Domain shadowing is a new type of attack. It is the latest evolution of online crime and is designed to compromise websites before security researchers and system administrators can react.
Cisco security researcher Nick Biasini reports that "massive" and ongoing attacks using Adobe Flash and Microsoft's Silverlight were launched in December, compared to the small sporadic campaigns of 2011. Here's his analysis:
“ Domain shadowing uses stolen registrant credentials, which is the most effective, difficult to block, technique used to date. The accounts are largely random, so there is no way to detect who will guess the next domain victim.
Furthermore, subdomains are very popular, short-lived, and random, with no discernible patterns. This makes blocking them increasingly difficult. Finally, research is hampered. It becomes progressively more difficult to obtain live samples from a page set up by an exploit kit, since it is active for less than an hour.”

Biasini says the attacks start with phishing emails purporting to come from the targeted registrar and are effective because most people don't regularly monitor their domain accounts.
Fast Flux versus Domain Shadowing is a new form of fast flux that keeps emerging exploits out of the sight of security researchers. Biasini calls it the new “industrialization of hacking.”
A third of the 10,000 fake domains in use come from GoDaddy.

The first series of subdomains is generally used to redirect victims to sub-level landing pages hosting the Angler exploit kit.
You can read more details about the new type of attack in the researcher's publication.
