Think about everything you’d normally protect to keep a domain from being hijacked. The registrar login. Two-factor on that account. The registrar lock that blocks transfers. Email on the account’s recovery address. For most people that list is domain security, and it’s built around one assumption: to steal a domain, an attacker has to get into the place where the domain lives.
The Sitting Ducks attack doesn’t bother with any of that. It never logs into your registrar, never changes your nameserver records, never touches your account. When it’s done, the registrar shows exactly what it showed yesterday — same owner, same nameservers, lock still on. And the attacker is serving whatever DNS records they like for your domain, to the whole internet.
How you take a domain you don’t own
A domain’s nameserver (NS) records at the registrar say who answers DNS questions for that name. They don’t contain the answers; they name the provider that holds them. So example.com might have NS records pointing at a managed DNS provider — ns1.somednsprovider.net and friends — and that provider holds the zone with the actual A records, MX records, and so on.
That delegation has a failure mode with a name: lame delegation. It’s when the nameservers listed for a domain don’t actually have the zone. The NS records say “ask this provider,” you ask the provider, and the provider shrugs — it has no configuration for that name. This happens constantly and boringly: someone spins up DNS hosting on a free trial, points their domain at it, the trial lapses and the zone gets deleted — but the NS records at the registrar still point at that provider. Or a company migrates DNS and removes the old zone but forgets to update the delegation. The domain half-works or quietly breaks, nobody files a ticket, and the pointer sits there dangling.
Now add the second ingredient. Some DNS providers let you create a zone for any domain name on a fresh account without proving you own it. You sign up, you type in example.com, and the service happily starts serving DNS for it — because from the provider’s point of view you’re just another customer configuring a zone. It never asks whether the NS records out in the world actually point back at them, or whether you’re the person who registered the name.
Put those two together and the attack writes itself. The attacker finds a domain whose NS records point at an exploitable provider but whose zone no longer exists there. They open an account at that provider, claim the zone, and fill it in. The NS records at the registrar never move — they already pointed at this provider. The provider was told to answer for the domain years ago and never stopped. The attacker just supplied the answers. From that moment they control where the name resolves, what server the web traffic hits, where the mail goes.
The elegance, if you can stomach calling it that, is that nothing on the victim’s side changes in any place the victim looks. The registrar is pristine. The WHOIS/RDAP record is pristine. There was no login, no transfer, no password reset email. The only thing that changed is the contents of a zone at a third party the owner probably forgot they were still delegated to.
This bug is older than a lot of people’s careers
The uncomfortable part isn’t that this is clever. It’s that it’s old. The attack class was first laid out by the security researcher Matthew Bryant in 2016, in work he called “The Orphaned Internet” — he showed you could take over roughly 120,000 domains by registering the right accounts at major cloud and DNS providers. That was not a quiet disclosure. It named the providers. It did the math.
Eight years later, at the end of July 2024, Infoblox and Eclypsium published a joint write-up and gave the technique the name that stuck: Sitting Ducks. Their numbers are the kind you read twice. An estimated million-plus registered domains exploitable at any given time, and tens of thousands already hijacked since 2019. In a November 2024 follow-up, Infoblox reported finding nearly 800,000 vulnerable domains over three months, of which roughly nine percent — about 70,000 — were subsequently hijacked. And the hijacking wasn’t new; Infoblox says criminals have used the method since 2018.
Between 2016 and 2024, the fix was understood and the vulnerable providers were named, and the attackable population didn’t shrink — by 2024 it was estimated at around a million. That gap is the actual story. A vulnerability that requires no exploit code, affects a million names, and sits unfixed for eight years is not a technical problem anymore. It’s an incentives problem. The domain owner doesn’t know they’re exposed. The DNS provider isn’t the one that gets robbed. The registrar’s records look fine. Everybody’s dashboard is green, and the duck is still sitting there.
Who’s been doing it, and what for
These aren’t theoretical hijacks collecting dust in a paper. Infoblox tracks a roster of actors who live on this technique. Vacant Viper has hijacked an estimated 2,500 domains a year since December 2019, feeding them into a traffic distribution system that pushes spam, serves malware families like DarkGate and AsyncRAT, and stands up command-and-control for remote access trojans. Horrid Hawk runs investment-fraud schemes through short-lived ads in dozens of languages. Hasty Hawk has taken over a couple hundred domains to run phishing pages that impersonate shipping notifications and fake charity-donation sites.
The reason hijacked domains are so valuable to these groups is the same reason the attack is hard to catch: they come with reputation. A domain that’s been registered for years, that mail filters and URL scanners have seen behaving normally, is far more useful for phishing than a freshly-registered lookalike. Sitting Ducks lets an attacker inherit an aged, trusted, legitimately-registered name — including, in the reported cases, names belonging to well-known brands, nonprofits, and government agencies — without the paperwork of actually owning it.
How not to be a duck
The defense is less about hardening and more about not leaving a loaded pointer lying around. The condition that makes a domain hijackable is specific, which means it’s checkable.
The thing to look for is a delegation that points somewhere empty. Every nameserver listed in your domain’s NS records should actually answer authoritatively for your domain — query each one directly and confirm it returns your zone with the authoritative-answer bit set, not a referral or a blank. If any of the nameservers you’re delegated to doesn’t know your domain, that’s the lame delegation, and that’s the open door. The usual culprits are the ones you’d expect: a hosting account you cancelled, a DNS provider you migrated off of, a free trial that expired — anything where you stopped paying for the zone but never changed the NS records at the registrar to match.
So the rule is boring and it works: when you move DNS off a provider, update the delegation before you tear down the old zone, and never leave a domain pointed at a provider where you no longer have an active, configured zone. If you’re choosing a managed DNS provider, prefer one that verifies you control a domain before it will serve a zone for it — that single check is what turns the provider from “exploitable” to “not,” and it’s worth asking about before you sign up.
None of this is exotic. It’s inventory. The domains that get taken this way are almost always the ones nobody is looking at — the forgotten project, the old campaign site, the subdomain from a vendor you stopped using. The attack has survived for eight years not because it’s sophisticated but because attention is scarce and pointers are forever. Go read your own NS records. Then go ask whoever they point at whether they’d really answer for you — and whether they’d answer for anyone else who asked nicely.