Savvy Seahorse gang uses DNS CNAME records to power investor scams
ID: 53d7b7b6-e438-59e5-8034-c7e5465e4038
STIX ID: report--53d7b7b6-e438-59e5-8034-c7e5465e4038
Feed Name: Bleeping Computer
Threat Score
Infoblox researchers detail a campaign by a threat actor dubbed Savvy Seahorse that uses abused DNS CNAME records as a traffic-distribution system (CNAME TDS), domain-generation and wildcard DNS techniques, and IP rotation to run multilingual Facebook-ad-driven investment scams; victims are steered to fraudulent registration pages and fake trading platforms assisted by chatbots to harvest personal and financial data and collect payments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
