Hazy Hawk is a financially motivated threat actor known for hijacking abandoned or unclaimed cloud resources by exploiting DNS misconfigurations, particularly dangling CNAME records, to take control of subdomains associated with legitimate organizations. The actor abuses these reclaimed subdomains to host scams and other malicious content, leveraging the residual trust of victim brands and infrastructure. This activity reflects a tradecraft focus on opportunistic initial access through cloud and DNS hygiene failures rather than malware-heavy intrusion chains. Hazy Hawk’s operations are characterized by reconnaissance for misconfigured internet-facing assets, takeover of cloud-linked resources that have been deprovisioned by their owners, and subsequent abuse of the compromised web presence for fraud and malicious distribution. The actor is publicly tracked under the name Hazy Hawk.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Hijacks abandoned cloud resources via DNS misconfigurations to repurpose high-profile domains for scam/malware delivery through TDS infrastructure.
DNS/dangling-CNAME hijacking of abandoned cloud resources to take over trusted subdomains and monetize via scams/malvertising/push-notification abuse.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.