July 17, 2019 By David Bisson 2 min read

The U.K. National Cyber Security Centre (NCSC) urged organizations to implement measures to mitigate the threat of DNS hijacking.

The agency published the alert after it discovered multiple attacks attempting to exploit the Domain Name System (DNS) over the last few months. One of the largest of these hijacking campaigns occurred in January, when threat actors compromised credentials to alter DNS records. This attack enabled the malefactors to redirect web traffic for commercial and government organizations worldwide, particularly those in the Middle East, to infrastructure under their control.

Following this campaign, NCSC witnessed several other attempts at DNS hijacking across multiple regions and sectors for the purpose of creating malicious DNS records, obtaining SSL certificates, conducting transparent proxying and/or hijacking domains. The tips in the agency’s report are meant to help organizations defend themselves against such attacks.

DNS Hijacking Activity Surges

NCSC’s disclosure came amid a surge of DNS hijacking activity. In November 2018, Cisco Talos detected an attack campaign in which bad actors used malware called DNSpionage to redirect traffic going to Lebanon and the United Arab Emirates (UAE) using .gov domains, as well as a Lebanese airline company.

Several months later, IXIA observed a DNS hijacking campaign that exploited consumer-grade routers to skim user input data for PayPal, Netflix, Gmail and Uber. Cisco Talos spotted the Sea Turtle threat actor updating its own hijacking campaigns with new infrastructure earlier this month, and Avast recently detected close to 200,000 hijacking attempts targeting Brazilians since February 2019.

Mitigate the Threat of DNS Hijacking

Security professionals can help defend their organizations against DNS hijacking by monitoring access to web applications and authentication logs for web traffic that could be coming from a single or small pool of web-facing IP addresses. It’s also critical to prioritize vulnerability remediation by gaining insight into all assets and components used in the network.

More from

We are moving!

< 1 min read - SecurityIntelligence.com is being sunset, but have no fear!We have a new home for all of your favorite security and X-Force content.Follow us to www.ibm.com/think to maintain access to the stories and news you love, both new and old.Security Intelligence will officially sunset on Friday, March 28, 2025. To access the latest security thought leadership, go here. To access the latest X-Force research, go here.If you are experiencing cybersecurity issues or an incident, contact X-Force® to help:US hotline: 1-888-241-9812 | Global hotline:…

Bypassing Windows Defender Application Control with Loki C2

10 min read - Windows Defender Application Control (WDAC) is a security solution that restricts execution to trusted software. Since it is classified as a security boundary, Microsoft offers bug bounty payouts for qualifying bypasses, making it an active and competitive field of research.Typical outcomes of a WDAC bypass bug bounty submission:Bypass is fixed; possible bounty awardedBypass is not fixed but instead "mitigated" by being added to the WDAC recommended block list. Likely no bounty awarded but honorable mention is typically givenBypass is not…

FYSA — VMware Critical Vulnerabilities Patched

< 1 min read - SummaryBroadcom has released a security bulletin, VMSA-2025-0004, addressing and remediating three vulnerabilities that, if exploited, could lead to system compromise. Products affected include vCenter Server, vRealize Operations Manager, and vCloud Director.Threat TopographyThreat Type: Critical VulnerabilitiesIndustry: VirtualizationGeolocation: GlobalOverviewX-Force Incident Command is monitoring activity surrounding Broadcom’s Security Bulletin (VMSA-2025-0004) for three potentially critical vulnerabilities in VMware products. These vulnerabilities, identified as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, have reportedly been exploited in attacks. X-Force has not been able to validate those claims. The vulnerabilities…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today