logo

Cloudy with a Chance of Hijacking Forgotten DNS Records Enable Scam Actor

ID: 19844d0b-4612-54f5-a92d-0b1ee3a427d9

STIX ID: report--19844d0b-4612-54f5-a92d-0b1ee3a427d9

Feed Name: Infoblox Threat Intel Blog

Threat Score
70/100

Date Published: 2025-05-20

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

This report profiles Hazy Hawk, an active criminal actor since at least December 2023 that locates and hijacks abandoned cloud resources (Azure, S3, Netlify, GitHub, CDNs, etc.) via dangling CNAME/DNS misconfigurations, uses those high-reputation subdomains to host cloaked URLs that funnel users through redirection chains and traffic distribution systems into scams, malware, and persistent push-notification fraud; it lists affected organizations, example indicators (TDS, redirect and push domains), and recommends DNS hygiene and protective DNS as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.