216.73.217.22

Compromised Routers, DNS, and a TDS Hidden in Aeza Networks

· Published 04/02/2026 15:26 · Modified 04/02/2026 21:20

Export JSON

Essential information

Published
04/02/2026 15:26
Modified
04/02/2026 21:20
Tags
2026-02-04 adtech aeza networks affiliate marketing compromised routers dns hijacking dnschanger shadow dns traffic distribution system
Related entities
10 observables, 9 techniques (mitre), 1 malware, 2 others

Description

A network and HTTP-based (TDS) hosted in Aeza International, a sanctioned bulletproof hosting company, has been discovered. The system compromises routers, altering their DNS settings to use shadow resolvers. These resolvers selectively modify responses, directing users to malicious content. The TDS incorporates a clever DNS trick to evade detection by security groups. The system, operational since mid-2022, appears to be run by a financially motivated actor in . It has the potential to interfere with devices on the network, alter DNS records, and conduct adversary-in-the-middle operations. The threat actor's ability to control DNS resolution poses significant risks beyond delivering unwanted advertising.

External references