Silent Push Tracks a Mass Phishing Operation Through Fast Flux

platform, threat

Key Findings

  • The fast-flux technique has evolved, making it easier for threat actors to use in phishing campaigns and harder for defenders to detect and apprehend cybercriminals.
  • Silent Push became a fast-flux customer to watch how the infrastructure behaves from the inside, and then turned what we learned into detection analytics.
  • From a single query in our platform, we identified thousands of live phishing domains, including a large, Canada-first banking campaign that hides behind commercial traffic-distribution cloaking.
  • Beyond CISA’s recommendations to protect against fast-flux attacks, our platform detects fast-flux infrastructure to provide proactive protection.


Executive Summary

While the “fast flux” technique of rapidly rotating a domain’s DNS records across many IP addresses and networks to avoid detection is not new, it has become more sophisticated and easier for threat actors to use in phishing campaigns and other malicious activities.

Going deeper into our research on fast flux, we became a customer to see its inner workings. We identified a large, active global phishing operation from a single query in our platform. This blog outlines some of the phishing campaign’s infrastructure; its structure is quite effective, making it nearly impossible for most defenders to detect.

Organizations should develop fast-flux detection analytics and blocking capabilities. Our platform enables security teams to protect against fast-flux infrastructure.

Background: Why Threat Actors Love Fast Flux

When The Honeynet Project first documented the fast-flux technique in 2007, the rotating IP address pool was the attacker’s own botnet: thousands of infected home computers acting as proxies in front of the real server. Since then, the technique has evolved and expanded, becoming easier for threat actors to use and harder for defenders to stop.

Today, that same capability is rented on a subscription basis, openly marketed on cybercrime forums, and sold by providers, including at least one sanctioned bulletproof hoster. Phishing operators simply point their domains at the service, and the provider rotates the underlying infrastructure.

Defenders have two ways to block a malicious site: block the domain, or block the IP address that it resolves to. Domain blocking works, but it is slow since it depends on registrars, registries, or courts, and it requires knowing every domain the operation uses.

Conversely, IP blocking is fast, but fast flux is built to defeat it: a single domain rotates across a constantly changing pool of IPs spread over different networks and often various countries. Block one IP, and the domain resolves to another within minutes. Defenders end up chasing a moving target of disposable addresses. For phishing, Command and Control (C2), and scam infrastructure, this turns IP blocking into a losing game and leaves the domain as the only durable point of failure.

Becoming a Customer to See Inside

To better understand how to detect this layer, our team of researchers did what defenders rarely can: we became a customer. We purchased a fast-flux service from a provider on the market, watched how the infrastructure behaves from the inside, and turned what we learned into detection analytics.

From a single query in our platform, we found thousands of live phishing domains. This includes a large, active, Canada-first banking phishing operation that hides behind commercial traffic-distribution cloaking. The operation is so effective that the overwhelming majority of outside scans see nothing but a “404” (Not Found) page.

In April 2025, CISA, jointly with the NSA, FBI, and international partners, published Fast Flux: A National Security Threat, warning that fast flux “exploits a gap commonly found in network defenses.” The advisory explicitly encourages service providers to “develop accurate, reliable, and timely fast-flux detection analytics and blocking capabilities.” This is what our preemptive cyber defense delivers.


Fast Flux as a Service: A Mature Criminal Market

We purchased a fast-flux package from a provider on the market. We paid, and within hours we had what any hosting customer gets: a client portal, a support ticket system, and provisioning instructions directing customers to delegate their domain to a specific DNS provider: the exact delegation signature our detections now key on.

Through OSINT research, one of our threat analysts identified another fast-flux panel offering posted on a Russian-language criminal forum by a user named “Yalishanda.” Tiered pricing was up to $550 for unlimited domains, with customer service in Russian, English, and Chinese.

Yalishanda was advertising custom encrypted proxy infrastructure, decoy traffic, and abuse-proof hosting on behalf of Media Land, a bulletproof hosting provider sanctioned by the U.S. Department of the Treasury for supporting ransomware and other cybercrime operations.

Screenshot of a fast flux panel advertised on a criminal forum by “Yalishanda”
Screenshot of a fast flux panel advertised on a criminal forum by “Yalishanda”

Pivoting further, we uncovered a second actor actively selling fast flux on the same DNS delegation layer: a service calling itself “ShadowRelay,” advertised on criminal forums since April 2026.

The sales pitch is bluntly direct: a “completely anonymous platform with no KYC, no verification,” registration with just a username and password, and payment accepted in nine cryptocurrencies, including Monero, processed directly without payment gateways.

Its customer panel sells fast flux by subscription tier, from $150 per month for a single domain to $700 per month for unlimited domains, with options to rotate IPs in RoundRobin mode or spread them across different domains. The service’s own description promises that its proxy IPs “can change several times an hour.”

ShadowRelay's forum advertisement (April 2026)
ShadowRelay’s forum advertisement (April 2026)

Screenshot of ShadowRelay's customer panel
ShadowRelay’s customer panel

What Silent Push Identified

Every fast-flux provider we have tracked protects itself the same way: the provider’s own domains never touch the customer infrastructure. Instead, each customer delegates to provider-controlled DNS, which then hands out the rotating IP addresses. That delegation layer is the detection opportunity, and it is invisible unless you know where to look.

Knowing Where to Look

One query in the Silent Push platform combines the nameserver signature with ASN and IP diversity scoring to isolate this provider’s fast-flux layer, surfacing every domain that delegates to it, the moment it appears (the Domain Search datasource requires an Enterprise subscription):

datasource = ["domainsearch"] AND asn_diversity_min = 4 AND ip_diversity_all_min = 4 AND asnum = ["14956", "58061", "49468", "215439", "197574", "209378", "198550"] AND nsname = "a.dnspod.com" AND asn_match_min = 3 AND asn_match = "limit"

Domain search fast flux detection
Domain search fast flux detection

The rotation is visible at the single-domain level. Loading one of the Canada Post lure domains into Total View’s Infrastructure Variance tab shows the domain resolving to 20 different IPs across 13 ASNs over a 90-day window; each bar below is a separate network the same domain answered from.

IP diversity view of the phishing domain (canada-post11[.]com) in Total View (Infrastructure Variance): 20 IPs across 13 ASNs over 90 days - the fast-flux rotation visible in a single domain
IP diversity view of the phishing domain (canada-post11[.]com) in Total View (Infrastructure Variance): 20 IPs across 13 ASNs over 90 days – the fast-flux rotation visible in a single domain

Layering our web-scan fingerprints on top of that feed exposed what the infrastructure is actually serving. One cluster alone is a phishing operation targeting nearly 2,000 domains. Roughly nine in ten of them impersonate Canadian organizations, including every major bank, the tax authority, the postal service, and provincial benefit programs.

The activity has been doubling month over month, with the heaviest volume on record in the most recent month. The campaign is still ramping up and shows no signs of slowing down.

It’s not just Canada. Behind the same fast-flux layer, we found bank look-alikes in the U.K., the U.S., Australia, and Europe, plus telecom providers, tax authorities, email marketing platforms, and crypto brands. One registration persona alone covers more than twenty bank brands across four continents.


Two Clusters and Two Playbooks

Cluster 1: The Canadian Banking Kit

Every domain in the Canadian operation sits behind Keitaro, a commercial traffic distribution system (TDS). Each visitor is profiled before seeing anything. The TDS issues tracking cookies containing a campaign ID, first-touch timestamp, and per-visitor counters, and it also profiles the device. Every response we probed requests mobile client hints, meaning the operation actively filters for victims on phones, consistent with links distributed by text message.

Visitors who pass the filter receive a single-use, per-victim entry URL. For example, ca/37b1477c-6e1c-4d92-b968-8a16537a8cda/aec2d7a4113dfcb1.phpa UUID folder generated server-side for one victim contains a randomly named landing page, burned the moment it is issued. Canadian residential users land on the phishing kit while security scanners, researchers, and foreign visitors get a “404” (Not Found) response instead.

Behind the gate, there is a phishing kit. An operator watches each victim live, receives keystrokes before form submission, and pushes each session to arbitrary next steps: fake OTP pages, verification screens, and error loops, while testing the stolen credentials against the real bank in parallel. This is not a static clone page; it is interactive, operator-driven account takeover at scale.

Fake Interac e-Transfer "deposit" page at etranferts[.]com
Fake Interac e-Transfer “deposit” page at etranferts[.]com

Cluster 2: The Callback Operation – Fake Fraud Hotlines

A second cluster behind the same fast-flux layer runs a different playbook across a wider target list; U.K. banks take the heaviest fire, but the same registration persona covers Canadian, U.S., Australian, and European banks, plus fintechs such as Wise, crypto wallets, and email marketing platforms.

The domains pose as “fraud team,” “security centre,” and “live help” pages for callback phishing, but the same pages also carry full cloned login forms that post the victim’s username and password to a security.php endpoint, so the operation takes the credentials directly and works the victim over the phone at the same time.

The payload goes beyond credentials. A verify-download.php gate pushes a Windows executable presented as a fraud-team “security verification” tool, locked behind a one-time code issued live by the “agent” through the site’s built-in chat – with no conversation, no payload.

The malicious binary ships in a password-protected ZIP, with the password returned by the server and shown on the page only after a valid code is entered, a trick that defeats email and web scanning.

One endpoint serves four modes (download, live chat, fraud report, and call verification) across multiple brand skins.

The division of labor makes callback phishing very effective: nothing in the lure itself is malicious, because the payload moves only once a live “support agent” has the victim engaged.

The cloned login form steals the credentials, while the floating “Verify Call” and “Live Chat” buttons route the victim to a live operator who issues a malicious binary.
The cloned login form steals the credentials, while the floating “Verify Call” and “Live Chat” buttons route the victim to a live operator who issues a malicious binary

What to Block and Monitor Now

Fast flux is a well-known and popular technique used by cybercriminal groups and nation-state actors alike. CISA’s advisory is direct: defenders should not assume their providers detect it. Organizations that want to close this gap should act on three fronts:

  • IOFA feeds: Exclusive to Enterprise clients, Silent Push Indicators of Future Attack (IOFA®) feeds for this fast-flux infrastructure – including the Fastflux, Dnspod Domains, and IPs feeds – are available via API and STIX/TAXII for direct integration into your firewall, SIEM, or EDR. These feeds flag domains the moment they are delegated to the fast-flux nameservers, before the first lure is sent, and track the rotating IP pools behind them, so blocking stays effective as addresses churn.
  • DNS-level detection: Per the CISA advisory, implement fast-flux detection analytics at the DNS level: alert on domains with high IP/ASN diversity, abnormally low TTLs, and inconsistent IP geolocation, and validate that your Protective DNS provider actually blocks fast-flux behavior rather than assuming coverage. Silent Push customers can run this check on any domain directly – Total View’s Infrastructure Variance tab shows a domain’s IP and ASN diversity over time, making fast-flux rotation visible in seconds.
  • Reputational filtering: Block traffic to and from domains and IPs associated with known bulletproof and abuse-tolerant networks, including infrastructure tied to sanctioned hosting providers. Not every ASN in a fast-flux rotation is bulletproof; the pool mixes abuse-tolerant networks with ordinary hosting, so block the confirmed bulletproof ASNs and monitor the rest. The abuse-tolerant networks behind these services remain stable even when IPs change, and our feeds identify them.

Silent Push IOFA feeds include these ASNs. Our brand and infrastructure impersonation engine helps security teams protect their organization proactively.


Interested in Learning More?

Start a conversation with one of our platform experts to learn how our preemptive cyber defense can give your team more lead time on adversary infrastructure, before an attack is launched.

We also offer a free Community Edition so defenders can see how our platform integrates with their existing security stack.