Netskope Threat Labs

DnsChanger

ATP Sandbox Adv. HeuristicsAV

DnsChanger is a trojan family that changes the DNS settings of infected systems to reroute traffic. Researchers associate the family with the Alureon malware and its domain generation algorithm. An international law enforcement operation dismantled the network behind it in November 2011, and temporary legitimate servers stayed online until July 2012 to avoid stranding millions of infected machines.

First seen
May 2022
Last seen
October 2026
DNSChanger
Alert Name
Dump:Trojan.DNSChanger.AF
JS:Trojan.DNSChanger.WW
MAC.OSX.Trojan.DNSChanger.Q
Script-JS.Trojan.DnsChanger
Script-WScript.Trojan.DnsChanger
Trojan.DNSChanger.VD
Win32.Trojan.DnsChanger