Categories: Cyber Security News

Fake CAPTCHA Bots & Malicious Apps – VexTrio’s New Tactics Hit Google Play and App Store Users

Cybersecurity researchers have uncovered an extensive malicious app operation by VexTrio. This cybercriminal organization has infiltrated major app stores with fake security tools, dating apps, and VPN services that have collectively garnered millions of downloads.

Sponsored
class="wp-block-heading" id="million-download-scam-apps-masquerade-as-legitimat">Million-Download Scam Apps Masquerade as Legitimate Services

VexTrio has released malicious applications under multiple developer names, including HolaCode, LocoMind, Hugmi, Klover Group, and AlphaScale Media, successfully bypassing app store security measures.

Dating apps like Hugmi and Cheri have each accumulated over one million downloads on Google Play despite user reviews revealing their fraudulent nature.

The organization’s “Spam Shield” app, marketed as a spam blocker for push notifications, exemplifies its deceptive tactics. While claiming to eliminate threats, the app merely disables browser notifications and displays fake monitoring interfaces showing blocked spam.

After a 24-hour trial period, users are forced into expensive subscription plans costing $6.99 monthly.

Technical analysis reveals that VexTrio’s VPN applications function as residential proxies rather than legitimate privacy tools, raising significant security concerns.

DNS records show these apps sharing infrastructure with VexTrio’s core operations, with IP address 136.243.216.249 simultaneously hosting HolaCode, AdsPro Digital, Los Pollos, and multiple scam applications.

Dns records show that vextrio domains are resolving at the same dedicated ip address as scam apps. Captured june 2025

Infrastructure Links Reveal Coordinated Criminal Enterprise

Researchers discovered that VexTrio’s applications contain deliberate naming confusion tactics, such as using the app ID “com.vpn.proxy.secure.wifi.turbovpn” to mislead users into believing their fake VPN is associated with the legitimate Turbo VPN service.

The apps’ terms and conditions frequently reference unrelated services, indicating rushed development and deployment processes.

Spam shield website links the app to the company media alliance s. R. O. Captured september 2024.

The criminal organization operates through shell companies registered in Prague, including Techintrade s.r.o. and OILIMPEX s.r.o., which produce nearly identical scam applications with shared codebases.

Sponsored

DNS evidence shows domains like vm-oilimpex.holacode.tech and vm-technitrade.holacode.tech resolving to dedicated VexTrio IP addresses.

Trademark Infringement and Celebrity Exploitation

VexTrio’s operations extend beyond app stores to include widespread trademark infringement, appropriating brands of celebrities like MrBeast, Donald Trump, and Elon Musk for cryptocurrency scams.

A collage of scam landing pages related to vextrio’s cryptocurrency, investment, sweepstake, and antivirus scam verticals

Their fake CAPTCHA robot images have appeared in numerous fraud reports over several years, serving as a recognizable signature of their operations.

The apps typically force users to watch incessant advertisements, bind them into difficult-to-cancel subscription contracts, and harvest personal information, including email addresses.

Security researchers warn that VexTrio’s ability to operate for over 15 years without significant legal consequences demonstrates critical gaps in current cybercrime enforcement.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

The post Fake CAPTCHA Bots & Malicious Apps – VexTrio’s New Tactics Hit Google Play and App Store Users appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Pixel Perfect Extension Abuse Enables Covert Script Injection and Security Header Removal

A browser extension that once earned a Featured badge from Google quietly turned into a…

9 minutes ago

US Military Reportedly Used Claude in Iran Strikes Despite Trump’s Ban

The U.S. Department of Defense deployed Anthropic’s Claude AI during Operation Epic Fury, a joint…

10 minutes ago

Hacked Prayer App Used as Cyber Weapon During US-Israel Strikes on Iran

As Israeli and US forces launched joint preemptive airstrikes on Tehran, a sophisticated cyber-psychological operation…

10 minutes ago

Domains will become the center of an AI-built world

Artificial intelligence (AI) has prompted a major shift in how we interact online. In just…

28 minutes ago

Top 5 FinTech Development Companies in 2026

The FinTech industry undergoes continuous transformation because companies work to develop better products which enable…

28 minutes ago

Top 10 AI Development Companies in Dubai, UAE and the Middle East

Looking for the right AI partner to transform your business operations? You’re not alone. As…

28 minutes ago

This website uses cookies.