Shadow DNS Hacking Routers Internet Traffic Through Compromised Routers
Internet routers, often trusted to manage web traffic, are susceptible to manipulation. A sophisticated "shadow" network has been identified, which hijacks home internet connections by exploiting vulnerable routers and altering their DNS configurations.
Internet routers, often trusted to manage web traffic, are susceptible to manipulation. A sophisticated "shadow" network has been identified, which hijacks home internet connections by exploiting vulnerable routers and altering their DNS configurations.
These compromised routers redirect web traffic queries to malicious resolvers operated by Aeza International, a firm previously sanctioned by the US government. This redirection enables threat actors to manipulate accessible websites, often leading users to fraudulent platforms or scams. Popular sites like Google may resolve correctly to avoid detection, while specific targets are redirected through a Traffic Distribution System (TDS) that evaluates the victim's device before delivering malicious content.
This campaign employs a stealthy evasion technique, which initially posed challenges for security analysts attempting to replicate malicious DNS responses. The rogue servers only respond when the Extension Mechanisms for DNS (EDNS0) protocol is disabled.
Internet routers, often trusted to manage web traffic, are susceptible to manipulation.
EDNS0 is a standard protocol extension used by legitimate resolvers for handling larger packet sizes and security features. By ignoring standard queries that include EDNS0, the attackers rendered their infrastructure invisible to automated scans and most security researchers. This allowed the network to operate undetected, providing legitimate IP addresses during inspections while delivering hijacked responses to victims.
To mitigate this threat, it is crucial for users to audit router configurations for unauthorized DNS settings and ensure router firmware is updated to the latest versions. Replacing obsolete hardware that lacks security patches is also essential to prevent initial compromises.
For further information, please visit the Infoblox analysis .
Based on reporting by Cyber Security News.
