News: Corporate Identity Theft and domain hijacking

Criminals are stealing domain names to commit Corporate Identity Theft.

This information collection will keep you informed and up to speed on incidents and who is affected.

NodeZro Logo
secret-is-out.nodezro.com
  • 1. Contact us to share articles you think we should include. (Submit article)
2

Featured articles and information:

2023-08-31 Source: securityweek.com
Dangling DNS Used to Hijack Subdomains of Major Organizations

Dangling DNS records were abused by researchers to hijack subdomains belonging to major organizations, warning that thousands of entities are impacted.

According to securityweek.com, researchers have abused dangling DNS records to hijack subdomains belonging to over a dozen major organizations, and they warn that thousands of entities are vulnerable to such attacks.

Read this and more great reporting from the author Eduard Kovacs on the link below.

2022-05-06 Source: Bleeping Computer LLC
Ferrari Corporate Identity Stolen in Domain Hijack

Ferrari had its Corporate Identity stolen and used to host a scam promoting a fake Ferrari NFT collection.

According to bleepingcomputer.com, ethical hacker and bug bounty hunter Sam Curry reported that the Ferrari subdomain forms.ferrari.com was hosting a fake NFT scam.

Read this and more great reporting from the author Ax Sharma on the link below.

2021-11-25 Source: Bleeping Computer LLC
Department for Transport Official Identity Abused After Domain Hijack

The Department for Transport (DfT) of the UK Government had its Identity stolen and used to expose end-users to explicit adult material.

According to bleepingcomputer.com, the domain name identity charts.dft.gov.uk was hijacked. The hackers directed all visitors to this domain name to a web page containing explicit adult material.

Read this and more great reporting from the author Ax Sharma on the link below.

2020-11-23 Wired Business Media
Joe Biden Identity Stolen In Subdomain Hijack

The current President of the United States had his identity stolen by hackers and used for website vandalism.

Securityweek.com reported on November 23, 2020 that Joe Biden had the domain name identity vote.joebiden.com hijacked. It is not known to us if then hackers used the indetity to target Joe Bides ecosystem.

Read this and more great reporting from securityweek.com on the link below.

Title Publisher Date Link
Galxe protocol experiences DNS attack, losses $150K cointelegraph.com 2023-10-06 https://cointelegraph.com/news/galxe-protocol-experiences-dns-attack-october-6
Identity attacks, which often involve impersonation and privilege escalation, are a growing persistent threat to organizations worldwide. darkreading.com 2023-09-27 https://www.darkreading.com/attacks-breaches/how-the-okta-cross-tenant-impersonation-attacks-succeeded
DNS security poses problems for enterprise IT networkworld.com 2023-09-26 https://www.networkworld.com/article/3707471/dns-security-poses-problems-for-enterprise-it.html
Balancer blames ‘social engineering attack’ on DNS provider for website hijack cointelegraph.com 2023-09-21 https://cointelegraph.com/news/balancer-social-engineering-attack-dns-provider-frontend-hijack
Dangling DNS Used to Hijack Subdomains of Major Organizations Securityweek.com 2023-08-31 https://www.securityweek.com/dangling-dns-used-to-hijack-subdomains-of-major-organizations/
Three Reasons Why CISOs Need to Know How Their Company Is Managing Their Domains circleid.com 2023-07-24 https://circleid.com/posts/20230724-three-reasons-why-cisos-need-to-know-how-their-company-is-managing-their-domains
Attackers target the Domain Name System, the internet’s phone book. Here’s how to fight back SiliconANGLE Media Inc 2023-07-14 https://siliconangle.com/2023/07/14/attackers-target-domain-name-system-internets-phone-book-heres-fight-back/
Malware Execution Method Using DNS TXT Record asec.ahnlab.com 2023-06-31 https://asec.ahnlab.com/en/54916/
Subdomain hijacking vulnerabilities report Corporation Service Company (CSC) 2023-04-18 https://www.businesswire.com/news/home/20230418005012/en/New-CSC-Research-Finds-One-in-Five-DNS-Records-are-Susceptible-to-Subdomain-Hijacking-Due-to-Insufficient-Cyber-Hygiene
GoDaddy says a multi-year breach hijacked customer websites and accounts arstechnica.com 2023-02-17 https://arstechnica.com/information-technology/2023/02/godaddy-says-a-multi-year-breach-hijacked-customer-websites-and-accounts/
Hackers Took Over a Subdomain of Wired.com for Several Months and Replaced It With Sleazy Online Casino Content futurism.com 2023-01-26 https://futurism.com/hackers-subdomain-wired
Domain shadowing becoming more popular among cybercriminals Bleeping Computer LLC 2022-09-21 https://www.bleepingcomputer.com/news/security/domain-shadowing-becoming-more-popular-among-cybercriminals/
DNS is now more important than ever for internet traffic Future Publishing Limited Quay House 2022-08-25 https://www.techradar.com/news/dns-is-now-more-important-than-ever-for-internet-traffic
Celer Network shuts down bridge over potential DNS hijacking Cointelegraph 2022-08-18 https://cointelegraph.com/news/celer-network-shuts-down-bridge-over-potential-dns-hijacking
Curve Finance’s Hackers Loot $570K Via DNS Hijacking Tron Weekly 2022-08-10 https://www.tronweekly.com/curve-finance-dns-hijacking/
DNS Hijack Compromised Ankr’s Services for Polygon and Fantom CryptoPotato 2022-07-02 https://cryptopotato.com/dns-hijack-compromised-ankrs-services-for-polygon-and-fantom/
Hackers Step Up Attempts to Hijack DeFi Websites Defiant Media Inc 2022-06-24 https://thedefiant.io/convex-exploit
Hackers Step Up Attempts to Hijack DeFi Websites Convex's Domain Name Server Targeted in Latest Spoofing Exploit Yahoo Inc 2022-06-24 https://finance.yahoo.com/news/hackers-step-attempts-hijack-defi-091956415.html
Iranian Hackers Spotted Using a new DNS Hijacking Malware in Recent Attacks The Hacker News 2022-06-13 https://thehackernews.com/2022/06/iranian-hackers-spotted-using-new-dns.html
Ferrari subdomain hijacked to push fake Ferrari NFT collection Bleeping Computer LLC 2022-05-06 https://www.bleepingcomputer.com/news/security/ferrari-subdomain-hijacked-to-push-fake-ferrari-nft-collection/
Subdomain takeover attacks on the rise and harder to monitor Help Net Security 2022-03-29 https://www.helpnetsecurity.com/2022/03/29/subdomain-takeovers-on-the-rise/
UK government transport website caught showing porn Bleeping Computer LLC 2021-11-25 https://www.bleepingcomputer.com/news/security/uk-government-transport-website-caught-showing-porn/
A Gov.uk site dedicated to porn? Absolutely. Best of British Porn? Not Quite. The Crow 2021-11-25 https://thecrow.uk/A-Gov.uk-site-dedicated-to-porn-Absolutely/
Hackers Compromise Web Portal Bitcoin.org — DNS Hijack Replaces Site With BTC Doubler Scam Saint Bitts LLC - Bitcoin.com 2021-09-23 https://news.bitcoin.com/hackers-compromise-web-portal-bitcoin-org-dns-hijack-replaces-site-with-btc-doubler-scam/
Over 60,000 parked domains were vulnerable to AWS hijacking Bleeping Computer LLC 2021-09-03 https://www.bleepingcomputer.com/news/security/over-60-000-parked-domains-were-vulnerable-to-aws-hijacking/
“It’s Always DNS!” Why DNS Is the Biggest Single Point of Failure in the New Norm CircleID 2021-05-24 https://circleid.com/posts/20210524-why-dns-is-the-biggest-single-point-of-failure-in-the-new-norm/
DNS hijacks at two cryptocurrency sites point the finger at GoDaddy, again The Record by Recorded Future 2021-03-15 https://therecord.media/two-cryptocurrency-portals-are-experiencing-a-dns-hijack-at-the-same-time/
The Hijacking of Perl.com The Perl Foundation 2021-02-28 https://www.perl.com/article/the-hijacking-of-perl-com/
Subdomain of Official Joe Biden Campaign Website Defaced by Turkish Hacker Wired Business Media 2020-11-23 https://www.securityweek.com/subdomain-official-joe-biden-campaign-website-defaced-turkish-hacker
Company web names hijacked via outdated cloud DNS records Sophos Ltd 2020-06-07 https://nakedsecurity.sophos.com/2020/07/07/company-web-names-hijacked-via-outdated-cloud-dns-records/
The Current State of Domain Hijacking, and a specific look at the ongoing issues at GoDaddy The Spamhaus Project SLU 2020-04-17 https://www.spamhaus.org/news/article/797/the-current-state-of-domain-hijacking-and-a-specific-look-at-the-ongoing-issues-at-godaddy
DNS hijacking grabs headlines, but it’s just the tip of the iceberg IDG Communications, Inc 2019-06-17 https://www.csoonline.com/article/3402678/dns-hijacking-grabs-headlines-but-its-just-the-tip-of-the-iceberg.html
DNS Hijacking Abuses Trust In Core Internet Service Cisco Systems, Inc 2019-04-17 https://blog.talosintelligence.com/2019/04/seaturtle.html
Cyberspies Hijacked the Internet Domains of Entire Countries WIRED Media Group 2019-04-17 https://www.wired.com/story/sea-turtle-dns-hijacking/
Gmail, Netflix and PayPal Users Targeted In DNS Hijacking Campaign Forbes 2019-04-07 https://www.forbes.com/sites/kateoflahertyuk/2019/04/07/gmail-netflix-and-paypal-users-targeted-in-dns-hijacking-campaign/
ICANN warns of “ongoing and significant” attacks against internet’s DNS infrastructure Techcrunch 2019-02-23 https://techcrunch.com/2019/02/23/icann-ongoing-attacks-dns/
A Deep Dive on the Recent Widespread DNS Hijacking Attacks Krebs on Security 2019-02-18 https://krebsonsecurity.com/2019/02/a-deep-dive-on-the-recent-widespread-dns-hijacking-attacks/
Inside the DNSpionage hacks that hijack domains at an unprecedented scale WIRED Media Group 2019-02-18 https://arstechnica.com/information-technology/2019/02/inside-the-dnspionage-hacks-that-hijack-domains-at-an-unprecedented-scale/
Linux.org Redirected to NSFW Page Spewing Racial Epithets Threatpost 2018-12-11 https://threatpost.com/linux-org-redirected-nsfw/139776/
Hackers Hijack DNS Server of BlackWallet to Steal $400,000 Bleeping Computer LLC 2018-01-14 https://www.bleepingcomputer.com/news/security/hackers-hijack-dns-server-of-blackwallet-to-steal-400-000/
The New York Times Web site was taken down by DNS hijacking. Here’s what that means. The Washington Post 2013-08-27 https://www.washingtonpost.com/news/the-switch/wp/2013/08/27/the-new-york-times-web-site-was-taken-down-by-dns-hijacking-heres-what-that-means/
72% of Organizations Experienced a DNS Attack in the Past Year Reed Exhibitions Ltd   https://www.infosecurity-magazine.com/news/72-orgs-dns-attack-last-year/
Title Publisher Date Link
Mitigate DNS Infrastructure Tampering US Government CISA 2019-09-19 https://www.cisa.gov/sites/default/files/publications/CISAInsights-Cyber-MitigateDNSInfrastructureTampering_S508C.pdf
Ongoing DNS hijacking and mitigation advice UK Government NCSC 2019-06-12 https://www.ncsc.gov.uk/news/ongoing-dns-hijacking-and-mitigation-advice
DNS Infrastructure Hijacking Campaign US Government CISA 2019-02-12 https://www.cisa.gov/uscert/ncas/alerts/AA19-024A
DNS hijacking activity UK Government NCSC 2019-02-05 https://www.ncsc.gov.uk/news/alert-dns-hijacking-activity
Emergency Directive 19-01 US Government CISA 2019-01-22 https://www.cisa.gov/sites/default/files/ed-19-01%20(1).pdf
Title Publisher Date Link
Retroactive Identification of Targeted DNS Infrastructure Hijacking Gautam Akiwate, Raffaele Sommese, Mattijs Jonker, Zakir Durumeric, KC Claffy, Geoffrey M. Voelker, Stefan Savage 2022-10-25 https://cseweb.ucsd.edu/~savage/papers/IMC2022-Hijack.pdf
A Comprehensive Measurement-based Investigation of DNS Hijacking Rebekah Houser; Shuai Hao; Zhou Li; Daiping Liu; Chase Cotton; Haining Wang 2021-11-22 https://ieeexplore.ieee.org/abstract/document/9603621
Zombie Awakening: Stealthy Hijacking of Active Domains through DNS Hosting Referral Eihal Alowaisheq, Siyuan Tang, Zhihao Wang, Fatemah Alharbi, Xiaojing Liao, XiaoFeng Wang 2020-11-02 https://dl.acm.org/doi/abs/10.1145/3372297.3417864
Overcoming Threats and Vulnerabilities in DNS Asadullah Shaikh, Bhavika Pardeshi, Faraz Dalvi 2020-04-08 https://papers.ssrn.com/sol3/Papers.cfm?abstract_id=3568728
Understanding the Security Threats of Esoteric Subdomain Takeover and Prevention Scheme. Rashid, S. M. Zia Ur & Kamrul, Md. Imtiaz & Alam, Asraful. 2019-02-07 https://www.researchgate.net/project/Domain-Hijacking-and-Advanced-Reconnaissance-Techniques
The Wolf of Name Street: Hijacking Domains Through Their Nameservers Thomas Vissers, Timothy Barron, Tom Van Goethem, Wouter Joosen, Nick Nikiforakis 2017-10-30 https://dl.acm.org/doi/abs/10.1145/3133956.3133988
All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS Records Daiping Liu, Shuai Hao, Haining Wang 2016-10-24 https://dl.acm.org/doi/abs/10.1145/2976749.2978387
Design and Implementation of Domain Hijacking Detection System Xue, Jupo Liu, Yang Chang, Peng Xiao, Jun 2015-07-09 https://www.researchgate.net/publication/281722851_Design_and_ Implementation_of_Domain_Hijacking_Detection_System
Perils of Transitive Trust in the Domain Name System Venugopalan Ramasubramanian and Emin Gun Sirer 2005-10-19 https://dl.acm.org/doi/10.5555/1251086.1251121

Learn more about NodeZro:

Book a demo now to see the NodeZro tools in action.


About NodeZro Ltd:

NodeZro specializes in mapping, monitoring and securing large and complex internet namespaces. NodeZro helps corporations and governments understand, sanitize and protect their vulnerable DNS networks across the globe.

NodeZro LTD is a UK company with Company No. 13737105.