Skip to main content

When you think .BRAND, think CSC.

Get started about .BRAND services

Address Emerging Domain and AI Threats with CSC and CrowdStrike

Make an inquiry

All fields marked with * are required.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

By submitting this form, you acknowledge that CSC will collect and process your personal data in accordance with our Privacy Notice.

As organizations expand their digital footprints, domain names have become a critical part of the external attack surface. Threat actors are exploiting lookalike, lapsed, and hijacked domains, as well as other weaknesses across the domain ecosystem to drive phishing, impersonation, malware, ransomware, business email compromise, and brand abuse.

This webinar examines how artificial intelligence is accelerating these risks by enabling threat actors to scale and refine domain- and brand-based attacks. It will also explore common domain ecosystem vulnerabilities, including subdomain hijacking exposure, third-party-owned domains configured for email, inconsistent adoption of domain security controls, and fragmented certificate management.

Webinar transcript

Disclaimer: Please be advised that this recorded webinar has been edited from its original format, which may have included a product demo and other engagement features. To set up a live demo, please complete the form above on our website. If you currently are not on our website and are watching this on our YouTube channel, there's a link to the website in the description of this video. Thank you.

Christy: Hello, everyone, and welcome to today's webinar, "Addressing Emerging Domain and AI Threats with CSC and CrowdStrike." My name is Christy DeMaio Ziegler, and I will be your moderator.

Joining us today is Mark Pickett and Vincent D'Angelo. Mark is Director of Americas for Counter Advisory Operations at CrowdStrike, where he is responsible for CrowdStrike intelligence across the Western Hemisphere. He brings 11 years of cybersecurity experience and 9 years of intelligence expertise, helping organizations build and supplement cyber threat intelligence functions within security operations. Mark supports organizations in strengthening their understanding of the threat landscape and applying intelligence to improve security outcomes. Vincent is Senior Director at CSC's Digital Brand Services, where he leads strategic innovations, partnerships, and thought leadership at the intersection of AI, digital identity, DNS, and cybersecurity. He advises many of the world's most recognized brands on securing digital assets, migrating cyber risks, and preparing for the next generation of AI-powered ecosystems.

And with that, let's welcome Vincent to get us started.

Vincent: Thank you, Christy. Very excited about today's agenda. We're going to briefly introduce CSC and CrowdStrike and then have a conversation around how domain and DNS are essentially the epicenter of a lot of the cyber risk on the internet today. We'll talk about AI's role related to domain threats. We'll dig into CSC's domain security research and discuss some of the broader domain ecosystem risks. And then, lastly, we'll discuss our very exciting integration and partnership between CSC and CrowdStrike.

So a little bit about CSC. CSC is the world's largest corporate domain registrar. We protect digital infrastructure related to domains, DNS, and certificates. We then provide brand protection and fraud protection solutions to identify those threats. And then we have an arsenal of takedown and enforcement services, ranging from takedowns for phishing, fraud, and digital brand abuse. CSC is the trusted partner of the largest share of the Forbes 2000 for these services. We protect 90% of the top Interbrands. As a registrar, we have two and a half million domains under management, and very honored and proud to secure CrowdStrike's domain portfolio as well as their registrar.

CSC is the world's largest filer of domain name disputes, with an almost near perfect success rate at the World Intellectual Property Organization. Most recently, we were also the recipients of two innovation awards, one for our Certificate Lifecycle Management Solution, as well as another for our Fraud Prevention Solution.

So over to Mark to give a little bit perspective about CrowdStrike.

Mark: Thank you, Vince. Mark Pickett with CrowdStrike. Thank you for the very kind words about my introduction. But overall, I am head of Counter Adversary Operations for a good portion of the globe when it comes to all of our threat intelligence as well as our Counter Adversary Operations. And the Counter Adversary Operations program is an intricate part of everything that CrowdStrike does. I like to say it's the tide that rises all CrowdStrike feature functionality.

So what is CrowdStrike? Well, we are a cloud- and AI-native platform. Many of you may know us from the EDR space or detection response space. But in actuality, we are a massive platform when it comes to security outcomes to help organizations stop breaches and defend against the bad guys, and which my team tracks day in and day out. So whether it is a cloud asset, an endpoint asset, an identity, a third-party log, or a domain, as Vince mentioned, that is a very large problem when it comes to lookalike domains that are being registered day in and day out to masquerade as your particular company to start these attacks, CrowdStrike is a platform that you can depend on to get the outcomes that you desire and, at the end of the day, stop a breach.

So Counter Adversary Operations, we are the visibility layer within that CrowdStrike platform. So if you think about the numbers at scale, it really is tremendous in what we have visibility to. We have kind of a CrowdStrike footprint visual as well. But just think of it as a high level of one in every four devices, from a commercial and governmental aspect, deployed across the world is under the CrowdStrike umbrella. So we have visibility into a massive pool of data and events that users do day in and day out. So we have unprecedented ability to take a look and threat hunt as well as disseminate threat intelligence across that massive telemetry dataset.

So when we're talking about how we work together between threat intelligence and threat hunting, it goes hand in hand. And that organization called Counter Adversary Operations is the tip of the spear of what CrowdStrike does. It really is the org that tells the difference between just an administrator within your organization or a user within your organization doing something day to day, or is it an adversary who found their way in through a social engineering campaign, leveraging fraudulent domain registrations, which is one of the most popular ways adversaries are tricking users to hijack their sessions or to hijack their username and credentials.

So when we talk about the scale and size, it is really important to understand because we need to be able to understand the adversary before we can defend against the adversary. And what we are seeing in today's modern e-crime actor is really taking advantage of English-speaking social engineering as well as domain abuse.

So who are we by the market standpoint? Well, yeah, we are market trusted and tested, as you can see from the graph on the right from the intelligence wing, where we work hand in hand with CSC. We were just named the leader in top right of the magic quadrant for all things threat intelligence. And that is all built off of actionable threat intelligence. So not just a bunch of bad things that you can't do anything about, but things that you can action not only within the platform, but within trusted partners like CSC. And you can also see that we are the top right within the magic quadrant as far as endpoint protection. And that is a very broad term these days with the evolution of SaaS applications and what users have the ability to access in today's modern enterprise.

Vince, I'll pass it over to you for the domain ecosystem.

Vincent: Yeah. Thank you, Mark. So when we think of domain names, they're essentially the backbone for digital identity. And that's one of the reasons that threat actors are increasingly looking to weaponize or register lookalike domain names. And when you peel back the onion, domain names are actually part of the initial attack vector across some of the most common methods for phishing, ransomware, brand abuse, malware attacks, and BEC. And obviously, AI is becoming an enabler of these attacks, not just creating confusingly similar lookalike domains, but creating these fake digital brand ecosystems across social media, mobile applications, the DNS as well as in emerging AI systems as well.

So when we think about different domain threats, we look at dormant domains as being one type, where a threat actor may register domains and they sit idle. They could sit idle for days, months, or even years. It's super critical to monitor the activity of those domain names so when they become weaponized, you could jump into action with a blocking measure or a takedown as well.

Lookalike domains is another area that Mark and I obviously dig it into with our solution here with CrowdStrike today. And it's probably the most commonly discussed attack method within the broader cybersecurity and cyber risk community.

However, there are three different other attack methods that come down to basic domain DNS hygiene and life cycle management and governance, especially with your domain registrar. So the first method that I'm going to discuss here is when a domain name is simply hijacked and the domain name itself is weaponized. The second, which is another common attack vector, is dangling DNS or when subdomains are weaponized with malicious content, for instance.

One of the most concerning attack methods, for me, is when domain names expire and they get reregistered. What typically happens is that is essentially the backdoor for a supply chain attack because those domains are obviously trusted by environments, especially in some of these emerging AI ecosystems where domain name hygiene is an afterthought.

So our objective here at CSC, and obviously with our partner, CrowdStrike, is to continue to talk about domain security not just as a way to optimize obviously your website or your mobile app or email security, but to look at domain security as a broader enterprise risk discussion. If you think about a domain name attack, it isn't just an IT function or a cybersecurity issue. There are downstream effects across all of the business-critical functions. So obviously, at CSC, we continue to advocate and educate on the importance of domain registrar services and coupling them with leading threat intelligence, like by our partner CrowdStrike, as well as takedown mechanisms that not only focus on the technical aspects of takedown, but really have a deep understanding of intellectual property and brands.

Mark: And Vince, I'll give you an example there, too, when it comes to like these lookalike domains or domains that have lapsed. So one of the most pervasive adversaries we're tracking right now is an adversary by the name of ShinyHunters. There are many other acronyms that go to this particular adversary group, but they are really the main English as a first language, advanced social engineering adversary that has really ransomed about $21 million this year from organizations.

To take a look at one of their affiliates, so one of their operators within the broader realm of their criminal organization, we did kind of a mean time or an average attack cycle of this particular adversary. They start their attack by registering a domain, registering a lookalike domain, assigning a mail server to it. Whether that is an expired or a newly registered, it's going to look similar to the organization that they are attacking. And then they're going to develop their phish kit. Something that has historically taken 16 hours, it now takes minutes with an AI. So how am I going to actually develop these links, develop these landing pages, develop these front-end websites that I'm going to perpetrate my credential and session hijacking campaign against?

So all of that pre-work, including domain registration, takes about 40 minutes. And then once they actually successfully phish a user, get them to click, log in to their fake splash page, give them their credentials, hijack their token, it takes about four minutes for them to jump into a SaaS application and start exfiltrating data. So really by the time they're in your environment, we're talking about anywhere between 30 seconds and 5 minutes before they're moving laterally into places where you keep customer data and keep data secure.

So how do we partner together with CSC to get that strong foundation to identify these as fast as possible, to build mitigating controls in once we do identify them, and then work together to actually take down this malicious registration to get everyone on board and rowing in that boat the same direction to stop these bad guys? So I'll pass it back to Vince.

Vincent: Thank you, Mark. Yeah, that's a great perspective, kind of connecting the dots between how these attacks start and how they develop, right, that leads to ultimately a breach downstream. And I actually did some work recently as well where we quantified domain name risks and domain security risks.

Obviously, the industry typically looks at it as phishing being sort of top of the sphere. But when you kind of start connecting the attacks to how they develop, it really comes down to the domain registrations, the fake digital brand content. And the actual link to losses and cyber risk losses is in the tens of billions probably, if not more. Until we did it, there really wasn't an official study around like what was the impact. So I appreciate that perspective there, Mark. Thank you.

So in terms of the attack surface and domain names, in this regard CSC publishes, on an annual basis, our Domain Security Report. So we look at the domain security posture. What does that mean? It's the adoption of underlying and preemptive domain security controls, like DMARC, SPF, DKIM, and six or seven others. We look at that across the top domains of the Forbes Global 2000. And then we look at the impersonation that's attacking those core brands and domains. And although, as a community, we've seen some progress in the adoption of DMARC, there's still a lot of work to be done in terms of some of the preemptive or proactive controls that could be put in place at the domain level.

So approximately 65% of the Forbes Global 2000 still lack some of these basic domain security protections. Unfortunately, about 100 of the Forbes 2000 don't have any of these controls in place. One in five DNS records across organizations that we studied are vulnerable to subdomain hijacking. We talked about the subdomain hijacking risks. Approximately 85% of impersonating domains that resemble the Global 2000 are owned by third parties, of which 40% are configured for email.

This last point relates to sort of the notion that you can't really defend what you don't know about. And there is a sprawl across domain registrars and certificate providers and cloud providers where this unknown attack surface exists. In this regard, 60% of organizations are using more than 3 certificate providers. So getting a handle on your digital assets, your domains, DNS certificates at the registrar level is foundational to domain security and some of the things that you could be doing proactively in addition to responding and mitigating threats.

The partnership, the integration, wanted to get your thoughts. Obviously, we came together, two great leaders in our respective fields to create one threat intelligence and one disruption solution. I think you've talked about some of these points earlier. Any other perspective to share before I kind of jump into the integration?

Mark: No. I mean, yes and no. I don't want to sound like a broken record. That's hard, right? But at the end of the day, like this is why we're partnering, this is why we're having today's discussion. I believe there are, what, 600,000 domains registered every single day. So like that influx and that waterfall of data to try to sift through and understand, am I affected, is something coming down the proverbial pipe, can be very difficult and overwhelming to deal with, right?

And at CrowdStrike, we use CSC internally. And then we're the first ones to pick up the phone and call you, Vince, when we wanted to share this with our customer base and build the internal integration right within our tools. So if we're notified of or come across a malicious domain that is by an adversary that we track or don't track, we're able to actually action it within the platform and then get it to your team to resolve right away. And your team is really the important like let's take the ball from the 50-yard line and score a touchdown. Like we will put all the preventions in place. We'll have all the automations through the SOAR technologies as well as detection creation. However, giving that to a human in the loop to make sure it gets done is very important. And that's why I'm thankful for the partnership.

Vincent: I appreciate that, Mark. And super excited on sort of how the partnership came together and how it works, frankly. So I'm going to kind of provide a quick overview of how the integration kind of works. And I think we've covered some of these facts on the conversation so far.

But essentially the malicious domains are identified in the CrowdStrike Falcon Platform. They're sent over to CSC via one-click integration via our Anti-Fraud API. At that point, we validate the threat and think about the different enforcement options that we could leverage. So it could range from an outreach to a hosting provider, a cloud provider, a mobile app platform. It could also involve a social media platform. Then we could escalate to a registrar for takedown measures.

So the point is that there's a toolbox that leverages phishing fraud and brand expertise, and we're managing this through a full-scale case management solution on behalf of our joint clients. We track all the activity, and then we provide confirmation. So essentially the application provides complete visibility into our work logs, timestamps. It could be multiple, many enforcement actions that involve the case. So that is the main point here is that we're supporting detection to disruption and managing the entire enforcement process from end to end.

The end goal here is to provide, and I think, Mark, you talked about this earlier, right, it's to provide a quicker response time because now we're working in minutes, not days as it was in years past. And you're doing so here in disrupting this activity with proven expertise, obviously CrowdStrike with being the leading threat intel provider and CSC having two decades of brand protection experience also as a corporate registrar. So obviously, having a global network of relationships at the registries, the cloud providers, the social media platforms.

And I talked about this earlier, but it does go beyond just blocking and technical means. One of the key differentiators is really understanding the policies of the individual hosting providers, registrars, the platforms, as well as understanding intellectual property. So connecting the dots between those critical areas is very important. And the fact that these solutions are trusted by tens of thousands of brands across two and a half million domain names is one of the reasons why we think it's such an important and missing element in the past in terms of a cybersecurity remediation toolbox.

So, Mark, any other thoughts to add to the integration? And obviously, this is the start of many things to come between our organizations.

Mark: Yeah. I think it's flexible, right, and I think that that's what we provide together as a keyword. The domain registration game is very challenging. I think we've talked about it a little bit here. But from like the parked domains, I can alert you all day long that there is a domain that is parked. But if it doesn't show malicious intent, the legality of it is you as an organization can't do anything even if it is the same word or the same lookalike vernacular abbreviation. An organization really can't do anything unless they can prove fraudulent activity.

So how do you solve that problem if there are just all these domains that are out there that look like you, you're susceptible to attacks, yet you can't do anything about them from like ICANN governance rules? So that's where creating detections from a CrowdStrike standpoint and like giving it to CSC as a monitoring solution as well to have the best of both worlds, right? If someone connects to it, CrowdStrike fire and alert. If there's an MX record that is associated to it, if something changes, CSC can help. So it's really that better together story, where we can continuously monitor for these domains. So when it inevitably becomes malicious because no one is out there just registering lookalike domains for purposes other than malicious intent, we can work together to solve a problem.

Vincent: Thank you, Mark. So over to you, too, on some closing thoughts and kind of your top few points that you'd like to drive home.

Mark: So CrowdStrike tracks a multitude of adversaries. I think last I checked it was 281 specific groups, whether those are nation state or e-crime actors. Overall, I mean think of them as roughly 300 criminal organizations, whether it's a state sponsored or just criminal gang of either kids or just fraudsters, right? It's a lot of people to keep track of. And what ends up happening is the adversary continues to evolve fast and quickly.

Where I mentioned we're on one in four devices deployed globally, well, guess what? The adversary doesn't or is tending to avoid endpoint detections by jumping right into SaaS applications for data exfiltration. What is the new step that's coming down? AI is evolving, and currently things are just moving quicker. So it's very important and imperative to do your foundational level of security, your detections with these domain registrations as a key entry point, as well as your systems that are set in place with enforcement of those particular domain registrations and takedowns.

Overall, we need to work together. Whether that is your organization monitoring the registered domains is from an area outside of IT or internal of IT, or whether it rolls up to legal as far as the enforcement or registration of it, everyone needs to be playing together, because it is a team sport, to stop these adversaries because they are moving so fast.

And in closing, Vince, I mean no matter how sophisticated the attacks are these days, whether you're a nation state or an e-crime actor, they're still targeting people, and the targeting is becoming less and less spray and prey style, but more targeted of specific personas. Where I see my modern e-crime adversary targeting IT folks, directors and above who have access to these particular sensitive areas where data is held because if they're able to phish them and gain their credential with these lookalike domains and phish kits, then they're going to have an easier time moving laterally through your system and doing eventually what they want to do, either locking it up and extorting or doing data exfiltration and extorting.

So it's not just the person from accounting who's clicking the wrong button these days. It's prescribed. It's well researched, and it is very, very well targeted. When these criminals are attacking these organizations, they're going after the people with the keys to the lockboxes. So at the end of the day, people are the weakest link. So how can we best support them? By staying ahead of the things that the adversaries are using to trick them.

Vincent: Yep. I appreciate your thoughts, Mark. So from CSC's perspective, I think that last bullet, prepare for AI-enabled attacks, you did an awesome job kind of describing some best practices around that area. Obviously, it was the primary focus of our conversation today. Though there are some proactive, preemptive controls that organizations can put in place to harden their digital identity.

And from CSC's perspective, it starts with your domain registrar. Domains, DNS, and certificates are the backbone and the lifeline of digital identity. So when we talk about those domain threats that we discussed early on, you have newly-registered domain names that are used in attacks, but you also have existing and legitimate and trusted domains. So making sure that you're purging your unused DNS records, you have entire life cycle management around domain names, you're putting in place the right controls, especially now also with certificates, because the life cycle of certificates is shrinking, has shrunk.

So having a full repository of that attack surface is super critical. So that could be if you're unaware of domains that your marketing department may be registering, or if there's a business unit that hasn't sort of been consolidated with your registrar, that is an attack surface that's not on your radar. And obviously you can't defend against risks that you do not know about. So really elevating the conversation of domain security to an enterprise risk level discussion, because, again, when domain names are compromised, either newly-registered or legitimate domains being weaponized, there are effects downstream and the financial impact is in the billions, as we've seen and discussed, in terms of cyber risks.

There are controls that you could put in place to harden your defenses that align with your zero trust strategies, so things like DNSSEC and domain registry locks that prevent domains from moving in terms of different registrars. There are CAA records that serve as certificate compliance methods to ensure that only your organization is putting in place new certificates. Obviously, we talked about DMARC, SPF, DKIM to protect the email channel from phishing.

And this is a point, in terms of this third point, assessing your supply chain, I've been in the brand protection industry for 25 years working with different registrars. And it's an area where with every innovation, with every wave, we've seen it with social media and mobile applications, the threat actors, they basically move to where the traffic is, the visitors are. Now we know that AI systems, that's where sort of the next wave of where the threat actors are going to target, and they're going to leverage some form of brand impersonation to launch attacks against humans today, but machines tomorrow, AI and agentic systems.

So we're starting to hear more about indirect prompt injections. You're talking about different vendors that are part of this AI ecosystem that are being targeted to create supply chain risks. It's important to educate some of these newer organizations that are managing and controlling your data, that are part of like your AI environments, are they up to par or better with their domain security controls? Are they working with the right cloud and DNS providers and putting in place the right trust and safety mechanisms to ensure that your AI environments are not at risk?

Another point, too, is that there are domain name dependencies across every layer of the AI stack, from the application layer, data layer, LLM, hardware infrastructure. Beneath the AI magic are domain name and DNS dependencies, and domain names will serve as a trust anchor when this essentially puts AI systems at risk. So being proactive in hardening your defenses is definitely an area where you could prepare for the next era of the web, which will be the agentic web era.