Infoblox and Eclypsium: since 2018, Russian hackers hijacked 35K+ registered domains using Sitting Ducks attacks that involve exploiting DNS configuration flaws
Threat actors have hijacked more than 35,000 registered domains in so-called Sitting Ducks attacks that allow claiming …
Context & Ripple Effects
This extends a long-running DNS-abuse arc: earlier coverage documented state-backed domain hijacking against critical infrastructure and a broader campaign serious enough to draw a DHS emergency directive over DNS attacks and its defensive implications.
The scale attributed to Sitting Ducks also fits Infoblox's prior tracking of infrastructure services built for cybercriminal use, including an actor associated with large-scale domain registrations and link-shortening services. It matters because DNS configuration weaknesses can turn legitimate registered domains into attacker-controlled assets.
First-order effects
- Owners of the affected domains face remediation of vulnerable DNS configurations and potential investigation of traffic, email, or services routed through hijacked domains.
- Infoblox and Eclypsium's findings give defenders a concrete, multi-year pattern to hunt for in domain and DNS-management environments.
Second-order effects
- DNS providers, registrars, and managed-service operators face pressure to identify configurations that leave domains claimable and to make ownership and delegation controls more visible to customers.
- Security teams must treat a domain's registration as insufficient evidence of trust, increasing the value of DNS telemetry and configuration validation alongside reputation-based blocking.
Third-order effects
- If configuration-based takeovers continue at this scale, DNS security will shift further from a registrar-administration task toward a continuously monitored control-plane risk shared by domain owners and providers.
- The pattern could favor platforms that can pair domain intelligence with configuration monitoring, while raising expectations for clearer provider accountability over misconfigured delegations.
The trend: Sitting Ducks is one instance of a broader trend in which attackers operationalize overlooked internet-control-plane misconfigurations to acquire trusted infrastructure at scale.