logo

p6.arpa Wildcard Abuse: Hunting Phishing Infrastructure Across IPv6 Prefixes

ID: 67b37e84-feb8-5310-81f2-20a393b4d950

STIX ID: report--67b37e84-feb8-5310-81f2-20a393b4d950

Feed Name: CloudSEK Blog

Threat Score
65/100

Date Published: 2026-03-25

Date Updated: 2026-05-13

...
...

The report documents an active phishing technique that abuses ip6.arpa reverse DNS by delegating /48 IPv6 reverse zones and adding wildcard A records so every randomized nibble-prefixed subdomain resolves to attacker infrastructure, allowing per-recipient unique phishing URLs that evade reputation-based email and URL scanners; a global scan of 127,906 prefixes found 384 zones with Cloudflare NS (staged) and two confirmed malicious zones (one Cloudflare-proxied, one hosted at 85.215.34.119), and the authors recommend DNS anomaly detection (block A/AAAA for .arpa), RPZ rules, enhanced URL extraction, and monitoring of delegated .ip6.arpa zones.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.