logo

Compromised Routers, DNS, and a TDS Hidden in Aeza Networks

ID: 55554c3f-e6e9-53d8-a5c3-7df152d96165

STIX ID: report--55554c3f-e6e9-53d8-a5c3-7df152d96165

Feed Name: Infoblox Blog

Threat Score
78/100

Date Published: 2026-02-03

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

This report details a persistent campaign where attackers compromise routers and configure them to use shadow DNS resolvers operated from Aeza International (AS210644), using an EDNS0-avoidance trick and an HTTP-based TDS to fingerprint users and funnel traffic to affiliate/adtech links or malicious content; the infrastructure has been active for years, includes dozens of recursive resolvers (examples listed), and enables potential adversary-in-the-middle actions beyond advertising.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.