Sitting Ducks: Cybercriminals Hijack 70,000 Domains for Phishing Frenzy

Cybercriminals are exploiting the Sitting Ducks attack technique to hijack domains for phishing and fraud. Nearly 70,000 domains have been hijacked recently, leveraging DNS misconfigurations. Despite increased awareness, the number of hijackings hasn’t decreased, leaving businesses and individuals vulnerable to malware and fraud while threat actors enjoy a quack-tastic time.

Pro Dashboard

Hot Take:

Why settle for a duck pond when you can have a domain lagoon? Cybercriminals have been quacking their way through cyberspace, turning legitimate domains into sitting ducks for phishing and fraud. With 70,000 domains already hijacked, it’s a wonder we aren’t all wearing tinfoil hats and using carrier pigeons for communication. Who knew ducks could be so dastardly?

Key Points:

  • Infoblox identified nearly 800,000 vulnerable domains, with 70,000 already hijacked.
  • The Sitting Ducks attack technique exploits DNS misconfigurations.
  • Hijacked domains include high-reputation brands, making detection difficult.
  • Rotational hijacking allows multiple threat actors to exploit the same domain.
  • Prominent threat actors include Vacant Viper, Horrid Hawk, and Hasty Hawk.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?