logo

Infoblox Threat Intel Blog

ID: ca5a5d7c-5b69-538a-89e5-cad879478bfa

STIX ID: identity--ca5a5d7c-5b69-538a-89e5-cad879478bfa

Feed Type: rss

Earliest post: 2024-05-28

Latest post: 2026-09-15

Research-driven DNS threat intelligence, highlighting emerging domains, threat actor infrastructure, and global DNS abuse patterns.

01/01/2020
09/29/2026
Title Date Published ↓Threat ScoreAuthorVisible
How Money Laundering, Scams, and Espionage Hide in a Web Full of Casino Garbage2026-09-1585Infoblox Threat IntelTrue
$7 Million in Expired Domains Fuel a Streaming Empire with a Malware Secret2026-08-1380Infoblox Threat IntelTrue
Dropcatch Scavengers: Expired Malicious Domains Become Cash Cows2026-08-1375Infoblox Threat IntelTrue
The Procurement Trap: Inside an AiTM Campaign Targeting Global Institutions2026-07-2175Infoblox Threat IntelTrue
Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real Victims2026-07-0778Infoblox Threat IntelTrue
From San Pedro to Salinas: How a Chinese Framework “DCloud Uni-App” Powers a Global Scam Economy2026-06-2570Infoblox Threat IntelTrue
Hot Take: Operation Endgame vs. SocGholish2026-06-1878Infoblox Threat IntelTrue
Residential Proxies in the Wild2026-06-0965Infoblox Threat IntelTrue
Lookalike Domains Expose the iPhone Theft Economy2026-05-1470Infoblox Threat IntelTrue
Hold the Phone! International Revenue Share Fraud Driven by Fake CAPTCHAs2026-04-2365Infoblox Threat IntelTrue
Scams, Slaves and (Malware-as-a) Service: Tracking a Trojan to Cambodia’s Scam Centers2026-04-1080Infoblox Threat IntelTrue
Patterns, Pirates, and Provider Action: What We Learned Working with Keitaro2026-03-3175Infoblox Threat IntelTrue
No Reach, No Risk: The Keitaro Abuse in Modern Cybercrime Distribution2026-03-2678Infoblox Threat IntelTrue
Inside Keitaro Abuse: A Persistent Stream of AI-Driven Investment Scams2026-03-1975Infoblox Threat IntelTrue
Abusing .arpa: The TLD That Isn’t Supposed to Host Anything2026-02-2670Infoblox Threat IntelTrue
Banners, Bots and Butchers: An Automated Long Con Targeting Japan, Asia, and Beyond2026-02-1770Infoblox Threat IntelTrue
Compromised Routers, DNS, and a TDS Hidden in Aeza Networks2026-02-0370Infoblox Threat IntelTrue
Inside a Malicious Push Network: What 57M Logs Taught Us2026-01-1550Infoblox Threat IntelTrue
Kimwolf Howls from Inside the Enterprise2026-01-1370Renée BurtonTrue
Scaling the Fraud Economy: Pig Butchering as a Service2026-01-0878Infoblox Threat IntelTrue
Parked Domains Become Weapons with Direct Search Advertising2025-12-1678Infoblox Threat IntelTrue
Parked Domains Become Weapons with Direct Search Advertising2025-12-1678Infoblox Threat IntelTrue
DNS Uncovers Infrastructure Used in SSO Attacks2025-12-0178Infoblox Threat IntelTrue
DNS Uncovers Infrastructure Used in SSO Attacks2025-12-0175Infoblox Threat IntelTrue
Vault Viper: High Stakes, Hidden Threats2025-10-2388Infoblox Threat IntelTrue
Vault Viper: High Stakes, Hidden Threats2025-10-2380Infoblox Threat IntelTrue
Pig Butchering Scams and Their DNS Trail: Linking Threats to Malicious Compounds2025-10-0975Infoblox Threat IntelTrue
Detour Dog: DNS Malware Powers Strela Stealer Campaigns2025-09-3080Infoblox Threat IntelTrue
Detour Dog: DNS Malware Powers Strela Stealer Campaigns2025-09-3080Infoblox Threat IntelTrue
Deniability by Design: DNS-Driven Insights into a Malicious Ad Network2025-09-1675Infoblox Threat IntelTrue
Deniability by Design: DNS-Driven Insights into a Malicious Ad Network2025-09-1678Infoblox Threat IntelTrue
Inside the Robot: Deconstructing VexTrio’s Affiliate Advertising Platform2025-08-1475Infoblox Threat IntelTrue
Inside the Robot: Deconstructing VexTrio’s Affiliate Advertising Platform2025-08-1478Infoblox Threat IntelTrue
VexTrio Unmasked: A Legacy of Spam and Homegrown Scams2025-08-1270Infoblox Threat IntelTrue
VexTrio Unmasked: A Legacy of Spam and Homegrown Scams2025-08-1272Infoblox Threat IntelTrue
VexTrio’s Origin Story: From Spam to Scam to Adtech2025-08-0675Infoblox Threat IntelTrue
VexTrio’s Origin Story: From Spam to Scam to Adtech2025-08-0675Infoblox Threat IntelTrue
Vexing and Vicious: The Eerie Relationship between WordPress Hackers and an Adtech Cabal2025-06-1275Infoblox Threat IntelTrue
Vexing and Vicious: The Eerie Relationship between WordPress Hackers and an Adtech Cabal2025-06-1278Infoblox Threat IntelTrue
Cloudy with a Chance of Hijacking Forgotten DNS Records Enable Scam Actor2025-05-2072Infoblox Threat IntelTrue
Cloudy with a Chance of Hijacking Forgotten DNS Records Enable Scam Actor2025-05-2070Infoblox Threat IntelTrue
Telegram Tango: Dancing with a Scammer2025-05-0645Infoblox Threat IntelTrue
Telegram Tango: Dancing with a Scammer2025-05-0635Infoblox Threat IntelTrue
Uncovering Actor TTP Patterns and the Role of DNS in Investment Scams2025-04-2870Infoblox Threat IntelTrue
DNS Early Detection – Malicious Trojan Installers for WINSCP and PUTTY – Breaking the Kill Chain2024-08-2975Michael ZuckermanTrue
DNS Early Detection – Breaking the Black Basta Ransomware Kill Chain2024-08-0178Michael ZuckermanTrue
Who Knew? Domain Hijacking Is So Easy2024-07-3175Infoblox Threat IntelTrue
Let’s Be Careful Out There2024-07-2545Cricket LiuTrue
Gambling is No Game: DNS Links Between Chinese Organized Crime and Sports Sponsorships2024-07-2275Infoblox Threat IntelTrue
RDGAs: The Next Chapter in Domain Generation Algorithms2024-07-1775Infoblox Threat IntelTrue

1–50 of 54