By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Experts Uncover 70,000 Hijacked Domains in Widespread ‘Sitting Ducks’ Attack Scheme
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Experts Uncover 70,000 Hijacked Domains in Widespread ‘Sitting Ducks’ Attack Scheme
Tech News

Experts Uncover 70,000 Hijacked Domains in Widespread ‘Sitting Ducks’ Attack Scheme

By Viral Trending Content 7 Min Read
Share
SHARE
Hijacked Domains

Multiple threat actors have been found taking advantage of an attack technique called Sitting Ducks to hijack legitimate domains for using them in phishing attacks and investment fraud schemes for years.

The findings come from Infoblox, which said it identified nearly 800,000 vulnerable registered domains over the past three months, of which approximately 9% (70,000) have been subsequently hijacked.

“Cybercriminals have used this vector since 2018 to hijack tens of thousands of domain names,” the cybersecurity company said in a deep-dive report shared with The Hacker News. “Victim domains include well-known brands, non-profits, and government entities.”

The little-known attack vector, although originally documented by security researcher Matthew Bryant way back in 2016, didn’t attract a lot of attention until the scale of the hijacks was disclosed earlier this August.

Cybersecurity

“I believe there is more awareness [since then],” Dr. Renee Burton, vice president of threat intelligence at Infoblox, told The Hacker News. “While we haven’t seen the number of hijackings go down, we have seen customers very interested in the topic and grateful for awareness around their own potential risks.

The Sitting Ducks attack, at its core, allows a malicious actor to seize control of a domain by leveraging misconfigurations in its domain name system (DNS) settings. This includes scenarios where the DNS points to the wrong authoritative name server.

However, there are certain prerequisites in order to pull this off: A registered domain delegates authoritative DNS services to a different provider than the domain registrar, the delegation is lame, and the attacker can “claim” the domain at the DNS provider and set up DNS records without access to the valid owner’s account at the domain registrar.

Hijacked Domains

Sitting Ducks is both easy to perform and stealthy, in part driven by the positive reputation that many of the hijacked domains have. Some of the domains that have fallen prey to the attacks include an entertainment company, an IPTV service provider, a law firm, an orthopedic and cosmetic supplier, a Thai online apparel store, and a tire sales firm.

The threat actors who hijack such domains take advantage of the brand reposition and the fact that they are unlikely to be flagged by security tools as malicious to accomplish their strategic goals.

“It is hard to detect because if the domain has been hijacked, then it is not lame,” Burton explained. “Without any other sign, like a phishing page or a piece of malware, the only signal is a change of IP addresses.”

“The number of domains is so vast that attempts to use IP changes to indicate malicious activity would lead to a lot of false positives. We ‘back in’ to tracking the threat actors that are hijacking domains by first understanding how they individually operate and then tracking that behavior.”

An important aspect that’s common to the Sitting Ducks attacks is rotational hijacking, where one domain is repeatedly taken over by different threat actors over time.

Hijacked Domains

“Threat actors often use exploitable service providers that offer free accounts like DNS Made Easy as lending libraries, typically hijacking domains for 30 to 60 days; however, we’ve also seen other cases where actors hold the domain for a long period of time,” Infoblox noted.

“After the short-term, free account expires, the domain is ‘lost’ by the first threat actor and then either parked or claimed by another threat actor.”

Some of the prominent DNS threat actors that have been found “feasting on” Sitting Ducks attacks are listed below –

  • Vacant Viper, which has used it to operate the 404 TDS, alongside running malicious spam operations, delivering porn, establishing command-and-control (C2), and dropping malware such as DarkGate and AsyncRAT (Ongoing since December 2019)
  • Horrid Hawk, which has used it to conduct investment fraud schemes by distributing the hijacked domains via short-lived Facebook ads (Ongoing since at least February 2023)
  • Hasty Hawk, which has used it to conduct widespread phishing campaigns that primarily mimic DHL shipping pages and fake donation sites that mimic supportukrainenow[.]org and claim to support Ukraine (Ongoing since at least March 2022)
  • VexTrio Viper, which has used to operate its TDS (Ongoing since early 2020)
Cybersecurity

Infoblox said a number of VexTrio Viper’s affiliates, such as GoRefresh, have also engaged in Sitting Ducks attacks to conduct fake online pharmaceutical campaigns, as well as gambling and dating scams.

“We have a few actors who appear to use the domains for malware C2 in which exfiltration is sent over mail services,” Burton said. “While others use them to distribute spam, these actors configure their DNS only to receive mail.”

This indicates that the bad actors are leveraging the seized domains for a broad spectrum of reasons, thereby putting both businesses and individuals at risk of malware, credential theft, and fraud.

“We have found several actors who have hijacked domains and held them for extensive periods of time, but we have been unable to determine the purpose of the hijack,” Infoblox concluded. “These domains tend to have a high reputation and are not typically noticed by security vendors, creating an environment where clever actors can deliver malware, commit rampant fraud, and phish user credentials without consequences.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution

Vodafone Foundation and Rethink Ireland announce recipients of €540,000 Fund to Boost Digital Literacy for Older Adults

Humanoid Robots in 2026, Real-World Uses, Pros, and Limits

Big data is transforming gaming experiences in Ireland

Commodore 64 Ultimate Review: An Astonishing Remake

TAGGED: Brand Protection, Cyber Security, Cybersecurity, DNS Security, Domain Hijacking, Infoblox, Internet, Malware, network security, online fraud, phishing attack, Threat Intelligence
Share This Article
Facebook Twitter Copy Link
Previous Article Aaron Judge And Shohei Ohtani Lead The Way In MLB Silver Slugger Awards 
Next Article Dragon Quest 3 HD-2D Remake is Now Available
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Thieves drill into German bank vault and steal millions from safety deposit boxes
World News
FII flows could return in 2026, markets not pricing in the upside yet: Vikas Khemani
Business
CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution
Tech News
2026 XRP outlook: breakout ahead or deeper pullback?
Crypto
15 New Games of January 2026
Gaming News
Scotland, Sardinia, Spain: These small towns will pay you to move there in 2026
Travel
17 Of The Year’s Biggest PS5 Games Are Up To 50 Percent Off
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Thieves drill into German bank vault and steal millions from safety deposit boxes

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Thieves drill into German bank vault and steal millions from safety deposit boxes
December 30, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?