logo

Passive Takeover - uncovering (and emulating) an expensive subdomain takeover campaign

ID: 3a070891-7278-56be-b0dc-8a0714ebadae

STIX ID: report--3a070891-7278-56be-b0dc-8a0714ebadae

Feed Name: KMsec blog

Threat Score
55/100

Date Published: 2023-03-05

Date Updated: 2026-04-19

...
...

The report describes a widespread, opportunistic 'passive takeover' subdomain-takeover campaign in which an actor operates roughly 700 IPs (many in AWS Elastic IP space) to claim dangling A records by provisioning cloud instances after discovering valid passive-DNS mappings; the author demonstrates a PoC, outlines the attacker methodology, lists detection/mitigation advice, and publishes a curated list of ~345 IPs and corresponding domains observed serving takeover pages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.