logo

Automatically Detecting DNS Hijacking in Passive DNS

ID: 88e05fc6-3a58-53d0-b879-d85e9be204b2

STIX ID: report--88e05fc6-3a58-53d0-b879-d85e9be204b2

Feed Name: Palo Alto Networks Unit 42

Threat Score
70/100

Date Published: 2024-11-04

Date Updated: 2026-04-28

Author: Moe Ghasemisharif, Janos Szurdi, Zhanhao Chen and Daiping Liu

...
...

This Unit 42 report describes an automated, machine-learning based pipeline that analyzed pDNS and geolocation data to detect DNS hijacking, identifying 6,729 confirmed hijacked DNS records between March and September 2024; notable cases include hijacks affecting a major U.S. utility company, an ISP, a Hungarian political party, a university, and a research center, and the report publishes associated IPs, nameservers, and domain-based IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.