logo

Savvy Seahorse gang uses DNS CNAME records to power investor scams

ID: 53d7b7b6-e438-59e5-8034-c7e5465e4038

STIX ID: report--53d7b7b6-e438-59e5-8034-c7e5465e4038

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-02-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Infoblox researchers detail a campaign by a threat actor dubbed Savvy Seahorse that uses abused DNS CNAME records as a traffic-distribution system (CNAME TDS), domain-generation and wildcard DNS techniques, and IP rotation to run multilingual Facebook-ad-driven investment scams; victims are steered to fraudulent registration pages and fake trading platforms assisted by chatbots to harvest personal and financial data and collect payments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.