\/2024\/03\/sign1-malware-analysis-campaign-history-indicators-of-compromise.html<\/a><\/li>\n<li><a href=\"https:\/\/blog.sucuri.net\/2023\/08\/from-google-dns-to-tech-support-scam-sites-unmasking-the-malware-trail.html\" target=\"_blank\">https:\/\/blog.sucuri.net\/2023\/08\/from-google-dns-to-tech-support-scam-sites-unmasking-the-malware-trail.html<\/a><\/li>\n<li><a href=\"https:\/\/blog.sucuri.net\/2024\/11\/php-reinfector-and-backdoor-malware-target-wordpress-sites.html\" target=\"_blank\">https:\/\/blog.sucuri.net\/2024\/11\/php-reinfector-and-backdoor-malware-target-wordpress-sites.html<\/a><\/li>\n<li><a href=\"https:\/\/insights.infoblox.com\/resources-whitepaper\/infoblox-whitepaper-cybercrime-central-vextrio-operates-massive-criminal-affiliate-program\/\" target=\"_blank\">https:\/\/insights.infoblox.com\/resources-whitepaper\/infoblox-whitepaper-cybercrime-central-vextrio-operates-massive-criminal-affiliate-program\/<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20100429075420\/http:\/crownstone.net\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20100429075420\/http:\/crownstone.net\/<\/a><\/li>\n<li><a href=\"https:\/\/bibliotecadelconsumidor.profeco.gob.mx\/media\/revistas\/RC-385 Marzo 2009.pdf\" target=\"_blank\">https:\/\/bibliotecadelconsumidor.profeco.gob.mx\/media\/revistas\/RC-385 Marzo 2009.pdf<\/a><\/li>\n<li><a href=\"https:\/\/www.adweek.com\/performance-marketing\/zoosk-badoo-topface-onedate-and-more-on-the-top-20-facebook-dating-apps-by-mau\/\" target=\"_blank\">https:\/\/www.adweek.com\/performance-marketing\/zoosk-badoo-topface-onedate-and-more-on-the-top-20-facebook-dating-apps-by-mau\/<\/a><\/li>\n<li><a href=\"https:\/\/www.adweek.com\/performance-marketing\/this-weeks-most-explosive-facebook-applications-23\/\" target=\"_blank\">https:\/\/www.adweek.com\/performance-marketing\/this-weeks-most-explosive-facebook-applications-23\/<\/a><\/li>\n<li><a href=\"https:\/\/datingspot24.com\/reviews\/onedate.com-experience\/\" target=\"_blank\">https:\/\/datingspot24.com\/reviews\/onedate.com-experience\/<\/a><\/li>\n<li><a href=\"https:\/\/www.aepd.es\/documento\/e-00900-2011.pdf\" target=\"_blank\">https:\/\/www.aepd.es\/documento\/e-00900-2011.pdf<\/a><\/li>\n<li><a href=\"https:\/\/trademarks.justia.com\/772\/30\/onedate-77230697.html\" target=\"_blank\">https:\/\/trademarks.justia.com\/772\/30\/onedate-77230697.html<\/a><\/li>\n<li><a href=\"https:\/\/assignments.uspto.gov\/assignments\/assignment-tm-4810-0406.pdf\" target=\"_blank\">https:\/\/assignments.uspto.gov\/assignments\/assignment-tm-4810-0406.pdf<\/a><\/li>\n<li><a href=\"https:\/\/rocketreach.co\/matteo-costa-email_48103689\" target=\"_blank\">https:\/\/rocketreach.co\/matteo-costa-email_48103689<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20111105025930\/http:\/www.tekkaweb.com:80\/customers.html\" target=\"_blank\">https:\/\/web.archive.org\/web\/20111105025930\/http:\/www.tekkaweb.com:80\/customers.html<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20111005171901\/http:\/www.tekkaweb.com\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20111005171901\/http:\/www.tekkaweb.com\/<\/a><\/li>\n<li><a href=\"https:\/\/www.linkedin.com\/company\/teknology-sa\/about\/\" target=\"_blank\">https:\/\/www.linkedin.com\/company\/teknology-sa\/about\/<\/a><\/li>\n<li><a href=\"https:\/\/annuaire-entreprises.data.gouv.fr\/entreprise\/tekka-next-812083806\" target=\"_blank\">https:\/\/annuaire-entreprises.data.gouv.fr\/entreprise\/tekka-next-812083806<\/a><\/li>\n<li><a href=\"https:\/\/business-monitor.ch\/en\/companies\/1024817-bidok-sagl\" target=\"_blank\">https:\/\/business-monitor.ch\/en\/companies\/1024817-bidok-sagl<\/a><\/li>\n<li><a href=\"https:\/\/www.moneyhouse.ch\/en\/company\/gl-holding-sa-14023417831\" target=\"_blank\">https:\/\/www.moneyhouse.ch\/en\/company\/gl-holding-sa-14023417831<\/a><\/li>\n<li><a href=\"https:\/\/www.shab.ch\/shabforms\/servlet\/Search?EID=7&#038;DOCID=5755294\" target=\"_blank\">https:\/\/www.shab.ch\/shabforms\/servlet\/Search?EID=7&#038;DOCID=5755294<\/a><\/li>\n<li><a href=\"https:\/\/business-monitor.ch\/en\/p\/marco-rufa-3689695\" target=\"_blank\">https:\/\/business-monitor.ch\/en\/p\/marco-rufa-3689695<\/a><\/li>\n<li><a href=\"https:\/\/www.zefix.ch\/de\/search\/entity\/list\/firm\/1183617\" target=\"_blank\">https:\/\/www.zefix.ch\/de\/search\/entity\/list\/firm\/1183617<\/a><\/li>\n<li><a href=\"https:\/\/www.tekkadigital.com\/press\/new-services\" target=\"_blank\">https:\/\/www.tekkadigital.com\/press\/new-services<\/a><\/li>\n<li><a href=\"https:\/\/www.northdata.com\/TEKKA DIGITAL SA, Canobbio\/CHE-303.540.263\" target=\"_blank\">https:\/\/www.northdata.com\/TEKKA DIGITAL SA, Canobbio\/CHE-303.540.263<\/a><\/li>\n<li><a href=\"https:\/\/www.slideshare.net\/slideshow\/tekka-the-new-mobile-enterteinment-era-for-mobile-users\/65543986\" target=\"_blank\">https:\/\/www.slideshare.net\/slideshow\/tekka-the-new-mobile-enterteinment-era-for-mobile-users\/65543986<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20190712114913\/https:\/www.tekkadigital.com\/press\/beseev\" target=\"_blank\">https:\/\/web.archive.org\/web\/20190712114913\/https:\/www.tekkadigital.com\/press\/beseev<\/a><\/li>\n<li><a href=\"https:\/\/nuraka.com\/onedatecom-review-scam\/\" target=\"_blank\">https:\/\/nuraka.com\/onedatecom-review-scam\/<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20230608204402\/https:\/www.adspro.eu\/about\" target=\"_blank\">https:\/\/web.archive.org\/web\/20230608204402\/https:\/www.adspro.eu\/about<\/a><\/li>\n<li><a href=\"https:\/\/www.facebook.com\/aimedteam\/\" target=\"_blank\">https:\/\/www.facebook.com\/aimedteam\/<\/a><\/li>\n<li><a href=\"https:\/\/rocketreach.co\/igor-voronin-email_121279938\" target=\"_blank\">https:\/\/rocketreach.co\/igor-voronin-email_121279938<\/a><\/li>\n<li><a href=\"https:\/\/business-monitor.ch\/de\/companies\/1063876-apexview-gmbh\/management\" target=\"_blank\">https:\/\/business-monitor.ch\/de\/companies\/1063876-apexview-gmbh\/management<\/a><\/li>\n<li><a href=\"https:\/\/www.northdata.de\/Laptsevich, Dzmitry, Praha\/sz3\" target=\"_blank\">https:\/\/www.northdata.de\/Laptsevich, Dzmitry, Praha\/sz3<\/a><\/li>\n<li><a href=\"https:\/\/or.justice.cz\/ias\/ui\/vypis-sl-detail?dokument=14213501&#038;subjektId=525992&#038;spis=161924\" target=\"_blank\">https:\/\/or.justice.cz\/ias\/ui\/vypis-sl-detail?dokument=14213501&#038;subjektId=525992&#038;spis=161924<\/a><\/li>\n<li><a href=\"https:\/\/or.justice.cz\/ias\/content\/download?id=db3de979e044479fb6d52515dd9942bc\" target=\"_blank\">https:\/\/or.justice.cz\/ias\/content\/download?id=db3de979e044479fb6d52515dd9942bc<\/a><\/li>\n<li><a href=\"https:\/\/www.linkedin.com\/in\/igor-voronin-681b2317\" target=\"_blank\">https:\/\/www.linkedin.com\/in\/igor-voronin-681b2317<\/a><\/li>\n<li><a href=\"https:\/\/www.northdata.de\/Cerutti,+Giulio+Vittorio+Leonardo,+London\/1b2e\" target=\"_blank\">https:\/\/www.northdata.de\/Cerutti,+Giulio+Vittorio+Leonardo,+London\/1b2e<\/a><\/li>\n<li><a href=\"https:\/\/www.hlidacstatu.cz\/Osoba\/DalsiDatabaze\/andrew-kunitsa\" target=\"_blank\">https:\/\/www.hlidacstatu.cz\/Osoba\/DalsiDatabaze\/andrew-kunitsa<\/a><\/li>\n<li><a href=\"https:\/\/www.crunchbase.com\/person\/kroum-vassilev\" target=\"_blank\">https:\/\/www.crunchbase.com\/person\/kroum-vassilev<\/a><\/li>\n<li><a href=\"https:\/\/ca.linkedin.com\/in\/kroum\" target=\"_blank\">https:\/\/ca.linkedin.com\/in\/kroum<\/a><\/li>\n<li><a href=\"https:\/\/www.linkedin.com\/company\/aimedglobal\/\" target=\"_blank\">https:\/\/www.linkedin.com\/company\/aimedglobal\/<\/a><\/li>\n<li><a href=\"https:\/\/www.profine-group.com\/en\/news-and-media\/\" target=\"_blank\">https:\/\/www.profine-group.com\/en\/news-and-media\/<\/a><\/li>\n<li><a href=\"https:\/\/bg.linkedin.com\/company\/immovlo\" target=\"_blank\">https:\/\/bg.linkedin.com\/company\/immovlo<\/a><\/li>\n<li><a href=\"https:\/\/bg.linkedin.com\/company\/enevlo\" target=\"_blank\">https:\/\/bg.linkedin.com\/company\/enevlo<\/a><\/li>\n<li><a href=\"https:\/\/bg.linkedin.com\/company\/kayabrands\" target=\"_blank\">https:\/\/bg.linkedin.com\/company\/kayabrands<\/a><\/li>\n<li><a href=\"https:\/\/adtailor.com\/aboutus.jsp\" target=\"_blank\">https:\/\/adtailor.com\/aboutus.jsp<\/a><\/li>\n<li><a href=\"https:\/\/www.advage.com\/\" target=\"_blank\">https:\/\/www.advage.com\/<\/a><\/li>\n<li><a href=\"https:\/\/smartbranding.com\/names-with-stories-the-story-behind-bookmark-com\/\" target=\"_blank\">https:\/\/smartbranding.com\/names-with-stories-the-story-behind-bookmark-com\/<\/a><\/li>\n<li><a href=\"https:\/\/www.instagram.com\/kroum\/\" target=\"_blank\">https:\/\/www.instagram.com\/kroum\/<\/a><\/li>\n<li><a href=\"https:\/\/www.facebook.com\/kroum\/\" target=\"_blank\">https:\/\/www.facebook.com\/kroum\/<\/a><\/li>\n<li><a href=\"https:\/\/www.youtube.com\/watch?v=f_jBRq7Gd_Y\" target=\"_blank\">https:\/\/www.youtube.com\/watch?v=f_jBRq7Gd_Y<\/a><\/li>\n<li><a href=\"https:\/\/www.instagram.com\/p\/Bb2HrBCj3XG\/?img_index=1\" target=\"_blank\">https:\/\/www.instagram.com\/p\/Bb2HrBCj3XG\/?img_index=1<\/a><\/li>\n<li><a href=\"https:\/\/www.reddit.com\/r\/breakingbad\/comments\/75uvjn\/los_pollos_hermanos_one_taste_and_you_will_know\/\" target=\"_blank\">https:\/\/www.reddit.com\/r\/breakingbad\/comments\/75uvjn\/los_pollos_hermanos_one_taste_and_you_will_know\/<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20241226171437\/https:\/www.portomontenegro.com\/shop-and-dine\/holacode\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20241226171437\/https:\/www.portomontenegro.com\/shop-and-dine\/holacode\/<\/a><\/li>\n<li><a href=\"https:\/\/www.holacode.dev\/\" target=\"_blank\">https:\/\/www.holacode.dev\/<\/a><\/li>\n<li><a href=\"http:\/\/www.podaci.net\/dodaci\/CGO\/OGLASI\/OGL-2022-17.pdf\" target=\"_blank\">http:\/\/www.podaci.net\/dodaci\/CGO\/OGLASI\/OGL-2022-17.pdf<\/a><\/li>\n<li><a href=\"https:\/\/biznis.rs\/vesti\/region\/malim-firmama-je-tesko-da-dodju-do-dobrih-programera\/\" target=\"_blank\">https:\/\/biznis.rs\/vesti\/region\/malim-firmama-je-tesko-da-dodju-do-dobrih-programera\/<\/a><\/li>\n<li><a href=\"https:\/\/tacolo.co\/\" target=\"_blank\">https:\/\/tacolo.co\/<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20240826003029\/https:\/www.lospollos.com\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20240826003029\/https:\/www.lospollos.com\/<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20241222190204\/http:\/adtrafico.com\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20241222190204\/http:\/adtrafico.com\/<\/a><\/li>\n<li><a href=\"https:\/\/www.qurium.org\/press-releases\/when-kehr-meets-vextrio-2\/\" target=\"_blank\">https:\/\/www.qurium.org\/press-releases\/when-kehr-meets-vextrio-2\/<\/a><\/li>\n<li><a href=\"https:\/\/help.archive.org\/help\/how-do-i-request-to-remove-something-from-archive-org\/\" target=\"_blank\">https:\/\/help.archive.org\/help\/how-do-i-request-to-remove-something-from-archive-org\/<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20240930220720\/https:\/adspro.group\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20240930220720\/https:\/adspro.group\/<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20190205204834\/http:\/adsprodigital.com\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20190205204834\/http:\/adsprodigital.com\/<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20240108235212\/https:\/apperito.com\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20240108235212\/https:\/apperito.com\/<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20240421142126\/https:\/locomind.net\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20240421142126\/https:\/locomind.net\/<\/a><\/li>\n<li><a href=\"https:\/\/apkpure.net\/developer\/LocoMind\" target=\"_blank\">https:\/\/apkpure.net\/developer\/LocoMind<\/a><\/li>\n<li><a href=\"https:\/\/apkpure.net\/app-booster-lite-ram-cleaner\/com.app.booster.lite.phonecleaner.batterysaver.cleanmaster\" target=\"_blank\">https:\/\/apkpure.net\/app-booster-lite-ram-cleaner\/com.app.booster.lite.phonecleaner.batterysaver.cleanmaster<\/a><\/li>\n<li><a href=\"https:\/\/apkpure.net\/fast-vpn-super-proxy\/com.vpn.proxy.secure.wifi.turbovpn\" target=\"_blank\">https:\/\/apkpure.net\/fast-vpn-super-proxy\/com.vpn.proxy.secure.wifi.turbovpn<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20250623130935\/https:\/www.datasnap.ch\/en\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20250623130935\/https:\/www.datasnap.ch\/en\/<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20241226183020\/https:\/articheck.ch\/en\/chunk-7EF5A3DJ.js\" target=\"_blank\">https:\/\/web.archive.org\/web\/20241226183020\/https:\/articheck.ch\/en\/chunk-7EF5A3DJ.js<\/a><\/li>\n<li><a href=\"https:\/\/youtu.be\/ardkiNptT1M?t=45\" target=\"_blank\">https:\/\/youtu.be\/ardkiNptT1M?t=45<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20200919052930\/https:\/www.adsbridge.com\/smartoffers\" target=\"_blank\">https:\/\/web.archive.org\/web\/20200919052930\/https:\/www.adsbridge.com\/smartoffers<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20240420070135\/https:\/www.adsbridge.com\/smartoffers\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20240420070135\/https:\/www.adsbridge.com\/smartoffers\/<\/a><\/li>\n<li><a href=\"https:\/\/www.adsbridge.com\/smartoffers\/\" target=\"_blank\">https:\/\/www.adsbridge.com\/smartoffers\/<\/a><\/li>\n<li><a href=\"https:\/\/www.adsbridge.com\/contact-us\/\" target=\"_blank\">https:\/\/www.adsbridge.com\/contact-us\/<\/a><\/li>\n<li><a href=\"http:\/\/lospollos.com\/\" target=\"_blank\">http:\/\/lospollos.com\/<\/a><\/li>\n<li><a href=\"https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-63\" target=\"_blank\">https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-63<\/a><\/li>\n<li><a href=\"https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-32\" target=\"_blank\">https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-32<\/a><\/li>\n<li><a href=\"https:\/\/youtu.be\/1SV4PYo76OE\" target=\"_blank\">https:\/\/youtu.be\/1SV4PYo76OE<\/a><\/li>\n<li><a href=\"https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-36\" target=\"_blank\">https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-36<\/a><\/li>\n<li><a href=\"https:\/\/www.youtube.com\/watch?v=ysPJdEykcZA\" target=\"_blank\">https:\/\/www.youtube.com\/watch?v=ysPJdEykcZA<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20240810135147\/https:\/blog.tacolo.co\/how-to-monetize-traffic-with-tacoloco-a-complete-guide\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20240810135147\/https:\/blog.tacolo.co\/how-to-monetize-traffic-with-tacoloco-a-complete-guide\/<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20240810130046\/https:\/blog.tacolo.co\/script-for-collecting-push-subscriptions-from-tacoloco-how-to-use-it-and-who-can-earn\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20240810130046\/https:\/blog.tacolo.co\/script-for-collecting-push-subscriptions-from-tacoloco-how-to-use-it-and-who-can-earn\/<\/a><\/li>\n<li><a href=\"https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-44\" target=\"_blank\">https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-44<\/a><\/li>\n<li><a href=\"https:\/\/www.linkedin.com\/in\/marius-gjura\/?originalSubdomain=nl\" target=\"_blank\">https:\/\/www.linkedin.com\/in\/marius-gjura\/?originalSubdomain=nl<\/a><\/li>\n<li><a href=\"https:\/\/www.linkedin.com\/in\/marius-gjura-832388149\/?originalSubdomain=al\" target=\"_blank\">https:\/\/www.linkedin.com\/in\/marius-gjura-832388149\/?originalSubdomain=al<\/a><\/li>\n<li><a href=\"https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-33\" target=\"_blank\">https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-33<\/a><\/li>\n<li><a href=\"https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-42\" target=\"_blank\">https:\/\/www.blackhatworld.com\/seo\/lospollos-global-smart-link-affiliate-program-weekly-payments-24-7-support.962481\/page-42<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20250418231441\/https:\/www.adtrafico.com\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20250418231441\/https:\/www.adtrafico.com\/<\/a><\/li>\n<li><a href=\"https:\/\/www.blackhatworld.com\/seo\/adtrafico-reliable-network-for-media-buyers-sweepstakes-dating-mobile-billing-and-more.1320953\/\" target=\"_blank\">https:\/\/www.blackhatworld.com\/seo\/adtrafico-reliable-network-for-media-buyers-sweepstakes-dating-mobile-billing-and-more.1320953\/<\/a><\/li>\n<li><a href=\"https:\/\/www.blackhatworld.com\/seo\/is-anyone-running-blank-checkout-offers.1572832\/\" target=\"_blank\">https:\/\/www.blackhatworld.com\/seo\/is-anyone-running-blank-checkout-offers.1572832\/<\/a><\/li>\n<li><a href=\"https:\/\/partnerkin.com\/en\/blog\/publications\/ecom_blank_sweeps\" target=\"_blank\">https:\/\/partnerkin.com\/en\/blog\/publications\/ecom_blank_sweeps<\/a><\/li>\n<li><a href=\"https:\/\/imgur.com\/a\/1O31sdd\" target=\"_blank\">https:\/\/imgur.com\/a\/1O31sdd<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20241228001607\/https:\/partnerkin.com\/en\/blog\/publications\/ecom_blank_sweeps\" target=\"_blank\">https:\/\/web.archive.org\/web\/20241228001607\/https:\/partnerkin.com\/en\/blog\/publications\/ecom_blank_sweeps<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20241012212642\/https:\/www.adtrafico.com\/blog\/top-3-offers-of-the-week-102\/\" target=\"_blank\">https:\/\/web.archive.org\/web\/20241012212642\/https:\/www.adtrafico.com\/blog\/top-3-offers-of-the-week-102\/<\/a><\/li>\n<li><a href=\"https:\/\/www.blackhatworld.com\/seo\/adtrafico-reliable-network-for-media-buyers-sweepstakes-dating-mobile-billing-and-more.1320953\/page-23\" target=\"_blank\">https:\/\/www.blackhatworld.com\/seo\/adtrafico-reliable-network-for-media-buyers-sweepstakes-dating-mobile-billing-and-more.1320953\/page-23<\/a><\/li>\n<li><a href=\"https:\/\/krebsonsecurity.com\/2025\/06\/inside-a-dark-adtech-empire-fed-by-fake-captchas\/\" target=\"_blank\">https:\/\/krebsonsecurity.com\/2025\/06\/inside-a-dark-adtech-empire-fed-by-fake-captchas\/<\/a><\/li>\n<li><a href=\"https:\/\/advidi.com\/\" target=\"_blank\">https:\/\/advidi.com\/<\/a><\/li>\n<li><a href=\"https:\/\/mikeschwalbachadvidi.wordpress.com\/\" target=\"_blank\">https:\/\/mikeschwalbachadvidi.wordpress.com\/<\/a><\/li>\n<li><a href=\"https:\/\/github.com\/infobloxopen\/threat-intelligence\/tree\/main\" target=\"_blank\">https:\/\/github.com\/infobloxopen\/threat-intelligence\/tree\/main<\/a><\/li>\n<li><a href=\"https:\/\/www.facebook.com\/igor.itpark.7\" target=\"_blank\">https:\/\/www.facebook.com\/igor.itpark.7<\/a><\/li>\n<\/ol>\n<style>\n.savy-seahorse-table {font-size:14px;word-break: keep-all;}.savy-seahorse-table td:last-child, .savy-seahorse-table th:last-child {padding-right:10px;}.code-format {\tfont-family: 'Courier New';}.image-caption {    font-size: 12px;margin-top:auto;}.list-spacing li{margin-bottom:20px}.img-container, .img-container-3-col {display: flex;}.img-container img {    width: 40%;    margin-bottom: 10px;    height: max-content !important;}.img-container-3-col img {width: 30%;margin-bottom: 10px;}@media (max-width: 767px) {.img-container, .img-container-3-col {display: block;}.img-container img, .img-container-3-col img {width: 100%;}.grid-container {    grid-template-columns: 1fr!important;  }}@media (min-width: 767px) {.img-50{width:50%;}}.grid-container {  display: grid;  grid-template-columns: repeat(2, 1fr);  gap: 40px;  max-width: 800px;  margin: 0 auto;  align-items: stretch;}.grid-item {   display: flex;  flex-direction: column;  justify-content: flex-start;}.grid-item img {  width: 100%;  height: auto;}<\/style>\n<p><script>\njQuery('.single h1').html('<span class=\"gradient\">VexTrio\u2019s Origin Story <\/span>: From Spam to Scam to Adtech');\n<\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u201cEveryone knows that eliminating spam is impossible to achieve, until an ignorant person who doesn\u2019t know this comes along and starts sending some (Italian) spammer to jail. &lt;beg&gt;\u201d \u2014Lex Tutor, 2011 This quote is powerful when you realize that it is referring to progenitors of the notorious VexTrio traffic distribution system (TDS). \u201cLex Tutor\u201d was [&hellip;]<\/p>\n","protected":false},"author":397,"featured_media":12113,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[254],"tags":[709,902,592,1287,1288],"class_list":{"0":"post-12088","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-threat-intelligence","8":"tag-vextrio","9":"tag-tds","10":"tag-ecosystem","11":"tag-malicious-advertising","12":"tag-spam-operation","13":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>VexTrio Unveiled: Inside the Notorious Scam Enterprise<\/title>\n<meta name=\"description\" content=\"We expose adtech operators who partner with malware threat actors to commit digital fraud on a global scale through their affiliate advertising networks\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"VexTrio Unveiled: Inside the Notorious Scam Enterprise\" \/>\n<meta property=\"og:description\" content=\"We expose adtech operators who partner with malware threat actors to commit digital fraud on a global scale through their affiliate advertising networks.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2025-08-06T19:55:34+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-08-12T18:43:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"906\" \/>\n\t<meta property=\"og:image:height\" content=\"573\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Infoblox Threat Intel\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"VexTrio Unveiled: Inside the Notorious Scam Enterprise\" \/>\n<meta name=\"twitter:description\" content=\"We expose adtech operators who partner with malware threat actors to commit digital fraud on a global scale through their affiliate advertising networks.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-1.jpg\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Infoblox Threat Intel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"40 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/vextrios-origin-story-from-spam-to-scam-to-adtech\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/vextrios-origin-story-from-spam-to-scam-to-adtech\\\/\"},\"author\":{\"name\":\"Infoblox Threat Intel\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\"},\"headline\":\"VexTrio\u2019s Origin Story: From Spam to Scam to Adtech\",\"datePublished\":\"2025-08-06T19:55:34+00:00\",\"dateModified\":\"2025-08-12T18:43:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/vextrios-origin-story-from-spam-to-scam-to-adtech\\\/\"},\"wordCount\":8181,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/vextrios-origin-story-from-spam-to-scam-to-adtech\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/vextrios-origin-story-from-spam-to-scam-to-adtech-1.jpg\",\"keywords\":[\"VexTrio\",\"TDS\",\"Ecosystem\",\"Malicious Advertising\",\"Spam Operation\"],\"articleSection\":[\"Infoblox Threat Intel\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/vextrios-origin-story-from-spam-to-scam-to-adtech\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/vextrios-origin-story-from-spam-to-scam-to-adtech\\\/\",\"name\":\"VexTrio Unveiled: Inside the Notorious Scam Enterprise\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/vextrios-origin-story-from-spam-to-scam-to-adtech\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/vextrios-origin-story-from-spam-to-scam-to-adtech\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/vextrios-origin-story-from-spam-to-scam-to-adtech-1.jpg\",\"datePublished\":\"2025-08-06T19:55:34+00:00\",\"dateModified\":\"2025-08-12T18:43:59+00:00\",\"description\":\"We expose adtech operators who partner with malware threat actors to commit digital fraud on a global scale through their affiliate advertising networks\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/vextrios-origin-story-from-spam-to-scam-to-adtech\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/vextrios-origin-story-from-spam-to-scam-to-adtech\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/vextrios-origin-story-from-spam-to-scam-to-adtech\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/vextrios-origin-story-from-spam-to-scam-to-adtech-1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/vextrios-origin-story-from-spam-to-scam-to-adtech-1.jpg\",\"width\":906,\"height\":573},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/threat-intelligence\\\/vextrios-origin-story-from-spam-to-scam-to-adtech\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Infoblox Threat Intel\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/threat-intelligence\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"VexTrio\u2019s Origin Story: From Spam to Scam to Adtech\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/b6aed8965e3298a0817c16d32c0a67ae\",\"name\":\"Infoblox Threat Intel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"url\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"contentUrl\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/avatar_user_397_1714162589-96x96.png\",\"caption\":\"Infoblox Threat Intel\"},\"description\":\"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/infoblox-threat-intel\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"VexTrio Unveiled: Inside the Notorious Scam Enterprise","description":"We expose adtech operators who partner with malware threat actors to commit digital fraud on a global scale through their affiliate advertising networks","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/","og_locale":"en_US","og_type":"article","og_title":"VexTrio Unveiled: Inside the Notorious Scam Enterprise","og_description":"We expose adtech operators who partner with malware threat actors to commit digital fraud on a global scale through their affiliate advertising networks.","og_url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/","og_site_name":"Infoblox Blog","article_published_time":"2025-08-06T19:55:34+00:00","article_modified_time":"2025-08-12T18:43:59+00:00","og_image":[{"width":906,"height":573,"url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-1.jpg","type":"image\/jpeg"}],"author":"Infoblox Threat Intel","twitter_card":"summary_large_image","twitter_title":"VexTrio Unveiled: Inside the Notorious Scam Enterprise","twitter_description":"We expose adtech operators who partner with malware threat actors to commit digital fraud on a global scale through their affiliate advertising networks.","twitter_image":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-1.jpg","twitter_misc":{"Written by":"Infoblox Threat Intel","Est. reading time":"40 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/#article","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/"},"author":{"name":"Infoblox Threat Intel","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae"},"headline":"VexTrio\u2019s Origin Story: From Spam to Scam to Adtech","datePublished":"2025-08-06T19:55:34+00:00","dateModified":"2025-08-12T18:43:59+00:00","mainEntityOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/"},"wordCount":8181,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-1.jpg","keywords":["VexTrio","TDS","Ecosystem","Malicious Advertising","Spam Operation"],"articleSection":["Infoblox Threat Intel"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/","url":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/","name":"VexTrio Unveiled: Inside the Notorious Scam Enterprise","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/#primaryimage"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-1.jpg","datePublished":"2025-08-06T19:55:34+00:00","dateModified":"2025-08-12T18:43:59+00:00","description":"We expose adtech operators who partner with malware threat actors to commit digital fraud on a global scale through their affiliate advertising networks","breadcrumb":{"@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-1.jpg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/vextrios-origin-story-from-spam-to-scam-to-adtech-1.jpg","width":906,"height":573},{"@type":"BreadcrumbList","@id":"https:\/\/www.infoblox.com\/blog\/threat-intelligence\/vextrios-origin-story-from-spam-to-scam-to-adtech\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Infoblox Threat Intel","item":"https:\/\/www.infoblox.com\/blog\/category\/threat-intelligence\/"},{"@type":"ListItem","position":3,"name":"VexTrio\u2019s Origin Story: From Spam to Scam to Adtech"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/b6aed8965e3298a0817c16d32c0a67ae","name":"Infoblox Threat Intel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","url":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","contentUrl":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/avatar_user_397_1714162589-96x96.png","caption":"Infoblox Threat Intel"},"description":"Infoblox Threat Intel is the leading creator of original DNS threat intelligence, distinguishing itself in a sea of aggregators. What sets us apart? Two things: mad DNS skills and unparalleled visibility. DNS is notoriously tricky to interpret and hunt from, but our deep understanding and unique access to the internet's inner workings allow us to track down threat actors that others can't see. We're proactive, not just defensive, using our insights to disrupt cybercrime where it begins. We also believe in sharing knowledge to support the broader security community by publishing detailed research and releasing indicators on GitHub. In addition, our intel is seamlessly integrated into our Infoblox Protective DNS solutions, so customers automatically get its benefits, along with ridiculously low false positive rates.","url":"https:\/\/www.infoblox.com\/blog\/author\/infoblox-threat-intel\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/12088","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/397"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=12088"}],"version-history":[{"count":3,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/12088\/revisions"}],"predecessor-version":[{"id":12116,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/12088\/revisions\/12116"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/12113"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=12088"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=12088"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=12088"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}