HomeSecurityGoDaddy: Web hosting provider downloaded 15,000 fake subdomains

GoDaddy: Web hosting provider downloaded 15,000 fake subdomains

provider Web hosting and domain registrar , GoDaddy , has taken down over 15,000 subdomains after a two-year investigation into a spam business that was trying to sell fake products.

Initially, users would receive a spam email promoting a product and if they clicked on any of the links contained in the message, they would be sent to one of the malicious subdomains hosted on legitimate websites without the knowledge of their owner.

All of the subdomains that were part of the scam shared one common element, they all sold products with fake endorsements from celebrities such as Stephen Hawking, Jennifer Lopez, Gwen Stefani, Blake Shelton, Wolf Blitzer, and others.

Regarding the fake products sold on these subdomains, the majority are health-related, such as CBD oil, weight loss pills, and dietary supplements.

GoDaddy

Attack investigation

The malicious scam operation was first discovered by security researcher Jeff White at Palo Alto Networks two years ago and since then he has been collecting the spam messages being sent and researching the URLs of the subdomains promoting these fake products.

After publishing the results of its investigation, GoDaddy launched its own investigation, discovering that the hackers behind the malicious actions used phishing or credential stuffing attacks to gain access to victims' accounts.

After gaining access to a user's GoDaddy account, cybercriminals will create a subdomain for their legitimate websites, which will later be used to host malicious pages to which they will lure users through spam email campaigns.

GoDaddy also reset the passwords for the accounts that had been compromised.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS