Infoblox researchers reported that a large-scale scam push-notification operation targeting primarily Android Chrome users was partially exposed after the threat actor made a DNS configuration error that left domains in a lame delegation state (a “Sitting Ducks” condition). By legitimately re-claiming an abandoned actor-controlled domain at its DNS provider—without accessing victim devices or the attacker’s servers—the researchers redirected notification and tracking traffic to infrastructure they controlled, gaining a live view of the criminal ecosystem behind the deceptive browser-notification spam.
Telemetry collected from victim browsers included rich JSON-style request data (e.g., device and locale details, lure text, and click behavior) and showed sustained, high-volume abuse: users could receive 100–140+ notifications per day for extended periods, with lures ranging from fake security alerts to gambling and adult content. Reporting indicates the researchers expanded collection from a single domain to nearly 120 domains, capturing tens of millions of records (including a cited figure of ~57 million logs over two weeks) and observing global activity across 60+ languages, with traffic heavily concentrated in South Asia (notably Bangladesh, India, Indonesia, and Pakistan).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Infoblox disclosed its findings on the large-scale push-notification scam network, including its low estimated monetization, heavy concentration of victims in South Asia, and abuse of dormant domains through 'Sitting Ducks' conditions. The report warned organizations to maintain DNS hygiene to reduce the risk of domain takeover.
Over a period described as several days to two weeks, the researchers gathered more than 57 million log records from thousands of victim devices, with peak collection around 30 MB per second. The telemetry showed victims receiving roughly 140 deceptive notifications per day on average and provided insight into the campaign's global reach and tactics.
Infoblox researchers legitimately reclaimed the misconfigured domain through the DNS provider and pointed it to infrastructure they controlled. Without altering victim devices or interacting with attacker systems, they were able to passively receive traffic intended for the scam operation.
One of the actor's domains was abandoned but retained active name server delegation, creating a 'Sitting Ducks' or lame-delegation takeover condition. This DNS hygiene failure allowed the domain to stop resolving normally while still presenting an opportunity for third-party re-registration and control.
A malvertising operation used deceptive websites to trick users, primarily Android Chrome users, into granting browser notification permissions. The campaign then sent fake security alerts, gambling lures, financial-brand impersonations, celebrity/news scams, and adult-content messages in more than 60 languages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.