GoDaddy shuts down 15k subdomains used in massive spam campaign

GoDaddy offices
Image Credit: GoDaddy

Web hosting provider and domain registrar GoDaddy has taken down over 15,000 subdomains following a two year investigation into a spam operation that tried to sell consumers fake products.

First users would receive a spam email promoting a product and if they happened to click on any of the links contained within the message, they would be sent to one of the fraudulent subdomains which were hosted on legitimate sites without their owner's knowledge.

All of the subdomains that were part of the scam shared one thing in common, they all sold products backed by fake endorsements from celebrities including Stephen Hawking, Jennifer Lopez, Gwen Stefani, Blake Shelton, Wolf Blitzer, the cast from Shark Tank and others.

In terms of the fake products being peddled on these scam subdomains, the majority were health-related such as CBD oil, weight loss pills and brain supplements.

Hacked GoDaddy accounts

The massive network of shady domains was first discovered by security researcher Jeff White at Palo Alto Networks two years ago and since then he has been collecting the spam emails sent out in the campaign and indexing the subdomain URLs promoting these fake products.

White shared his findings with GoDaddy earlier this year and the company then launched its own investigation into the matter in which it discovered that the group behind the scam had likely used either phishing or credential stuffing attacks to gain access to its customers' accounts.

After gaining access to a user's GoDaddy account, the cybercriminals would create a subdomain for their legitimate sites that would later be used to host shady product pages and lure users with spam email campaigns.

The web host has put the number of hacked accounts at “several hundred”. After taking down more than 15k subdomains from its servers, GoDaddy also reset the passwords for the accounts that had been compromised and notified the users that had been impacted.

In related web hosting news, ICANN, the organization which oversees the domain name system, has proposed an end to price caps on the .org, .info and .biz top-level domains. The move comes at a time when the domain name system has seen thousands of new extensions added over the past five years, all of which are free to set their own prices. If the change does go into effect, the cost of hosting a website could rise significantly over the next few years.

Via ZDNet

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
An American flag flying outside the US Capitol building against a blue sky
Mass federal layoffs will have “devastating impact on cybersecurity, former NSA cybersecurity director warns
A TV remote pointing at YouTube logo
YouTube warns of phishing video using its CEO as bait
China
Microsoft says Chinese Silk Typhoon hackers are targeting cloud and IT apps to steal business data
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
BadBox malware hit after infecting over 500,000 Android devices
Webex by Cisco banner on a Chromebook
Cisco warns some Webex users of worrying security flaw, so patch now
Red padlock open on electric circuits network dark red background
AI-powered cyber threats are becoming the biggest worry for businesses everywhere
Latest in News
An Nvidia GeForce RTX 5080 resting on an RTX 5090 on a gray crafting mat.
Corsair tells us only one of its prebuilt PCs with an RTX 5000 GPU has suffered from chip-level fault, suggesting it’s as rare as Nvidia claimed
ChatGPT WhatsApp
New survey suggests the vast majority of iPhone and Samsung Galaxy users find AI useless – and to be honest, I’m not surprised
A hunter holds up a Grav Bowfin and smiles
How to catch a Gravid Bowfin in Monster Hunter Wilds
Quordle on a smartphone held in a hand
Quordle hints and answers for Friday, March 7 (game #1138)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Friday, March 7 (game #369)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Friday, March 7 (game #635)