logo

Hackers Abuse .arpa Top-Level Domain to Host Phishing Scams

ID: 841c24a7-46c9-59d9-8959-666cd530476c

STIX ID: report--841c24a7-46c9-59d9-8959-666cd530476c

Feed Name: HackRead

Threat Score
65/100

Date Published: 2026-03-03

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

Infoblox researchers uncovered an active phishing campaign in which threat actors leverage the reserved .arpa TLD and free IPv6 tunnels to host fraudulent sites that evade traditional security checks. The actors pair this with dangling CNAME hijacks, domain shadowing, and Traffic Distribution Systems to scale attacks against organizations (including media and universities) and deliver payment‑card‑stealing phishing lures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.