Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    My favorite projector from Samsung doubles as a gaming hub, and it’s discounted for Labor Day

    September 1, 2025

    Web3’s Speed Is No Longer Optional. It’s the Path to Adoption.

    September 1, 2025

    LayerX uses AI to cut enterprise back-office workload, scores $100M in Series B

    September 1, 2025
    Facebook X (Twitter) Instagram
    Trending
    • My favorite projector from Samsung doubles as a gaming hub, and it’s discounted for Labor Day
    • Web3’s Speed Is No Longer Optional. It’s the Path to Adoption.
    • LayerX uses AI to cut enterprise back-office workload, scores $100M in Series B
    • The M4 iPad Pro is discounted $100 as a last-minute Labor Day deal
    • Google Confirms Gmail Data Breach Warning Is Fake News
    • IEEE Presidents Note: Preserving Tech History’s Impact
    • Android Droppers Now Deliver SMS Stealers and Spyware, Not Just Banking Trojans
    • How to make IT operations more efficient
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Apps»Hackers are hijacking forgotten subdomains to spread malware through trusted sites; this overlooked trick could hit you next
    Apps

    Hackers are hijacking forgotten subdomains to spread malware through trusted sites; this overlooked trick could hit you next

    TechurzBy TechurzJune 1, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Representational image of a cybercriminal
    Share
    Facebook Twitter LinkedIn Pinterest Email


    • Outdated DNS records create invisible openings for criminals to spread malware through legitimate sites
    • Hazy Hawk turns misconfigured cloud links into silent redirection traps for fraud and infection
    • Victims think they’re visiting a real site, until popups and malware take over

    A troubling new online threat is emerging in which criminals hijack subdomains of major organizations, such as Bose, Panasonic, and even the US CDC (Centers for Disease Control and Prevention), to spread malware and perpetrate online scams.

    As flagged by security experts Infoblox, at the center of this campaign is a threat group known as Hazy Hawk, which has taken a relatively quiet but highly effective approach to compromise user trust and weaponize it against unsuspecting visitors.

    These subdomain hijackings are not the result of direct hacking but rather of exploiting overlooked infrastructure vulnerabilities.


    You may like

    An exploit rooted in administrative oversight

    Instead of breaching networks through brute force or phishing, Hazy Hawk exploits abandoned cloud resources linked to misconfigured DNS CNAME records.

    These so-called “dangling” records occur when an organization decommissions a cloud service but forgets to update or delete the DNS entry pointing to it, leaving the subdomain vulnerable.

    For example, a forgotten subdomain like something.bose.com might still point to an unused Azure or AWS resource, and if Hazy Hawk registers the corresponding cloud instance, the attacker suddenly controls a legitimate-looking Bose subdomain.

    This method is dangerous because misconfigurations are not typically flagged by conventional security systems.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    The repurposed subdomains become platforms for delivering scams, including fake antivirus warnings, tech support cons, and malware disguised as software updates.

    Hazy Hawk doesn’t just stop at hijacking – the group uses traffic distribution systems (TDSs) to reroute users from hijacked subdomains to malicious destinations.

    These TDSs, such as viralclipnow.xyz, assess a user’s device type, location, and browsing behavior to serve up tailored scams.

    Often, redirection begins with seemingly innocuous developer or blog domains, like share.js.org, before shuffling users through a web of deception.

    Once users accept push notifications, they continue to receive scam messages long after the initial infection, establishing a lasting vector for fraud.

    The fallout from these campaigns is more than theoretical and has affected high-profile organizations and firms like the CDC, Panasonic and Deloitte.

    Individuals can guard against these threats by refusing push notification requests from unfamiliar sites and exercising caution with links that seem too good to be true.

    For organizations, the emphasis must be on DNS hygiene. Failing to remove DNS entries for decommissioned cloud services leaves subdomains vulnerable to takeover.

    Automated DNS monitoring tools, especially those integrated with threat intelligence, can help detect signs of compromise.

    Security teams should treat these misconfigurations as critical vulnerabilities, not minor oversights.

    You might also like

    forgotten Hackers hijacking Hit malware overlooked sites spread subdomains Trick trusted
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article12 of Our Favorite Chrome Extensions
    Next Article Chopper Steals the Show in Netflix’s ‘One Piece’ Reveal
    Techurz
    • Website

    Related Posts

    Security

    ScarCruft Uses RokRAT Malware in Operation HanKook Phantom Targeting South Korean Academics

    September 1, 2025
    AI

    This iPhone trick hides my apps in a secret folder only I can access – here’s why I love it

    August 31, 2025
    AI

    One of the biggest new features on the Google Pixel 10 is also one of the most overlooked

    August 24, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    You Can Now Get Starlink for $15-Per-Month in New York, but There’s a Catch

    July 11, 20257 Views

    Non-US businesses want to cut back on using US cloud systems

    June 2, 20257 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    You Can Now Get Starlink for $15-Per-Month in New York, but There’s a Catch

    July 11, 20257 Views

    Non-US businesses want to cut back on using US cloud systems

    June 2, 20257 Views
    Our Picks

    My favorite projector from Samsung doubles as a gaming hub, and it’s discounted for Labor Day

    September 1, 2025

    Web3’s Speed Is No Longer Optional. It’s the Path to Adoption.

    September 1, 2025

    LayerX uses AI to cut enterprise back-office workload, scores $100M in Series B

    September 1, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.