Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery

Hazy Hawk is a threat actor that has been seen using DNS record misconfigurations to take over decommissioned cloud resources belonging to well-known companies, such as Microsoft Azure endpoints and Amazon S3 buckets.

According to Infoblox, the compromised domains are then used to host URLs that leverage traffic distribution systems (TDSes) to send consumers to malware and frauds. The threat actor has also taken over resources hosted on GitHub, Netlify, Cloudflare CDN, Akamai, and Bunny CDN.

After taking over multiple sub-domains linked to the U.S. Centers for Disease Control (CDC) in February 2025, the DNS threat intelligence organization claimed to have initially identified the threat actor.

The same threat actor has since been shown to have targeted additional government institutions worldwide read more about Hazy Hawk Exploits DNS Records to Hijack CDC Corporate Domains for Malware Delivery.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *