{"id":6139,"date":"2025-08-14T10:03:33","date_gmt":"2025-08-14T10:03:33","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/14\/vextrio-hackers-attacking-users-via-fake-captcha-robots-and-malicious-apps-into-google-play-and-app-store\/"},"modified":"2025-08-14T10:03:33","modified_gmt":"2025-08-14T10:03:33","slug":"vextrio-hackers-attacking-users-via-fake-captcha-robots-and-malicious-apps-into-google-play-and-app-store","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/14\/vextrio-hackers-attacking-users-via-fake-captcha-robots-and-malicious-apps-into-google-play-and-app-store\/","title":{"rendered":"VexTrio Hackers Attacking Users via Fake CAPTCHA Robots and Malicious Apps into Google Play and App Store"},"content":{"rendered":"<p>    VexTrio Hackers Attacking Users via Fake CAPTCHA Robots and Malicious Apps into Google Play and App Store<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated cybercriminal organization known as VexTrio has been orchestrating a massive fraud empire through deceptive CAPTCHA robots and malicious applications distributed across Google Play and the App Store.<\/p>\n<p>This criminal network, operating for over 15 years, has successfully infiltrated legitimate app stores with fraudulent software that has collectively garnered over one million downloads, while simultaneously conducting extensive spam campaigns targeting millions of users worldwide.<\/p>\n<p>The threat actors behind VexTrio employ a multi-pronged attack strategy that combines <a href=\"https:\/\/cybersecuritynews.com\/lumma-stealer-exploits-fake-captcha-pages\/\" target=\"_blank\" rel=\"noreferrer noopener\">fake CAPTCHA<\/a> verification systems with malicious mobile applications to harvest user data and generate revenue through subscription fraud.<\/p>\n<p>Their infamous robot CAPTCHA prompts users with messages like \u201cPRESS THE \u2018ALLOW\u2019 BUTTON TO VERIFY YOU\u2019RE HUMAN!\u201d which serves as a gateway to their broader criminal ecosystem.<\/p>\n<p>This deceptive interface has become synonymous with VexTrio operations and has been documented in numerous security reports over the years.<\/p>\n<p>VexTrio\u2019s operations extend far beyond simple spam, encompassing a comprehensive traffic distribution system (TDS) that delivers fraudulent content across multiple verticals including dating, cryptocurrency, and sweepstakes scams.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEh2q1VRWq7m6B1uGCmJyVY3XsC8Q5i8-hnPsSCRm_yZXEB79OT5xEZQszEY7V0p5q9QP6BQ3PHBH6owSB37gQvRWQ8YokyxbrTuAsXEcHm52XWchuIEPYUK_VPICodGpXmOUq7DRkhVKEVGqJcetL0iJhHxtA-XM094W_exNSNbGRyXhjhyphenhyphen2jcTgRTzpGQ\/s16000\/Scam%2520landing%2520pages%2520%28Source%2520-%2520Infoblox%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Scam landing pages (Source \u2013 Infoblox)<\/figcaption><\/figure>\n<\/div>\n<p>Infoblox analysts <a href=\"https:\/\/blogs.infoblox.com\/threat-intelligence\/vextrio-unmasked-a-legacy-of-spam-and-homegrown-scams\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> that the organization controls the majority of landing pages delivered through their smartlinks, benefiting doubly from their affiliate network operations.<\/p>\n<p>The group\u2019s infrastructure reveals a complex web of shell companies and technical partnerships that blur the lines between legitimate business and cybercrime.<\/p>\n<p>The criminal organization has developed an extensive portfolio of malicious applications masquerading as legitimate services.<\/p>\n<p>Their app catalog includes fake VPNs, device monitoring tools, spam blockers, and dating applications published under various developer names including HolaCode, LocoMind, Hugmi, Klover Group, and AlphaScale Media.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgAt3dQy7Fhq1nTi7tlndeQK59WZVqdrBJjk22dNPvP_7UEMBJ5Zvpo8C8D3HecM8-PIFhdDB3A2p7N05gobL0Fr2197UQ54CsbhPDb68LvtN68xfFjqxLTINWUsPU706EWW6oe-kL5UuGZzqIMkWFsER20Kffmku5Bw3wPQL_sJfgNf2-35qLsXzMqK_U\/s16000\/Google%2520Play%2520page%2520for%2520the%2520Spam%2520Shield%2520app%2520listed%2520as%2520developed%2520by%2520HolaCode%2520in%2520December%25202024%2520and%2520ApLabz%2520in%2520early%25202025%2520%28Source%2520-%2520Infoblox%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Google Play page for the Spam Shield app listed as developed by HolaCode in December 2024 and ApLabz in early 2025 (Source \u2013 Infoblox)<\/figcaption><\/figure>\n<\/div>\n<p>These applications employ sophisticated social engineering techniques to extract subscription fees from unsuspecting users while bombarding them with intrusive advertisements.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-infection-mechanism-and-persistence-tactics\"><strong>Infection Mechanism and Persistence Tactics<\/strong><\/h2>\n<p>VexTrio\u2019s mobile applications utilize a carefully orchestrated infection chain that begins with seemingly legitimate functionality before transitioning to malicious behavior.<\/p>\n<p>Their spam blocker application, Spam Shield, exemplifies this approach by initially providing basic notification blocking services while displaying fabricated security reports.<\/p>\n<p>The application presents users with <a href=\"https:\/\/cybersecuritynews.com\/paid-search-monitoring-the-overlooked-cybersecurity-risk-you-cant-afford-to-ignore\/\" target=\"_blank\" rel=\"noreferrer noopener\">fake monitoring<\/a> interfaces showing blocked spam and malicious notifications, creating an illusion of protection that justifies subscription fees.<\/p>\n<p>The technical implementation reveals DNS records linking malicious applications to VexTrio\u2019s infrastructure.<\/p>\n<p>DNS analysis shows that IP address 136.243.216.249 simultaneously hosts HolaCode, AdsPro Digital, Los Pollos, and multiple scam applications, demonstrating the interconnected nature of their operations.<\/p>\n<p>The applications employ residential proxy networks disguised as VPN services, raising significant privacy concerns as user traffic becomes part of their proxy infrastructure.<\/p>\n<p>VexTrio\u2019s <a href=\"https:\/\/cybersecuritynews.com\/detecting-and-responding-to-new-nation-state-persistence-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">persistence<\/a> strategy extends beyond individual applications to encompass an entire ecosystem of fraudulent services.<\/p>\n<p>Their email marketing operations utilize lookalike domains of established services such as SendGrid and MailGun, with domains like sendgrid.rest and mailgun.fun configured with specific SPF records that authorize mail servers at IP address 78.47.103.187.<\/p>\n<p>This infrastructure supports massive spam <a href=\"https:\/\/cybersecuritynews.com\/incorporating-cybersec-credentials-into-marketing-campaigns\/\" target=\"_blank\" rel=\"noreferrer noopener\">campaigns<\/a> that feed victims into their application ecosystem, creating a self-reinforcing cycle of fraud that has enabled the organization to operate with impunity for over a decade while generating substantial criminal profits through subscription scams and data harvesting.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong><code>Boost\u00a0your\u00a0SOC and help your team protect your business with free top-notch threat intelligence:\u00a0<a href=\"https:\/\/intelligence.any.run\/plans\/?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=alert_fatigue&amp;utm_content=lookup_plan&amp;utm_term=120825\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Request TI Lookup Premium Trial<\/a>.<\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/vextrio-hackers-attacking-users-via-fake-captcha-robots\/\">VexTrio Hackers Attacking Users via Fake CAPTCHA Robots and Malicious Apps into Google Play and App Store<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/vextrio-hackers-attacking-users-via-fake-captcha-robots\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>VexTrio Hackers Attacking Users via Fake CAPTCHA Robots and Malicious Apps into Google Play and App Store A sophisticated cybercriminal organization known as VexTrio has been orchestrating a massive fraud empire through deceptive CAPTCHA robots and malicious applications distributed across Google Play and the App Store. This criminal network, operating for over 15 years, has [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-6139","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6139"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6139"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6139\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6139"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6139"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6139"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}