DangleGeddon: AI Automates Dangling DNS Takeovers

Silent Push says its DangleGeddon research used AI to automate dangling DNS takeovers and found hundreds of exploitable subdomains, including U.S. federal sites and domains tied to Société Générale, Ford and Eli Lilly.

Security firm Silent Push published research showing artificial intelligence can automate and scale dangling DNS takeover attacks, identifying hundreds of vulnerable subdomains across government and industry in a project it calls DangleGeddon.

A dangling DNS takeover happens when a DNS record points to a cloud resource that no longer exists. If the cloud endpoint is recreated by an outsider, the attacker can control the subdomain that points to it. Silent Push treated the issue as an actor seeking disruption might, rather than a profit-driven criminal, and used AI to broaden and speed discovery.

The research team used Claude Opus 5 to generate context-aware takeover scripts and scanned roughly 12,500 domains. AI was used to discard records without active allocations or valid DNS registration, reducing the initial data set to several hundred precise, exploitable targets. The researchers also automated the build-out of infrastructure required to claim dangling endpoints. The report states the process left them “one button push away from Dangle Day.”

Silent Push ran controlled tests and alerted affected domain owners by placing a notice on impacted subdomains. The warning page included the heading “Security Notice” and stated the subdomain was being held by a security researcher to prevent abuse and that no data was collected on the page.

Examples disclosed in the report included a U.S. federal domain that pointed to an unassigned Azure blob storage container; the report noted a takeover could allow phishing pages that leverage trust in .gov addresses and bypass some automated filters. The team also identified a Société Générale record pointing to an unassigned Azure Blob tied to an application, a Ford record mapped to a development application gateway on an Azure virtual machine, and an Eli Lilly record referencing an Apple device guide.

Silent Push described possible downstream effects. Attackers controlling legitimate subdomains could host phishing pages or malware, harvest developer credentials and API keys for lateral movement, and use the trust in government or corporate domains to evade defenses. The report projects that large-scale takeovers could disrupt online banking, real-time payments and trading platforms in the financial sector, spread malicious content through manufacturing supply chains, and affect research, clinical trials and distribution in pharmaceuticals.

The research contrasts motives: it notes financially motivated cybercriminals have used dangling records for profit, while a hostile nation-state actor would seek wide disruption. The team also said AI techniques that expand and speed these attacks could lower the technical barrier for smaller criminal groups seeking financial gain.

Silent Push recommended that administrators and developers identify and remove stale DNS records, track cloud resource lifecycle changes, and monitor for unclaimed endpoints that could be recreated by outsiders. The report summed its finding with a brief caution: “don’t leave records dangling.”

Articles by this author