#infoblox

2 posts · Last used 3d

Back to Timeline
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange · 3d ago
Season's Scammings 🔅 🎄 We've been tracking a cluster of personal loan phishing sites that work hard to look like independent lenders — different brands, different domains, even deliberately varied infrastructure. Look closely enough, though, and the seams show. Similar underlying templates. The same technology stack. And passive DNS tying their thousands of domains back to the same operator. The sites present as loan applications. Name, address, employment details, financial history. And then, at the final step: your Social Security Number. No real company name. No regulatory disclosure. Just a form — and your most sensitive personal data sent off to who-knows-where for who-knows-what. A significant portion of the domains are seasonal — Christmas cash, Thanksgiving funds, Black Friday loans. Financially stretched consumers, at exactly the moment they're most likely to reach for a quick fix. ⛔ mychristmaswallet[.]com ⛔ cashzillaloans[.]com ⛔ personalreliefwallet[.]com ⛔ thanksgivingcash-5k[.]com ⛔ christmascashhelp-direct[.]com #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #scam
0
0
0
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange · Jul 23, 2026
We've been tracking an AiTM phishing campaign targeting universities, enterprises, and multinational institutions — EU and UN agencies included. The actor favors likely compromised domains to host fake document portals and spoofed login pages. The attack chain runs through multiple phishing kits — EvilProxy, FlowerStorm, Kali365 — all built to proxy sessions in real time. The victim completes MFA. The attacker collects the session token. Authentication worked perfectly, for both parties. What makes this trackable: RDGA patterns, subdomain conventions, and infrastructure reuse leave a legible fingerprint in passive DNS — upstream of the login page, before any credential changes hands. :no_entry:️ usersatisfactionlab[.]de :no_entry:️ assessmentevaluationreport[.]com :no_entry:️ duemineral[.]uk https://www.infoblox.com/blog/threat-intelligence/the-procurement-trap-inside-an-aitm-campaign-targeting-global-institutions/ #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm #rdga
0
0
0
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange · Jul 06, 2026

We track algorithms that generate domain names (RDGA). Now we're looking at one that generates the content. It's a strange collision of domain parking and AI generated nonsense.

A portfolio of parked domains, each with a wildcard DNS record and a backend that serves pre-generated AI content for specific keyword combinations:

  • insurance.howtomakeasmoothie[.]com → "Why You Need Insurance When Making Smoothies"
  • insurance.backsplashdesign[.]com → "A Guide to Backsplash Insurance"
  • yacht.insurance.backpainmedication[.]com → a wellness journey involving sailing, spinal health, and coverage options

The subdomain labels are the content brief. The domain topic is the flavour. The result is grammatically sound, mildly persuasive, and reads like it was written by someone who has heard of both topics but has never encountered either. It's AI slop at its finest. The article on smoothie insurance confidently recommends coverage "for peace of mind." The one on backsplash insurance suggests you may need a specialist endorsement. Nobody proofread these. Nobody needed to — the target audience is a crawler, not a person, and crawlers don't find non-sequiturs suspicious.

One template, one analytics pixel (stats.computer[.]com), one CDN (images.computer[.]com) — repeated across what appears to be a large portfolio of parked-for-sale domains, each advertising itself for sale in the page header while the AI content quietly earns its keep.

Unknown subdomains redirect to the parking marketplace. Only the pre-generated keyword combinations serve content — "insurance" being the obvious choice at the CPM rates that keyword commands.

We're not flagging a threat. It's the technique that's worth noting as an indicator of where we could be headed. RDGAs generate domain names at scale to serve malware or evade detection. This applies the same logic to content. And the wildcard DNS backend is already exactly what you'd need for the next step: on-demand generation, where a query could produce a fresh AI-written page in real time. That capability exists now. It just isn't what's running here. Yet.

#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #spam #adtech #rdga

6
1
8

You've seen all posts