Security Market Segment LS
Friday, 15 November 2024 13:39

Infoblox Threat Intel identifies new ‘malicious DNS threat actors’ linked to domain hijacking Featured

By Gordon Peters

Hijacking domains using a ‘Sitting Ducks attack’ remain an under-recognised topic in the cybersecurity community, according to Infoblox which says that few threat researchers are familiar with this attack vector and knowledge is scarce - however, the prevalence of these attacks and the risk to organisations are significant.

“During a Sitting Ducks attack, the malicious actor gains full control of the domain by taking over its DNS configurations. Cybercriminals have used this vector since 2018 to hijack tens of thousands of domain names,” notes Infoblox, adding that “Victim domains include well-known brands, non-profits, and government entities”.

“Infoblox Threat Intel crafted a monitoring initiative after the initial paper on Sitting Ducks attacks was published in July 2024. The results are very sobering, as 800,000 vulnerable domains were identified, and about 70,000 of those were later identified as hijacked,” Infoblox warned.

Here’s Infoblox report:

The Vipers and Hawks Feasting on Sitting Ducks Attacks

Vacant Viper

Vacant Viper is one of the earliest known threat actors to exploit ‘Sitting Ducks’ and has hijacked an estimated 2,500 domains each year since December 2019. This actor uses hijacked domains to augment its malicious traffic distribution system (TDS) called 404TDS with the intention to run malicious spam operations, deliver porn, establish remote access trojan (RAT) C2s, and drop malware such as DarkGate and AsyncRAT. Vacant Viper does not hijack domains for a specific brand connection but instead for a set of domain resources that have high reputations and will not be blocked by security vendors. The newly published report lists examples of attack chains showing redirection techniques used both by the 404TDS and its affiliates, including how Vacant Viper uses hijacked domains in the 404TDS.

Vextrio Viper

This actor has used hijacked domains as part of its massive TDS infrastructure since early 2020. Vextrio runs the largest known cybercriminal affiliate program, routing compromised web traffic to over 65 affiliate partners, some of whom have also stolen domains via Sitting Duck’ for their own malicious activities. Many of these affiliates use a Russian antibot service as a method to filter out bots and security researchers. The functionality of antibot includes the ability to set rules to block certain bot services or users based on their IP geolocation, user-agent, etc.

New actors Horrid Hawk and Hasty Hawk

The animal designation of Hawks was given because the threat actors swoop in and hijack vulnerable domains, much like hawks dive down to snatch their prey. Infoblox has named several new actors thriving on hijacked domains.

Horrid Hawk: A DNS threat actor that has been hijacking domains and using them for investment fraud schemes since at least February 2023. This actor is interesting because it uses hijacked domains in every step of its campaigns, crafting convincing lures containing non-existent government investment programs or summits. It embeds the hijacked domains in short-lived Facebook ads targeting users in over 30 languages spanning multiple continents.

Hasty Hawk: Another threat actor discovered during Infoblox’s research into ‘Sitting Ducks’ hijackings. Since at least March 2022, Hasty Hawk has hijacked over 200 domains to operate widespread phishing campaigns that primarily spoof DHL shipping pages and fake donation sites to support Ukraine. The actor exploits many providers, often reconfiguring hijacked domains to host content on Russian IPs. Hasty Hawk uses Google Ads and other means, such as spam messages, to distribute malicious content. It also uses a TDS to route users to different webpages that vary in content and language depending on their geolocation and other user characteristics. Hasty Hawk switches some of its domains back and forth between various campaign themes.”

The full report can be found here. More information on the Sitting Duck vulnerability can be found here.

About Infoblox
Infoblox unites networking and security to deliver unmatched performance and protection. Trusted by Fortune 100 companies and emerging innovators, we provide real-time visibility and control over who and what connects to your network, so your organisation runs faster and stops threats earlier. Visit Infoblox.com, or follow-us on LinkedIn or X.

Read 2103 times

Please join our community here and become a VIP.

Subscribe to ITWIRE UPDATE Newsletter here
JOIN our iTWireTV our YouTube Community here
BACK TO LATEST NEWS here




EXL AI IN ACTION VIRTUAL EVENT 20 MARCH 2025

Industry leaders are looking to transform their businesses and achieve measurable outcomes with AI.

As organisations across APAC navigate the complexities of AI adoption, this must-attend event brings together industry leaders, real-world demonstrations, and visionary panel discussions to bridge the gap between proof-of-concepts and enterprise-wide AI implementation.

Learn how to overcome common challenges in deploying AI at scale.​

Unlock cost savings, efficiency, and better customer experiences with AI.

Discover how industry expertise and data intelligence enable practical AI deployment.

Register for the event now!

REGISTER!

PROMOTE YOUR WEBINAR ON ITWIRE

It's all about Webinars.

Marketing budgets are now focused on Webinars combined with Lead Generation.

If you wish to promote a Webinar we recommend at least a 3 to 4 week campaign prior to your event.

The iTWire campaign will include extensive adverts on our News Site itwire.com and prominent Newsletter promotion https://itwire.com/itwire-update.html and Promotional News & Editorial. Plus a video interview of the key speaker on iTWire TV https://www.youtube.com/c/iTWireTV/videos which will be used in Promotional Posts on the iTWire Home Page.

Now we are coming out of Lockdown iTWire will be focussed to assisting with your webinars and campaigns and assistance via part payments and extended terms, a Webinar Business Booster Pack and other supportive programs. We can also create your adverts and written content plus coordinate your video interview.

We look forward to discussing your campaign goals with you. Please click the button below.

MORE INFO HERE!

BACK TO HOME PAGE
Share News tips for the iTWire Journalists? Your tip will be anonymous

Subscribe to Newsletter

*  Enter the security code shown: img0

WEBINARS & EVENTS

CYBERSECURITY

PEOPLE MOVES

GUEST ARTICLES

Guest Opinion

ITWIRETV & INTERVIEWS

RESEARCH & CASE STUDIES

Channel News

Comments