CDC dangling domain hijack (Incident)
ID: 8d02e995-8325-520c-b038-40202550865b
STIX ID: report--8d02e995-8325-520c-b038-40202550865b
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-03-10
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Attackers exploited poor DNS hygiene (dangling CNAME records) at the U.S. CDC to claim a released Azure-hosted domain and host malicious content under a CDC subdomain. By leveraging the CDC domain's high reputation and a Traffic Distribution System, the actor got malicious links indexed by search engines, redirecting users to scam sites, scareware, and malware; attribution points to a Russian-operated TDS on the dark web.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
