Phishing Threat From New .zip Top-Level Domain
ID: f3127a27-d923-54a5-a06c-1f517bdfb3e6
STIX ID: report--f3127a27-d923-54a5-a06c-1f517bdfb3e6
Feed Name: Arctic Wolf Blog
Threat Score
Arctic Wolf warns that Google's newly available .zip top-level domain is being abused in phishing campaigns because domains can appear as familiar file names (for example, "update.zip"). The advisory notes observed phishing activity using .zip domains, recommends blocking or restricting the TLD at network/DNS/proxy layers, increasing monitoring for related TTPs, and providing targeted user awareness training to reduce successful social engineering.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
