A ‘dangling DNS takeover’ is a known attack method that allows a bad actor to take over a subdomain whenever a DNS record points to a cloud resource after the resource has been deleted. The link is left ‘dangling’, pointing to nothing. It is a simple case of poor security hygiene, but not uncommon.
If an attacker can find that link – which is not difficult with internet scans – and reconstruct the cloud resource but now under his own control, he can then gain access to the subdomain. Historically, the attack has primarily been used by cybercriminals for financial gain.
Security firm Silent Push asked itself, “What if we looked at it the same way a trained nation-state attacker would?” Nation states prioritize the generation of chaos and disruption over monetization; and have a new tool at their disposal – artificial intelligence. The result of its consequent research has now been published.
AI proved to be a force multiplier for dangling DNS takeover in the project and research Silent Push calls ‘DangleGeddon’. It massively expanded domain and subdomain discovery. Claude Opus 5 was used for context enriched takeover script generation, targeting 12,500 domains.
AI was also used to filter out those resources that lacked allocation or DNS registration, reducing the initial large dataset to a precise list of several hundred exploitable targets. This process found new targets, broadening the attack surface beyond what was known to possible human attackers.













