Compromised Routers, DNS, and a TDS Hidden in Aeza Networks
ID: 4269a34c-e503-532c-a98d-f8f01cb9ec4b
STIX ID: report--4269a34c-e503-532c-a98d-f8f01cb9ec4b
Feed Name: Infoblox Threat Intel Blog
This report describes a long-running campaign where routers were compromised and their DNS settings changed to use shadow resolvers hosted by a bulletproof hosting provider (Aeza International), enabling a DNS+HTTP traffic distribution system that fingerprints devices and redirects users to affiliate/adtech links or malicious content; the actor employs an EDNS0-based probing restriction and short TTLs to evade detection and maintain control, and the infrastructure has been observed actively redirecting traffic and, in some cases, delivering cryptominers and locking admin access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
