DNSChanger is a trojan/botnet malware family used to hijack DNS resolution by modifying DNS settings on infected systems and network devices. The content states it was used beginning in 2007 by a cybercriminal ring that infected approximately 4 million computers in more than 100 countries, including about 500,000 in the United States, and also affected Windows and Mac systems as well as routers. On infected hosts, DNSChanger redirected DNS requests to attacker-controlled rogue DNS servers, allowing the operators to manipulate outbound Internet traffic, redirect users seeking legitimate websites to attacker-selected destinations, substitute advertisements, and generate fraudulent affiliate, referral, and advertising revenue. In some cases it also prevented antivirus and operating system updates, increasing exposure to additional malware.
The malware is strongly associated in the content with the Estonian cybercrime organization Rove Digital, its hosting subsidiary Esthost, and the FBI-led Operation Ghost Click investigation. The scheme allegedly generated at least $14 million in illicit revenue and impacted individuals, businesses, and government entities, including NASA. The content also links DNSChanger distribution infrastructure to fake codec and media-themed social-engineering campaigns, with samples such as hificodec1001.exe detected by multiple vendors as Trojan.DNSChanger variants.
The content further describes later DNSChanger activity targeting vulnerable consumer routers. A campaign between December 2018 and April 2019 remotely reconfigured DNS servers on vulnerable routers, including D-Link devices such as the DSL-2640B, to hijack user traffic. Related reporting in the content says attackers exploited unauthenticated router web-interface flaws to change DNS settings, used automation tools and publicly disclosed exploits, and in some cases leveraged Google Cloud Platform infrastructure to distribute a DNSChanger variant. High-confidence indicators and artifacts directly mentioned include the sample name hificodec1001.exe and the domain HIFICODEC.COM associated with DNSChanger-labeled malware distribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Rove Digital ran a sophisticated operation in which the DNSChanger malware changed the DNS settings on the victim's computers.
12 distinct techniques documented for this family, organized by ATT&CK tactic.
The content catalogs numerous websites and domains hosting fake codec/software downloads, such as HIFICODEC.COM, MEDIACODEC2006.COM, ZCODEC.COM, PLAYERCODEC.NET, and related domains tied to executable installers.
In 2017, an exploit got posted to exploit-db.com that allows unauthenticated modification of the device's DNS server settings. This vulnerability is used by the DNSChanger malware during its 2018-2019 campaign.
21 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DNSChanger is a malware variant used to hijack DNS settings on vulnerable routers, redirecting user traffic to malicious infrastructure for purposes such as malvertising, phishing, and persistent traffic interception.
Router-targeting malware known for modifying DNS settings to hijack/search-redirect traffic; referenced as an example of attackers changing router DNS to malicious resolvers.
Router-targeting malware known for modifying DNS settings to hijack/search-redirect traffic; referenced as an example of how attackers could abuse router DNS changes.
Router-targeting malware (historical reference) that modified DNS settings to hijack/search-redirect traffic at scale.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.