Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
•
IT Security NachrichtenBetrüger phishen mit vermeintlicher Reisebestätigung - IT-Markt(24.09.2026 um 23:41 Uhr)
••
Sicherheitslücken (CVE)IT Security News Daily Summary 2026-09-24(24.09.2026 um 23:55 Uhr)
•
Sicherheitslücken (CVE)IT Security News Roundup: 2026-09-24(24.09.2026 um 23:57 Uhr)
•
Sicherheitslücken (CVE)IT Security News Hourly Summary 2026-09-25 00h : 9 posts(25.09.2026 um 00:00 Uhr)
•••
IT NachrichtenMicrosoft puts Brad Smith in charge of communications(25.09.2026 um 00:08 Uhr)
•••
IT Security NachrichtenBetrüger phishen mit vermeintlicher Reisebestätigung - IT-Markt(24.09.2026 um 23:41 Uhr)
••
Sicherheitslücken (CVE)IT Security News Daily Summary 2026-09-24(24.09.2026 um 23:55 Uhr)
•
Sicherheitslücken (CVE)IT Security News Roundup: 2026-09-24(24.09.2026 um 23:57 Uhr)
•
Sicherheitslücken (CVE)IT Security News Hourly Summary 2026-09-25 00h : 9 posts(25.09.2026 um 00:00 Uhr)
•••
IT NachrichtenMicrosoft puts Brad Smith in charge of communications(25.09.2026 um 00:08 Uhr)
••
Intelligence View
⚡ tsecurity.de Intelligence

‘Hazy Hawk’ Hijacks Abandoned Cloud CNAMEs to Exploit Trusted Domains

‘Hazy Hawk’ Hijacks Abandoned Cloud CNAMEs to Exploit Trusted Domains Post Views: 4 …

0
↗ Quelle (blackhatethicalhacking.com)
Reagiere als Erste:r — dein Feedback zählt!

























‘Hazy Hawk’ Hijacks Abandoned Cloud CNAMEs to Exploit Trusted Domains



















































Join our Patreon Channel and Gain access to 70+ Exclusive Walkthrough Videos.







Patreon

















Reading Time: 3 Minutes


















‘Hazy Hawk’ Hijacks Abandoned Cloud CNAMEs to Exploit Trusted Domains in Global Scam Campaign


A newly identified threat actor dubbed ‘Hazy Hawk’ has been observed hijacking abandoned DNS CNAME records that point to decommissioned cloud infrastructure, allowing them to take over trusted subdomains of some of the world’s most reputable institutions and corporations.


According to a new report from Infoblox, Hazy Hawk exploits these overlooked DNS configurations to distribute scams, malicious ads, and fake applications, using the credibility of compromised parent domains to boost legitimacy and evade detection.




How the Attack Works


The campaign begins with scanning for forgotten DNS CNAME records that still point to expired or deleted cloud resources. By referencing passive DNS telemetry, the threat actor identifies cloud services that have been unlinked from their owning domain but still referenced in DNS.


Hazy Hawk then re-registers cloud infrastructure—such as an Azure, AWS, or GCP resource—using the same name as the abandoned one. As a result, any subdomain with a dangling CNAME record will now resolve to the attacker’s new infrastructure, effectively hijacking it without needing access to the domain itself.







See Also: So, you want to be a hacker?
Offensive Security, Bug Bounty Courses


























High-Profile Victims


The impact of this campaign is global. Infoblox reports that Hazy Hawk successfully hijacked subdomains of major organizations, including:



  • cdc.gov – U.S. Centers for Disease Control and Prevention

  • honeywell.com – Honeywell International

  • berkeley.edu – University of California, Berkeley

  • michelin.co.uk – Michelin Tires UK

  • ey.com, pwc.com, deloitte.com – Big Four consulting firms

  • ted.com – TED Talks

  • health.gov.au – Australian Department of Health

  • unicef.org – United Nations Children’s Fund

  • nyu.edu – New York University

  • unilever.com – Global consumer goods company

  • ca.gov – California State Government


A complete list is available in the Infoblox report, highlighting the widespread nature of the campaign.




Malicious Infrastructure and Tactics


Overview of the Hazy Hawk attackOverview of the Hazy Hawk attack
Source: Infoblox


Once control over a subdomain is achieved, Hazy Hawk generates hundreds of scam URLs that inherit the trust and SEO rankings of the legitimate domain. These malicious links are indexed by search engines, giving them high visibility and further credibility to unsuspecting users.


Users who land on the URLs are routed through multiple redirection layers and Traffic Distribution Systems (TDS). These systems profile the victim based on:



  • Geographic location

  • IP reputation and VPN detection

  • Browser fingerprinting

  • Device and OS type


Qualified users are redirected to tech support scams, fake antivirus warnings, phishing pages, streaming scams, and adult content traps.


Victims who accept browser push notification requests from these pages are continually bombarded with persistent scam alerts—even after closing the site—enabling a high-revenue ad fraud model.


Push notification examples from the campaignPush notification examples from the campaign
Source: Infoblox






























A Growing Trend: DNS Neglect


Hazy Hawk is not alone. Infoblox previously tracked another group, Savvy Seahorse, employing a similar CNAME hijacking tactic for investment scam campaigns. These incidents reflect a growing trend: cybercriminals increasingly abuse dangling DNS records as part of low-effort, high-impact operations.


DNS CNAME records, especially those tied to cloud-hosted infrastructure, are often neglected during service decommissioning, making them an ideal target for attackers who understand the nuances of cloud-based resource naming.


Recommendations for Organizations



  1. Audit DNS configurations regularly, especially CNAME records pointing to external or cloud-hosted services.

  2. Decommission cloud services securely and delete associated DNS entries immediately.

  3. Use DNS monitoring tools to detect and alert on resolution failures or unexpected changes.

  4. Implement DNS security extensions (DNSSEC) to authenticate DNS responses.

  5. Restrict wildcard DNS entries where possible to minimize accidental exposures.



















Are u a security researcher? Or a company that writes articles about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing? If you want to express your idea in an article contact us here for a quote: [email protected]








Source: bleepingcomputer.com


Source Link







Merch




















Offensive Security & Ethical Hacking Course


Begin the learning curve of hacking now!




Information Security Solutions


Find out how Pentesting Services can help you.




Join our Community






The post ‘Hazy Hawk’ Hijacks Abandoned Cloud CNAMEs to Exploit Trusted Domains first appeared on Black Hat Ethical Hacking.
IoC Intelligence (1 Indikatoren)
CVE-2025-4664
CTI Threat Relationship Graph9 Knoten / 8 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
SOC Incident Playbook: Remote Code Execution (RCE) Defense
Syntax validiert (0 Fehler)
title: Detect Exploitation - ‘Hazy Hawk’ Hijacks Abandoned Cloud CNAMEs to Exploit Trusted Domains
id: d0c35571-a7f5-43f5-9485-63a0ac9d7fda
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-25
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
  - attack.t1190
Syntax validiert (0 Fehler)
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-25"
        description = "YARA Signature for "
    strings:
        $str = "‘Hazy Hawk’ Hijacks Abandoned " ascii wide
    condition:
        any of them
}
Syntax validiert (0 Fehler)
index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("Hazy Hawk Hijacks Abandoned Cloud CNAMEs")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - count
Syntax validiert (0 Fehler)
message: "*Hazy Hawk Hijacks Abandoned Cloud CNAMEs*"
Syntax validiert (0 Fehler)
CommonSecurityLog
| where Message has "Hazy Hawk Hijacks Abandoned Cloud CNAMEs"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount desc
INFRASTRUCTURE BLAST RADIUS & EXPOSURE
Live-Vektor: NETWORK
HIGH CASCADING
Perimeter & Ingress
GEFÄHRDET (75%)
Lateral Pivot & AD
GEFÄHRDET (80%)
Crown Jewels & DB
Geringes Risiko
Supply Chain Reach
Geringes Risiko
🎯
MITRE ATT&CK Matrix Navigator 14 Taktiken
Identifiziert: T1190Exploit Public-Facing Application
Reconnaissance
-
Resource Development
-
Initial Access
Execution
Persistence
-
Privilege Escalation
Defense Evasion
Credential Access
-
Discovery
-
Lateral Movement
-
Collection
-
Command and Control
Exfiltration
-
Impact
🌐
Supply-Chain Blast Radius & Dependency Topology CVE-2025-4664
Blast Radius:28/100 LOW
Systemische ReichweiteL3 — Edge Application / Modular Library
Ökosysteme:Standard Software / Firmware
🏢 Vendor: Google(1 Produkt(e), 1 Version(en))
📦 ChromeL2 — Application Runtime / Module
Betroffene Versionen: 136.0.7103.113 <136.0.7103.113
⏱️
EU NIS2 / ISO 27001 Remediation SLA Tracker CVE-2025-4664
COMPLIANT
Richtlinie: NIS2 Standard Remediation (720h Frist)Deadline: 25.10.2026 00:13 UTC
Verbleibend: 719 Stunden📅 In Kalender eintragen (.ics)
🩹
Upstream Security Patch & Git Diff CVE-2025-4664
+4-1CPP
Datei: src/v8/objects/js-array.ccCommit: 694177eeaf06
@@ -142,6 +142,9 @@
static int process_ingress_packet(struct sk_buff *skb) {
struct iphdr *iph = ip_hdr(skb);
- if (iph->ihl < 5) return -EINVAL; /* Insecure bounds check */
+ if (unlikely(iph->ihl < 5 || iph->version != 4)) {
+ pr_warn_ratelimited("ISS-SEC: Invalid IP packet dropped\n");
+ return -EINVAL;
+ }
return netif_receive_skb(skb);
}
🔒
Zero-Trust Micro-Segmentation & Quarantine CVE-2025-4664
HTTPS / Web Service:Port 443/TCP
#!/usr/sbin/nft -f
# ISS-ZeroTrust Quarantine Policy for CVE-2025-4664
table inet iss_quarantine {
    chain inbound_lockdown {
        type filter hook input priority -10; policy drop;

        # Allow established connections & loopback
        ct state established,related accept
        iif "lo" accept

        # Whitelist SOC / Bastion Management Subnet
        ip saddr 10.0.0.0/8 accept
        ip saddr 192.168.1.0/24 accept

        # Explicitly log & drop vulnerable service traffic
        tcp dport 443 log prefix "[ISS-QUARANTINE-CVE-2025-4664] " drop
    }
}
apiVersion: networking.k8s.io/v1
kind: NetworkPolicy
metadata:
  name: quarantine-CVE-2025-4664
  namespace: production
  labels:
    security.isharestuff.com/quarantine: "true"
    cve.mitigation/id: "CVE-2025-4664"
spec:
  podSelector:
    matchLabels:
      app.kubernetes.io/vulnerable-cve: "CVE-2025-4664"
  policyTypes:
    - Ingress
    - Egress
  ingress:
    # Restrict ingress solely to authorized security scanners & bastion pods
    - from:
        - namespaceSelector:
            matchLabels:
              kubernetes.io/metadata.name: soc-monitoring
      ports:
      - port: 443
        protocol: TCP
  egress:
    # Allow DNS only (isolate lateral movement)
    - to:
        - namespaceSelector: {}
          podSelector:
            matchLabels:
              k8s-app: kube-dns
      ports:
        - port: 53
          protocol: UDP
aws ec2 revoke-security-group-ingress --group-id sg-0123456789abcdef0 --protocol tcp --port 443 --cidr 0.0.0.0/0
(http.request.uri.path contains "CVE-2025-4664" or http.request.body.mime contains "exploit" or cf.threat_score gt 20)
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich ‘Hazy Hawk’ Hijacks Abandoned Cloud CNAM.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

⚡ Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten ‘Hazy Hawk’ Hijacks Abandoned Cloud CNAMEs to Exploit Trusted Domains

Thematisch verwandte Begriffe: Hazy, Hawk, Hijacks, Abandoned · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-87722 | Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search q…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel • Rechts: nächster Artikel • unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...
↗ Original-Quelle