National cybersecurity center issued an alert for ongoing DNS hijacking attack, a large-scale global campaign that targets various countries around the world.
NCSC recently observed various targeted attacks which exploit the Domain Name System (DNS) to deface or take down the websites and steal sensitive data.
DNS hijacking attack performs unauthorized alteration of DNS entries in a zone file on an authoritative DNS server or the modification of domain configurations in relation to a domain registrar.
The unauthorized alteration let attacker redirect the malicious traffic and compromise the victim Domain name system to obtain the data.
Due to the alteration of the DNS records, the organization will lose the complete control of the domain and threat actors will change the domain ownership details which is very hard to recover.
There are other dangerous risks involved by Hijacking the Domain Name System, in which DNS Hijacking campaign targeting various domains that belong to organizations, government, telecommunications, and internet infrastructure entities.
Once the attacker hijacks the DNS, they create a phishing website which is associated with the domain that organization familiar. later threat actors used it to phish the employee and gathering the sensitive information.
By abusing the domain-validated SSL certificates which is used to create the DNS records, the attack uses these certificate to create a phishing website and makes to looks like the more legitimate site and easily tricks victims to give away their personal data.
The attack could modify the domain zone entries such as “A” or “CNAME” records and replace with their own infrastructure records and point traffic to their own IP which is known as transparently proxying traffic that used to intercept the victim’s data.
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity updates also you can take the Best Cybersecurity course online to keep yourself updated.
Microsoft Teams users across the globe are experiencing significant disruptions in file-sharing capabilities due to…
Cloud computing has transformed the way organizations operate, offering unprecedented scalability, flexibility, and cost savings.…
Security awareness has become a critical component of organizational defense strategies, particularly as companies adopt…
Security researchers have unveiled a new malware process injection technique dubbed "Waiting Thread Hijacking" (WTH),…
The global regulatory landscape for cybersecurity is undergoing a seismic shift, with the European Union’s…
A sophisticated new malware suite targeting macOS, dubbed "PasivRobber," has been discovered by security researchers.…