Threat reportPhishingTL-2026-2529

Mass Phishing Operation Abuses Fast-Flux DNS to Evade Detection (Yalishanda / ShadowRelay)

highACTIVE

Mass Phishing Operation Abuses Fast-Flux DNS to Evade (TL-2026-2529), also tracked as Yalishanda/ShadowRelay Fast-Flux Phishing Operation, is a high-severity phishing campaign, first published 2026-09-15. It is attributed to Yalishanda (Russia) with medium confidence, affects Canada Revenue Agency Impersonated brand / phished tax-portal login, maps to 10 MITRE ATT&CK techniques (T1027.013, T1111, T1204.001), and is covered by 9 detection rules and 18 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
10MITRE ATT&CK
Actors
3Yalishanda
Detection rules
9SPL · KQL · Sigma
IOCs
18Indicators of compromise

Key facts for TL-2026-2529

Threat ID
TL-2026-2529
Also known as
Yalishanda/ShadowRelay Fast-Flux Phishing Operation, Fast-Flux Canadian Banking Phishing Campaign
Severity
HIGH
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution
Yalishanda, Media Land bulletproof hosting, ShadowRelay
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
FINANCIAL
Target sectors
banking, financial services, government administration, tax administration, postal services, social benefits, telecoms, cryptocurrency, payments
Target regions
canada, united kingdom, united states of america, australia, Europe
Detection rules
9
Indicators of compromise
18

Malware and tooling in Mass Phishing Operation Abuses Fast-Flux DNS to Evade

Malware and tooling: Keitaro

How Mass Phishing Operation Abuses Fast-Flux DNS to Evade works

Silent Push identified roughly 2,000 active phishing domains operating behind two commercial fast-flux DNS services -- one run by sanctioned bulletproof hoster Yalishanda (Aleksandr Volosovik) via Media Land, the other by an independent provider called ShadowRelay active since April 2026 -- rotating DNS records across dozens of IPs and multiple ASNs within minutes to defeat IP-based blocking. Roughly nine in ten of the domains impersonate Canadian institutions (banks, the Canada Revenue Agency, Canada Post, provincial benefit programs), with the remainder targeting UK, US, Australian, and European banks, telecoms, and crypto platforms.

Silent Push researchers purchased direct access to two commercial fast-flux DNS services to observe a mass phishing operation from the inside. The first service is run by Yalishanda -- the online handle of Aleksandr (Alexander) Volosovik, general director of the Russian bulletproof-hosting firm Media Land LLC, which the US Treasury's OFAC, the UK's FCDO, and Australia's DFAT sanctioned in November 2025 for supporting ransomware groups including LockBit, BlackSuit, and Play. The Department of Justice unsealed a related criminal indictment on July 14, 2026, charging Volosovik, Media Land operations coordinator Kirill Zatolokin, and financial/legal manager Yulia Pankova, along with Medialand LLC and ML.Cloud LLC, with conspiracy to commit computer fraud, wire fraud, and money laundering tied to more than $62 million in losses across 42 victims in 21 US states. The second service, ShadowRelay, is an independent fast-flux provider that has advertised on Russian-language criminal forums since April 2026, selling $150-$700/month subscriptions and accepting nine cryptocurrencies including Monero; its proxy IPs can rotate several times per hour.

Both services provide customers with an ever-changing pool of proxy IP addresses spread across many autonomous systems, letting a single phishing domain's DNS A records be re-pointed every few minutes (single-flux) so that IP-based blocklists and takedown requests cannot keep pace. Silent Push fingerprinted roughly 2,000 phishing domains sharing this infrastructure by combining a common nameserver signature (a.dnspod.com) with high IP/ASN diversity across a pool of seven ASNs (14956, 58061, 49468, 215439, 197574, 209378, 198550). One example domain, canada-post11.com, resolved to 20 distinct IP addresses across 13 different ASNs over a 90-day observation window. Roughly nine in ten of the tracked domains impersonate Canadian institutions -- major banks, the Canada Revenue Agency, Canada Post, and provincial benefit programs -- while the remainder spoof UK, US, Australian, and European banks, telecom carriers, email/notification platforms (including Wise), and cryptocurrency services; one single registrant persona alone covered more than twenty distinct bank brands across four continents.

Delivery is mobile-first: victims are driven to the phishing pages primarily via SMS (smishing), and the landing infrastructure requests mobile client hints and serves per-victim single-use URLs built around UUID-based landing pages with tracking cookies carrying campaign IDs and per-victim counters, so a burned link cannot be re-crawled by researchers. Non-targeted visitors -- security scanners, out-of-region visitors, and researchers -- are served 404 responses after device/behavioral profiling, a deliberate anti-analysis control. Silent Push identified the commercial Keitaro traffic-distribution system routing this filtered traffic to the phishing pages.

Two operational clusters were documented downstream of the fast-flux infrastructure. A 'Canadian Banking Kit' cluster runs interactive, operator-monitored phishing sessions against Canadian bank customers with fake one-time-passcode (OTP) verification pages, allowing the operator to relay stolen credentials and OTP codes for real-time account takeover while the victim is still engaged. A separate 'Callback Operation' cluster impersonates bank/institution fraud-response teams, combining credential harvesting with delivery of malicious binaries packaged in password-protected ZIP archives -- a technique that defeats automated email and web-gateway malware scanning that cannot open encrypted archives. Silent Push reports the overall campaign's volume is 'doubling month over month' and is 'still ramping up,' with no observed slowdown as of the September 15, 2026 report date.

MITRE ATT&CK techniques used in TL-2026-2529

Stealth

T1027.013 Encrypted/Encoded File; T1684.001 Impersonation

Credential Access

T1111 Multi-Factor Authentication Interception

Execution

T1204.001 Malicious Link

Command and Control

T1568.001 Fast Flux DNS

Resource Development

T1583.001 Domains; T1583.004 Server; T1608.001 Upload Malware

defense-evasion

T1633.001 System Checks

Initial Access

T1660 Phishing

Affected products and versions in Mass Phishing Operation Abuses Fast-Flux DNS to Evade

  • Canada Revenue Agency — Impersonated brand / phished tax-portal login page
    Vulnerable versions: N/A - social engineering, not a software vulnerability
    Fixed in: N/A
  • Canada Post — Impersonated brand / phished parcel-tracking notification page
    Vulnerable versions: N/A
    Fixed in: N/A
  • Wise — Impersonated brand / phished payment-notification templates
    Vulnerable versions: N/A
    Fixed in: N/A
  • Allica Bank — Impersonated brand / phished online-banking login page
    Vulnerable versions: N/A
    Fixed in: N/A

Remediation for Mass Phishing Operation Abuses Fast-Flux DNS to Evade

Patches

  • Not applicable -- this is a social-engineering and hosting-infrastructure-evasion campaign, not a software vulnerability; no vendor patch exists

Immediate actions

  • Detect and block domains matching Silent Push's fast-flux signature: nsname = a.dnspod.com combined with asn_diversity_min >= 4 and ip_diversity_all_min >= 4 across ASNs 14956, 58061, 49468, 215439, 197574, 209378, 198550 (asn_match_min = 3)
  • Alert on and block SMS-delivered links to newly-registered lookalike domains impersonating the Canada Revenue Agency, Canada Post, provincial benefit portals, and major Canadian/UK/US/Australian/European banks
  • Brief fraud/call-center and customer-facing staff on the 'fraud-team callback' impersonation pattern and the 'fake OTP verification page' live-relay account-takeover technique so inbound 'verification' requests are treated as suspect

Workarounds

  • Enforce out-of-band or app-based transaction verification instead of SMS-delivered links or SMS OTP for banking and government-portal logins
  • Configure email/web security gateways to flag or quarantine password-protected archive attachments from unsolicited 'fraud team' or 'account verification' communications, since these defeat automated scanning

Longer-term hardening

  • Adopt fast-flux detection per CISA AA25-093A: monitor DNS TTL anomalies, IP/ASN diversity, and NS-record churn rather than relying solely on static IP blocklists, which fast-flux is specifically designed to outrun
  • Subscribe to threat-intel sharing covering bulletproof-hosting-linked fast-flux infrastructure (e.g., CISA's Automated Indicator Sharing) to receive updated domain feeds tied to Media Land/Yalishanda and emerging services like ShadowRelay
  • Deploy DNS-layer protective resolvers and secure email/web gateways capable of heuristic fast-flux blocking rather than single-IP reputation lookups

Timeline of Mass Phishing Operation Abuses Fast-Flux DNS to Evade

  • CISA, NSA, FBI, and international partners publish Advisory AA25-093A, 'Fast Flux: A National Security Threat,' warning that fast-flux DNS is being adopted by criminal and nation-state actors to evade IP-based blocking.
  • The US Treasury (OFAC), UK Foreign Commonwealth and Development Office, and Australia's Department of Foreign Affairs and Trade announce coordinated sanctions against Media Land, ML Cloud, and individuals Aleksandr Volosovik ('Yalishanda'), Kirill Zatolokin, and Yulia Pankova for supporting ransomware operations including LockBit, BlackSuit, and Play.
  • ShadowRelay begins advertising a subscription-based fast-flux DNS service ($150-$700/month, nine accepted cryptocurrencies including Monero) on Russian-language criminal forums, independent of the Yalishanda/Media Land operation.
  • Silent Push begins a roughly 90-day observation window during which the phishing domain canada-post11.com is tracked resolving across 20 distinct IP addresses spanning 13 different ASNs.
  • The US Department of Justice unseals a December 2024 indictment charging Aleksandr Volosovik, Kirill Zatolokin, and Yulia Pankova, along with Medialand LLC and ML.Cloud LLC, with computer fraud, wire fraud, and money laundering conspiracy tied to more than $62 million in losses across 42 victims in 21 US states.
  • Silent Push publishes research showing it purchased direct access to both the Yalishanda/Media Land and ShadowRelay fast-flux services, identifying roughly 2,000 active phishing domains -- about 90% impersonating Canadian institutions -- and reporting the campaign's volume is doubling month over month.

Sources cited for Mass Phishing Operation Abuses Fast-Flux DNS to Evade

Detection coverage for TL-2026-2529

As of 2026-09-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2529 across Splunk SPL, Microsoft KQL and Sigma, covering 18 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
18 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats