Horrid Hawk is a cybercriminal DNS-focused threat actor associated with the large-scale "Sitting Ducks" domain hijacking attack vector. Active since at least February 2023, the actor hijacks vulnerable domains and repurposes them throughout the full fraud chain, including lure delivery, redirection, and scam hosting. Horrid Hawk is primarily linked to investment fraud operations rather than malware deployment or ransomware activity. The actor is notable for systematically abusing hijacked domains to lend legitimacy to fraudulent investment-themed campaigns. Its lures have included fabricated government investment programs and summit-related themes designed to appear credible to targets. Distribution has relied heavily on short-lived social media advertising, especially Facebook ads, with campaigns localized in more than 30 languages and aimed at victims across multiple continents, indicating broad international targeting and operational scalability. Horrid Hawk is one of several criminal clusters exploiting DNS misconfigurations and weak domain delegation controls to seize control of third-party domains. Within this ecosystem, the actor stands out for monetizing hijacked infrastructure through fraud and spoofing rather than through malware delivery or traffic distribution services. The available reporting supports a financially motivated profile centered on initial access via domain hijacking, defense evasion through use of trusted hijacked domains, and follow-on spoofing and scam operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Horrid Hawk hijacks domains to run global investment fraud campaigns, using convincing lures and Facebook ads in multiple languages.
Horrid Hawk is a criminal group involved in DNS hijacking attacks, using compromised domains to run investment scams.
Horrid Hawk uses Sitting Ducks domain hijacking to conduct investment fraud schemes, distributing hijacked domains through short-lived Facebook ads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.