logo

Cybercriminals Using Novel DNS Hijacking Technique for Investment Scams

ID: 2904d359-1920-5097-8125-e725b41d81bb

STIX ID: report--2904d359-1920-5097-8125-e725b41d81bb

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2024-03-05

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Infoblox researchers describe “Savvy Seahorse,” a DNS-based fraud operation that uses CNAME-based traffic distribution, DGA-generated short-lived subdomains, and social-media ads (plus fake ChatGPT/WhatsApp bots) to lure multi-language victims into fake investment platforms, collect personal data, and steal deposited funds; the infrastructure’s CNAME/TDS design enhances evasion and resistance to takedown.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.