logo

Sitting Ducks and Scammy Notifications: Inside a Global Malvertising Operation

ID: 038318b3-b998-5923-8cdd-2d6b19a2df8f

STIX ID: report--038318b3-b998-5923-8cdd-2d6b19a2df8f

Feed Name: securityonline.info

Threat Score
60/100

Date Published: 2026-01-19

Date Updated: 2026-04-23

Author: Ddos

...
...

Infoblox researchers hijacked abandoned domains exploited by a global push-notification scam network, passively collecting 57 million logs over two weeks and observing thousands of Android Chrome devices receiving abusive, multilingual deceptive notifications (averaging ~140/day) primarily targeting South Asia. The operation leveraged a "Sitting Ducks" DNS delegation weakness to claim neglected domains, enabling large-scale delivery of phishing/clickbait/lure notifications; despite low direct monetization, the investigation highlights active exploitation and the systemic risk of poor DNS hygiene.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.