{"id":11656,"date":"2026-03-25T12:51:00","date_gmt":"2026-03-25T12:51:00","guid":{"rendered":"https:\/\/events.aavar.org\/avar2025\/?page_id=11656"},"modified":"2026-03-25T12:51:00","modified_gmt":"2026-03-25T12:51:00","slug":"high-stakes-hidden-threats-unmasking-the-vault-viper-network-with-dns","status":"publish","type":"page","link":"https:\/\/events.aavar.org\/avar2025\/index.php\/high-stakes-hidden-threats-unmasking-the-vault-viper-network-with-dns\/","title":{"rendered":"High Stakes, Hidden Threats: Unmasking the Vault Viper Network with DNS"},"content":{"rendered":"\n[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column]\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div style=\"height:200px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"banner-text has-x-large-font-size wp-block-paragraph\">AGENDA<\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><\/div>\n<\/div>\n\n\n\n<p>[\/vc_column] [\/vc_row]<\/p>\n\n\n\n<div style=\"height:40px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p class=\"agenda-link wp-block-paragraph\"><strong><a href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/agenda\/\">&lt;&#8212; Back<\/a><\/strong><\/p>\n\n\n\n<p class=\"agenda-heading wp-block-paragraph\">High Stakes, Hidden Threats: Unmasking the Vault Viper Network with DNS<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Southeast Asia\u2019s cyber threat landscape is evolving faster than ever before. This transformation has been marked by the proliferation of industrial scale scam centres and cyber-enabled fraud operations, driven by sophisticated transnational criminal syndicates and interconnected networks of money launderers, human traffickers, data brokers, and other specialist service providers \u2013 particularly those involved in casinos and online gambling.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Against this backdrop, in February 2025, Infoblox Threat Intel, in collaboration with the United Nations Office on Drugs and Crime Regional Office for Southeast Asia and Pacific (UNODC ROSEAP), set out to examine a cluster of illegal online gambling platforms. In what followed, Infoblox researchers uncovered one of Asia\u2019s leading iGaming software suppliers or \u2018white labels\u2019 distributing a custom browser with significant security implications. Advertised as \u201cprivacy-friendly&#8217; and able to bypass censorship where online gambling is strictly prohibited. The browser proceeds to route all connections through servers in China and installs several persistent, involuntary programs that run silently in the background \u2013 features consistent with remote access trojans (RATs) and other malware.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Through DNS analysis, reverse engineering and threat hunting, as well as more conventional investigative work, Infoblox Threat Intel has been able to end a decade\u2019s long mystery, ultimately unmasking the broader criminal network behind this operation and its direct link to the infamous Suncity Group and convicted Triad boss, Alvin Chau. This abstract offers a glimpse into the first public release of what has been dubbed Vault Viper, marking the second in a series of previously unreported threat actors and criminal service providers operating at the intersection of illicit online gambling, cyber-enabled fraud, high-tech money laundering and human trafficking. Building on Infoblox\u2019s past Vigorish Viper research, the investigation traces tens of thousands of associated domains \u2013 with several still currently in use by documented criminal networks \u2013 detailing Vault Viper\u2019s vast DNS footprint, command-and-control (C2) infrastructure, unique tooling, and ownership structure concealed through a tangled web of companies registered in dozens of countries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The presentation will conclude with a discussion around various challenges in investigating, classifying, and disrupting this unique category of threat actor. Attendees will also gain a new perspective on the implications of growing criminal sophistication and professionalism within the regional cyber threat landscape, as well as the value of a DNS-based approach in identifying and disrupting sprawling criminal networks.<\/p>\n\n\n\n<div style=\"height:42px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Mael-Le-Touz.png\" alt=\"\" class=\"wp-image-11660\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Mael-Le-Touz.png 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Mael-Le-Touz-300x300.png 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Mael-Le-Touz-150x150.png 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/Mael-Le-Touz-200x200.png 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong><strong>Ma\u00ebl Le Touz &#8211; Infoblox<\/strong><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Ma\u00ebl Le Touz is a Staff Threat Researcher at Infoblox where he specializes in the detection of threats as they manifest in the domain name system (DNS).&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">His background is in financial fraud investigation and he has strong experience in reverse engineering. He reverse engineered critical components of the Decoy Dog malware that confirmed the DNS C2 was distinct from the open source Pupy project.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">He recently focused his research on the Chinese speaking landscape, contributing to the discovery of VIgorish VIper and a number of other criminal syndicates dealing in gambling, malware,scams and trafficking. He was a speaker at a number of cyber security conferences including Black Hat, Infosecurity and Les Assises.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\"><div class=\"wp-block-image is-resized is-style-rounded\">\n<figure class=\"aligncenter size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"500\" height=\"500\" src=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/John-Wojcik.png\" alt=\"\" class=\"wp-image-11661\" style=\"width:225px\" srcset=\"https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/John-Wojcik.png 500w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/John-Wojcik-300x300.png 300w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/John-Wojcik-150x150.png 150w, https:\/\/events.aavar.org\/avar2025\/wp-content\/uploads\/2026\/03\/John-Wojcik-200x200.png 200w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><\/figure>\n<\/div><\/div>\n\n\n\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:66.66%\">\n<p class=\"speaker-heading wp-block-paragraph\"><strong><strong><strong><strong>John Wojcik &#8211; Infoblox<\/strong><\/strong><\/strong><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">John Wojcik is a Senior Threat Researcher at Infoblox where he specializes in DNS threat intelligence and cyber and cyber-enabled crimes in East and Southeast Asia. As part of Infoblox\u2019s Threat Intel, he works with governments and enterprises in the region to strengthen resilience against evolving and accelerating cyber risks through DNS.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">John joins Infoblox as a former Senior Analyst with UNODC\u2019s Regional Office for Southeast Asia and the Pacific in Bangkok, Thailand, where he led the agency\u2019s open-source and criminal intelligence portfolios, specializing in cyber-enabled fraud, high-tech money laundering, and virtual assets.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At Infoblox, he focuses on DNS threat intelligence and supporting Protective DNS adoption, where his research aims to demonstrate how visibility and intelligence at the DNS layer can serve as key line of defense against modern-day threats. He continues to share his expertise to strengthen resilience and support the broader security community.<\/p>\n<\/div>\n<\/div>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>[vc_row full_width=&#8221;stretch_row&#8221; el_class=&#8221;agenda-banner&#8221; el_id=&#8221;agenda_banner&#8221;] [vc_column] AGENDA [\/vc_column] [\/vc_row] &lt;&#8212; Back High Stakes, Hidden Threats: Unmasking the Vault Viper Network with DNS Southeast Asia\u2019s cyber threat landscape is evolving faster than ever before. This transformation has been marked by the proliferation of industrial scale scam centres and cyber-enabled fraud operations, driven by sophisticated transnational criminal syndicates and interconnected networks of money<\/p>\n<div class=\"h10\"><\/div>\n<p><a class=\"more-link2\" href=\"https:\/\/events.aavar.org\/avar2025\/index.php\/high-stakes-hidden-threats-unmasking-the-vault-viper-network-with-dns\/\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-11656","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11656","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/comments?post=11656"}],"version-history":[{"count":1,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11656\/revisions"}],"predecessor-version":[{"id":11662,"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/pages\/11656\/revisions\/11662"}],"wp:attachment":[{"href":"https:\/\/events.aavar.org\/avar2025\/index.php\/wp-json\/wp\/v2\/media?parent=11656"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}