Domain shadowing is an attack technique where threat actors compromise a legitimate domain's DNS server and secretly insert malicious records to redirect traffic for phishing, malware distribution, data exfiltration, or command-and-control operations. By piggybacking on a trusted domain, attackers make malicious activity appear credible and avoid detection.
Domain Shadowing
Another way that we could trick end users is through something called domain shadowing. It's a way that we can get away with a little bit more using a legitimate domain.
Let's develop a little scenario here. Let's say we have this machine right here that has a user on it, and we're trying to trick them to go to a site, and our site that we chose was malware.com. Now, this is obviously problematic, because why would they click on a link going to there? Why would they ever go to something called malware rs.com? We need to figure out some sort of domain that looks a little more legitimate, or if we could find a legitimate domain and actually have some control over it, then that would actually be an ideal situation. That's what domain shadowing is.
Let's say we happen to compromise one of Microsoft's servers. In fact, it's their DNS server, so we're in charge of their DNS server. What we're going to do, rather than do something really bad with the server and bring it down and cause all sorts of problems to Microsoft, but only for a very short period of time because they will get it back up and running quickly and figure out their security hole and then patch it, is we could really leverage this domain to our advantage.
We could create some records on their DNS server that point to our resources, and then when we're pointing to those resources, it looks much more legitimate, and we do it stealthily. We do it in the shadow. We do it in a way that they don't see that we've made some sort of alteration, so it looks very normal.
You can imagine Microsoft's DNS servers have a ton of records, so to go in there and sneak one in there might go unnoticed. Not with Microsoft, because they've got lots of software and stuff that monitors for that thing. But that's what we're learning to do, right, the defense side of this? That's why we're learning the offense side.
But anyway, this is the scenario of domain shadowing, where we sneak a record into there and use somebody else's domain for our purposes. We could be using this to send out phishing emails, or maybe they have links to some sort of malware distributions, or perhaps it's to carry out some sort of data exfiltration or command and control.
Here's the attack card on domain shadowing. That's when we're using some sort of legitimate DNS server, but we are using it for illegitimate purposes. We're sneaking some sort of records in there to go undetected, and we're using it for one of many different things, to carry out whatever kind of malicious activity that we want to carry out.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →