Criminals are spending millions on malicious domains — and it's paying off for them in a big way

A computer being guarded by cybersecurity.
(Image credit: iStock)

To host command and control (C2) servers, distribute malware, or perform other malicious activities, hackers need a domain name. They can automate the process of obtaining domain names with a Domain Generation Algorithm (DGA). However, to actually be able to use these domains, they also need to register them with a domain registrar. 

To do that, one group of hackers started using Registered Domain Generation Algorithms (RDGAs), which appears, unfortunately, to be working.

Cybersecurity researchers from Infoblox Threat Intel reported a threat actor dubbed Revolver Rabbit has registered over 500,000 domains this way - which would have required them to invest at least a million dollars, which is quite the sum of money.

A profitable endeavor

The hacker used the RDGA to create command and control (C2) and decoy domains for the XLoader infostealing malware.

XLoader is a versatile and potent piece of malware that serves multiple functions, including data theft, credential stealing, and functioning as a remote access Trojan (RAT). It is an evolution of the notorious FormBook malware, which was also known for its information-stealing capabilities. XLoader has been used in various cybercriminal campaigns, often targeting both Windows and macOS platforms.

“It must be a profitable malware for Revolver Rabbit given their investment in domain names” the researchers said. “Connecting the Revolver Rabbit RDGA to an established malware after months of tracking highlights the importance of understanding RDGAs as a technique within the threat actor’s toolbox.”

Infoblox’s report concluded that RDGAs are a “formidable and underestimated” threat. By using the novel technique, threat actors can easily scale their spam, malware, and scam operations, most of the time flying below the cybersecurity industry’s radars. In fact, Infoblox regularly discovers “tens of thousands of new domains”, which are then captured into clusters of actor-controlled assets. 

Most of these domains, the researchers claim, go unnoticed by the security industry. Revolver Rabbit’s activity was ongoing for almost a year and it wasn’t flagged for being malicious.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
WordPress on a laptop
Over 20,000 WordPress sites hit by damaging malware campaign
A person at a laptop with a cybersecure lock symbol floating above it.
Cybercrime gang targets victims with "triple threat" attacks
Ransomware
Researchers hijack thousands of backdoors thanks to expired domains
Criminals are abusing top-level government domains across multiple countries
Flags of Iran, China, Russia and North Korea on a wall. China North Korea Iran Russia alliance
Cybercrime is helping fund rogue nations across the world - and it's only going to get worse, Google warns
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Cisco, ASUS, QNAP, and Synology devices hijacked to major botnet
Latest in Security
NHS
NHS IT supplier hit with major fine following ransomware attack
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Latest in News
Screenshot from action RPG soulslike Lies of P
Lies of P Overture won't elaborate on the game's eyebrow-raising post-credits twist, and I think that's good news
Nintendo Switch 2
The Switch 2 launching with a Mario Kart game 'is very unlike Nintendo' compared to the original Switch releasing with Breath of the Wild, says former marketing leads: 'That's what's gonna make you want to buy the new hardware'
Waze voice control
Waze is ditching Google Assistant for Gemini on iOS, and for good reasons
Apple Watch Ultra 2 displaying a step count and distance
Using a smartwatch could be a game-changer for people with diabetes, new research suggests
Focal Bathys MG
Focal just upgraded its audiophile noise-cancelling wireless headphones with even better sound, better noise cancelling, and a way higher price
A PC gamer celebrating, sat in a gaming chair in front of a monitor
Windows 11’s Game Bar gets a fresh coat of paint, plus a tweak to work better on handhelds – and I like the direction Microsoft’s heading in here