Hacking

Sitting Ducks: Domain Hijacking Threats Targeting Brands Since 2018

Published  ·  3 min read

Multiple threat actors have been exploiting an attack method known as "Sitting Ducks" to hijack legitimate domains for phishing schemes and investment fraud, with some cases dating back years.

According to a report by Infoblox, nearly 800,000 registered domains were identified as vulnerable over the last three months, with about 9% (70,000) successfully hijacked.

"Cybercriminals have used this vector since 2018 to hijack tens of thousands of domain names," said Infoblox in its detailed analysis. "Victim domains include well-known brands, non-profits, and government entities."

What is the Sitting Ducks Attack?

The Sitting Ducks attack exploits DNS misconfigurations, allowing threat actors to seize control of domains without accessing the owner’s account at the registrar. This is possible when domains delegate DNS services to a different provider, leaving them vulnerable to hijacking if the configuration is “lame” (incomplete).

The attack requires:

  1. Delegation of DNS services to a provider other than the domain registrar.
  2. Misconfigured DNS delegations.
  3. The attacker’s ability to claim the domain and configure records without proper authorization.

Hijacked domains are often used in phishing campaigns, investment fraud, or malware distribution, capitalizing on the domains’ positive reputations to evade detection.

Recent Findings and Actors Involved

The scale of Sitting Ducks hijacks only gained attention after disclosures earlier this year. Despite increased awareness, hijackings have not decreased. Infoblox highlighted that these domains are challenging to detect due to their unchanged appearance post-hijack.

Some of the prominent DNS threat actors exploiting Sitting Ducks include:

  1. Vacant Viper: Active since December 2019, used for malicious spam, C2 operations, and malware delivery (e.g., AsyncRAT).
  2. Horrid Hawk: Operates investment fraud schemes using hijacked domains distributed through short-lived Facebook ads. Active since February 2023.
  3. Hasty Hawk: Known for phishing campaigns mimicking DHL shipping pages and fake donation sites supporting Ukraine. Active since March 2022.
  4. VexTrio Viper: Active since early 2020, involved in fake pharmaceutical campaigns, gambling, and dating scams.

Rotational Hijacking

A notable feature of Sitting Ducks attacks is rotational hijacking, where different actors take turns controlling the same domain over time. Attackers often use free DNS service providers, holding domains temporarily before losing control, enabling other attackers to claim them.

Broad Spectrum of Threats

Infoblox also noted actors using hijacked domains for spam and malware C2 operations. Some domains with high reputations remain under the radar of security tools, enabling attackers to conduct fraud and phishing campaigns with minimal detection.

Sitting Ducks attacks are a severe threat, impacting businesses and individuals by exposing them to phishing, malware, and credential theft. As these attacks continue to evolve, organizations must be vigilant about securing their DNS configurations to prevent domain hijacking.

 

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067