July 17, 2019 By David Bisson 2 min read

The U.K. National Cyber Security Centre (NCSC) urged organizations to implement measures to mitigate the threat of DNS hijacking.

The agency published the alert after it discovered multiple attacks attempting to exploit the Domain Name System (DNS) over the last few months. One of the largest of these hijacking campaigns occurred in January, when threat actors compromised credentials to alter DNS records. This attack enabled the malefactors to redirect web traffic for commercial and government organizations worldwide, particularly those in the Middle East, to infrastructure under their control.

Following this campaign, NCSC witnessed several other attempts at DNS hijacking across multiple regions and sectors for the purpose of creating malicious DNS records, obtaining SSL certificates, conducting transparent proxying and/or hijacking domains. The tips in the agency’s report are meant to help organizations defend themselves against such attacks.

DNS Hijacking Activity Surges

NCSC’s disclosure came amid a surge of DNS hijacking activity. In November 2018, Cisco Talos detected an attack campaign in which bad actors used malware called DNSpionage to redirect traffic going to Lebanon and the United Arab Emirates (UAE) using .gov domains, as well as a Lebanese airline company.

Several months later, IXIA observed a DNS hijacking campaign that exploited consumer-grade routers to skim user input data for PayPal, Netflix, Gmail and Uber. Cisco Talos spotted the Sea Turtle threat actor updating its own hijacking campaigns with new infrastructure earlier this month, and Avast recently detected close to 200,000 hijacking attempts targeting Brazilians since February 2019.

Mitigate the Threat of DNS Hijacking

Security professionals can help defend their organizations against DNS hijacking by monitoring access to web applications and authentication logs for web traffic that could be coming from a single or small pool of web-facing IP addresses. It’s also critical to prioritize vulnerability remediation by gaining insight into all assets and components used in the network.

More from

Exploiting GOG Galaxy XPC service for privilege escalation in macOS

7 min read - Being part of the Adversary Services team at IBM, it is important to keep your skills up to date and learn new things constantly. macOS security was one field where I decided to put more effort this year to further improve my exploitation and operation skills in macOS environments. During my research, I decided to try and discover vulnerabilities in software that I had pre-installed on my laptop, which resulted in the discovery of this vulnerability. In this article, I…

Taking the complexity out of identity solutions for hybrid environments

4 min read - For the past two decades, businesses have been making significant investments to consolidate their identity and access management (IAM) platforms and directories to manage user identities in one place. However, the hybrid nature of the cloud has led many to realize that this ultimate goal is a fantasy. Instead, businesses must learn how to consistently and effectively manage user identities across multiple IAM platforms and directories. As cloud migration and digital transformation accelerate at a dizzying pace, enterprises are left…

IBM identifies zero-day vulnerability in Zyxel NAS devices

12 min read - While investigating CVE-2023-27992, a vulnerability affecting Zyxel network-attached storage (NAS) devices, the IBM X-Force uncovered two new flaws, which when used together, allow for pre-authenticated remote code execution. Zyxel NAS devices are typically used by consumers as cloud storage devices for homes or small to medium-sized businesses. When used together, the flaws X-Force discovered allow a remote attacker to execute arbitrary code on the device with superuser permissions and without requiring any credentials. This results in complete control over the…

What cybersecurity pros can learn from first responders

4 min read - Though they may initially seem very different, there are some compelling similarities between cybersecurity professionals and traditional first responders like police and EMTs. After all, in a world where a cyberattack on critical infrastructure could cause untold damage and harm, cyber responders must be ready for anything. But are they actually prepared? Compared to the readiness of traditional first responders, how do cybersecurity professionals in incident response stand up? Let’s dig deeper into whether the same sense of urgency exists…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today