logo

CDC dangling domain hijack (Incident)

ID: 8d02e995-8325-520c-b038-40202550865b

STIX ID: report--8d02e995-8325-520c-b038-40202550865b

Feed Name: Wiz Cloud Threat Landscape

Threat Score
70/100

Date Published: 2025-03-10

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Attackers exploited poor DNS hygiene (dangling CNAME records) at the U.S. CDC to claim a released Azure-hosted domain and host malicious content under a CDC subdomain. By leveraging the CDC domain's high reputation and a Traffic Distribution System, the actor got malicious links indexed by search engines, redirecting users to scam sites, scareware, and malware; attribution points to a Russian-operated TDS on the dark web.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.