SRG has turned its extortion setup into a moving target. Taking down one server or blocking one IP no longer cleanly breaks the service, because the same domains can keep resolving through different compromised devices.
Resecurity says the group is using fast flux across infected routers, modems, gateways, and other IoT and CPE devices to rotate DNS answers for its infrastructure. It has observed nodes in 18 countries and 22 ISPs, tied to domains used by SRG.
That raises the cost of disruption for the sectors SRG already targets, including legal, financial services, healthcare, insurance, and hospitality. The campaign is no longer just fast social engineering; it now has a resilient infrastructure layer built to survive simple takedowns.