Story perspectives
70,000 Domains Exploited by Threat Actors: Security Alert
9/30/2025
34 5
1 of 1
Story summary
- Silent Push identified 70,000+ domains offering subdomain rental services exploited by threat actors.
- Dynamic DNS providers lack oversight, enabling anonymous registrations and minimal regulatory constraints.
- Advanced Persistent Threat groups, including APT28 and APT29, use DDNS for C2.
- Attackers exploit DDNS for resilient infrastructure using domain generation algorithms.
- Organizations should monitor DDNS, block abuse, and strengthen security hygiene.
