This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.
This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.
Posts
This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.
This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.
This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.
We track algorithms that generate domain names (RDGA). Now we're looking at one that generates the content. It's a strange collision of domain parking and AI generated nonsense.
A portfolio of parked domains, each with a wildcard DNS record and a backend that serves pre-generated AI content for specific keyword combinations:
- insurance.howtomakeasmoothie[.]com → "Why You Need Insurance When Making Smoothies"
- insurance.backsplashdesign[.]com → "A Guide to Backsplash Insurance"
- yacht.insurance.backpainmedication[.]com → a wellness journey involving sailing, spinal health, and coverage options
The subdomain labels are the content brief. The domain topic is the flavour. The result is grammatically sound, mildly persuasive, and reads like it was written by someone who has heard of both topics but has never encountered either. It's AI slop at its finest. The article on smoothie insurance confidently recommends coverage "for peace of mind." The one on backsplash insurance suggests you may need a specialist endorsement. Nobody proofread these. Nobody needed to — the target audience is a crawler, not a person, and crawlers don't find non-sequiturs suspicious.
One template, one analytics pixel (stats.computer[.]com), one CDN (images.computer[.]com) — repeated across what appears to be a large portfolio of parked-for-sale domains, each advertising itself for sale in the page header while the AI content quietly earns its keep.
Unknown subdomains redirect to the parking marketplace. Only the pre-generated keyword combinations serve content — "insurance" being the obvious choice at the CPM rates that keyword commands.
We're not flagging a threat. It's the technique that's worth noting as an indicator of where we could be headed. RDGAs generate domain names at scale to serve malware or evade detection. This applies the same logic to content. And the wildcard DNS backend is already exactly what you'd need for the next step: on-demand generation, where a query could produce a fresh AI-written page in real time. That capability exists now. It just isn't what's running here. Yet.
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #spam #adtech #rdga
This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.
Poisonseed has successfully phished enterprise email accounts for over a year to further their crypto seed phrase poisoning attacks. 🎣 ✉️ 💸
It's been one year since @troyhunt@infosec.exchange's Mailchimp phishing incident (https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/) which resulted in threat actors downloading his entire email list and creating an API key likely in an attempt to send mass emails from his account.
Before we get into some fresh domains you can hunt, here's a bit of background on this ongoing threat...
The threat actors behind this campaign are seemingly associated with The Com / Scattered Spider threat actors and use a compromised email account to send CRM phishing emails and also crypto seed phrase poisoning / crypto phishing emails. They essentially compromise a CRM to send more CRM phishing emails from it – a supply chain compromise that just keeps spreading -- very clever! The threat actors are targeting Mailchimp, Sendgrid, ActiveCampaign and allegedly other CRM providers.
We've had some great writeups in the last year on this threat including:
Validin: "Pulling the Threads on the Phish of Troy Hunt" @ https://www.validin.com/blog/pulling_threads_on_phishing_campaign
Silent Push: "PoisonSeed Campaign Targets CRM and Bulk Email Providers in Supply Chain Spam Operation" https://www.silentpush.com/blog/poisonseed/
NViso: "Shedding Light on PoisonSeed’s Phishing Kit" https://blog.nviso.eu/2025/08/12/shedding-light-on-poisonseeds-phishing-kit/
Domain Tools: "Newly Identified Domains Likely Linked to Continued Activity from PoisonSeed E-Crime Actor" https://dti.domaintools.com/research/newly-identified-domains-likely-linked-to-continued-activity-from-poisonseed-e-crime-actor
Over the last year, Poisonseed have successfully phished *dozens* of major organizations, seemingly with no or minimal public disclosures about these incidents from impacted organizations. And while we don't share victim details, we have a breakdown of the industries who have been impacted by the CRM phishing campaigns (essentially every major industry):
This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.
This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.
We discovered a phishing actor that is abusing .arpa to host content on domains that should not resolve to an IP address. The actor uses free services to create domain names from reverse DNS strings for IPv6 tunnels that use the .arpa top level domain. These domains are unlikely to be blocked, much less scrutinized, by security systems as they aren’t supposed to be used in URLs. But this actor is doing just that. Every day.
We’ve seen a constant flow of phishing emails using these domains as phishing links since last November. The scam uses a toolkit that has been used since at least 2017. Another campaign using the same toolkit leverage hijacked CNAMEs of well-known government agencies, universities, telecommunication companies, media organizations, and retailers from around the world.
In our latest blog, we explain what these actors are doing and how they are doing it. We even share all the indicators we’ve uncovered.
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #hijackedcname