logo

Hiding in Plain Sight: Abusing Composite Domain Names

ID: 5effcde5-0692-5f2f-b598-a3d033bc3a8f

STIX ID: report--5effcde5-0692-5f2f-b598-a3d033bc3a8f

Feed Name: Infoblox Blog

Date Published: 2026-04-09

Date Updated: 2026-04-28

Author: Vadym Tymchenko

...
...

This report analyzes DNS domain-embedding (composite query) services that encode target domains within trusted service domains (e.g., example-com.translate.goog), demonstrates how attackers exploit these services to bypass DNS/IP/SSL-based security controls, describes a multi-stage detection pipeline to extract and validate embedded domains, and presents telemetry showing significant blind spots—about 7% of distinct domains and thousands of embedded domains daily, including dozens to hundreds matching threat intelligence feeds.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.