# Mass Phishing Operation Abuses Fast-Flux DNS to Evade Detection (Yalishanda / ShadowRelay)

> Silent Push identified roughly 2,000 active phishing domains operating behind two commercial fast-flux DNS services -- one run by sanctioned bulletproof hoster Yalishanda (Aleksandr Volosovik) via Media Land, the other by an independent provider called ShadowRelay active since April 2026 -- rotating DNS records across dozens of IPs and multiple ASNs within minutes to defeat IP-based blocking. Roughly nine in ten of the domains impersonate Canadian institutions (banks, the Canada Revenue Agency, Canada Post, provincial benefit programs), with the remainder targeting UK, US, Australian, and European banks, telecoms, and crypto platforms.

- **Published:** 2026-09-15T00:00:00Z
- **Last reviewed:** 2026-09-15T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2529
- **ID:** TL-2026-2529
- **Severity:** HIGH
- **Category:** PHISHING
- **Status:** ACTIVE
- **Actor:** Yalishanda (Russia)
- **Detections:** 9 · **IOCs:** 18 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Silent Push researchers purchased direct access to two commercial fast-flux DNS services to observe a mass phishing operation from the inside. The first service is run by Yalishanda -- the online handle of Aleksandr (Alexander) Volosovik, general director of the Russian bulletproof-hosting firm Media Land LLC, which the US Treasury's OFAC, the UK's FCDO, and Australia's DFAT sanctioned in November 2025 for supporting ransomware groups including LockBit, BlackSuit, and Play. The Department of Justice unsealed a related criminal indictment on July 14, 2026, charging Volosovik, Media Land operations coordinator Kirill Zatolokin, and financial/legal manager Yulia Pankova, along with Medialand LLC and ML.Cloud LLC, with conspiracy to commit computer fraud, wire fraud, and money laundering tied to more than $62 million in losses across 42 victims in 21 US states. The second service, ShadowRelay, is an independent fast-flux provider that has advertised on Russian-language criminal forums since April 2026, selling $150-$700/month subscriptions and accepting nine cryptocurrencies including Monero; its proxy IPs can rotate several times per hour.

Both services provide customers with an ever-changing pool of proxy IP addresses spread across many autonomous systems, letting a single phishing domain's DNS A records be re-pointed every few minutes (single-flux) so that IP-based blocklists and takedown requests cannot keep pace. Silent Push fingerprinted roughly 2,000 phishing domains sharing this infrastructure by combining a common nameserver signature (a.dnspod.com) with high IP/ASN diversity across a pool of seven ASNs (14956, 58061, 49468, 215439, 197574, 209378, 198550). One example domain, canada-post11.com, resolved to 20 distinct IP addresses across 13 different ASNs over a 90-day observation window. Roughly nine in ten of the tracked domains impersonate Canadian institutions -- major banks, the Canada Revenue Agency, Canada Post, and provincial benefit programs -- while the remainder spoof UK, US, Australian, and European banks, telecom carriers, email/notification platforms (including Wise), and cryptocurrency services; one single registrant persona alone covered more than twenty distinct bank brands across four continents.

Delivery is mobile-first: victims are driven to the phishing pages primarily via SMS (smishing), and the landing infrastructure requests mobile client hints and serves per-victim single-use URLs built around UUID-based landing pages with tracking cookies carrying campaign IDs and per-victim counters, so a burned link cannot be re-crawled by researchers. Non-targeted visitors -- security scanners, out-of-region visitors, and researchers -- are served 404 responses after device/behavioral profiling, a deliberate anti-analysis control. Silent Push identified the commercial Keitaro traffic-distribution system routing this filtered traffic to the phishing pages.

Two operational clusters were documented downstream of the fast-flux infrastructure. A 'Canadian Banking Kit' cluster runs interactive, operator-monitored phishing sessions against Canadian bank customers with fake one-time-passcode (OTP) verification pages, allowing the operator to relay stolen credentials and OTP codes for real-time account takeover while the victim is still engaged. A separate 'Callback Operation' cluster impersonates bank/institution fraud-response teams, combining credential harvesting with delivery of malicious binaries packaged in password-protected ZIP archives -- a technique that defeats automated email and web-gateway malware scanning that cannot open encrypted archives. Silent Push reports the overall campaign's volume is 'doubling month over month' and is 'still ramping up,' with no observed slowdown as of the September 15, 2026 report date.

## MITRE ATT&CK

- T1583.001 Domains
- T1583.004 Server
- T1608.001 Upload Malware
- T1660 Phishing
- T1204.001 Malicious Link
- T1568.001 Fast Flux DNS
- T1111 Multi-Factor Authentication Interception
- T1684.001 Impersonation
- T1633.001 System Checks
- T1027.013 Encrypted/Encoded File

## Sources

- [Silent Push Tracks a Mass Phishing Operation Through Fast Flux](https://www.silentpush.com/blog/fast-flux-phishing/)
- [CISA Advisory AA25-093A: Fast Flux: A National Security Threat](https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-093a)
- [United States, Australia, and United Kingdom Sanction Russian Cybercrime Infrastructure Supporting Ransomware](https://home.treasury.gov/news/press-releases/sb0319)
- [Three Russian Nationals and Two Companies Indicted for International Cybercrimes Resulting in More Than $62M in Victim Losses](https://www.justice.gov/opa/pr/three-russian-nationals-and-two-companies-indicted-international-cybercrimes-resulting-more)
- [Notice of OFAC Sanctions Action](https://www.federalregister.gov/documents/2025/11/21/2025-20573/notice-of-ofac-sanctions-action)
- [Russian bulletproof hosting provider sanctioned over ransomware ties](https://www.bleepingcomputer.com/news/security/us-sanctions-russian-bulletproof-hosting-provider-media-land-over-ransomware-ties/)
- [Britain U.S., Australia sanction Russian cybercrime group Media Land](https://www.upi.com/Top_News/US/2025/11/19/uk-australia-russia-cybercrime-media-land/9151763569335/)
- [Actor yalishanda: A snapshot of a prolific bulletproof hoster](https://www.intel471.com/blog/actor-yalishanda-a-snapshot-of-a-prolific-bulletproof-hoster)
- [Bulletproof hosting: How cybercrime stays resilient](https://www.intel471.com/blog/bulletproof-hosting-yalishanda-ransomware-banking-trojans-information-stealers)
- [Dynamic Resolution: Fast Flux DNS, Sub-technique T1568.001 - Enterprise | MITRE ATT&CK](https://attack.mitre.org/techniques/T1568/001/)
- [Fake CAPTCHA IRSF Scam and 120 Keitaro Campaigns Drive Global SMS, Crypto Fraud](https://thehackernews.com/2026/04/fake-captcha-irsf-scam-and-120-keitaro.html)
- [Why the Keitaro TDS keeps causing security headaches](https://www.techtarget.com/searchsecurity/feature/Why-the-Keitaro-TDS-keeps-causing-security-headaches)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2529
