logo

Cloudy with a Chance of Hijacking Forgotten DNS Records Enable Scam Actor

ID: 8e816b12-f621-58d2-adaf-3204229d43d0

STIX ID: report--8e816b12-f621-58d2-adaf-3204229d43d0

Feed Name: Infoblox Threat Intel Blog

Threat Score
72/100

Date Published: 2025-05-20

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

Hazy Hawk is a cybercriminal affiliate group that finds and hijacks abandoned cloud resources (dangling CNAMEs and other DNS misconfigurations) on high-profile domains to host large volumes of obfuscated URLs that redirect users through intermediate sites and traffic distribution systems into scams, malware, and persistent browser push-notification campaigns; the report documents affected sectors and example domains, explains their CNAME-hijack and redirection techniques, and recommends DNS hygiene and protective DNS solutions to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.