logo

Who Knew? Domain Hijacking Is So Easy

ID: 4f4832b0-664a-505c-b839-6a76ae6f76fc

STIX ID: report--4f4832b0-664a-505c-b839-6a76ae6f76fc

Feed Name: Infoblox Threat Intel Blog

Threat Score
75/100

Date Published: 2024-07-31

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

Researchers at Infoblox and Eclypsium describe the "Sitting Ducks" attack: a DNS hijacking technique that abuses lame name server delegations and exploitable authoritative DNS or hosting providers to claim and operate legitimately registered domains without accessing the domain owner’s registrar account. The report documents active abuse by multiple Russian-nexus cybercriminal actors and TDS operators (35k+ hijacked domains observed since 2018, with over a million exploitable domains estimated), outlines observed malicious uses (phishing, malware delivery, C2, spam, scams), and provides actionable mitigation guidance for domain owners, registrars, DNS providers, and regulators.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.