Shadow DNS Operation Abuses Compromised Routers to Manipulate Internet Traffic
ID: 01a48755-b38d-52f3-bb3a-48658e5b8e2a
STIX ID: report--01a48755-b38d-52f3-bb3a-48658e5b8e2a
Feed Name: GBHackers
A sophisticated, multi-year campaign compromises consumer and small-business routers to override DNS settings and route queries through attacker-controlled 'shadow' resolvers (linked to Aeza International, AS210644). The operators use EDNS0-aware evasion and a two-stage TDS with JavaScript fingerprinting to selectively redirect victims to affiliate/ad networks, scams, or malicious payloads; researchers observed dozens of resolvers, specific IPs/domains used for redirection and proof of additional payloads like cryptominers. Organizations and home users are advised to verify router DNS settings, update firmware, change default credentials, monitor DNS behavior, and deploy encrypted DNS where possible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
