Hasty Hawk is a cybercriminal threat actor associated with large-scale phishing operations conducted through hijacked domains obtained via the DNS takeover technique commonly referred to as a Sitting Ducks attack. Active since at least March 2022, the actor has hijacked more than 200 domains and repurposed them for phishing infrastructure. Its campaigns have primarily impersonated DHL shipping pages and fraudulent donation sites themed around support for Ukraine. Hasty Hawk distributes malicious content through online advertising, including Google ads, as well as spam messaging, and uses a traffic distribution system to route victims to different landing pages based on geolocation and other user characteristics. The actor has also rotated hijacked domains between multiple campaign themes, indicating an adaptable and operationally mature phishing workflow. Infrastructure associated with these campaigns has included hosting on Russian IP space, but attribution to a specific state or country of origin is not established on that basis alone. Hasty Hawk is best characterized as a financially motivated phishing actor focused on spoofing, traffic redirection, and abuse of compromised domain reputation to increase the credibility and reach of fraudulent campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hasty Hawk hijacks domains for phishing campaigns, spoofing shipping and donation sites, and uses TDS and ad platforms for distribution, often hosting on Russian IPs.
Hasty Hawk leverages Sitting Ducks domain hijacking for widespread phishing campaigns, impersonating DHL shipping pages and fake donation sites supporting Ukraine.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.