Sitting Ducks and Scammy Notifications: Inside a Global Malvertising Operation
ID: 038318b3-b998-5923-8cdd-2d6b19a2df8f
STIX ID: report--038318b3-b998-5923-8cdd-2d6b19a2df8f
Feed Name: securityonline.info
Infoblox researchers hijacked abandoned domains exploited by a global push-notification scam network, passively collecting 57 million logs over two weeks and observing thousands of Android Chrome devices receiving abusive, multilingual deceptive notifications (averaging ~140/day) primarily targeting South Asia. The operation leveraged a "Sitting Ducks" DNS delegation weakness to claim neglected domains, enabling large-scale delivery of phishing/clickbait/lure notifications; despite low direct monetization, the investigation highlights active exploitation and the systemic risk of poor DNS hygiene.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
