The .gov Illusion: Inside the 16,800-Domain “Operation Trust Trap” Campaign
ID: 92ea322f-3ef7-5632-8c54-dfa38f0becf8
STIX ID: report--92ea322f-3ef7-5632-8c54-dfa38f0becf8
Feed Name: securityonline.info
Cyble Research and Intelligence Labs (CRIL) uncovered “Operation Trust Trap,” a large-scale phishing campaign of ~16,800 rapidly rotating domains that mimic government URLs via subdomain trust injection and hyphen manipulation to harvest credentials and payment data; the campaign is US‑centric (targeting state services like DMVs and toll systems) with international lures and an infrastructure hosted on Tencent/Alibaba Cloud, and CRIL observed a cluster consistent with APT36 activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
