Terms:
DGA - Domain Generation Algorithm. Used to generate a large amount of domain names.
PUP - Potential Unwanted Program. Unwanted software that often is malicious or violates privacy/ease of use.
Recently, we started seeing an uptick of DNS blocks for DGA-like domains. Everything was blocked, but it wasn’t immediately clear what was causing the uptick so it was time to do some digging. I quickly found some reference to the blocked domains in Hybrid Analysis and eventually found that the initial indicators were leaning towards a campaign called ApateWeb.
Originally found by Unit 42 ApateWeb: An Evasive Large-Scale Scareware and PUP Delivery Campaign back in 2024, ApateWeb seems aimed at two things: delivering scareware and PUPs (everything from adware, browser extensions, pornware, etc) and trying to use an infrastructure setup that was resilient and resistant to detection. This included purchasing a massive amount of domains, redirecting to search engines or displaying error pages if the url doesn’t contain the custom info, and abusing wildcard DNS.
Figure 1. Key characteristics of the campaign’s infrastructure and workflow.
Alas, it is not 2024 last time I checked and most of the information I was seeing was from then and early 2025, like this post analysing ApateWeb Tracking a Malicious Blogspot Redirection Campaign to ApateWeb | Validin. After a cursory search, I found that I was not alone in seeing this uptick. Malware Trends: January 1 – March 31, 2026 showed that there was a noticeable increase in ApateWeb activity in that period, but the actual post was more a summary of statistics than explanation of what they were seeing and IoCs. ApateWeb is back, if it ever left.
Time to pivot.
Now I have a friend @neurovagrant who is fantastic at investigating domain names, so I decided to send some of the domains we were seeing his way to get his input. Goodness did we find a lot. Pivoting off one of the domains, preferencenail[.]com, we found a list of well over a thousand DGA-like domains all registered through gandi[.]net. Some registered as newly as 2026-04-24. Most of them redirected to ad sites like adsterra[.]com or google, and the ASN and IPs resolved almost all line up with ApateWeb-style front ends: in our set that’s mostly AS7979 and 172.240 addresses, on top of the 192.243/173.233 style layer-1 IPs Unit 42 called out in 2024. Follow-on analysis lines up the AS7979/172.240 side with the same family, which is what we actually see the most of in our data.
Another interesting point is multiple sites frequently map to a Google Analytics 4 measurement ID that seems to be used likely as another way to measure traffic. G-ZK3VGW18DE
Would dig into this a bit more but sadly don’t have the time at the moment. Still, wanted to share our findings and the related IoCs.
IoCs included in the attached file.
apateweb_chilly_ian.csv (763.8 KB)
