Remember the December 13 email blast that threatened to blow up buildings and schools unless recipients paid a $20,000 ransom? It triggered mass evacuations, closures, and lockdowns in the US, Canada, and elsewhere around the world.
An investigation shows the spam run worked by abusing a weakness at GoDaddy that allowed the scammers to hijack at least 78 domains belonging to Expedia, Mozilla, Yelp, and other legitimate people or organizations. The same exploit allowed the scammers to hijack thousands of other domains belonging to a long list of other well-known organizations for use in other malicious email campaigns. Some of those other campaigns likely included ones that threatened to publish embarrassing sex videos unless targets paid ransoms.
Distributing the malicious emails across such a broad swath of reputable domains belonging to well-recognized organizations was a major coup. The technique, known as snowshoe spamming, drastically increased the chances the emails would be delivered because it weakened the reputation metrics spam filters rely on. Rather than appearing as fringe content sent by one or a handful of sketchy domains, the snowshoe technique gave the emails an air of legitimacy and normalcy. The technique gets its name because, like snowshoes, it distributes the heavy load evenly across a wide area.
Commandeered by Spammy Bear
Domains that sent the December bomb threats included wotdonate.com, wothome.com, wotlifestyle.com, wotnetwork.com, and wotscooking.com, which whois records show are all owned by Expedia. Other domains included Yelpmarketingservices.com, virtualfirefox.com, and blueestatescoffee.com, which are registered to Yelp, Mozilla, and food service giant Aramark, respectively. In all, Ars knows of 78 domains used to send the threats, although the total number is likely higher.
Meanwhile, the number of domains hijacked by the same person or group and used in other campaigns is much higher still. An analysis of historical Internet records compiled by independent researcher Ronald Guilmette shows that in the last few years, that person or group has commandeered almost 4,000 domains belonging to about 600 people, companies or organizations. The list of registered domain holders—to name a small few—include Facebook, MasterCard International, Hilton International, ING Bank, Dignity Health, the Church of Scientology, Warner Bros. Entertainment, Massachusetts Institute of Technology, McDonalds Corporation, and certificate authority DigiCert.