A recent investigation into a hacker domain server shows how a simple DNS error can open a "window" into the criminal infrastructure.
See also: Hackers abuse legitimate cloud platforms to “host” phishing kits

The campaign abused browser notifications, bombarding Android users with fake security warnings, gambling bait, and adult offers. Randomly named domains and hidden hosting were used to mask the operator while keeping the clicks and ad revenue flowing.
The problem occurred when a domain stopped resolving, even though notifications continued to arrive. Instead of active landing pages, victims saw browser errors.
What initially looked like a routine outage turned out to be a misconfigured nameserver, which left the domain in a “lame delegation” state, no longer pointing to a valid backend.
See also: Microsoft “hit” the infrastructure of the malicious RedVDS service

Infoblox researchers discovered this vulnerability and realized that the malicious actor had lost control of the DNS, while devices around the world continued to “communicate” with the domain. By legitimately registering the same domain with the DNS provider, the team redirected traffic to infrastructure it managed, without touching the victims’ devices or the attacker’s servers.
From that point on, every push message and tracking request sent by the hacker network also ended up on the researchers’ server, providing a live view of its operation. Over the next few days, thousands of infected browsers from around the world connected to their infrastructure. Each request included detailed JSON files with information about the device, language, bait text, and user click behavior.
See also: Hacker jailed for breaching Rotterdam and Antwerp ports

In total, the team collected tens of millions of records, revealing aggressive use of impersonation of well-known brands and intimidation tactics aimed at increasing clicks. The records showed that a typical user could receive over a hundred notifications a day, often for months.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
