Abusing .arpa: The TLD That Isn’t Supposed to Host Anything
ID: b05c9225-7b75-5337-8663-99ca18f27fa3
STIX ID: report--b05c9225-7b75-5337-8663-99ca18f27fa3
Feed Name: Infoblox Threat Intel Blog
This report examines active phishing campaigns that use a novel technique: creating A records for IPv6 reverse DNS (ip6.arpa) names after acquiring delegated IPv6 space—enabling malicious, reputation-free links embedded in email images that redirect users through traffic distribution systems to fraudulent landing pages. The actors also leverage hijacked dangling CNAMEs and domain shadowing across reputable services (e.g., Cloudflare, Hurricane Electric) to increase deliverability and evade detection; the report includes example indicators, abused domains, and notes on detection challenges and mitigation implications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
