Course

Traffic Distribution Systems in the Cybercrime Ecosystem

About this learning content: Courses, lessons, assessments, explanations and illustrations may be created with the help of artificial intelligence. We review and check the material and do our best to avoid incorrect or outdated information, but mistakes, omissions or ambiguous questions may remain. Please verify information before relying on it for professional, security, legal or operational decisions. Read the full notice or report an issue.
Difficulty Intermediate
Modules 4
Lessons 13
Time 11 hr 9 min
Language en
Created by Threat Intelligence Lab
Updated 11 September 2026
Traffic Distribution Systems in the Cybercrime Ecosystem learning journeyA light-theme visual introduction to the learner journey through this course.THREAT INTELLIGENCE LAB • 2026Traffic Distribution Systems in the Cybercrime EcosystemTRAFFICTDSFILTER & ROUTEDECOYHARMFUL PATH

About this course

An expanded defensive threat-intelligence course built around named case studies and dated evidence. Learners examine Keitaro abuse, ParrotTDS, 404 TDS, Prometheus/Cookie Reloaded, VexTrio, TAG-124/KongTuke, zTDS/DriveSurge, BlackTDS, CloudFront-assisted routing, and bulletproof-hosting providers. It teaches chain reconstruction, network context, cloaking, safe collection, analytic confidence, detection, and disruption while distinguishing legitimate technology, compromised infrastructure, criminal services, and researcher-assigned cluster names.

What you'll learn

  • Explain the complete traffic path from acquisition through TDS classification to decoy, scam, phishing, malware, or monetization outcomes.
  • Distinguish product names, criminal services, actor labels, campaign names, and overlapping researcher terminology.
  • Reconstruct dated case studies involving named TDS platforms and record the networks and services visible at each stage.
  • Explain how bulletproof hosting, compromised sites, shared hosting, CDNs, DNS, and upstream providers can support different parts of the ecosystem.
  • Collect and analyze TDS evidence safely while preserving time, vantage, provenance, confidence, and alternative explanations.
  • Design layered detections and disruption actions that remain useful after domains and infrastructure rotate.

Before you begin

You will get more from this course if these foundations are already familiar.

  • Basic web and threat-intelligence knowledge — Learners should understand URLs, domains, DNS, IP addresses, HTTP responses, browser redirects, and basic intelligence concepts such as indicators and confidence.

Course content