Elektrine lite

← Feed

Infoblox Threat Intel

InfobloxThreatIntel@infosec.exchange

<p>This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.</p>

Posts

  • Post #4496659

    Season&#39;s Scammings 🔅 🎄 We&#39;ve been tracking a cluster of personal loan phishing sites that work hard to look like independent lenders — different brands, different domains, even deliberately varied infrastructure. Look closely enough, though, and the seams show. Similar underlying templates. The same technology stack. And passive DNS tying their thousands of domains back to the same operator. The sites present as loan applications. Name, address, employment details, financial history....

  • Post #4040835

    We&#39;ve been tracking an AiTM phishing campaign targeting universities, enterprises, and multinational institutions — EU and UN agencies included. The actor favors likely compromised domains to host fake document portals and spoofed login pages. The attack chain runs through multiple phishing kits — EvilProxy, FlowerStorm, Kali365 — all built to proxy sessions in real time. The victim completes MFA. The attacker collects the session token. Authentication worked perfectly, for both parties. Wha...

  • Post #3843187

    Interesting scam story with support and commentary from one of our researchers. Quoting Zach Edwards from his highlights of the story: A bunch of NFL players were targeted in an ecommerce investment scam and likely lost millions of dollars to a 24-year old guy based in the U.S.. The threat actor(s) behind it created multiple Shopify stores and were creating numerous “manual orders” on Shopify for bulk orders and then marking them as paid. The victims were given admin credentials on those Shopi...

  • Post #3631550

    We track algorithms that generate domain names (RDGA). Now we&#39;re looking at one that generates the content. It&#39;s a strange collision of domain parking and AI generated nonsense. A portfolio of parked domains, each with a wildcard DNS record and a backend that serves pre-generated AI content for specific keyword combinations: - insurance.howtomakeasmoothie[.]com → &quot;Why You Need Insurance When Making Smoothies&quot; - insurance.backsplashdesign[.]com → &quot;A Guide to Backsplash In...

  • Post #781606

    Poisonseed has successfully phished enterprise email accounts for over a year to further their crypto seed phrase poisoning attacks. 🎣 ✉️ 💸 It&amp;#39;s been one year since @troyhunt&amp;#39;s Mailchimp phishing incident (https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/) which resulted in threat actors downloading his entire email list and creating an API key likely in an attempt to send mass emails from his account. Before we get into some fresh domains you ca...

  • Post #607884

    We discovered a phishing actor that is abusing .arpa to host content on domains that should not resolve to an IP address. The actor uses free services to create domain names from reverse DNS strings for IPv6 tunnels that use the .arpa top level domain. These domains are unlikely to be blocked, much less scrutinized, by security systems as they aren’t supposed to be used in URLs. But this actor is doing just that. Every day. We’ve seen a constant flow of phishing emails using these domains as ph...