Rove Digital was a ROKSO-listed cybercrime gang dismantled in the November 9, 2011 Ghost Click joint U.S.-Estonian law enforcement operation. The group operated the DNSChanger malware, which modified victims’ DNS settings to redirect users to fraudulent or manipulated destinations, including sites impersonating legitimate web merchants, banks, and other companies. The malware also replaced legitimate advertisements from companies such as Google and Microsoft with ads controlled by the gang, generating illicit revenue and stealing income from legitimate advertisers and clients. In some cases, the malware blocked antivirus definition updates, hindering detection and removal. The operation reportedly generated more than $10 million in illicit gains and infected millions of users. Vladimir Tsastsin is identified as the leader. Known aliases mentioned in the content include Cernel, Esthost, Estdomain, and Ukrtelegroup. The content also states that Atrivo/Intercage, operated by Emil Kacperski, provided bulletproof hosting to Rove Digital on hundreds of IP addresses as early as September 2004.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercrime group behind the DNSChanger malware operation, hijacking victims' DNS settings to redirect users to attacker-controlled websites and replace advertisements for profit.
Cybercrime group dismantled in Operation Ghost Click; operated DNS-changing malware to redirect victims to fraudulent or substituted websites and ads, generating illicit advertising revenue and interfering with antivirus updates.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.