Cybercriminals Using Novel DNS Hijacking Technique for Investment Scams
ID: 2904d359-1920-5097-8125-e725b41d81bb
STIX ID: report--2904d359-1920-5097-8125-e725b41d81bb
Feed Name: The Hacker News
Threat Score
Infoblox researchers describe “Savvy Seahorse,” a DNS-based fraud operation that uses CNAME-based traffic distribution, DGA-generated short-lived subdomains, and social-media ads (plus fake ChatGPT/WhatsApp bots) to lure multi-language victims into fake investment platforms, collect personal data, and steal deposited funds; the infrastructure’s CNAME/TDS design enhances evasion and resistance to takedown.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
