By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Experts Uncover 70,000 Hijacked Domains in Widespread ‘Sitting Ducks’ Attack Scheme
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Experts Uncover 70,000 Hijacked Domains in Widespread ‘Sitting Ducks’ Attack Scheme
Tech News

Experts Uncover 70,000 Hijacked Domains in Widespread ‘Sitting Ducks’ Attack Scheme

By Viral Trending Content 7 Min Read
Share
SHARE
Hijacked Domains

Multiple threat actors have been found taking advantage of an attack technique called Sitting Ducks to hijack legitimate domains for using them in phishing attacks and investment fraud schemes for years.

The findings come from Infoblox, which said it identified nearly 800,000 vulnerable registered domains over the past three months, of which approximately 9% (70,000) have been subsequently hijacked.

“Cybercriminals have used this vector since 2018 to hijack tens of thousands of domain names,” the cybersecurity company said in a deep-dive report shared with The Hacker News. “Victim domains include well-known brands, non-profits, and government entities.”

The little-known attack vector, although originally documented by security researcher Matthew Bryant way back in 2016, didn’t attract a lot of attention until the scale of the hijacks was disclosed earlier this August.

Cybersecurity

“I believe there is more awareness [since then],” Dr. Renee Burton, vice president of threat intelligence at Infoblox, told The Hacker News. “While we haven’t seen the number of hijackings go down, we have seen customers very interested in the topic and grateful for awareness around their own potential risks.

The Sitting Ducks attack, at its core, allows a malicious actor to seize control of a domain by leveraging misconfigurations in its domain name system (DNS) settings. This includes scenarios where the DNS points to the wrong authoritative name server.

However, there are certain prerequisites in order to pull this off: A registered domain delegates authoritative DNS services to a different provider than the domain registrar, the delegation is lame, and the attacker can “claim” the domain at the DNS provider and set up DNS records without access to the valid owner’s account at the domain registrar.

Hijacked Domains

Sitting Ducks is both easy to perform and stealthy, in part driven by the positive reputation that many of the hijacked domains have. Some of the domains that have fallen prey to the attacks include an entertainment company, an IPTV service provider, a law firm, an orthopedic and cosmetic supplier, a Thai online apparel store, and a tire sales firm.

The threat actors who hijack such domains take advantage of the brand reposition and the fact that they are unlikely to be flagged by security tools as malicious to accomplish their strategic goals.

“It is hard to detect because if the domain has been hijacked, then it is not lame,” Burton explained. “Without any other sign, like a phishing page or a piece of malware, the only signal is a change of IP addresses.”

“The number of domains is so vast that attempts to use IP changes to indicate malicious activity would lead to a lot of false positives. We ‘back in’ to tracking the threat actors that are hijacking domains by first understanding how they individually operate and then tracking that behavior.”

An important aspect that’s common to the Sitting Ducks attacks is rotational hijacking, where one domain is repeatedly taken over by different threat actors over time.

Hijacked Domains

“Threat actors often use exploitable service providers that offer free accounts like DNS Made Easy as lending libraries, typically hijacking domains for 30 to 60 days; however, we’ve also seen other cases where actors hold the domain for a long period of time,” Infoblox noted.

“After the short-term, free account expires, the domain is ‘lost’ by the first threat actor and then either parked or claimed by another threat actor.”

Some of the prominent DNS threat actors that have been found “feasting on” Sitting Ducks attacks are listed below –

  • Vacant Viper, which has used it to operate the 404 TDS, alongside running malicious spam operations, delivering porn, establishing command-and-control (C2), and dropping malware such as DarkGate and AsyncRAT (Ongoing since December 2019)
  • Horrid Hawk, which has used it to conduct investment fraud schemes by distributing the hijacked domains via short-lived Facebook ads (Ongoing since at least February 2023)
  • Hasty Hawk, which has used it to conduct widespread phishing campaigns that primarily mimic DHL shipping pages and fake donation sites that mimic supportukrainenow[.]org and claim to support Ukraine (Ongoing since at least March 2022)
  • VexTrio Viper, which has used to operate its TDS (Ongoing since early 2020)
Cybersecurity

Infoblox said a number of VexTrio Viper’s affiliates, such as GoRefresh, have also engaged in Sitting Ducks attacks to conduct fake online pharmaceutical campaigns, as well as gambling and dating scams.

“We have a few actors who appear to use the domains for malware C2 in which exfiltration is sent over mail services,” Burton said. “While others use them to distribute spam, these actors configure their DNS only to receive mail.”

This indicates that the bad actors are leveraging the seized domains for a broad spectrum of reasons, thereby putting both businesses and individuals at risk of malware, credential theft, and fraud.

“We have found several actors who have hijacked domains and held them for extensive periods of time, but we have been unable to determine the purpose of the hijack,” Infoblox concluded. “These domains tend to have a high reputation and are not typically noticed by security vendors, creating an environment where clever actors can deliver malware, commit rampant fraud, and phish user credentials without consequences.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Best Streaming Service of the Year: Tech Advisor Awards 2025-26

Factor Meal Delivery Promo: Free $200 Withings Body-Scan Scale

IBM warns of critical API Connect auth bypass vulnerability

IBM warns of critical API Connect auth bypass vulnerability

U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware

TAGGED: Brand Protection, Cyber Security, Cybersecurity, DNS Security, Domain Hijacking, Infoblox, Internet, Malware, network security, online fraud, phishing attack, Threat Intelligence
Share This Article
Facebook Twitter Copy Link
Previous Article Aaron Judge And Shohei Ohtani Lead The Way In MLB Silver Slugger Awards 
Next Article Dragon Quest 3 HD-2D Remake is Now Available
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Isiah Whitlock Jr.’s Health Before Death: What We Know About the ‘Short Illness’ He Had
Celebrity
How Russia’s War Machine Brutalizes and Exploits Its Own Soldiers
World News
Plans submitted to convert 11-story Holiday Inn in Denver into housing
Business
China’s move to pay interest on e-CNY sparks US stablecoin debate
Crypto
New destinations and Eurostar rivals: How Channel Tunnel rail travel might change in the future
Travel
XRP ไม่ได้เฉยอีกต่อไป ข้อมูล Flare แฉเงินกว่า 1.2 แสนล้านบาทล็อกใน DeFi
Crypto
Best Streaming Service of the Year: Tech Advisor Awards 2025-26
Tech News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

How Russia’s War Machine Brutalizes and Exploits Its Own Soldiers

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
How Russia’s War Machine Brutalizes and Exploits Its Own Soldiers
December 31, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?