logo

Passive Takeover - uncovering (and emulating) an expensive subdomain takeover campaign

ID: 5e2feeb0-79f3-5411-8ddf-ca19b1c2bc13

STIX ID: report--5e2feeb0-79f3-5411-8ddf-ca19b1c2bc13

Feed Name: KMsec blog

Threat Score
50/100

Date Published: 2023-03-05

Date Updated: 2026-04-19

...
...

This write-up details an opportunistic 'passive takeover' technique where an actor leverages passive DNS and cloud instance provisioning (notably AWS Elastic IPs/EC2 and DigitalOcean) to occupy dangling A records and host a visible takeover page; the author reproduces the method, lists detection/mitigation steps, and publishes ~345 observed IPs/hostnames associated with the operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.