Cybersecurity researchers from Infoblox have revealed new research on VexTrio, a “massive criminal affiliate program” that the team says counts more than five dozen criminal organizations in its customer list.

As explained by the researchers, VexTrio is a complex, and massive, traffic direction system (TDS). It operates similarly to a legitimate marketing affiliate network, in that a threat actor will forward victim traffic from their own services (for example, compromised websites) to a TDS server under VexTrio’s control. 

