216.73.217.22

Beneath the Surface: Detecting and Blocking Hidden Malicious Traffic Distribution Systems

· Published 05/03/2025 16:24 · Modified 05/03/2025 17:05

Export JSON

Essential information

Published
05/03/2025 16:24
Modified
05/03/2025 17:05
Tags
2025-03-05 cloaking darknet malvertising phishing traffic distribution systems
Related entities
6 techniques (mitre)

Description

This analysis explores the use of (TDS) by threat actors to redirect network traffic for illicit purposes like and . TDS act as central hubs, obfuscating final destinations and hindering detection. The study found that malicious TDS exhibit distinct topological characteristics compared to benign networks, including longer redirection chains, more URLs, and higher connectivity. Using these insights, a machine learning-based detection system was developed to identify various types of malicious TDS infrastructure. The research also presents case studies of TDS usage in campaigns, , services, and techniques.

External references