Azure DNS Zone Hijacking

Last Updated: 2026-08-24T14:18:04Z

What’s Happening

Attackers are hijacking subdomains by creating Azure DNS Zones for domains that were previously delegated to Azure & not properly decommissioned. This is made possible by Azure not having an authorization check on creating Public DNS Zones. Abuse requires a misconfiguration & has been ongoing since ~2018 at least.

Actions

Establish proper DNS lifecycle management. Ensure you remove unneeded NS records. Check for domain resolution to uncommon AS. Some IPs from a specific case below.

Notes

This is me using some IoCs to excuse me posting “TIL” about something that bit us (and a couple other companies by the looks of it). Chances are the old-heads already know this.

Situation: Previously a subdomain of ours was delegate to Azure. This domain was (partially) decommissioned in 2025, with the Azure DNS Zone being removed but the NS record pointing to Azure DNS servers remaining active. April 2026 new A records were set up pointing to AS 212238 IPs, hosting what appears to be a Thai language gambling ad. We strongly believe this was made possible by the attacker… just creating a new Public DNS Zone in Azure in their own Tenant (Tutorial: Host your domain in Azure DNS | Microsoft Learn). The one tricky part is obtaining a zone with matching nameservers as these are chosen somewhat randomly by Azure, we don’t know how this was achieved in this case.

Checking our TI providers IP lookup we are (by far) not the only “customer” on the IPs below, unfortunately I can’t properly export the list for sharing, maybe one of the DNS wizards here has the ability to do so - we are talking a couple hundred domains dating back to sometimes 2018.

While we didn’t do a full analysis on potential malicious behaviour by the hosted site (e.g. cookie extraction for parent domains, clickfix, …) I included the other domains it contacted in our sandboxes in the IoCs. I’ll also include an example or two for other domains where this is still live.

Credit for detecting the original issue that sparked the investigation & reporting it to our VDP to Teun van der Ploeg.

IoCs:

A records post compromise:
86.38.247[.]29
209.92.170[.]22

Other domains used by the loaded page:
cdn.stillsunday[.]pl
www.bigc.co[.]th
appbox.z28akc6bv4[.]com
st.bigc-cs[.]com

Sample "live" cases:
welcome-to-mikalai-world3.labs.vocovo[.]com
new.fly.myvegas[.]com
1 Like

Wild! So this is similar to subdomain hijacking, but for Azure itself?

It’s a sort of subdomain hijacking, but using leftover NS records instead of CNAME/A/AAAA records? It’s a little more powerful as it allows the attacker to actually make changes in the zone but in the ends it’s the same issue.

Obvious disclaimer: We can’t prove this is exactly what happened as we do not have visibility on the Azure tenant of the attacker, but we had multiple folx here come to the same conclusion & it matches the documentation.

1 Like

@neurovagrant was kind enough to help me out with some historical DNS data so we now have an at least partial list of organisations impacted. I’ll include the list of identified likely-hijacked zones below - the full list of domains is too large to share here, even as an attachment (lol, 600k+ domains), but you can find it over on my server: https://files.nyanbinary.de/misc/rdns.json

admin.countrywidehomes.ca
horus.vumacam.co.za
club.mutual.club
testing.direct.id
test.auditing.docuware.cloud
dxp.cue.cloud
portal.salama.ae
azure-pub.onedata.de
eisblock.deepshore.de
poc.intershop.de
op.ohb-ds.de
certify.hbt.de
robin.assfinet.de
cluster.conplement.de
workshop.appsfactory.de
pentest.app.better.care
dimension.nsva.se
infralab.sdc.se
int.levler.se
tanzu.moussaud.org
websiteone.agileventures.org
rc.applefcu.org
mig1.indigita.ch
cbdc-sandbox.industria.tech
ssai.ssajiopre-0.serverside.ai
ssai.stage2.serverside.ai
adt.datamole.ai
stlouis.saas.autonomize.ai
outlook-timesheet.taitotalo.fi
consul2.nerd.dk
chipper.nuuday.dk
mecoms-accept-ukz-meep.coronaenergy.co.uk
azure.mckinsey.digital
carrefour-foodlovers.robotkittens.nl
prod.medme.pl
devtest.betterspace360.com
webmail.ox2.com
dev.stack8.com
dmp.andea.com
email.bemea.com
ctcue.solutions.iqvia.com
2021seramagique.lanla.com
2021willbemagical.lanla.com
a8.styla.com
capex.ccorpusa.com
qa-001.altitude.telemedicineclinic.com
sdge.olivineinc.com
az.iwsinc.com
cloud.integration.imos3d.com
prototypes.bliksund.com
oas.wirecard.com
dev.cloud.onguard.com
bi-staging.beyondtrustcloud.com
vcenter.northwestcraneservice.com
deming.dev.ussc.spacee.com
legacyapis.dev.brasfieldgorrie.com
frc.rsmeansonline.com
adesso.gianmarcoleone.com
auth.endosnipe.com
test.doctorcareanywhere.com
azure.shardsecure.com
openshift.synpulse.com
edcm-dev-minio.theglue.com
test.autovinlive.com
hermes.cerberusinteractive.com
nexus-infradev.objective.com
az.macheye.com
sign.petroyag.com
clapp.rohlig.com
azure.pitang.com
test.scanreach.com
adinsure.adacta-fintech.com
azure.stanusch.com
beta.maxuc.metaswitch.com
files.gvenglish.com
stage.seismicai.com
confused-test.peppercornai.com
dev-azure.ibi.com
xx.cfs.ci-aldi.com
uat.askdelphi.com
adaptive.thezishi.com
training.nectari.com
training.consulcesi.com
itsm.consulcesi.com
staging.campaigntrack.com
cloud.amrock.com
powerhub.sunrock.com
perks.sonatabank.com
rbsd8s.veripark.com
abc-test.bosframework.com
ats.prideglobal.com
apps.ahsresidential.com
skillsrating.cefriel.com
hellopnt.shell.com
svhyperautoazt.shell.com
losgozos.fundacioncajasol.com
relationclients.123-im.com
az.jessicadeen.com
nordic.seagen.com
acme-test.intven.com
asev3.spenn.com
test1.complion.com
nps1.phillipsedison.com
prototype.bluetown.com
test.scanreco.com
cloud-test.detego.com
prod.mhp.m2.branderstudio.com
az.osano.com
devz31o9.xmpro.com
labs.vocovo.com
test.aservo.com
k8s-az.ai2-jp.com
ditb.jems-group.com
seats.aerq.com
demo02.campminder.com
sandbox.campminder.com
pim.bestseller.com
cl-0f323225.classter.com
auth.prod.docdigitizer.com
tmp.cfaas.com
fly.myvegas.com
bit.comitas.com
example.ruilopes.com
vpp.acc.enervalis.com
mg-test.condatis.com
iscloud.dexis.com
dev.teklinks.com
poc.axiossystems.com
mps.mecoms.com
hbs-stg.hiqo-solutions.com
sodexo.sprylabprojects.com
use.efleets.com
kube-azure.testingxperts.com
dev.mirasys.com
silver.sit.manage.equisoft.com
titan.ipxretirement.com
cloud.qrypt.com
*.azure.pharmagest.com
dc.ramquest.com
internet.allwest.com
dev.nvacommunity.com
dqplus.data3sixty.com
aml.fincom.co
cost.blueticks.co
qrex.athena.io
meta.ptc.io
bt.redbird.io
ontic.newknowledge.io
27-9.client.aifi.io
datamarketplace.thalesdigital.io
knowledgemanagement.thalesdigital.io
mb.festool.io
sharp.festool.io
v2.dsapp.io
staging2.spiderads.io
gitpod.oediv.io
streaming.yom.ooo
login.filbo.ro
m4.evp-perf.midokura.jp
demo01.sukurire.jp
retail-cloud.sato.co.jp
corp.sollio.coop
digitalservices.msg.group
som.radixeng.com.br
confraria.fastacai.com.br
influencers.editorasanar.com.br
dev.taggy.com.br
az.scalair.fr
dev.dream.jobs
rdl.cinnamon.is
v2.kigadu.at
evodmhub.rmplc.net
meelabs.ksc.net
ise.citymd.net
azr.tgscloud.net
zone2.frontdeskanywhere.net
wald.jellyfish.net
international.jellyfish.net
sg5.serverssh.net
o365.phoneappli.net
misttraingirls.johren.net
demo.caspeco.net
sandbox.netatmo.net
demo.sympahr.net
voice.tls.net
dt.swiftlycontent.net
azcc.observabilities.k8s.iqmetrix.net
testenv2.printix.net
tpa.allpay.net
stg.allpay.net
ug-msdn.unitymsp.it
videogw.arrb.com.au
inchid.subarumelbourne.com.au
dev.swoopfunding.com.au
staging.automation.ai.shk.com.au
members.stonier.com.au
mail.colyirr.com.au
members.bayoffireswines.com.au
members.brooklandvalley.com.au
cs.evoenergy.com.au
www1.utc.edu.au
app.ventumair.eu
europarl.connectedviews.eu

Most of these are still up (as in: DNS is still hijacked) though we have a few sites that don’t show the same Thai gambling template. Additionally, while crawling the identified sites I ran across another few domains on other IPs that are linked & host similar content (I’m only including new domains that are still up here - a lot of the new ones are already down or were never live):

jpcm.clan.pe -> 38.247.64.220
fadi.it.com -> 38.127.8.49

Which in return can yield us a long list of domains and …

I’ll stop the rabbit hole here for now & would explicitly ask y’all if anyone has a good idea what to do here: Taking down these instances (either on Azure level or on IP level) is something MS & the hoster can do, but unfortunately, unlike normal Subdomain Hijacking, this doesn’t resolve the issue, this can only be done by MS actually implementing proof-of-ownership for DNS Zone creation or the owning org cleaning up their dangling NS records. I’m reaching out to a few orgs (.de & Beyondtrust) but I don’t have high hopes that even they’ll all respond…