logo

Abusing .arpa: The TLD That Isn’t Supposed to Host Anything

ID: b05c9225-7b75-5337-8663-99ca18f27fa3

STIX ID: report--b05c9225-7b75-5337-8663-99ca18f27fa3

Feed Name: Infoblox Threat Intel Blog

Threat Score
70/100

Date Published: 2026-02-26

Date Updated: 2026-04-28

Author: Infoblox Threat Intel

...
...

This report examines active phishing campaigns that use a novel technique: creating A records for IPv6 reverse DNS (ip6.arpa) names after acquiring delegated IPv6 space—enabling malicious, reputation-free links embedded in email images that redirect users through traffic distribution systems to fraudulent landing pages. The actors also leverage hijacked dangling CNAMEs and domain shadowing across reputable services (e.g., Cloudflare, Hurricane Electric) to increase deliverability and evade detection; the report includes example indicators, abused domains, and notes on detection challenges and mitigation implications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.