Automatically Detecting DNS Hijacking in Passive DNS
ID: 88e05fc6-3a58-53d0-b879-d85e9be204b2
STIX ID: report--88e05fc6-3a58-53d0-b879-d85e9be204b2
Feed Name: Palo Alto Networks Unit 42
Date Published: 2024-11-04
Date Updated: 2026-04-28
Author: Moe Ghasemisharif, Janos Szurdi, Zhanhao Chen and Daiping Liu
This Unit 42 report describes an automated, machine-learning based pipeline that analyzed pDNS and geolocation data to detect DNS hijacking, identifying 6,729 confirmed hijacked DNS records between March and September 2024; notable cases include hijacks affecting a major U.S. utility company, an ISP, a Hungarian political party, a university, and a research center, and the report publishes associated IPs, nameservers, and domain-based IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
