Tag: traffic distribution systems (TDSes)

Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery
News

Hazy Hawk Exploits DNS Records to Hijack CDC, Corporate Domains for Malware Delivery

Hazy Hawk is a threat actor that has been seen using DNS record misconfigurations to take over decommissioned cloud resources belonging to well-known companies, such as Microsoft Azure endpoints and Amazon S3 buckets. According to Infoblox, the compromised domains are then used to host URLs that leverage traffic distribution systems (TDSes) to send consumers to malware and frauds. The threat actor has also taken over resources hosted on GitHub, Netlify, Cloudflare CDN, Akamai, and Bunny CDN. After taking over multiple sub-domains linked to the U.S. Centers for Disease Control (CDC) in February 2025, the DNS threat intelligence organization claimed to have initially identified the threat actor. The same threat actor has since been shown to have targeted additional government insti...
New Investment Scams Use Facebook Ads, RDGA Domains, and IP Checks to Filter Victims
News

New Investment Scams Use Facebook Ads, RDGA Domains, and IP Checks to Filter Victims

Researchers studying cybersecurity have exposed two threat actors that use traffic distribution systems (TDSes) to hide their activities and stage celebrity endorsements to plan investment schemes. The DNS threat intelligence company Infoblox has dubbed the activity clusters Reckless Rabbit and Ruthless Rabbit. It has been noted that the attacks use fake sites, such as bitcoin exchanges, to entice victims. These platforms are then promoted on social media. The use of online forms to gather user information is a significant component of many scams. According to security researchers Darby Wise, Piotr Glaska, and Laura da Rocha, Reckless Rabbit fabricates Facebook advertisements that result in phony news stories that include a celebrity endorsing the investing platform. An embedd...