Cyber threats are evolving rapidly and leveraging real-world events to deceive victims. With the coronavirus (COVID-19) driving a surge in cloud adoption, there are not only attacks targeting the cloud users but also threats originating from the cloud. Unit 42, the threat intelligence team at of Palo Alto Networks found more than 86,600 domains hosted in public clouds are risky or malicious. Threats originating from the cloud are more difficult to defend because malicious actors leverage the cloud resources to evade detection and amplify the attack.
In a release, it says, "Of the over 86,600 domains, 2,829 domains hosted in public clouds are found as risky or malicious. Unit 42 researchers analysed 1.2 million newly registered domain (NRD) names containing keywords related to the COVID-19 pandemic for seven weeks from 9th March to 26 April 2020. Over 86,600 domains are classified as 'risky' or 'malicious', spread across various regions. The US has the highest number of malicious domains (29,007), followed by Italy (2,877), Germany (2,564), and Russia (2,456)."
"In India, there are a total of 92 malicious themed domains and the top four host organisations such as Web Werks India Pvt Ltd (28.26%), Amazon Technologies Inc (16.30%), ASN block not managed by the RIPE (NCC 6.52%) and Microsoft Corp at 4.35%," Unit 42 says.
Unit 42 researchers found more than 56,200 of the NRDs are hosted in one of the top four popular cloud service providers (CSPs), such as Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), and Alibaba. AWS leads the pack with 70.1% domains hosted on its servers, followed by GCP at 24.6% and Azure at 5.3%. Alibaba hosts less than 1% of the over 56,200 NRDs.
Unit 42 says, "During our research, we noticed that some malicious domains resolve to multiple internet protocol (IP) addresses, and some IP addresses are associated with multiple domains. This many-to-many mapping often occurs in cloud environments due to the use of content delivery networks (CDNs) and can make IP-based firewalls ineffective."
"In a CDN, hundreds or thousands of domains in the nearby geographical location may resolve to the same IP of an edge server. CDNs reduce network latency and improve service availability by caching the static web content on edge servers. However, because a malicious domain shares the same IPs as other benign domains in the same CDN, it also acts as a cover for malicious domains. In our analysis, a Cloudflare IP 23.227.38[.]64 is associated with more than 150 risky or malicious domains. E.g., covid-safe[.]shop, cubrebocascovid[.]com, www.covidkaukes[.]lt, protection-contre-le-coronavirus[.]com. In the same dataset, more than 2,000 other benign domains also resolve to the same IP," Unit 42 says.
In the second scenario, the report points out "when a single domain resolves to multiple IPs, the domain may have a set of redundant hosts all serving the same content, or the domain may again be hosted in a CDN. If a domain has multiple redundant hosts, a DNS will hold multiple A records for this domain. If a domain is hosted in a CDN, the domain can resolve to different IP addresses based on the client’s location. The IP of the closest edge server is always returned when a client queries DNS servers for this domain. In our analysis, the domain covid19-fr.johanrin[.]com resolves to 28 different IPs where each IP belongs to an Amazon CloudFront edge server. E.g., 52.85.151[.]68, 99.84.191[.]82, 13.249.44[.]82, 54.192.30[.]118."
According to Unit 42, this many-to-many domain to IP mapping makes it difficult to block malicious domains by IP addresses. "A blacklisted IP in a layer-3 firewall may fail to block the traffic to/from a malicious domain while unintentionally making many other benign domains unreachable. A more intelligent layer-7 firewall is necessary to inspect the domain names in the application layer and selectively pass or block sessions," it added.
The COVID-19 related domains studied in this research were obtained from the RiskIQ dataset. The dataset keeps track of the newly observed domains that contain keywords related to COVID-19, including “coronav”, “covid”, “ncov”, “pandemic”, “vaccine,” and “virus.” Between the seven weeks under study, 1.2 million domains were registered with one of these keywords. 86,607 domains are categorized as risky or malicious by Palo Alto Networks URL Filtering.
Below figures describes the number of NRDs containing each keyword and the number of these NRDs observed every week and also illustrates the types of malicious domains identified in the dataset.
The research found that on average, every day, 1,767 malicious COVID-19 themed domains are created. Of the over 86,600 domains, 2,829 domains hosted in public clouds are found as risky or malicious, with AWS again leading the pack with 79.2% share in domain hosting. It is followed by GCP with 14.6%, Azure at 5.9% and Alibaba at 0.3%.

It says, "Adversaries are disguising malicious activities such as phishing and malware delivery in the cloud. Threats originating from the cloud can be more difficult to defend because malicious actors leverage the cloud resources to evade detection and amplify the attack. Organizations need to have a cloud-native security platform and a more advanced application-aware firewall to secure their environments."
"With thousands of malicious domains coming online every day, it is imperative to protect every endpoint with continuous monitoring and automatic threat prevention tools because cloud-hosted applications and services are exposed to the same threats as non-cloud endpoints. The problem becomes even more complicated when working in a multi-cloud environment. Due to the complexity of cloud management, user-induced misconfigurations lead to the most security incidents. Cloud native security platforms (CNSPs) help organizations monitor and secure resources across multiple cloud providers, workloads and hybrid cloud environments," the threat intelligence team of Palo Alto Networks concludes.