Compromised Routers, DNS, and a TDS Hidden in Aeza Networks
ID: 55554c3f-e6e9-53d8-a5c3-7df152d96165
STIX ID: report--55554c3f-e6e9-53d8-a5c3-7df152d96165
Feed Name: Infoblox Blog
Threat Score
This report details a persistent campaign where attackers compromise routers and configure them to use shadow DNS resolvers operated from Aeza International (AS210644), using an EDNS0-avoidance trick and an HTTP-based TDS to fingerprint users and funnel traffic to affiliate/adtech links or malicious content; the infrastructure has been active for years, includes dozens of recursive resolvers (examples listed), and enables potential adversary-in-the-middle actions beyond advertising.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
