Infoblox Threat Intelligence (ITI) with Dave Mitchell
Dave Mitchell will introduce the Infoblox Threat Intelligence (ITI) team, highlighting its specialized focus and unique capabilities in DNS-based security. He’ll explore the evolving threat landscape, sharing insights into emerging attack vectors and adversary tactics. The session will demonstrate how Infoblox’s deep expertise in DNS enables superior threat detection and protection. Attendees will gain a clear understanding of what sets Infoblox apart in the cybersecurity ecosystem. As a “recovering operator,” Mitchell explained that his team’s sole focus is DNS, a namespace so vast that it offers attackers near-infinite room to operate. He emphasized that Infoblox’s intelligence is entirely original and not repackaged from other sources. Their process involves a reputation system where algorithms analyze newly registered domains, clustering suspicious ones based on shared attributes like registration patterns and name server behavior. Human researchers then investigate these clusters to identify, name, and track threat actors, building robust signatures that can follow adversaries even as they adapt their tactics. This proactive approach results in a “low regret” security posture, blocking domains that users have no legitimate reason to visit.
This DNS-centric intelligence allows Infoblox to provide “protection before impact.” Mitchell shared that over a recent 90-day period, their system already contained 75% of malicious domains before a single customer query was ever made to them. This is possible because the team observes threat actor infrastructure as it’s being built. A significant portion of the presentation focused on the growing threat of malicious advertising technology (“malvertising”). He detailed how threat actors operate sophisticated Traffic Distribution Systems (TDS) that function like legitimate ad-tech platforms but serve malicious content. These systems use cloaking techniques to profile visitors, redirecting them to scams, info-stealers, or fake software updates only if they match specific criteria, while sending researchers or bots to harmless decoy sites like Google or Alibaba.
Mitchell provided a deep dive into the malvertising ecosystem, illustrating how criminal affiliate networks push everything from cryptocurrency and dating scams to dangerous malware like the SocGholish info-stealer. He highlighted a major threat actor his team has been tracking called Vextrio (also known as “Los Pollos”), a sophisticated cartel that runs a massive TDS operation. Beyond malvertising, he also touched on the persistent problem of lookalike domains, which are impossible for brands to proactively register across all 1,300+ top-level domains, and an advanced command-and-control technique where compromised websites use DNS text records to covertly fetch and decode malicious redirect URLs. These examples underscore the complexity of modern threats and the critical role of specialized, protective DNS in disrupting the attack chain.
Presented by Dave Mitchell, Senior Director, Threat Intelligence. Recorded live at Security Field Day 14 in Silicon Valley on September 24, 2025. Watch the entire presentation at https://techfieldday.com/appearance/infoblox-presents-at-security-field-day-14/ or visit https://techfieldday.com/event/xfd14/ or https://Infoblox.com for more information.
Transcript
Hey, afternoon everybody. My name's Dave Mitchell. I'm on the, uh, thread intel team over here at Infoblox.
Um, recovering operator. Did about 20 years at telcos and, and, uh, web properties, and then got into vendor land a little over 10 years ago to try to build products in tech that I wished I would've had when I was an operator. So, why DNS?
Uh, so I like to joke. There's so much room for activities. You know, some rough math just with DNS namespace, just with a domain and a TLD.
It's 92 orders of magnitude larger than all of the IPV four space in the world. So you can pretty much do whatever you want. There's close to 1300 top level domains at this point, mix and match.
It's nearly infinite namespace, and the attackers have more than likely figured a lot of these tricks out, and they're getting better on a, on a daily basis. But on the counterpoint of that is DNS can actually block that in a very efficient me, me, uh, mechanism along with your entire suite security stack. Again, Kesh already, uh, talked about this.
We do DNS all day every day. Our team is, uh, fairly large. Uh, we even have software developers, so we've got 12, 13 actual researchers across the globe and a large team building, building these actual algorithms that actually get fed into the product.
Um, and really all we do is stare at DNS all day. McKay, you already touched on this when it comes to timelines, but you know, the long and short of it is, you know, around, you know, 20 18, 20 19 when Renee came on board, she realized we needed a new approach to how we were tackling the DNS problem. It's not repackaging or curating other data sets.
Those are good, but, you know, as a vendor, you don't want to necessarily cause a, a false positive with, um, your product because you're packaging other in other data. So we took her expertise. I've only been here a little about a year and a half, and merged all that together into what we feed into threat defense across the board, just some of our threat actors, and they're named after based on what they do.
You know, Vipers are, you know, malicious ad tech and then, uh, Hawks or, you know, DNS hijacking, there's a bunch of different ones. Decoy Dog was a fun one that before I even started working at Infoblox, I was working with Renee on that through the security industry. We had both found it at nearly the same time.
People were like, well, you two please start working together because you're driving us both crazy. Uh, that, that's actually a fun one. We still believe it's a nation state.
We just don't know which one. Um, very well done when it comes to DNS Command and control. So getting to work with Renee and the team, uh, is really great.
I think we're up to seven, maybe eight countries with researchers in, and now we just brought in a, um, organized crime expert in Southeast Asia who we just brought over from the United Nations. So we're gonna really start focusing on that part of the world as well. So just a little bit of on why, you know, Intel is unique.
Again, we're not repackaging any of the intelligence that we have in there. It's all original intelligence that we're creating from raw data sets and correlation together. And this is just from, you know, the lookalikes.
And, you know, as you've, you know, some of the questions I heard before, heard vendor A say they do DNS. Okay, well, again, it's really what you know, you're the best at. Are we building next gen firewalls?
Absolutely not. This is our bread and butter, and this is why we're able to really beat all of the other vendors that are out there that are saying they're doing, doing DNS. They're obviously doing great work with what they do with, with what they're, um, you know, main products are.
But DNS is our main product, and that's why we're able to really beat everybody across the board. And this is just lookalikes, which I'll touch on later. It's a fun problem that everyone has to deal with.
So, again, DNS is used at some point across the attack chain, whether it's beginning communication in C two or xFi at the end. So even if you actually missed it at the beginning, say somebody took their corporate laptop home, wasn't necessarily on the network, got infected with something, well, they bring it back on the network, we're gonna detect it going out to and control, essentially make the malware inert. Um, and along with, you know, xFi at the end.
So at some point, you know, with the exception of very you small niche NA Nation states that know that they can pivot to direct ip, and that's where we cover it on the firewalls. That way everything uses DNS at least once. And even they use DNS once until they realize Exactly, Uh, just you some light numbers, you know, about about 12 million active indicators.
You know, and this was over the last 90 days, and we were doing, we call it protect protection before impact. Um, we were doing 70, around 75, 70 6% of the domains that were in there, we already had in the feed before we saw a single customer actually make a DNS query towards it. And that's how we're able to get to those, you know, 60 plus day numbers of having it in there.
And that's really because we're watching the infrastructure as it's being built, right? You know, these guys can't go launch these attacks without staging a large amount of data. I mean, even just the US Postal Service scams are using thousands, tens of thousands of domains that takes time, DevOps expertise and all of that to really roll out.
But we can watch that in real time because DNS is a nice open ledger that allows us to see what everyone's doing. So our reputation process is very simple. It's, it's just like a, a stoplight, you know, domain comes in right off the bat, it's unclassified.
So we've got algorithms running 24 hours a day. It'll pick that new domain up that just showed up and start running it through and go, okay, well, it either matched all of the, these particular attributes and we'll use statistics to start clustering 'em together. So it might be based on how the name actually looks, how it's being registered time, windows, things like that.
And then we'll start clustering those together, and then that'll pop out into an un unnamed actor that we're going to track. And then that's where our researchers will kind of dig in and go, okay, let's, you know, that's 40,000 domains. What's actually going on there?
That's when we dig in and find out what they're actually doing. And then that's when we build these signatures, and that's how they become tracked threat actors. And then it's easy enough, these, these algorithms keep running and okay, they modify one little thing, they think they're gonna throw us off.
Well, the algorithms pick that up, and then we start clustering more in. So we're able to track a wide variety of things in real time just using, you know, big data mechanisms, but we're just pulling in raw data sets, um, from all over in order to do that. But the one thing we always, you know, Renee loves to say, it's a really re uh, low regret way to protect your network, right?
Any of these suspicious feeds, if we think they're suspicious, there's probably absolutely no reason anybody on your network should be going to 'em in the first place. If somebody gets blocked by it, maybe one out of every 10 million times it might be this random new website that somebody wanted to go to to download a meme. 9% of the time, they're not gonna be places you want to go to.
And a large variety of these, these suspicious ones will actually get promoted to malicious after we've gathered more data as we start tracking them. And in the rare event, you know, say somebody's website gets compromised to their domain and we move them to malicious. Well, as we notice that, okay, well, they realize they got hacked, that they've cleaned it up, then it can kind of roll back into benign.
These are just some of the attributes. Um, there's many, many more, uh, that we keep adding, and we're always looking for new data sets to keep enhancing these algorithms. Um, you know, further up the stack as well.
But, you know, just think about if somebody registered 5,000 domains with GoDaddy in a time window, those might be related even with the privacy protection, how the domains are, where are they being hosted for authoritative name server are the authoritative name servers, um, moving around, that's usually pretty suspect are the A records actually moving around across countries. Uh, all of these different things come into play. So luckily, again, because it's an open ledger, we're able to track all of these things with our algorithms and be able to do it that way.
This is probably pretty much the same slide. It's just, you know, statistics to start. Then from statistics, we go into signatures in order to keep enhancing these algorithms.
Statistics are a big part of it. We've got a couple of statisticians on the team, and my boss is a mathematician, so she makes me feel, uh, dumb on a daily basis. Um, but it's, it's quite fun to be able to have this many people in a, in a threat intel organization who really know DNS as well.
It's hard to find people who can spell DNS let alone live and breathe it every day. So it's, it's quite a lot of fun. So I wish I had two hours just for this, uh, the threat landscape is, we was talking about dumpster fires earlier.
It's, it's a dumpster fire, um, and it's not getting any better. Um, but DNS can actually take a big chunk out of all of that before it gets to your firewalls, before it gets to your eds. Blocking in at DNS is is a big deal.
Now, command and control, we've been hearing this for a long time, right? You know, malware has to dial out somewhere. I remember, you know, years ago with, uh, you know, FireEye and things like that were coming outta the early two thousands, you know, being able to track C twos based on ip.
Well, obviously all that has morphed and changed. That's really hard to do at a pure packet level in, in the data plane, right? You, you gotta look at every, every single connection and all of that.
And that's really hard. It's expensive, it's exhaustive on the equipment, but doing it in DNS really pretty easy. So being able to track it, these are just, you know, days from compromise.
But you, you, you can see right there, right at, you know, day zero, day one, you can actually block it with DNS before they start becoming chatty. Um, the ran this would obviously be quite helpful for, you know, anti ransomware in general. Um, a lot of the EBTs are very good at DNS these days, even if they have to pivot to, to an IP at some point.
They've got really large infrastructure set up when it comes to C two. With DNS, You bring up an interesting point, FireEye, you know, one of the, the use cases there was the beaconing report, right? Mm-hmm.
Have your SecOps open a beaconing report every morning. Yeah. Run things down.
What would be the equivalent if someone wants to replace like FireEye with Infoblox? What would be the equivalent of that? We've got a beaconing report in there too.
Is anything beaconing out based on what, you know, we know that this is actually a command and control cluster, um, how often it's chatting, so on and so forth. So very similar, but we don't have to be in the data path and we don't need to have a port mirror in order to do it. Love it.
So this is, uh, you know, a pretty unique way, um, for DNS command and control that I'm gonna get into malicious advertising tech here shortly, um, that threat actors are using. So in this, in this instance, they're compromising tens or hundreds of thousands of WordPress sites, and they're injecting small bits of code at the top that are hidden. And if you come in and it looks at, you know, you're coming from, you know, hotel or your, you know, your, you know, cell phone or wherever it knows where you're coming from, it knows your user agent, it will actually then do a DNS query to a domain that they own on the backend, but it'll be a DNS text record lookup for, for that actual domain.
And what'll get handed back to them is a base 64 encoded message that that front end WordPress site will then decode and it's actually a URL, and it'll hand it back to you as a client in a redirect and move you that way. So that's how they've been able to really mask a lot of their command and control by actually hiding it in the compromised website as opposed to waiting in, you know, for the actual backend, pretty unique way of doing it. We've been tracking this.
We've done what we call, uh, industry hugs, where we reach out to folks and try to, you know, get some, you know, extra collection of data, uh, out there and then also shut 'em down and then watch how they pivot. So we've been really working on one of these threat actors that we call Vex Trio, I would say pretty much seven days a week for the last 13 months we've been tracking these guys and we've made a lot of headway, which I'll get into. So malicious ad tech, uh, again, I started working on this probably three or four months after getting here.
I also kind of thought like, advertising sounds like a nuisance kind of boring. It took me about 30 minutes to realize this is a great way to deliver threats. Um, and not to mention print money, uh, for the threat actors.
So we already saw a little bit, uh, you know, Mikesh said when it comes to legitimate ad tech, it's pretty simple. Ad tech powers the internet. You guys can already tell how much money it makes.
That's why we get to use a lot of the stuff out there for free. We just have to sacrifice our souls and our marketing to, to be able to do it. Um, but it's, it's pretty simple.
It's an ab you know, if you've got two different marketing campaigns out there based on who's coming from where you wanna serve them, one or the other, you can do that. And that's what really came out with what's called a traffic distribution system. It's just intelligent routing at, at the, at the application layer.
So the threat actors, you know, really started getting into this around 20 14, 20 15, and they've been really perfecting it ever since. Uh, the only real difference, um, is this affiliate network advertising called CPAs Click, click per action or cost per Action affiliates. And when you look at the, I had a slide in our black hat deck of just the sheer number of companies that are involved in advertising tech.
I mean, thousands. It's pretty easy to hide in there and be a malicious entity and be able to do this. So what these, these cost per action affiliates do is they'll recruit you.
You probably have gotten, uh, you know, if you're on Instagram or anything like that, hey, you can do some advertising, make some money. Well, generally you're doing that and they're giving you these things called smart links to go put on whatever website you have to generate traffic. You don't know where the traffic goes, you're just doing it.
And so that's where these, this cloaked stuff is. Whereas, you know, with Google ads and you know, you know where the traffic is going to go, right? It's going to United Airlines or Marriott Hotels or wherever, who's paying for an ad.
Malicious advertisers can pay these, um, these click CPA affiliates in order to do that. And so based on the traffic profile coming in, you can get redirected. And this is why it's been really difficult for, for threat researchers, is if you try to hit one of these URLs more than once in 24 hours, or you don't have the attributes that they want, you go to a decoy like Alibaba, Google, Bing, you name it, and you can go all over a URL scan all day long and you'll see these really bizarre looking URLs and they'll end up at Google.
Those are decoys. And if you actually match the right thing, depending on how you're bouncing around, you might actually get a malicious advertisement. Those can be scams, those can be disinformation campaigns, those can be info stealers, you know, fake browser updates, you name it.
Well, this is like what, what we call a little plinko diagram here. And, and this is where the cloaking is, is a big deal for these guys. It's higher enough affiliates to push, uh, these advertisements out there and get people infected.
Um, and then you also have affiliates that are other threat actors. So they're just kind of the middleman. And that's where we've been really trying to push this message that malicious ad tech is a real big problem that needs to be taken into account at a regulatory level because these, these CPA, you know, companies, these ad tech companies are playing the, well, I don't know who's really on my network.
So they're their know your customer. You know, rules are really, you know, pretty weak. They're trying to catch up, but there's, you know, hundreds of these guys out there.
And so they just play dumb of, I didn't know that affiliate was, you know, sock oish, which is pushing info dealers all day long. So there's a lot of, you know, shell game going on. But we've built many algorithms to be able to track these.
I would say in general, we see malicious ad tech in in close to 65 to 70% of our customers, um, including our own network. You can particular keywords. If you've searching Google, the top three results will actually be smart links that'll take you into a traffic distribution system.
I'll show you some slides here. I'm sure everyone has visited, visited one, whether you knew it was or not back one, I already kind of touched on this, the enterprise threats. And you know, this is where in general there's been confusion are, are, are these just scams, you know, trying to target my mom or my grandma, things like that.
Absolutely, there's a big risk to consumers. They make a fortune ripping off people this way, but the threats to the enterprise are, are there, you know, if I'm a malicious threat actor and I know that I can place an advertisement with these particular, uh, you know, ad tech firms and push an info stealer, I'm going to do that because I know every company in here has email security that works quite well. The end points are hardened, you name it.
Now, this is a new way to get tra uh, to get pieces of software onto people's machines. Um, and there's a lot of good links in here that we can send out, but it's, uh, pretty pervasive across the board. Here's just some fun with cloaking.
Um, we love our little robots. Uh, those are associated with one of our threat actors called Vex Trio. Um, as you can see right here, this starts off with a Twitter shortener link.
And then because we actually match the criteria to get in there, you can start seeing these three oh sevens and 3 0 2 redirects. The largest chain I've ever seen was 57 H TT P redirects. And you can imagine on each one of those ads are being displayed, so all the way across the board, and sometimes these, these companies are actually the advertiser, the publisher, and the affiliate.
So they might be getting paid in three different locations. And, uh, then you end up at this, you know, strange domain. You get some, uh, scams there.
Uh, there was a really, really large, um, we, we called Doppelganger that was a Russian organization pushing disinformation, you know, over the last, you know, five to eight years. And they were using these traffic distributions, uh, systems in order to do it. Here's a question for you.
Yeah. top? They almost always seem to be this type of crap.
I'm sure there are one or two, but I can't li I can't name one off the top of my head. You guys know of any? No, but there are, you know, and that definitely comes into play too, with the different registries, which TLDs are the most abused.
Yeah. Um, and there's some, you know, like XY, Z registry is heavily abused. They're really great to work with.
Um, and then there's others that, you know, you don't hear from. So, um, it, it, it kind of, you know, when you look at, I think there's nearly 1300 DLDs, you know, if one starts getting, you know, too, you know, tackled by, by the threat actors, then they'll move to one that's, you know, a little less, you know, quiet again. So you can kind of see here, this is just some JavaScript showing you what, what you have to match in there in order to get to the URL.
And then they've got these anti-bot systems, you know, a lot of this technology that we've seen, they would be able to sell to real e-commerce sites and make, make good money doing it. They just sell it to their own e-commerce sites in order to do it that way. And then they don't have to pay taxes and things like that.
Here's, uh, you know, a few more. This was one of our slides at Black Hat. Uh, our robot is really great 'cause it, it pretends it's a capcha, but you're enabling notifications in your browser, and then that's when you start getting push ads.
Um, Renee took her mom's old Android phone and we infected it with this stuff, and it took a four and a half hour battery life and put it down to 40 minutes. It was just every, every 10 seconds and each one of those ads that's popping up, somebody's getting paid even if you're not clicking on 'em. So that's how they're doing it, is they're pushing these ads to you, so you're seeing 'em.
So that's still an ad impression. People get paid. Um, the Bitcoin, you know, the crypto scams are plentiful with this.
Uh, ones that we were really surprised to see were these dating scams, um, and how profitable they actually are. I mean, there are hundreds, if not thousands of them, they'll even camp on, um, real, you know, real domains. One's called cider instead of Tinder, and they've got all sorts of different things and people don't know that These are all just chatbots behind the scenes.
You have to read really, really far into the T's and C's that says, this is for entertainment purposes only, but people will pay 9 95 to sign up for these things, and then it's really difficult to get it to stop recurring charge on your card. And, you know, they're like, well, and then because you've given them your email address, now you, they believe that you've signed up to be spammed all at the same time. So these guys have really, really gotten good at this.
Um, you know, DevOps shops, you can just look in passive DNS and see that they're using every sort of DevOps tech that we use and, and they're quite good at it. And this is where the, you know, the malware pieces, these are, you know, really dangerous affiliates that are using these advertising platforms. You know, these are the fake updates like from Soc Oish and things like that, info Steelers, uh, the McAfee one's great.
So the fake EV stuff will pop up and it's actually looks pretty good. Like if you didn't know it was in your browser, you might, you know, I joked with my mom, if if your computer says you have a virus, you don't, please don't. Please don't click on it.
And when you click all the way through, it will take you to McAfee and you can buy real McAfee. 99, these guys make $170 on the deal. Yeah, don't, I don't understand how that math works, but it does.
So VEX Trio, and this is, we've got a three part series with blogs. Um, we've been tracking these guys. One of our guys on the team had been starting since 2022.
We could not figure out who they were. We thought they were advertising on the dark web. We dug around, we found a fr one of our, uh, friends found a frame in a YouTube video that was in Russian with a guy demonstrating a new ad affiliate platform that every, everybody should do.
And we saw the URL structure was the exact one that we had been tracking for a long time. One frame in one video led us to this place called los, and if everybody likes Breaking Bad Los Poeo anos, and they also have a push notification, one called Taco Loco. Um, they're based in Switzerland and Eastern Europe.
I'm pretty sure they've never had a good taco in their life, but they love breaking bad. And it's, it's been a lot of fun, you know, tracking these guys really, I mean, we're impressed with how, how good they are, they're able to pivot. They've got, I think we were tracking over 90 different shell companies that they could move things around with.
Wow. The minute one starts getting heat, they changed the name. This was originally Ads Pro and then it became Los pos.
And now, you know, depending on how much heat we put on 'em, we'll see what it gets renamed to next. Um, and this is just one of many. Now the interesting part is this is a cartel we're taking down.
Now we're gonna watch which of the other ones pick up the slack because these guys were making so much money. Well, alright, customer base, come on over here. And you know, these TDSs are also being used for these phishing and MFA attacks.
These are, these are really bad at this point. Um, they're getting people with just exhaustion, um, paying, you know, not paying attention. You know, some of these, you know, free places where you can host websites.
You know, sometimes 90% of the, the sites that are up there are all phishing. They've gotten quite good with the, the phishing kits as a service, but now you can advertise them across the TDS. Click on it.
Oh, well it looks, looks like my Office 365 login. I should totally try that. Um, so hopefully, hopefully people identify those, but as we know, people do like to click on things.
And then just the last one I want to touch on is, you know, just lookalikes. These are fun because it hits everybody. It's, we, we used to say back in the day when it was only, you know, five top level domains, buy everything that looks like your company, right?
Well you've got 1300 top level domains, not as easy anymore. So this is where protective DNS is really critical to kind of come in and do that. We already know what all of the different things with lookalikes even just, they can look at fonts and see that they can take an R and an N and it'll look like an MI saw one that looked like Microsoft the other day and if you couldn't see it very well, you might, you might think it looked like Microsoft.
So they've tried every different thing and they're really great at it, um, when it comes to full automation. But these are just some of the ones that we've caught. Um, some of these you would think people wouldn't click on, but you know, it's as things are flying across too.
And that's where the traffic distributions can C systems can come into play. You might only see it for a minute, but you know, you got O'S or Zeros instead of o's and you know, even some of the different fonts and and things like that are, are always kind of fun. So these, these are a big problem.
They affect everyone. Um, so that's why having, you know, protective DNS platform in play to at least alert you to the fact since you can't go out there and you know, proactively buy every one of these domains, it would cost you tens of millions of dollars. At least you know, when somebody is gonna pop up and start using it.
And then you can go at least get that domain taken down and we've got a service to do that as well. And with that, you know, feel free to ping us on Mastodon or whatever else, but we've got a bunch of fun research up there and, um, be happy to work with anybody. If you guys got any fun stuff to throw our way, we'd love to dig into it.