logo

Pig Butchering Scams and Their DNS Trail: Linking Threats to Malicious Compounds

ID: 5a9b0863-8c04-501d-886c-a43e6d521e23

STIX ID: report--5a9b0863-8c04-501d-886c-a43e6d521e23

Feed Name: Infoblox Threat Intel Blog

Date Published: 2025-10-09

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

The report analyzes industrialized pig-butchering fraud run from Southeast Asian crime strongholds (GTSEZ in Laos and KK Park in Myanmar), showing how syndicates leverage pig-butchering-as-a-service to mass-produce near-identical investment/gambling sites, reuse DNS/hosting templates, briefly expose infrastructure before hiding behind Cloudflare, and launder proceeds through no-KYC crypto casinos. Using passive DNS and shared code patterns, researchers link clusters to Kings Romans’ Landun/Blue Shield brand and the Carrod Securities case, noting rotating wallet addresses and scripted social-engineering playbooks. The authors argue that DNS-centric detection and recognition of shared infrastructure fingerprints are key to disrupting these fast-moving, disposable-domain campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.