Target Industry
Hazy Hawk targets a wide range of sectors including government agencies, education, healthcare, and non-profit organisations.
Overview
The threat actor group, Hazy Hawk, has been exploiting gaps in Domain Name System (DNS) records since December 2023. It has targeted large organisations such as Deloitte, Panasonic, and PricewaterhouseCoopers (PwC).
Impact
The impact of DNS hijacking on organisations can be quite significant. Hijacked domains can be used to distribute malware, phishing attacks, and other malicious activities, compromising the security of the targeted organisations. This can lead to a loss of trust among customers and partners due to the hosting of malicious content.
Exploitation
DNS hijacking is a serious threat that can redirect users to malicious sites. Threat actors may install malware on a user’s computer to change local DNS settings or exploit routers with default passwords to alter DNS settings for all connected users.
Man-in-the-middle attacks involve intercepting communication between a user and a DNS server, while rogue DNS servers involve hacking a DNS server to change its records. These methods can lead to phishing attacks, malware distribution, and other malicious activities, severely compromising the security of targeted organisations.
Indicators of Compromise
InfoBox has provided a GitHub page which lists the malicious domains used by Hazy Hawk.
Containment, Mitigations & Remediations
It is highly recommended to implement DNS over HTTPS (DoH) or DNS over TLS (DoT) to encrypt DNS queries and responses, preventing interception and manipulation. Opt for a DNS provider that offers robust security features, such as Domain Name System Security Extensions (DNSSEC), which adds an extra layer of authentication to DNS responses. Regularly review DNS logs for unusual or suspicious activity.
Threat Landscape
The DNS threat landscape is evolving rapidly, with various types of attacks becoming more sophisticated and widespread. This has been due to poor management of DNS records, such as not regularly updating or removing obsolete records.
Threat Group
Hazy Hawk is a sophisticated cybercrime group identified by Infoblox. It has been active since at least December 2023 and is known for hijacking abandoned cloud resources, such as Amazon S3 buckets and Azure endpoints, by exploiting DNS misconfigurations.
The exact location of the Hazy Hawk cybercrime group is not publicly known. It operates globally, targeting organisations across various countries, including the United States, Australia, and several in Europe.
Further Information













