DNS Deep Dive: Pushpaganda Network IoCs

HUMAN's Satori Threat Intelligence and Research Team recently uncovered a novel threat combining ad fraud, social engineering, and scareware that they named "Pushpaganda." The operation generated invalid organic traffic from real mobile devices by tricking users into enabling push notifications—the source of its name—which then delivered alarming messages designed to make victims act on fabricated issues.

The campaign abused Google's Discovery feeds by employing advanced SEO techniques and AI-generated content to inject deceptive news stories into the personalized content streams of Android and Chrome users. Once a user was lured to an actor-controlled domain and enabled notifications, they were served scareware, fake legal threats, and financial scams.

The in-depth Pushpaganda analysis publicized1 113 domain IoCs. Aided by the WhoisXML API MCP Server, we determined that some were owned by legitimate entities and excluded them from our investigation, limiting our analysis to 90 domain IoCs.

Our DNS deep dive led to these discoveries:

  • Five unique client IP addresses communicated with four domain IoCs
  • One domain IoC was bulk-registered with two look-alikes
  • Eight domain IoCs were likely registered with malicious intent
  • 1,055 email-connected domains
  • 162 IP addresses, 101 were confirmed malicious
  • Eight IP-connected domains
  • 858 string-connected domains, one was confirmed malicious

Download a sample of the threat research materials now or contact sales to discuss your intelligence needs for threat detection and response or other cybersecurity use cases.

  • [1] https://www.humansecurity.com/learn/resources/satori-threat-intelligence-alert-pushpaganda-manipulates-google-discovery-feeds-with-ai-generated-content-to-spread-malicious-notifications/
Try our WhoisXML API for free
Get started