June 7, 2017 By Larry Loeb 2 min read

The number of initiatives targeting malicious domains has grown within the cybersecurity world. A new project, named Shadowfall, was announced this week by RSA, in collaboration with Malwarebytes, Palo Alto Networks and Broad Analysis. The firm explained it had carried out an operation designed to damage the RIG exploit kit’s functionality.

Working Within the Shadows

RIG has been the top exploit kit since Angler was taken down, delivering both Cerber and CryptoMix ransomwares as well as the SmokeLoader backdoor. Typically, it inserts fake iframes into compromised WordPress, Joomla and Drupal sites. These cause victim browsers to land on attacker-controlled webpages.

SecurityWeek noted that RIG uses domain shadowing as one of its main characteristics. This method occurs when attackers steal actual credentials from domain owners and then use them to create subdomains pointing to malicious servers. These malicious servers hide in legitimate domains, making them unlikely to be blacklisted simply because of the suspicion of malfeasance.

According to RSA, the “shadowing activity was observed in over 30,000 subdomains total affecting over 800 domains. The active subdomains were constantly fluctuating with entries continually being added and removed in an automated fashion with an average of 900 record modifications per day.” These subdomains are short-lived, typically only existing for 24 to 48 hours.

Using the Exploit Kit’s Common Link

The domains did contain one common link: They had a high incidence of being registered by GoDaddy, one of the biggest registrars on the internet. RSA enlisted GoDaddy’s help in the project, and they worked together to identify malware-used domains.

How the threat actors actually obtain the credentials for the domains is still somewhat opaque. There have been some data dumps in the past, but RSA suggested that there was anecdotal evidence pointing to usage of Internet of Things (IoT) botnets to brute force WordPress sites, along with the use of sophisticated spear fishing campaigns.

With GoDaddy’s aid, the groups managed to remove thousands of active shadow domain resources through revocation. This action undoubtedly put a crimp into RIG’s operation, but even RSA wondered how long such an action will last. As it explained, “Determining the impact of such a takedown on the inextricable pile of ongoing ransomware, malvertising and malspam campaigns is significantly more challenging.”

More from

How to craft a comprehensive data cleanliness policy

3 min read - Practicing good data hygiene is critical for today’s businesses. With everything from operational efficiency to cybersecurity readiness relying on the integrity of stored data, having confidence in your organization’s data cleanliness policy is essential.But what does this involve, and how can you ensure your data cleanliness policy checks the right boxes? Luckily, there are practical steps you can follow to ensure data accuracy while mitigating the security and compliance risks that come with poor data hygiene.Understanding the 6 dimensions of…

2024 roundup: Top data breach stories and industry trends

3 min read - With 2025 on the horizon, it’s important to reflect on the developments and various setbacks that happened in cybersecurity this past year. While there have been many improvements in security technologies and growing awareness of emerging cybersecurity threats, 2024 was also a hard reminder that the ongoing fight against cyber criminals is far from over.We've summarized this past year's top five data breach stories and industry trends, with key takeaways from each that organizations should note going into the following…

Black Friday chaos: The return of Gozi malware

4 min read - On November 29th, 2024, Black Friday, shoppers flooded online stores to grab the best deals of the year. But while consumers were busy filling their carts, cyber criminals were also seizing the opportunity to exploit the shopping frenzy. Our system detected a significant surge in Gozi malware activity, targeting financial institutions across North America. The Black Friday connection Black Friday creates an ideal environment for cyber criminals to thrive. The combination of skyrocketing transaction volumes, a surge in online activity…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today