Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems
ID: 04358367-0964-510d-9f21-2429d22c96e4
STIX ID: report--04358367-0964-510d-9f21-2429d22c96e4
Feed Name: Palo Alto Networks Unit 42
Date Published: 2025-03-05
Date Updated: 2026-04-28
Author: Zhanhao Chen, Daiping Liu, Wanjin Li and Fan Fei
This Unit 42 report analyzes how adversaries abuse Traffic Distribution Systems (TDS) to build resilient, scalable redirection networks for phishing, malvertising, illicit gambling/adult services and cloaking. It presents large-scale topological findings showing malicious TDS have longer redirection chains, more distinct URLs and higher connectivity; provides case studies and IoCs (including ~139 .lol DGA domains and specific domains); and describes an ML-based detector claimed to achieve 93% precision and 0.4% false positive rate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
