Researchers Expose $10 Domain Controlling 25,000 Endpoints in Global Hack
Huntress uncovered a threat where a $10 unregistered domain silently controlled over 25,000 endpoints, including sensitive university, OT, and government networks.
Key Points
- A $10 domain controlled over 25,000 endpoints via a privileged PowerShell payload.
- Affected networks included universities, OT, government, and healthcare entities.
- The payload disabled cybersecurity products and blocked their updates.
Full Details
Researchers at Huntress have revealed a sophisticated cyber threat hidden within what appeared to be adware, where a single unregistered domain available for as little as $10 could have granted malicious actors silent control over more than 25,000 compromised endpoints worldwide. Starting in March 2025, the domain deployed a PowerShell-based payload running with elevated privileges to disable cybersecurity products, block update servers, and prevent reinstallation. Among the observed hosts, 324 belonged to sensitive networks, including 221 universities and colleges, 41 operational technology (OT) networks, 35 government entities, and three healthcare organizations. The attack highlights the vulnerability of critical infrastructure to low-cost, high-impact threats. This discovery underscores the need for enhanced monitoring of domain registrations and endpoint security in sensitive sectors.
Why It Matters
This incident demonstrates how low-cost threats can compromise critical infrastructure, urging stricter domain monitoring and endpoint security protocols.
Get stories like this delivered daily
AI-curated news, personalized to your interests. Zero noise.
Start 7-Day Free Trial →More in Global News
Iran war: What is happening on day 51 of the US-Iran conflict?
Tehran will keep the strategic Strait of Hormuz closed until Washington ends the blockade of Iranian ports.
Bodies of 50 infants dumped at Trinidad graveyard
Police say a preliminary investigation shows it may be a case of an "unlawful disposal of unclaimed corpses".
Iran war live: Tehran says no date set for US talks, Hormuz Strait closed
IRGC says the Strait of Hormuz will remain closed until the US stops blockading Iranian ports.
Trinidad and Tobago police uncover 56 bodies, mostly children, at cemetery
Police suspect the grim discovery in the city of Cumuto may be a case of 'unlawful disposal of unclaimed corpses'.