logo

Ghost Click/DNSChanger: Could ISPs have stopped it?

ID: 6ba5999e-2f11-5b1e-a55b-4544a9269fc3

STIX ID: report--6ba5999e-2f11-5b1e-a55b-4544a9269fc3

Feed Name: The Spamhaus Project

Threat Score
70/100

Date Published: 2011-11-15

Date Updated: 2026-04-30

Author: The Spamhaus Team

...
...

The report summarizes the DNSChanger (Ghost Click) operation by Rove Digital that hijacked infected computers' DNS settings to redirect users to attacker-controlled sites and replace ads, outlines the large scale impact, and recommends how ISPs could detect and mitigate such DNS hijacking (traffic monitoring, blocking DROP-listed IP ranges, or isolating and notifying infected customers).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.