logo

Phishing Schemes Abuse .arpa TLD and IPv6 Tunnels to Evade Detection

ID: c653304d-f3e7-529d-8121-05362059e517

STIX ID: report--c653304d-f3e7-529d-8121-05362059e517

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-02-28

Date Updated: 2026-04-21

Author: Dhivya

...
...

Infoblox Threat Intel details a sophisticated phishing campaign that abuses the .arpa namespace and IPv6 tunnel services to publish conventional A records under reverse DNS domains, bypassing reputation-based security controls. Attackers use malspam with hyperlinked images, a Traffic Distribution System that fingerprints users (favoring mobile/residential IPs), and hijacked/expired CNAMEs from trusted organizations; the report includes numerous IOCs and recommends monitoring the .arpa namespace and unusual DNS record additions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.