@InfobloxThreatIntel@infosec.exchange
Post #607884
2026-02-26 17:51 UTC
We discovered a phishing actor that is abusing .arpa to host content on domains that should not resolve to an IP address. The actor uses free services to create domain names from reverse DNS strings for IPv6 tunnels that use the .arpa top level domain. These domains are unlikely to be blocked, much less scrutinized, by security systems as they aren’t supposed to be used in URLs. But this actor is doing just that. Every day.
We’ve seen a constant flow of phishing emails using these domains as phishing links since last November. The scam uses a toolkit that has been used since at least 2017. Another campaign using the same toolkit leverage hijacked CNAMEs of well-known government agencies, universities, telecommunication companies, media organizations, and retailers from around the world.
In our latest blog, we explain what these actors are doing and how they are doing it. We even share all the indicators we’ve uncovered.
https://www.infoblox.com/blog/threat-intelligence/abusing-arpa-the-tld-that-isnt-supposed-to-host-anything/
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #hijackedcname
Replies (2)
-
@InfobloxThreatIntel@infosec.exchange 2026-02-26 17:52
This is the same toolkit, but for a different campaign, that was used to create the Thanksgiving scam we mentioned in a previous post. https://infosec.exchange/@InfobloxThreatIntel/115611651417357684
-
@agowa338@chaos.social 2026-02-26 17:55
@InfobloxThreatIntel@infosec.exchange I've seen people also do this for legitimate reasons. Like e.g. running fedi instances. And they've quite been pissed by the CA/Browser Forum changing the rules for TLS certificates so that you can't get ones for *.arpa domains anymore (soon at least). So I guess your problem will solve itself then?