Operation TrustTrap Reveals 16,800 Fake Domains Exploiting User Trust
ID: 84a1340f-d009-5147-b272-957baaf79600
STIX ID: report--84a1340f-d009-5147-b272-957baaf79600
Feed Name: The Cyber Express
Operation TrustTrap is a large-scale domain-spoofing campaign tracked by CRIL that leveraged over 16,800 malicious domains to impersonate government portals (notably DMV/toll/registration services) and harvest credentials and payment card data. Attackers used "subdomain trust injection" and hyphen-based semantic manipulation to create visually convincing URLs, mainly hosted on Tencent Cloud and Alibaba Cloud APAC and registered through registrars like Gname.com; CRIL observed targeting across the US, India, Vietnam, and the UK and noted similarities to APT36 activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
