logo

Analysis of Domain Fronting Technique: Abuse and Hiding via CDNs

ID: 995bbce7-df3b-536b-8df5-ab4a0bfd9100

STIX ID: report--995bbce7-df3b-536b-8df5-ab4a0bfd9100

Feed Name: Zscaler Security Research Blog

Threat Score
60/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This ThreatLabz report explains domain fronting — a technique that hides the true HTTPS destination by using a different SNI than the HTTP Host header — and shows how attackers abuse CDNs (Azure, CloudFlare, Discord) to deliver malicious/phishing content and establish C2 channels. The document includes observed malicious domains, a case study demonstrating SNI/Host mismatches, and recommended defenses (maximum TLS interception, detection of SNI/Host mismatches, and Zscaler prevention features), plus notes on the related ‘domain hiding’/ESNI concerns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.