Infoblox reported that the VexTrio cybercriminal network operated a large traffic distribution and scam-enablement ecosystem that relied on DNS manipulation, compromised routers, and hosting infrastructure to steer victims to malicious content. The reporting links VexTrio to Savvy Seahorse, a campaign that used Facebook ads and fake investment brands to lure users onto fraudulent trading platforms, with DNS services helping conceal the underlying infrastructure and redirect traffic through intermediary domains and systems.
A later Infoblox investigation said the operation also leveraged compromised SOHO routers, a traffic distribution system (TDS), and infrastructure associated with Aeza Networks to mask backend services and route victims based on geography, device, or campaign logic. Together, the findings describe a resilient criminal ecosystem that blended ad-driven social engineering with covert DNS and network-layer redirection to support investment fraud and other malicious web operations at scale.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Infoblox reported on a traffic distribution system hidden in Aeza Networks infrastructure and tied it to compromised routers and DNS abuse. The publication revealed additional technical details about the infrastructure supporting malicious traffic routing.
Infoblox published a threat-intelligence profile describing VexTrio as a large cybercriminal network. The report consolidated public technical details about the group's infrastructure and role in malicious online activity.
Infoblox published research examining how malicious traffic distribution systems route victims from initial clicks to harmful destinations. The report publicly documented TDS techniques and infrastructure used to steer users into cybercriminal activity.
The Five Eyes governments released a joint cybersecurity advisory on the Chinese state-sponsored threat actor Volt Typhoon, detailing its activity and tradecraft. The advisory marked a coordinated public warning and attribution effort by allied authorities.
Infoblox published research on the Savvy Seahorse operation, describing how the threat actor used Facebook ads and DNS infrastructure to lure victims to fraudulent investment platforms. The report publicly exposed the campaign's social engineering and infrastructure tactics.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
blogs.infoblox.com
Open sourceinfoblox.com
Open sourceinfoblox.com
Open sourceinfoblox.com
Open sourceinfoblox.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.