DNSChanger is a malware family best known for hijacking Domain Name System settings on infected systems and network devices in order to redirect victim traffic through attacker-controlled name servers. Active since at least 2007, it was used at large scale by the Rove Digital criminal operation in a scheme that infected millions of systems across more than 100 countries and generated illicit revenue through advertising fraud, affiliate abuse, and traffic redirection. Victims included consumers, enterprises, and government organizations. The malware was also associated with the FBI’s Operation Ghost Click, which disrupted the rogue DNS infrastructure and led to arrests tied to the operation.
On endpoint systems, DNSChanger functioned as a Trojan that modified DNS configuration so that web requests could be steered to destinations chosen by the operators. This enabled search and advertising hijacking, redirection to fraudulent or monetized pages, and in some cases interference with antivirus and operating system updates. Some samples also used a domain generation algorithm to produce pseudo-random domains after DNS settings were changed; available reverse engineering indicates these domains were likely used as probes to verify that malicious DNS changes had taken effect and to signal newly infected hosts to rogue name servers rather than to provide conventional command-and-control rendezvous.
DNSChanger also expanded beyond traditional Windows infections to affect macOS systems and consumer routers. Later campaigns targeted vulnerable network devices by remotely altering router DNS settings, allowing attackers to hijack traffic for all users behind the device without installing malware on each endpoint individually. Documented campaigns from 2018 to 2019 targeted vulnerable consumer routers, including certain D-Link models, and used automated exploitation to reconfigure DNS settings at scale. This router-focused activity supported traffic hijacking, phishing, malvertising, and malware distribution.
Historically, DNSChanger was distributed through socially engineered malware ecosystems that included fake codec and media-related installers, and it has been linked to broader affiliate-driven cybercrime operations. Its defining behavior is DNS manipulation for monetization and traffic control rather than destructive impact, making it a notable example of large-scale criminal infrastructure abuse and network-level user redirection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Rove Digital ran a sophisticated operation in which the DNSChanger malware changed the DNS settings on the victim's computers.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
The content catalogs numerous websites and domains hosting fake codec/software downloads, such as HIFICODEC.COM, MEDIACODEC2006.COM, ZCODEC.COM, PLAYERCODEC.NET, and related domains tied to executable installers.
In 2017, an exploit got posted to exploit-db.com that allows unauthenticated modification of the device's DNS server settings. This vulnerability is used by the DNSChanger malware during its 2018-2019 campaign.
32 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DNSChanger is a malware variant used to hijack DNS settings on vulnerable routers, redirecting user traffic to malicious infrastructure for purposes such as malvertising, phishing, and persistent traffic interception.
Router-targeting malware known for modifying DNS settings to hijack/search-redirect traffic; referenced as an example of attackers changing router DNS to malicious resolvers.
Router-targeting malware known for modifying DNS settings to hijack/search-redirect traffic; referenced as an example of how attackers could abuse router DNS changes.
Router-targeting malware (historical reference) that modified DNS settings to hijack/search-redirect traffic at scale.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.