HomeSecurityResearchers gain access to hacker domain server

Researchers gained access to hacker domain server

A recent investigation into a hacker domain server shows how a simple DNS error can open a "window" into the criminal infrastructure.

See also: Hackers abuse legitimate cloud platforms to “host” phishing kits

hacker domain server
Researchers gained access to hacker domain server

The campaign abused browser notifications, bombarding Android users with fake security warnings, gambling bait, and adult offers. Randomly named domains and hidden hosting were used to mask the operator while keeping the clicks and ad revenue flowing.

The problem occurred when a domain stopped resolving, even though notifications continued to arrive. Instead of active landing pages, victims saw browser errors.

What initially looked like a routine outage turned out to be a misconfigured nameserver, which left the domain in a “lame delegation” state, no longer pointing to a valid backend.

See also: Microsoft “hit” the infrastructure of the malicious RedVDS service

Researchers gained access to hacker domain server
Researchers gained access to hacker domain server

Infoblox researchers discovered this vulnerability and realized that the malicious actor had lost control of the DNS, while devices around the world continued to “communicate” with the domain. By legitimately registering the same domain with the DNS provider, the team redirected traffic to infrastructure it managed, without touching the victims’ devices or the attacker’s servers.

From that point on, every push message and tracking request sent by the hacker network also ended up on the researchers’ server, providing a live view of its operation. Over the next few days, thousands of infected browsers from around the world connected to their infrastructure. Each request included detailed JSON files with information about the device, language, bait text, and user click behavior.

See also: Hacker jailed for breaching Rotterdam and Antwerp ports

Researchers gained access to hacker domain server
Researchers gained access to hacker domain server

In total, the team collected tens of millions of records, revealing aggressive use of impersonation of well-known brands and intimidation tactics aimed at increasing clicks. The records showed that a typical user could receive over a hundred notifications a day, often for months.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS