Cybersecurity report

# Home Routers Under Attack via DNSChanger Malware on Windows, Android Devices

Proofpoint, December 13, 2016. That the 2016 'DNSChanger' activity is an unrelated router-targeting exploit kit delivered through malvertising, not a return of the Rove Digital DNSChanger operation taken down in 2011: it attacks SOHO router vulnerabilities from the victim's browser and carries no operator, infrastructure or code continuity with Rove Digital..

**Source type:** Cybersecurity report

**Published:** December 13, 2016

**Research grade:** T2

**Used in entries:** 1

## Bibliographic record

**Publisher:** Proofpoint

**Published:** December 13, 2016

**Source type:** Cybersecurity report

**Research grade:** Source grade T2

**Language:** English

**Official record:** Not an official publication

**Address:** [https://www.proofpoint.com/us/blog/threat-insight/home-routers-under-attack-dnschanger-malware-windows-android-devices](https://www.proofpoint.com/us/blog/threat-insight/home-routers-under-attack-dnschanger-malware-windows-android-devices)

**What it supports:** That the 2016 'DNSChanger' activity is an unrelated router-targeting exploit kit delivered through malvertising, not a return of the Rove Digital DNSChanger operation taken down in 2011: it attacks SOHO router vulnerabilities from the victim's browser and carries no operator, infrastructure or code continuity with Rove Digital.

**Dataset id:** src\_proofpoint\_dnschanger\_ek\_2016

## Research notes

- By Kafeine (Proofpoint threat research). Page header reads 'December 13, 2016'; article:published\_time is 2016-12-13T11:06:47-08:00.
- The post carries an in-line note '[Updated December 19, 2016 to reflect additional data received from one of the affected traffic brokers...]' - the original publication date is 2016-12-13.
- Name collision only: the post never mentions Rove Digital, the 2011 Operation Ghost Click takedown or the substitute DNS servers.

How this source is used

Cited 1 time across 1 record type.

The role on each citation records what the source was relied on for. A primary source establishes the fact, a supporting source corroborates it, technical evidence describes the infrastructure, and a later outcome records what happened afterwards.

Sources were reviewed to a research cutoff of August 23, 2026. Addresses recorded after that date are not reflected here.

## Cited by

### Later activity

1 citation

Cited for activity recorded after the takedown.

-
[No documented return](https://takedownindex.org/takedowns/operation-ghost-click)

Relationship not established, Operation Ghost Click

Background

[All sources](https://takedownindex.org/sources)
