Simone Catania published an article for InternetX on domain shadowing.
What is domain shadowing?
Domain shadowing is a technique that cybercriminals use to secretly create and control subdomains under a legitimate domain without the owner’s knowledge or consent. This tactic has become a significant concern for DNS experts and brand managers.
By gaining unauthorized access to a domain’s DNS settings or domain registration accounts, often via phishing or credential stuffing, hackers can create a network of malicious subdomains. This approach allows threat actors to bypass traditional security measures, hinder domain takedown processes and make it difficult for security researchers to track their infrastructure.
You can read the full article on InternetX which delves into the origins of domain shadowing and a look at real world scenarios.