Target Industry

Hazy Hawk targets a wide range of sectors including government agencies, education, healthcare, and non-profit organisations.

Overview

The threat actor group, Hazy Hawk, has been exploiting gaps in Domain Name System (DNS) records since December 2023. It has targeted large organisations such as Deloitte, Panasonic, and PricewaterhouseCoopers (PwC). 

Impact

The impact of DNS hijacking on organisations can be quite significant. Hijacked domains can be used to distribute malware, phishing attacks, and other malicious activities, compromising the security of the targeted organisations. This can lead to a loss of trust among customers and partners due to the hosting of malicious content. 

Exploitation

DNS hijacking is a serious threat that can redirect users to malicious sites. Threat actors may install malware on a user’s computer to change local DNS settings or exploit routers with default passwords to alter DNS settings for all connected users. 

Man-in-the-middle attacks involve intercepting communication between a user and a DNS server, while rogue DNS servers involve hacking a DNS server to change its records. These methods can lead to phishing attacks, malware distribution, and other malicious activities, severely compromising the security of targeted organisations.  

Indicators of Compromise

InfoBox has provided a GitHub page which lists the malicious domains used by Hazy Hawk 

Containment, Mitigations & Remediations

It is highly recommended to implement DNS over HTTPS (DoH) or DNS over TLS (DoT) to encrypt DNS queries and responses, preventing interception and manipulation. Opt for a DNS provider that offers robust security features, such as Domain Name System Security Extensions (DNSSEC), which adds an extra layer of authentication to DNS responses. Regularly review DNS logs for unusual or suspicious activity. 

Threat Landscape

The DNS threat landscape is evolving rapidly, with various types of attacks becoming more sophisticated and widespread. This has been due to poor management of DNS records, such as not regularly updating or removing obsolete records. 

Threat Group

Hazy Hawk is a sophisticated cybercrime group identified by Infoblox. It has been active since at least December 2023 and is known for hijacking abandoned cloud resources, such as Amazon S3 buckets and Azure endpoints, by exploiting DNS misconfigurations. 

The exact location of the Hazy Hawk cybercrime group is not publicly known. It operates globally, targeting organisations across various countries, including the United States, Australia, and several in Europe. 

Further Information

Infoblox report 

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content