Oasis Ticket Sales Scams: How to Stay Safe
During our weekly meetings with the banking industry and Police Scotland, we continue to see a significant increase in ticket scams over the last three…
Cybercriminals are increasingly using domain shadowing, a form of domain name system (DNS) hijacking, according to a new report from Palo Alto Networks Unit 42.
Domain shadowing is a subcategory of DNS hijacking – an attack on the system that translates domain names to IP addresses, essentially acting like a phone book for the internet. In domain shadowing, hackers compromise the DNS of a legitimate domain and insert their own subdomains, keeping the existing domains intact to prevent any suspicion from the owner of the compromised DNS.
Cybercriminals use domain shadowing to host malicious websites, such as those used in phishing attacks, scams or malware distribution.
Original domains hosting such sites are often quickly identified as malicious, and cyber security applications, such as firewalls, can easily detect if a user is attempting to access the malicious domain. To reduce the chances of a dangerous site being flagged, hackers use the domain names of legitimate organisations to host their own content.
The report from Palo Alto Networks detected over 12,000 shadowed domains between April and June 2022. Still, it emphasised that only 200 of these domains were previously marked as malicious by vendors on VirusTotal, demonstrating the effectiveness of using a shadowed domain to store malicious content without being detected.
Researchers shared some phishing attacks found during their research using domain shadowing, highlighting how easily a compromised domain can be used to further cybercriminals’ reach.
Researchers also noted one phishing attack used 16 compromised domains to host over 600 shadowed domains.
Because of the difficulty detecting shadowed domains, Palo Alto Networks emphasised that the phenomenon is an active threat to enterprises.
Preventions:
Domain shadowing relies on hackers having constant access to an organisation’s domain name system. Therefore, the best way to prevent your domain from being used to host malicious subdomains is to implement cyber security practices that protect your network and servers:
Related Links:
https://unit42.paloaltonetworks.com/domain-shadowing/ – Published September 21st