logo

Abusing .arpa: The TLD That Isn’t Supposed to Host Anything

ID: debcf79f-9382-53d7-b8ac-3e3dd908166c

STIX ID: report--debcf79f-9382-53d7-b8ac-3e3dd908166c

Feed Name: Infoblox Blog

Threat Score
70/100

Date Published: 2026-02-26

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

This intelligence report describes phishing campaigns that weaponize IPv6 reverse DNS (ip6.arpa) by creating A records for reverse FQDNs—combined with hijacked CNAMEs, subdomain shadowing, and traffic distribution systems—to evade detection and host malicious landing pages; the report includes campaign timelines, example HTML/lures, provider abuse (Cloudflare, Hurricane Electric), short-lived indicators, and a table of observed domains and TDS hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.