logo

Russia takes aim at Sitting Ducks domains, bags 30,000+

ID: f38d9db4-0129-59c5-bde1-4d593dc09919

STIX ID: report--f38d9db4-0129-59c5-bde1-4d593dc09919

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-07-31

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Infoblox and Eclypsium warn that a long-standing DNS misconfiguration vulnerability—nicknamed "Sitting Ducks"—is being actively exploited by Russia-affiliated criminals to hijack orphaned or weakly managed domains. The flaw, known since 2016 and resurfacing in multiple major providers and registrars, has enabled an estimated ~30,000 domain takeovers since 2019 and is being used for phishing, scams, spam, porn distribution, and as command-and-control infrastructure; the researchers urge domain owners, registrars, DNS providers, and regulators to take both immediate mitigations and pursue long-term standards changes to reduce the DNS attack surface.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.