logo

The Next Level: Typo DGAs Used in Malicious Redirection Chains

ID: 34130545-7852-5434-9b67-490942a3190a

STIX ID: report--34130545-7852-5434-9b67-490942a3190a

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2025-03-06

Date Updated: 2026-04-28

Author: Reethika Ramesh and Janos Szurdi

...
...

Unit 42 reports an active, large-scale campaign using newly registered domains and a novel "typo DGA" (dictionary-based DGA with typographical errors) to redirect traffic to adult Android app landing pages and malicious infrastructure. The campaign leveraged automated epoch-timestamp subdomains and a shared IP (91.195.240.123); investigators observed 6,057 NRDs involved in the immediate campaign and linked 444,898 domains to the same registrant email, with 96% of sampled files contacting the IP identified as malicious. The report provides indicators (sample NRDs, typo DGA domains, IP) and recommends protections via Palo Alto Networks products.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.