Hackers abuse .arpa DNS and ipv6 to evade phishing defenses
ID: 3eb33c18-88ee-511f-875b-d4f039068387
STIX ID: report--3eb33c18-88ee-511f-875b-d4f039068387
Feed Name: Bleeping Computer
Infoblox observed a sophisticated phishing campaign that leverages abuse of the special-use .arpa reverse DNS (ip6.arpa) by obtaining IPv6 address blocks and configuring non-standard DNS records (e.g., A records) and hijacked CNAMEs to host short-lived phishing sites. Attackers use reputable DNS providers (Cloudflare, Hurricane Electric) and traffic distribution systems to evade detection and selectively serve phishing content, making these URLs harder for email gateways and reputation systems to flag.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
