Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Infoblox Threat Intel

@InfobloxThreatIntel@infosec.exchange
  • Open on infosec.exchange

This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.

0 Followers
0 Following
7 Posts
Joined December 20, 2023
Prolific Puma Malicious Link Shortener:
https://blogs.infoblox.com/cyber-threat-intelligence/prolific-puma-shadowy-link-shortening-service-enables-cybercrime/
Sitting Ducks DNS Attack:
https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/
Vigorish Viper China Organized Crime:
https://insights.infoblox.com/resources-report/infoblox-report-vigorish-viper-a-venomous-bet
VexTrio Deploys New DNS TDS:
https://blogs.infoblox.com/cyber-threat-intelligence/cyber-threat-advisory/vextrio-deploys-dns-based-tds-server/
Decoy Dog is No Ordinary Pupy:
https://blogs.infoblox.com/cyber-threat-intelligence/decoy-dog-is-no-ordinary-pupy-distinguishing-malware-via-dns/
Infoblox Threat Intel:
https://www.infoblox.com/threat-intel/

Posts

Open post
InfobloxThreatIntel
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange · 3d ago
Infoblox Threat Intel
@InfobloxThreatIntel@infosec.exchange

This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.

infosec.exchange
Season's Scammings 🔅 🎄 We've been tracking a cluster of personal loan phishing sites that work hard to look like independent lenders — different brands, different domains, even deliberately varied infrastructure. Look closely enough, though, and the seams show. Similar underlying templates. The same technology stack. And passive DNS tying their thousands of domains back to the same operator. The sites present as loan applications. Name, address, employment details, financial history. And then, at the final step: your Social Security Number. No real company name. No regulatory disclosure. Just a form — and your most sensitive personal data sent off to who-knows-where for who-knows-what. A significant portion of the domains are seasonal — Christmas cash, Thanksgiving funds, Black Friday loans. Financially stretched consumers, at exactly the moment they're most likely to reach for a quick fix. ⛔ mychristmaswallet[.]com ⛔ cashzillaloans[.]com ⛔ personalreliefwallet[.]com ⛔ thanksgivingcash-5k[.]com ⛔ christmascashhelp-direct[.]com #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #scam
0
0
0
0
Open post
InfobloxThreatIntel
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange · Jul 23, 2026
Infoblox Threat Intel
@InfobloxThreatIntel@infosec.exchange

This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.

infosec.exchange
We've been tracking an AiTM phishing campaign targeting universities, enterprises, and multinational institutions — EU and UN agencies included. The actor favors likely compromised domains to host fake document portals and spoofed login pages. The attack chain runs through multiple phishing kits — EvilProxy, FlowerStorm, Kali365 — all built to proxy sessions in real time. The victim completes MFA. The attacker collects the session token. Authentication worked perfectly, for both parties. What makes this trackable: RDGA patterns, subdomain conventions, and infrastructure reuse leave a legible fingerprint in passive DNS — upstream of the login page, before any credential changes hands. :no_entry:️ usersatisfactionlab[.]de :no_entry:️ assessmentevaluationreport[.]com :no_entry:️ duemineral[.]uk https://www.infoblox.com/blog/threat-intelligence/the-procurement-trap-inside-an-aitm-campaign-targeting-global-institutions/ #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm #rdga
0
0
0
0
Open post
InfobloxThreatIntel
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange · Jul 15, 2026
Infoblox Threat Intel
@InfobloxThreatIntel@infosec.exchange

This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.

infosec.exchange
Interesting scam story with support and commentary from one of our researchers. Quoting Zach Edwards from his highlights of the story: A bunch of NFL players were targeted in an ecommerce investment scam and likely lost millions of dollars to a 24-year old guy based in the U.S.. The threat actor(s) behind it created multiple Shopify stores and were creating numerous “manual orders” on Shopify for bulk orders and then marking them as paid. The victims were given admin credentials on those Shopify stores so that when they logged in they could see the revenue growth and orders, and unless you drilled into the order details, you may not have any clue that something was wrong. #scam #cybercrime #cybersecurity https://www.barrons.com/articles/nfl-players-shopify-fake-stores-4d90d418?st=ZVjTeu
0
0
0
0
Open post
InfobloxThreatIntel
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange · Jul 06, 2026
Infoblox Threat Intel
@InfobloxThreatIntel@infosec.exchange

This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.

infosec.exchange

We track algorithms that generate domain names (RDGA). Now we're looking at one that generates the content. It's a strange collision of domain parking and AI generated nonsense.

A portfolio of parked domains, each with a wildcard DNS record and a backend that serves pre-generated AI content for specific keyword combinations:

  • insurance.howtomakeasmoothie[.]com → "Why You Need Insurance When Making Smoothies"
  • insurance.backsplashdesign[.]com → "A Guide to Backsplash Insurance"
  • yacht.insurance.backpainmedication[.]com → a wellness journey involving sailing, spinal health, and coverage options

The subdomain labels are the content brief. The domain topic is the flavour. The result is grammatically sound, mildly persuasive, and reads like it was written by someone who has heard of both topics but has never encountered either. It's AI slop at its finest. The article on smoothie insurance confidently recommends coverage "for peace of mind." The one on backsplash insurance suggests you may need a specialist endorsement. Nobody proofread these. Nobody needed to — the target audience is a crawler, not a person, and crawlers don't find non-sequiturs suspicious.

One template, one analytics pixel (stats.computer[.]com), one CDN (images.computer[.]com) — repeated across what appears to be a large portfolio of parked-for-sale domains, each advertising itself for sale in the page header while the AI content quietly earns its keep.

Unknown subdomains redirect to the parking marketplace. Only the pre-generated keyword combinations serve content — "insurance" being the obvious choice at the CPM rates that keyword commands.

We're not flagging a threat. It's the technique that's worth noting as an indicator of where we could be headed. RDGAs generate domain names at scale to serve malware or evade detection. This applies the same logic to content. And the wildcard DNS backend is already exactly what you'd need for the next step: on-demand generation, where a query could produce a fresh AI-written page in real time. That capability exists now. It just isn't what's running here. Yet.

#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #spam #adtech #rdga

6
1
8
0
Open post
InfobloxThreatIntel
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange · Mar 25, 2026
Infoblox Threat Intel
@InfobloxThreatIntel@infosec.exchange

This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.

infosec.exchange

Poisonseed has successfully phished enterprise email accounts for over a year to further their crypto seed phrase poisoning attacks. 🎣 ✉️ 💸

It's been one year since @troyhunt@infosec.exchange's Mailchimp phishing incident (https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/) which resulted in threat actors downloading his entire email list and creating an API key likely in an attempt to send mass emails from his account.

Before we get into some fresh domains you can hunt, here's a bit of background on this ongoing threat...

The threat actors behind this campaign are seemingly associated with The Com / Scattered Spider threat actors and use a compromised email account to send CRM phishing emails and also crypto seed phrase poisoning / crypto phishing emails. They essentially compromise a CRM to send more CRM phishing emails from it – a supply chain compromise that just keeps spreading -- very clever! The threat actors are targeting Mailchimp, Sendgrid, ActiveCampaign and allegedly other CRM providers.

We've had some great writeups in the last year on this threat including:

Validin: "Pulling the Threads on the Phish of Troy Hunt" @ https://www.validin.com/blog/pulling_threads_on_phishing_campaign

Silent Push: "PoisonSeed Campaign Targets CRM and Bulk Email Providers in Supply Chain Spam Operation" https://www.silentpush.com/blog/poisonseed/

NViso: "Shedding Light on PoisonSeed’s Phishing Kit" https://blog.nviso.eu/2025/08/12/shedding-light-on-poisonseeds-phishing-kit/

Domain Tools: "Newly Identified Domains Likely Linked to Continued Activity from PoisonSeed E-Crime Actor" https://dti.domaintools.com/research/newly-identified-domains-likely-linked-to-continued-activity-from-poisonseed-e-crime-actor

Over the last year, Poisonseed have successfully phished *dozens* of major organizations, seemingly with no or minimal public disclosures about these incidents from impacted organizations. And while we don't share victim details, we have a breakdown of the industries who have been impacted by the CRM phishing campaigns (essentially every major industry):

infosec.exchange

Troy Hunt (@troyhunt@infosec.exchange) - Infosec Exchange

2
0
3
0
Open post
InfobloxThreatIntel
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange · Feb 26, 2026
Infoblox Threat Intel
@InfobloxThreatIntel@infosec.exchange

This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.

infosec.exchange
Replying to @InfobloxThreatIntel@infosec.exchange
This is the same toolkit, but for a different campaign, that was used to create the Thanksgiving scam we mentioned in a previous post. https://infosec.exchange/@InfobloxThreatIntel/115611651417357684
1
0
1
0
Open post
InfobloxThreatIntel
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange · Feb 26, 2026
Infoblox Threat Intel
@InfobloxThreatIntel@infosec.exchange

This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.

infosec.exchange

We discovered a phishing actor that is abusing .arpa to host content on domains that should not resolve to an IP address. The actor uses free services to create domain names from reverse DNS strings for IPv6 tunnels that use the .arpa top level domain. These domains are unlikely to be blocked, much less scrutinized, by security systems as they aren’t supposed to be used in URLs. But this actor is doing just that. Every day.

We’ve seen a constant flow of phishing emails using these domains as phishing links since last November. The scam uses a toolkit that has been used since at least 2017. Another campaign using the same toolkit leverage hijacked CNAMEs of well-known government agencies, universities, telecommunication companies, media organizations, and retailers from around the world.

In our latest blog, we explain what these actors are doing and how they are doing it. We even share all the indicators we’ve uncovered.

https://www.infoblox.com/blog/threat-intelligence/abusing-arpa-the-tld-that-isnt-supposed-to-host-anything/

#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #hijackedcname

25
4
23
0

Remote instance

infosec.exchange
Open on original server

Media

313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 18:21:22 UTC