{"id":1294,"date":"2025-05-20T18:57:09","date_gmt":"2025-05-20T15:57:09","guid":{"rendered":"https:\/\/trustcrypt.com\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/"},"modified":"2025-05-20T18:57:09","modified_gmt":"2025-05-20T15:57:09","slug":"hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains","status":"publish","type":"post","link":"https:\/\/trustcrypt.com\/ar\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/","title":{"rendered":"Hazy Hawk Group Leverages DNS Misconfigurations to Compromise Trusted Domains"},"content":{"rendered":"<p>A threat actor identified as &#8220;Hazy Hawk&#8221; is capitalizing on neglected DNS CNAME records associated with abandoned cloud services. This exploitation allows them to seize control of trusted subdomains belonging to governments, educational institutions, and Fortune 500 companies, which they utilize for the distribution of scams, counterfeit applications, and malicious advertisements.<\/p>\n<p>Research conducted by security experts reveals that Hazy Hawk begins by scanning domains for CNAME records that point to outdated cloud endpoints, a process made possible through passive DNS data validation techniques. Once an abandoned CNAME record is identified, the actor registers a new cloud resource that mirrors the original CNAME name, redirecting the legitimate subdomain to their newly established cloud-hosted site.<\/p>\n<p>This strategy has permitted these attackers to commandeer a range of domains, facilitating various malicious operations, including cloaking harmful activities and hosting scam content or serving as redirect hubs within broader fraud campaigns. <\/p>\n<p>Some significant examples of the hijacked domains include:<\/p>\n<p>&#8211; <strong>cdc.gov<\/strong> \u2013 U.S. Centers for Disease Control and Prevention<br \/>\n&#8211; <strong>honeywell.com<\/strong> \u2013 Multinational conglomerate<br \/>\n&#8211; <strong>berkeley.edu<\/strong> \u2013 University of California, Berkeley<br \/>\n&#8211; <strong>michelin.co.uk<\/strong> \u2013 Michelin Tires UK<br \/>\n&#8211; <strong>ey.com, pwc.com, deloitte.com<\/strong> \u2013 Global &#8220;Big Four&#8221; consulting firms<br \/>\n&#8211; <strong>ted.com<\/strong> \u2013 Nonprofit media organization (TED Talks)<br \/>\n&#8211; <strong>health.gov.au<\/strong> \u2013 Australian Department of Health<br \/>\n&#8211; <strong>unicef.org<\/strong> \u2013 United Nations Children&#8217;s Fund<br \/>\n&#8211; <strong>nyu.edu<\/strong> \u2013 New York University<br \/>\n&#8211; <strong>unilever.com<\/strong> \u2013 Global consumer goods company<br \/>\n&#8211; <strong>ca.gov<\/strong> \u2013 California State Government<\/p>\n<p>For comprehensive insights, refer to the complete list of affected domains outlined in the research.<\/p>\n<p>Once control of a subdomain is secured, Hazy Hawk generates numerous malicious URLs that leverage the high trust score associated with the parent domain, rendering them seemingly legitimate on search engines. Users who click on these URLs are redirected through a series of domains and traffic distribution systems (TDS) that assess their device type, IP address, VPN utilization, and other factors to identify potential victims.<\/p>\n<p>Infoblox&#8217;s investigations have revealed that these manipulated sites are primarily employed for various forms of scams, including tech support fraud, misleading antivirus alerts, counterfeit streaming services, and phishing endeavors. Individuals duped into accepting browser push notifications receive ongoing alerts, even after navigating away from the scam sites, creating a lucrative revenue stream for Hazy Hawk.<\/p>\n<p>In prior analyses, researchers also reported on another threat group known as &#8220;Savvy Seahorse,&#8221; which employed similar tactics utilizing CNAME records to construct a nontraditional TDS that directed users to fraudulent investment platforms.<\/p>\n<p>The overlooked nature of CNAME records renders them particularly susceptible to covert exploitation, and it is evident that an increasing number of threat actors are attempting to leverage this vulnerability. The success of Hazy Hawk&#8217;s operations also hinges on organizations failing to eliminate DNS records after the decommissioning of cloud services, thus allowing attackers to replicate original resource names without any authentication.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A threat actor identified as &#8220;Hazy Hawk&#8221; is capitalizing on neglected DNS CNAME records associated with abandoned cloud services. This&#8230;<\/p>\n","protected":false},"author":1,"featured_media":1295,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"Default","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[28],"tags":[326,423,521],"class_list":["post-1294","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-cloud","tag-dns","tag-subdomain"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Hazy Hawk Group Leverages DNS Misconfigurations to Compromise Trusted Domains - Trustcrypt<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustcrypt.com\/ar\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/\" \/>\n<meta property=\"og:locale\" content=\"ar_AR\" \/>\n<meta property=\"og:locale:alternate\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hazy Hawk Group Leverages DNS Misconfigurations to Compromise Trusted Domains\" \/>\n<meta property=\"og:description\" content=\"A threat actor identified as &#8220;Hazy Hawk&#8221; is capitalizing on neglected DNS CNAME records associated with abandoned cloud services. This...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/trustcrypt.com\/ar\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/\" \/>\n<meta property=\"og:site_name\" content=\"Trustcrypt\" \/>\n<meta property=\"article:published_time\" content=\"2025-05-20T15:57:09+00:00\" \/>\n<meta name=\"author\" content=\"Trustscrypt\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629\" \/>\n\t<meta name=\"twitter:data1\" content=\"Trustscrypt\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631\" \/>\n\t<meta name=\"twitter:data2\" content=\"\u062f\u0642\u064a\u0642\u062a\u0627\u0646\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/trustcrypt.com\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/\",\"url\":\"https:\/\/trustcrypt.com\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/\",\"name\":\"Hazy Hawk Group Leverages DNS Misconfigurations to Compromise Trusted Domains\",\"isPartOf\":{\"@id\":\"https:\/\/trustcrypt.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/trustcrypt.com\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/trustcrypt.com\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains.webp\",\"datePublished\":\"2025-05-20T15:57:09+00:00\",\"author\":{\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\"},\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/trustcrypt.com\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\/\/trustcrypt.com\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/#primaryimage\",\"url\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains.webp\",\"contentUrl\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains.webp\",\"width\":1792,\"height\":1024,\"caption\":\"Hazy Hawk Group Leverages DNS Misconfigurations to Compromise Trusted Domains\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/trustcrypt.com\/#website\",\"url\":\"https:\/\/trustcrypt.com\/\",\"name\":\"Trustcrypt\",\"description\":\"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/trustcrypt.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"ar\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\",\"name\":\"Trustscrypt\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"caption\":\"Trustscrypt\"},\"sameAs\":[\"http:\/\/trustcrypt.com\"],\"url\":\"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hazy Hawk Group Leverages DNS Misconfigurations to Compromise Trusted Domains - Trustcrypt","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustcrypt.com\/ar\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/","og_locale":"ar_AR","og_type":"article","og_title":"[:en]Hazy Hawk Group Leverages DNS Misconfigurations to Compromise Trusted Domains[:] - Trustcrypt","og_description":"A threat actor identified as &#8220;Hazy Hawk&#8221; is capitalizing on neglected DNS CNAME records associated with abandoned cloud services. This...","og_url":"https:\/\/trustcrypt.com\/ar\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/","og_site_name":"Trustcrypt","article_published_time":"2025-05-20T15:57:09+00:00","author":"Trustscrypt","twitter_card":"summary_large_image","twitter_misc":{"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629":"Trustscrypt","\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631":"\u062f\u0642\u064a\u0642\u062a\u0627\u0646"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustcrypt.com\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/","url":"https:\/\/trustcrypt.com\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/","name":"Hazy Hawk Group Leverages DNS Misconfigurations to Compromise Trusted Domains","isPartOf":{"@id":"https:\/\/trustcrypt.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustcrypt.com\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/#primaryimage"},"image":{"@id":"https:\/\/trustcrypt.com\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/#primaryimage"},"thumbnailUrl":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains.webp","datePublished":"2025-05-20T15:57:09+00:00","author":{"@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f"},"inLanguage":"ar","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustcrypt.com\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/"]}]},{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/trustcrypt.com\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains\/#primaryimage","url":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains.webp","contentUrl":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/05\/hazy-hawk-group-leverages-dns-misconfigurations-to-compromise-trusted-domains.webp","width":1792,"height":1024,"caption":"Hazy Hawk Group Leverages DNS Misconfigurations to Compromise Trusted Domains"},{"@type":"WebSite","@id":"https:\/\/trustcrypt.com\/#website","url":"https:\/\/trustcrypt.com\/","name":"Trustcrypt","description":"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustcrypt.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ar"},{"@type":"Person","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f","name":"Trustscrypt","image":{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","caption":"Trustscrypt"},"sameAs":["http:\/\/trustcrypt.com"],"url":"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/"}]}},"_links":{"self":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/1294","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/comments?post=1294"}],"version-history":[{"count":0,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/1294\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/media\/1295"}],"wp:attachment":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/media?parent=1294"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/categories?post=1294"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/tags?post=1294"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}