VexTrio: Affiliate Traffic and DNS Routing
Study a large affiliate ecosystem connecting compromised websites, SocGholish, ClearFake, Keitaro, and DNS-based routing.
In this lesson, you will learn to:
- Map VexTrio affiliate and routing relationships.
- Explain DNS-based TDS behavior and shared-hosting implications.
VexTrio: Affiliate Traffic and DNS Routing
Uses Infoblox research to examine VexTrio’s affiliate model, shared hosting migration, DNS TXT redirection, Google Public DNS use, and limits of actor naming.
VexTrio sits between affiliates and destinations
Infoblox describes VexTrio as a long-running malicious traffic-broker ecosystem that accepts traffic from affiliates and routes it toward scams, browser hijackers, adware, spyware, and other destinations. Its 2024 research identified relationships in which SocGholish and ClearFake sent victims into VexTrio. One observed ClearFake chain used a ClearFake-operated Keitaro instance before opening a VexTrio URL.
VexTrio query parameters can identify traffic source, affiliate, and campaign. Those values are valuable relationship evidence, but their meaning must be derived from repeated observation and source reporting. An affiliate can control the compromised-site injection while VexTrio controls later routing. Multiple actors can occupy one chain, so shared traffic does not collapse them into one organization.
DNS can carry the next destination
Infoblox documented VexTrio-injected JavaScript querying a malicious DNS TDS for TXT data that encoded the next URL. One reported implementation communicated through Google Public DNS. This can evade controls focused only on HTTP URLs because the navigation instruction arrives through DNS before the browser visits the next host.
Collect the query name, resolver, TXT response, decoded value, timing, injected script, and subsequent navigation. Google Public DNS is a legitimate resolver used as transport in the observed chain; it is not VexTrio infrastructure. The actor-controlled names and authoritative behavior matter. Defenders can combine unusual browser-driven DNS queries, known injection patterns, redirect destinations, and endpoint context.
The network footprint moved toward shared providers
Infoblox reported in 2024 that the known VexTrio domain population exceeded 70,000 and that more than 55 percent of domains once assigned to dedicated infrastructure had moved to shared hosting. It also described a DNS-based TDS first observed in late December 2023. These figures describe the researchers’ corpus and observation period; they are not an internet-wide census.
Shared hosting complicates IP blocking because unrelated sites can share an address. Prefer domain, DNS, content, and behavioral evidence with time windows. Hosting movement may be an evasion or cost choice, but the provider’s legitimacy cannot be inferred from one customer. Disruption at the traffic-broker layer can affect many destinations, while remediation of compromised WordPress sites reduces the incoming supply.
Resources
- Infoblox: VexTrio Affiliate Program — Study VexTrio relationships, ClearFake’s Keitaro handoff, DNS routing, domain scale, and shared-hosting migration.
- Infoblox: VexTrio DNS TDS — Review the DNS TXT redirect mechanism and Google Public DNS transport observation.