Cyber Security News

Shadow DNS Hacking Routers Internet Traffic Through Compromised Routers

Most internet users trust their routers to direct traffic correctly, never suspecting that the very signposts of the web could be manipulated.

A sophisticated “shadow” network has been silently hijacking home internet connections by compromising vulnerable routers and altering their DNS configurations.

Instead of using a legitimate Service Provider’s servers, these infected devices send all web traffic queries to malicious resolvers hosted by Aeza International, a bulletproof hosting firm previously sanctioned by the US government.

This silent redirection allows threat actors to selectively manipulate which websites users can reach, often steering them toward fraudulent advertising platforms or malicious scams.

While popular sites like Google often resolve correctly to avoid suspicion, specific targets trigger a complex redirection chain.

This involves a secondary HTTP-based Traffic Distribution System (TDS) that fingerprints the victim’s device before delivering the final payload.

Infoblox analysts identified this widespread campaign after connecting scattered user reports of “insane” internet behavior with anomalous DNS patterns.

They observed that the threat actors largely target older router models, fundamentally altering the trust chain for every device on the home network.

Victims reported bizarre issues, such as an inability to access Google Sheets or persistent browser redirects, often assuming their computers—not their routers—were at fault.

The EDNS0 Evasion Technique

The most technically intriguing aspect of this campaign is its stealthy evasion method. Security analysts initially struggled to replicate the malicious DNS responses because the rogue servers would not answer standard queries.

The breakthrough came when analysts discovered that the shadow resolvers only respond if the Extension Mechanisms for DNS (EDNS0) protocol is explicitly disabled.

An overview of the two-part TDS hosted in Aeza International (Source – Infoblox)

Since EDNS0 is a standard protocol extension used by almost all modern legitimate resolvers to handle larger packet sizes and security features, standard security scanning tools automatically include it.

By configuring their servers to ignore these standard queries, the attackers effectively made their infrastructure invisible to automated scans and most security researchers.

This simple yet effective filter allowed the malicious network to operate undetected for years, serving correct IP addresses to researchers while delivering hijacked responses to actual victims using older, non-compliant equipment or specific configurations.

To mitigate this threat, users must audit router configurations for unauthorized DNS settings.

Updating router firmware to the latest versions is critical, as is replacing obsolete hardware that no longer receives security patches to prevent initial compromise.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago