Rove Digital was an Estonian cybercrime group best known for operating the DNSChanger malware as part of the Ghost Click criminal enterprise. The group altered DNS settings on victim systems to hijack web traffic, redirect users to fraudulent or manipulated destinations, and invisibly substitute legitimate online advertisements with ads under the gang’s control. This activity monetized victim traffic at scale and generated illicit revenue while harming advertisers, merchants, banks, and end users. In some cases, the malware also interfered with antivirus updates, increasing the longevity of infections and hindering remediation. Rove Digital is associated with aliases including Cernel, Esthost, Estdomain, and Ukrtelegroup. Vladimir Tsastsin was identified as the group’s leader. The operation relied on criminal infrastructure and long-lived hosting support, including bulletproof hosting services linked to Atrivo/Intercage. The group’s activity was significant enough to prompt a joint United States-Estonia law-enforcement action in 2011 that dismantled the Ghost Click network. Operationally, Rove Digital demonstrated capabilities spanning initial access through malware distribution, persistence via DNS-setting manipulation that maintained traffic control, defense evasion through blocking or degrading antivirus updates, and post-exploitation monetization through traffic redirection and ad replacement. Its core objective was financial gain rather than espionage or disruption. The campaign affected millions of users, with a large fraction of victims located in the United States.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cybercrime group behind the DNSChanger malware operation, hijacking victims' DNS settings to redirect users to attacker-controlled websites and replace advertisements for profit.
Cybercrime group dismantled in Operation Ghost Click; operated DNS-changing malware to redirect victims to fraudulent or substituted websites and ads, generating illicit advertising revenue and interfering with antivirus updates.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.