Researchers detailed the GhostDNS operation, a DNS-hijacking toolkit that compromised poorly secured SOHO and home routers in Brazil to redirect victims to phishing pages for banks and other services. The leaked source code showed a mature kit with versions dating back to 2017, including phishing templates, rogue DNS configurations, and tooling to alter router settings through CSRF requests and brute-forced default credentials. In some cases, the malware reset router passwords to attacker-controlled values such as deadcorp2017 and Snowden, giving operators persistent access to infected devices.
Separate analysis tied the campaign to malvertising that redirected Brazilian users from legitimate sites through attacker infrastructure, including domains such as googleads.store, to scripts that probed common private gateway addresses and attempted DNS changes across multiple router models. Once a router's DNS settings were changed, victims were sent to counterfeit banking portals, including fake Banco do Brasil pages, where attackers harvested login credentials and payment card data. The reporting indicates the campaign was heavily concentrated in Brazil, where weak default router passwords remained common, and that the operation extended into a broader criminal market selling both the toolkit and stolen financial data.

Map this exposure pattern across your cloud, code, and identities.
5 events from the most recent confirmed update back to the earliest known activity.
Avast said credit card details stolen via GhostDNS were still available for sale in April 2020, typically priced between $10 and $25. This showed the campaign's monetization ecosystem was still active at that time.
In May 2019, Avast Web Shield blocked a Sendspace URL that led researchers to a malicious RAR archive named "KL DNS.rar" containing GhostDNS source code, phishing pages, and DNS-hijacking infrastructure. The find exposed multiple versions of the toolkit and its supporting components.
Avast reported that GhostDNS source code was being sold on darknet markets for about $450. This indicated the DNS-hijacking toolkit had entered a broader criminal marketplace.
Avast found five GhostDNS source code implementations in the leaked archive, with the oldest file metadata dating to July 2017. The code showed the toolkit was already developed to hijack router DNS settings, reset router credentials, and support phishing against Brazilian targets.
CUJO AI analyzed an ongoing campaign in which victims visiting pages associated with ofuxico.com.br were redirected to malicious infrastructure on googleads.store. The attack used browser-based CSRF requests and weak/default router credentials to change DNS settings on Brazilian home routers and redirect users to fake banking pages.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.