A malicious advertisement circulating on a large online advertising network is used to propagate a command to change settings in the DNS (Domain Name System) of routers.
An attack that uses advertisements from a third-party service and appears on websites is called "malvertising" and is usually carried out by redirecting the user to an online site that is malicious or under the control of cybercriminals and serves a malicious purpose.
However, in the incident detected by Sucuri, the malicious user inserted the command directly into the ad, which is propagated to websites via the googlesyndication.com domain, which is owned by Google, to store and serve advertising content and use Google AdSense resources.
Analyzing the URL of the malicious ad, Sucuri's Fioravante Souza found that its creator had encoded the command in order to hide the threat. However, the researchers managed to decode it, only encountering a new obstacle in the delay in identifying the malicious code.
A DNS was designed to translate a website's IP address into human-readable text. By going to a different server interpreting the addresses and providing the domain name, an attacker could convert a different IP to the domain required by the victim, spreading malicious content.

