Skip to main content
radar

Radar #14: Week of 12/22/2025

Graham Helton

The Low Orbit Security Radar is a weekly security newsletter from an offensive practitioner's perspective. One idea, curated news, and links worth your time.

This Week


$ radar --status
SIGNAL: REACQUIRED
LAST_TX: 01/27/2025
STATUS: OPERATIONAL
[Low Orbit Radar, back online]

We've had a gap in transmissions. Some housekeeping before we resume.

  1. The Low Orbit Radar is back. Monday mornings.
  2. Low Orbit Radar Issues will take the following format.
# Radar #X: Week of MM/DD/YYYY

## This Week [2-4 paragraphs]
One observation, technique, or idea worth sharing. 2-4 paragraphs.

## News [1-2 paragraphs]
News items worth paying attention to, with brief analysis.

## Caught My Eye [0-n links]
Links that earned a bookmark.
  1. The content will continue to be an analysis of the security industry from my offensive security perspective.

News


Don't directly navigate to websites, use dashboards

A decade ago, ~5% of parked domain visits led to malicious content. Now it's over 90%. These "parked" domains are collected by "investors" called "domainers" and often serve ads to collect passive income to pay for their domain renewals.

Infoblox published an incredible investigation into what really happens when visiting these seemingly benign pages and uncovered a complex web of how a single mistyped url can lead to sketchy results at best and malware at worst.

Interestingly, the actor is using double fast flux on the domains which rotates both the IP and DNS nameservers making it difficult to track, block, and detect.

Source: https://www.infoblox.com/blog/threat-intelligence/parked-domains-become-weapons-with-direct-search-advertising/

Parked domains being used for malicious purposes isn't new, but the scale is daunting. You can check for common variations of a domain using dnstwist. I know that typing a domain you visit often is second nature, but utilizing personal dashboards such as Glance is probably wise. Organizations should consider having an internal dashboard with common links.

Caught My Eye