#Aeza
DNSハイジャックに関与した制裁対象のブレットプルーフホスト

研究者によると、金銭目的の脅威アクターが数十のDNS(ドメインネームシステム)リゾルバーをハッキングし、それらを、犯罪とのつながりを理由に米財務省から制裁を受けたロシアのブレットプルーフ・ホスティングサービスのインフラに接続していた。 ネットワークセキュリティ企業Infobloxは火曜日のブログ投稿で、設定が改ざんされ、DNSクエリをAeza…
DNSハイジャックに関与した制裁対象のブレットプルーフホスト
研究者によると、金銭目的の脅威アクターが数十のDNS(ドメインネームシステム)リゾルバーをハッキングし、それらを、犯罪とのつながりを理由に米財務省から制裁を受けたロシアのブレットプルーフ・ホスティングサービスのインフラに接続していた。 ネットワークセキュリティ企業Infobloxは火曜日のブログ投稿で、設定が改ざんされ、DNSクエリをAeza Internationalがホストするシャドーリゾルバーへ転送するようにされた侵害済みルーターを観測したと述べた。財務省は7月、Aezaが複数のサイバー犯罪グループと結び付けられたことを受け、Aezaおよび同社の幹部をドル決済システムから遮断した(参照:米国、インフォスティーラーとランサムウェアをホスティングしたAezaグループを制裁)。 シャドーAezaシステムは通常、GoogleやFacebookのような非常に人気の高いドメインを正しいIPアドレスに解決していた。予測不能な間隔で行われる一部のDNSクエリには、マルウェアや詐欺などの悪意あるコンテンツが返された。Infobloxは、この作戦(2022年半ばから稼働していたようだ)を、「アフィリエイトマーケティング領域の、金銭目的の無名アクター」によるものだとした。 「これだけは強調してもしきれません。DNSリゾルバーは権力を持つ立場にあるのです」とInfobloxは記した。 ハッカーは古いルーターを標的にしたが、2025年にはRedditユーザーの1人が、インターフェースが誤ってインターネットに公開されていた仮想ルーターがハッカーに侵害されたと訴えた。ハッカーはユーザーをrootアカウントから締め出し、暗号資産マイナーを仕込んだ。 この脅威アクターは、DNSハイジャックを、ユーザーをフィンガープリントして2つの異なるアドテックプラットフォームへ誘導するために用いられるトラフィック配信システムと組み合わせていた。 この活動がこれほど長期間検知されなかった理由の一つは、シャドーリゾルバーが特定の形式のDNSクエリにのみ応答する点にある可能性がある。具体的には、Infobloxによれば、ハッカーはEDNS(DNS拡張機構)を無効化していた。これは、元のプロトコル仕様を超えてDNSクエリのサイズを拡張するための広く普及した手法だ。「ほとんどのDNSリゾルバーはEDNS0を有効にしているため、Aezaホストへのクエリは通常、不正な形式の応答になる」と同社は述べた。 Infobloxの脅威インテリジェンス担当バイスプレジデントであるRenée Burton氏はメールで、「この活動は、DNS解決の完全性が企業と家庭の双方を守るうえで極めて重要であることを思い起こさせる。これがなければ、組織は自社デバイスがどこに接続しているのかを制御できない」と述べた。 ルーター(特に小規模オフィス/ホームオフィス向けのルーター)は、その所有者の大半が更新をインストールしない傾向にあるため、恒常的にハッキングの標的となっている。英国のブロードバンド比較サイトの利用者3,000人超を対象にした2025年の調査では、ユーザーの84%がルーターのファームウェアを一度も更新しないと回答した。 メーカーは、ルーターがファームウェア更新を自動的に受け取れるようにする点では改善してきたが、サポート終了(EOL)のルーターは、見た目には通常どおり動作し続けているにもかかわらず、サポートされない。FBIは2025年5月、SOHOルーターの所有者に対し、サポートされていない機器はアップグレードするか、少なくともリモート管理を無効化するよう注意喚起した。 翻訳元:
blackhatnews.tokyo
February 9, 2026 at 10:42 PM
RE: https://infosec.exchange/@InfobloxThreatIntel/116018733747580425

Incidentally, Aeza has been a blackhole-worthy operation for years.
infosec.exchange
February 5, 2026 at 4:24 PM
Compromised Routers, DNS, And A TDS Hidden In Aeza Networks https://packetstorm.news/news/view/40317 #news
February 4, 2026 at 7:05 PM
Compromised Routers, DNS, and a TDS Hidden in Aeza Networks www.infoblox.com/blog/threat-...
Compromised Routers, DNS, and a TDS Hidden in Aeza Networks
Compromised routers silently reroute DNS, enabling a powerful Traffic Distribution System (TDS) that forces users to scams and malware via affiliate marketing.
www.infoblox.com
February 4, 2026 at 4:12 AM
🕵️ Aéza, linked to the pro-Kremlin Doppelganger disinfo network, has been sanctioned by the US, Australia, and the UK for aiding cybercriminals. The EU, however, has taken no action. investigace.cz
From Darknet to Disinfo: How a ‘Bulletproof’ Russian Host Evades EU Sanctions - VSquare.org
The Russian server hosting company Aéza is known for its involvement in the pro-Kremlin Doppelganger disinformation campaign, which spread propaganda through look-alike clones of major news outlets.
vsquare.org
January 18, 2026 at 7:30 PM
🕵️ Aéza, linked to the pro-Kremlin Doppelganger disinfo network, has been sanctioned by the US, Australia, and the UK for aiding cybercriminals. The EU, however, has taken no action. investigace.cz
From Darknet to Disinfo: How a ‘Bulletproof’ Russian Host Evades EU Sanctions - VSquare.org
The Russian server hosting company Aéza is known for its involvement in the pro-Kremlin Doppelganger disinformation campaign, which spread propaganda through look-alike clones of major news outlets.
vsquare.org
January 11, 2026 at 7:30 PM
Me and my friend Aeza had some fun. (I made these last week and forgot to post them)
January 11, 2026 at 7:56 AM
🕵️ Aéza, linked to the pro-Kremlin Doppelganger disinfo network, has been sanctioned by the US, Australia, and the UK for aiding cybercriminals. The EU, however, has taken no action. @investigacecz.bsky.social
From Darknet to Disinfo: How a ‘Bulletproof’ Russian Host Evades EU Sanctions - VSquare.org
The Russian server hosting company Aéza is known for its involvement in the pro-Kremlin Doppelganger disinformation campaign, which spread propaganda through look-alike clones of major news outlets.
vsquare.org
January 4, 2026 at 8:23 PM
適当にぼや〜っとSims4!🌙🌱 260104-02
YouTube video by ぷー
youtube.com
January 4, 2026 at 10:07 AM
💥Linked to the pro-Kremlin Doppelganger disinformation campaign, the Russian hosting firm Aéza has been sanctioned by the US, Australia, and the UK and its founders charged in Russia. Yet despite operating servers in Europe, the EU has taken no action.
From Darknet to Disinfo: How a ‘Bulletproof’ Russian Host Evades EU Sanctions - VSquare.org
The Russian server hosting company Aéza is known for its involvement in the pro-Kremlin Doppelganger disinformation campaign, which spread propaganda through look-alike clones of major news outlets.
vsquare.org
January 2, 2026 at 5:05 PM
Russian bulletproof hosting company Aeza (under international sanctions) told its customers earlier this month that Roskomnadzor had demanded deletion of VPN servers it was hosting.
t.me/aezachat_ru/...
Валерий // ае́за in Aéza ❯ чат
Не факт, нам просто прислали список IP, которым необходимо направить требование об удалении Необходимо удалить VPN, либо ограничить доступ к запрещенным ресурсам, либо любым другим способом сделать т...
t.me
December 29, 2025 at 5:16 PM
🕵️ Aéza, linked to the pro-Kremlin Doppelganger disinfo network, has been sanctioned by the US, Australia, and the UK for aiding cybercriminals. The EU, however, has taken no action. @investigacecz.bsky.social
From Darknet to Disinfo: How a ‘Bulletproof’ Russian Host Evades EU Sanctions - VSquare.org
The Russian server hosting company Aéza is known for its involvement in the pro-Kremlin Doppelganger disinformation campaign, which spread propaganda through look-alike clones of major news outlets.
vsquare.org
December 28, 2025 at 8:25 PM
💥Linked to the pro-Kremlin Doppelganger disinformation campaign, the Russian hosting firm Aéza has been sanctioned by the US, Australia, and the UK and its founders charged in Russia. Yet despite operating servers in Europe, the EU has taken no action.
From Darknet to Disinfo: How a ‘Bulletproof’ Russian Host Evades EU Sanctions - VSquare.org
The Russian server hosting company Aéza is known for its involvement in the pro-Kremlin Doppelganger disinformation campaign, which spread propaganda through look-alike clones of major news outlets.
vsquare.org
December 26, 2025 at 5:05 PM
🕵️ Aéza, linked to the pro-Kremlin Doppelganger disinfo network, has been sanctioned by the US, Australia, and the UK for aiding cybercriminals. The EU, however, has taken no action. @investigacecz.bsky.social
From Darknet to Disinfo: How a ‘Bulletproof’ Russian Host Evades EU Sanctions - VSquare.org
The Russian server hosting company Aéza is known for its involvement in the pro-Kremlin Doppelganger disinformation campaign, which spread propaganda through look-alike clones of major news outlets.
vsquare.org
December 21, 2025 at 8:29 PM
💥Linked to the pro-Kremlin Doppelganger disinformation campaign, the Russian hosting firm Aéza has been sanctioned by the US, Australia, and the UK and its founders charged in Russia. Yet despite operating servers in Europe, the EU has taken no action.
From Darknet to Disinfo: How a ‘Bulletproof’ Russian Host Evades EU Sanctions - VSquare.org
The Russian server hosting company Aéza is known for its involvement in the pro-Kremlin Doppelganger disinformation campaign, which spread propaganda through look-alike clones of major news outlets.
vsquare.org
December 19, 2025 at 5:05 PM
🕵️ Aéza, linked to the pro-Kremlin Doppelganger disinfo network, has been sanctioned by the US, Australia, and the UK for aiding cybercriminals. The EU, however, has taken no action. @investigacecz.bsky.social
From Darknet to Disinfo: How a ‘Bulletproof’ Russian Host Evades EU Sanctions - VSquare.org
The Russian server hosting company Aéza is known for its involvement in the pro-Kremlin Doppelganger disinformation campaign, which spread propaganda through look-alike clones of major news outlets.
vsquare.org
December 14, 2025 at 8:29 PM
💥Linked to the pro-Kremlin Doppelganger disinformation campaign, the Russian hosting firm Aéza has been sanctioned by the US, Australia, and the UK and its founders charged in Russia. Yet despite operating servers in Europe, the EU has taken no action.
From Darknet to Disinfo: How a ‘Bulletproof’ Russian Host Evades EU Sanctions - VSquare.org
The Russian server hosting company Aéza is known for its involvement in the pro-Kremlin Doppelganger disinformation campaign, which spread propaganda through look-alike clones of major news outlets.
vsquare.org
December 12, 2025 at 5:06 PM
Paper 1.21.8 (Protocol 764)

🇷🇺 Russia
AS216246 (Aeza Group LLC)
Max players: 20

Online Mode: ❌

🕐 Crawled at 2025-12-03 03:07:25.831 UTC

#Minecraft #MinecraftServer #MCScan #kittyscan
December 12, 2025 at 3:54 AM
Les sanctions coordonnées contre Media Land et Aeza visent le cœur de l’infrastructure russe d’hébergement « inviolable », clé pour les campagnes de ransomwares et d’opérations de cybercriminalité à l’échelle internationale. www.zataz.com/sanctions-co...
ZATAZ » Sanctions contre l’hébergement russe pro-ransomware
www.zataz.com
December 10, 2025 at 5:49 PM
🕵️ Aéza, linked to the pro-Kremlin Doppelganger disinfo network, has been sanctioned by the US, Australia, and the UK for aiding cybercriminals. The EU, however, has taken no action. @investigacecz.bsky.social
From Darknet to Disinfo: How a ‘Bulletproof’ Russian Host Evades EU Sanctions - VSquare.org
The Russian server hosting company Aéza is known for its involvement in the pro-Kremlin Doppelganger disinformation campaign, which spread propaganda through look-alike clones of major news outlets.
vsquare.org
December 7, 2025 at 8:27 PM
📌 Aeza Hosting Orders Removal of VPN Servers Under Roskomnadzor Pressure https://www.cyberhub.blog/article/16472-aeza-hosting-orders-removal-of-vpn-servers-under-roskomnadzor-pressure
Aeza Hosting Orders Removal of VPN Servers Under Roskomnadzor Pressure
Aeza, a Russian hosting provider, has begun notifying its users to remove VPN servers that facilitate access to internet resources blocked within Russia. This action follows a directive from Roskomnadzor, Russia's federal communications regulator. Users have been given a 24-hour ultimatum to comply or face potential service termination. The directive specifically targets services that enable access to information or resources restricted on Russian territory. However, the notification lacks specific details regarding the timeline for enforcement or a comprehensive list of affected services. This development underscores the ongoing efforts by Russian authorities to enforce internet censorship through pressure on infrastructure providers. For cybersecurity professionals, this event highlights the increasing role of hosting providers in enforcing state-level censorship measures. The primary impact is on users who rely on Aeza's infrastructure to host VPN services, potentially disrupting their ability to bypass geo-restrictions and access blocked content. This move may signal a broader trend of hosting providers being co-opted into censorship enforcement, with implications for internet freedom and cybersecurity practices in Russia. The lack of specific details in the notification makes it challenging to assess the full scope and impact of this directive.
www.cyberhub.blog
December 7, 2025 at 7:20 PM
Sanction The Russians Keep The Pipes Open — The Aeza case shows how Western transit and legal shields keep Russian ransomware and disinformation online.
Sanction The Russians Keep The Pipes Open
The Aeza case shows how Western transit and legal shields keep Russian ransomware and disinformation online.
www.bullionbite.com
December 7, 2025 at 4:49 PM
💥Linked to the pro-Kremlin Doppelganger disinformation campaign, the Russian hosting firm Aéza has been sanctioned by the US, Australia, and the UK and its founders charged in Russia. Yet despite operating servers in Europe, the EU has taken no action.
From Darknet to Disinfo: How a ‘Bulletproof’ Russian Host Evades EU Sanctions - VSquare.org
The Russian server hosting company Aéza is known for its involvement in the pro-Kremlin Doppelganger disinformation campaign, which spread propaganda through look-alike clones of major news outlets.
vsquare.org
December 5, 2025 at 5:03 PM
Esta es de las mejores canciones de JuanGa y se callan:
music.youtube.com/watch?v=AEzA...
Insensible
YouTube video by Juan Gabriel - Topic
music.youtube.com
December 4, 2025 at 8:51 PM