logo

DNS Early Detection – Breaking the Fake Web3 Gaming Kill Chain

ID: 978f66b8-1266-586b-a9e6-68d6e70bffe7

STIX ID: report--978f66b8-1266-586b-a9e6-68d6e70bffe7

Feed Name: Infoblox Threat Intel Blog

Threat Score
70/100

Date Published: 2024-05-29

Date Updated: 2026-04-28

Author: Michael Zuckerman

...
...

Infoblox analyzed a Russian cybercrime campaign that uses counterfeit Web3 gaming projects, fake websites, ads, and messaging channels to lure victims into downloading infostealers (Stealc, Rhadamanthys, RisePro, AMOS) targeting Windows and macOS; Infoblox’s DNS Early Detection flagged 71.43% of the campaign domains as SUSPICIOUS an average of 115.4 days before OSINT listings and often within days of WHOIS registration, demonstrating the value of proactive suspicious-domain feeds for early blocking and disruption.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.