---
title: "Spammers hijack domains tied to GoDaddy"
canonical: "https://www.virtcloudrocks.com/space/INFOSEC/blog/852299/Spammers%20hijack%20domains%20tied%20to%20GoDaddy"
format: markdown
---
Two of the most disruptive and widely-received spam email campaigns over the past few months that shut down dozens of schools, businesses and government buildings late last year were made possible thanks to an authentication weakness at [**GoDaddy.com**](http://GoDaddy.com), the world’s largest domain name registrar.

Perhaps more worryingly, experts warn this same weakness that let spammers hijack domains tied to GoDaddy also affects a great many other major Internet service providers, and is actively being abused to launch phishing and malware attacks which leverage dormant Web site names currently owned and controlled by some of the world’s most trusted corporate names and brands.

Read the whole article for more details here, 

> Macro (auibutton)

  


As per information received from SANS.org, **SANS NewsBites Vol. 21 Num. 007**, <span style="color: #000000">GoDaddy is “taking corrective action immediately” to address a weakness in its DNS setup process that spammers exploited to launch disturbing email campaigns: the December 2018 emails with threat hoax that caused schools, businesses, and government buildings to shut down. The weakness allowed the attackers to piggyback on the reputations of known and trusted website names.</span>

  


<span style="color: #000000">Read more in:</span>

> Macro (auibutton)

> Macro (auibutton)