Analysis of Domain Fronting Technique: Abuse and Hiding via CDNs
ID: 995bbce7-df3b-536b-8df5-ab4a0bfd9100
STIX ID: report--995bbce7-df3b-536b-8df5-ab4a0bfd9100
Feed Name: Zscaler Security Research Blog
This ThreatLabz report explains domain fronting — a technique that hides the true HTTPS destination by using a different SNI than the HTTP Host header — and shows how attackers abuse CDNs (Azure, CloudFlare, Discord) to deliver malicious/phishing content and establish C2 channels. The document includes observed malicious domains, a case study demonstrating SNI/Host mismatches, and recommended defenses (maximum TLS interception, detection of SNI/Host mismatches, and Zscaler prevention features), plus notes on the related ‘domain hiding’/ESNI concerns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
