logo

Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems

ID: 04358367-0964-510d-9f21-2429d22c96e4

STIX ID: report--04358367-0964-510d-9f21-2429d22c96e4

Feed Name: Palo Alto Networks Unit 42

Threat Score
65/100

Date Published: 2025-03-05

Date Updated: 2026-04-28

Author: Zhanhao Chen, Daiping Liu, Wanjin Li and Fan Fei

...
...

This Unit 42 report analyzes how adversaries abuse Traffic Distribution Systems (TDS) to build resilient, scalable redirection networks for phishing, malvertising, illicit gambling/adult services and cloaking. It presents large-scale topological findings showing malicious TDS have longer redirection chains, more distinct URLs and higher connectivity; provides case studies and IoCs (including ~139 .lol DGA domains and specific domains); and describes an ML-based detector claimed to achieve 93% precision and 0.4% false positive rate.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.