Cisco's Talos: state-backed hackers are continuing to brazenly hijack domains, targeting key infrastructure of several countries, in a months-long DNS campaign
Despite widespread attention since January, DNS campaign shows no signs of abating. — The wave of domain hijacking attacks besetting …
Context & Ripple Effects
This is a persistence report, not a new discovery: the same state-backed DNS hijacking wave that prompted a DHS emergency directive and a detailed teardown in February (Krebs's deep dive) is still running two months on, per Cisco Talos. The point of the story is that public disclosure and federal directives did not stop it.
The campaign also sits inside a longer pattern for Talos and for Cisco gear specifically: backdoored Cisco routers across at least four countries flagged in 2015 (the stealthy router backdoor), Talos later catching North Korea's Lazarus hitting internet backbone infrastructure, and Recorded Future's finding that Salt Typhoon breached telcos and ISPs by exploiting Cisco routers. Network plumbing — routers and DNS alike — keeps turning out to be where state actors settle in.
First-order effects
- Organizations whose domains were hijacked face ongoing interception risk right now: traffic meant for their mail and web servers can be silently redirected until records are reclaimed and registrar controls hardened.
- US federal agencies remain bound by the DHS emergency directive from the January disclosures, meaning audits of DNS records and registrar accounts are still active work rather than a closed incident.
Second-order effects
- Registrars and DNS providers come under pressure to make account takeover harder — mandatory multi-factor authentication, registrar locks — because every hijacked domain in this campaign traces back to compromised registrar credentials.
- Rivals to Cisco's security franchise get ammunition: each Talos-attributed campaign touching network infrastructure sharpens the pitch for competitors selling alternative routing and DNS security stacks to governments and telcos.
Third-order effects
- If hijacking campaigns persist past disclosure and directives, DNS control-plane security stops being a hygiene checklist item and becomes treated like critical-infrastructure defense, with regulators likely to formalize requirements around registrar authentication and record integrity.
- The pattern across this coverage — router backdoors, backbone-targeting malware, telco breaches via Cisco gear — points toward nation-state actors standardizing on durable footholds in shared network infrastructure, which raises the systemic stakes for any single vendor's installed base.
The trend: State-backed hackers are treating core internet plumbing — DNS records and network equipment — as persistent strategic terrain that survives public disclosure, pushing governments and vendors toward regulating and hardening the control plane itself.