Guardio Labs uncovers a sprawling campaign of subdomain hijacking, compromising over 8,000 domains from respected brands. The campaign, known as SubdoMailing, leverages the credibility of these domains to send millions of malicious emails daily. The report highlights the scale of the issue and calls for enhanced domain security.
Table of contents
“SubdoMailing” — Thousands of Hijacked Major-Brand Subdomains Found Bombarding Users With Millions of Malicious EmailsThousands of Hijacked Domains — and Counting!How a Clearly Scammy Email Passed Spam FiltersResurrecting 2001 Martha Stewart’s SweepstakesClassic Subdomain Hijacking DangerSPF-Takeover — Another Tactic UncoveredFrom Subdomain Hijacking to Mass “SubdoMailing”“ResurrecAds” Threat Actor — UncoveredTracking IOCs and Connecting Loose EndsSubdoMailing — In NumbersSort: