Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Infoblox Threat Intel

@InfobloxThreatIntel@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

This account is shared by Infoblox Threat Intel researchers including Axur research team. We analyze data and create algorithms to find malicious and suspicious domains and IPs, using DNS.

0 Followers
0 Following
11 Posts
Joined December 20, 2023
Prolific Puma Malicious Link Shortener:
https://blogs.infoblox.com/cyber-threat-intelligence/prolific-puma-shadowy-link-shortening-service-enables-cybercrime/
Sitting Ducks DNS Attack:
https://blogs.infoblox.com/threat-intelligence/who-knew-domain-hijacking-is-so-easy/
Vigorish Viper China Organized Crime:
https://insights.infoblox.com/resources-report/infoblox-report-vigorish-viper-a-venomous-bet
VexTrio Deploys New DNS TDS:
https://blogs.infoblox.com/cyber-threat-intelligence/cyber-threat-advisory/vextrio-deploys-dns-based-tds-server/
Decoy Dog is No Ordinary Pupy:
https://blogs.infoblox.com/cyber-threat-intelligence/decoy-dog-is-no-ordinary-pupy-distinguishing-malware-via-dns/
Infoblox Threat Intel:
https://www.infoblox.com/threat-intel/
Open post
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange
· 2w ago
Is your bank now offering gambling? Probably not, but someone wants you to think so. A previously documented cluster (https://infosec.exchange/@InfobloxThreatIntel/116001809925553061) has ramped up its activity across Latin America over the past few weeks, spoofing the brands of regional financial institutions to distribute algorithmically generated domains (RDGA) via Meta Ads, with per-user tracking capabilities throughout the entire activity flow. The sites and apps this Latin American cluster are promoting appear to be classic scam gambling or "scambling" websites, a topic we recently covered @ "How Money Laundering, Scams, and Espionage Hide in a Web Full of Casino Garbage" @ https://www.infoblox.com/blog/threat-intelligence/how-money-laundering-scams-and-espionage-hide-in-a-web-full-of-casino-garbage/ The sites behind these domains operate with multiple anti-analysis layers: through user-agent gating, they serve differentiated content based on device, browser, and region, actively blocking any client outside the target profile. The kit has a clear Russian development context, featuring Russian-language comments at the code level and integrated Yandex telemetry fields. This isn't the first time that a scambling campaign has seen ties to Russia, with @briankrebs@infosec.exchange writing about this last Summer in his piece "Affiliates Flock to 'Soulless' Scam Gambling Machine" @ https://krebsonsecurity.com/2025/08/affiliates-flock-to-soulless-scam-gambling-machine/ When a victim accesses one of the sites in the current campaign from a target environment, it deploys a layout spoofing Google Play, financial brands, and other brands to distribute Progressive Web Apps (PWAs), Chrome-installable applications that bypass any official app store and require no malicious binaries. Once installed, these PWAs act as a traffic-funneling mechanism toward illegal casinos operated from Russia or low-regulation jurisdictions such as Curaçao. Some of these casinos are conveniently tailored to the target the region, accepting payments through local financial institution gateways in addition to cryptocurrency. In other cases, there are signs of fraud based on the impersonation of state lotteries and betting markets on already-concluded events — indicators of potential crypto-based asset theft schemes. The campaign has confirmed presence in Argentina, Chile, Brazil, Mexico, and Colombia. If history is any indication, if you take the bait and deposit at one of these casinos they are promoting, which can seem like "free money" as they promote generous deposit bonuses, you will likely never see that money again. And even if you win on any games they are hosting, you'll likely face one cash out challenge after another until the organization attempts to disappear. Scam, Run, Rinse and Repeat - a process which is becoming a criminal business model as scambling continues to scale in 2026. #scambling #malvertising #RDGA #FakeApp #Scam #Gambling
Infoblox Blog

Illegal Gambling Sites Reveal Three Types of Cybercrime

Casino websites that look nearly identical disguise three major types of crime: money laundering, gambling scams, and a front for China-aligned APT malware C2.

4
0
6
0
Open post
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange
· 1mo ago
validx[.]shop looked fine at first glance. "Normal" name servers, a real mail setup, nothing that immediately stood out at the apex level. One subdomain didn't quite fit, though. It was getting DNS queries that were absurdly long and frequent for a new domain that nobody was really visiting. Rather than that being web traffic, we detected it as likely tunneling. Turns out it wasn't a one-off. The same setup shows up on hundreds of other domains. The domain names follow a similar pattern: short, brandable and portmanteau-y (i.e., cordkit, zenithly, queuebox), spread across a long list of cheap gTLDs with the same registrar. The tunnel itself is answering with TXT records like: ⚠️ "H2;n=5;k=3;ol=2004;sz=800;cz=gz" As best as we can tell, that's a shard count, a reconstruction threshold, a length, a chunk size, and a compression flag. We checked the signature against a number of known DNS tunnelling tools and none of them write a header like this. We watched two more domains get registered mid-investigation, hours apart, which was fun to see and immediately block :ablobcatpopcorn: We've got the infrastructure and the method. We haven't got a payload, and we haven't matched this header format to anything documented publicly. Has anyone else run into this, recognize the TXT format above, or have a sample of a possible malware source? We'd like to hear from you. ⛔ validx[.]shop ⛔ cordkit[.]online ⛔ zenithly[.]best ☠️ 95[.]179[.]159[.]229 #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #c2
16
0
18
0
Open post
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange
· 3w ago
Solicitar senha. Solicitar token. Token inválido. Aguardar. That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time. Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one. No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like. Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal. Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other. Phishing domains: ⛔️ pactualapp[.]com ⛔️ pactualpj[.]com ⛔️ pactual[.]live ⛔️ ativarbia[.]net ⛔️ ativarbia[.]com ⛔️ pactualapp[.]live ⛔️ centraldecancelamentos[.]pt ⛔️ verificador-cliente[.]live ⛔️ ativador-login[.]click #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm
1
0
1
0
Open post
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange
· 3mo ago

We track algorithms that generate domain names (RDGA). Now we're looking at one that generates the content. It's a strange collision of domain parking and AI generated nonsense.

A portfolio of parked domains, each with a wildcard DNS record and a backend that serves pre-generated AI content for specific keyword combinations:

  • insurance.howtomakeasmoothie[.]com → "Why You Need Insurance When Making Smoothies"
  • insurance.backsplashdesign[.]com → "A Guide to Backsplash Insurance"
  • yacht.insurance.backpainmedication[.]com → a wellness journey involving sailing, spinal health, and coverage options

The subdomain labels are the content brief. The domain topic is the flavour. The result is grammatically sound, mildly persuasive, and reads like it was written by someone who has heard of both topics but has never encountered either. It's AI slop at its finest. The article on smoothie insurance confidently recommends coverage "for peace of mind." The one on backsplash insurance suggests you may need a specialist endorsement. Nobody proofread these. Nobody needed to — the target audience is a crawler, not a person, and crawlers don't find non-sequiturs suspicious.

One template, one analytics pixel (stats.computer[.]com), one CDN (images.computer[.]com) — repeated across what appears to be a large portfolio of parked-for-sale domains, each advertising itself for sale in the page header while the AI content quietly earns its keep.

Unknown subdomains redirect to the parking marketplace. Only the pre-generated keyword combinations serve content — "insurance" being the obvious choice at the CPM rates that keyword commands.

We're not flagging a threat. It's the technique that's worth noting as an indicator of where we could be headed. RDGAs generate domain names at scale to serve malware or evade detection. This applies the same logic to content. And the wildcard DNS backend is already exactly what you'd need for the next step: on-demand generation, where a query could produce a fresh AI-written page in real time. That capability exists now. It just isn't what's running here. Yet.

#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #spam #adtech #rdga

9
1
8
0
Open post
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange
· 2mo ago
We've been tracking an AiTM phishing campaign targeting universities, enterprises, and multinational institutions — EU and UN agencies included. The actor favors likely compromised domains to host fake document portals and spoofed login pages. The attack chain runs through multiple phishing kits — EvilProxy, FlowerStorm, Kali365 — all built to proxy sessions in real time. The victim completes MFA. The attacker collects the session token. Authentication worked perfectly, for both parties. What makes this trackable: RDGA patterns, subdomain conventions, and infrastructure reuse leave a legible fingerprint in passive DNS — upstream of the login page, before any credential changes hands. :no_entry:️ usersatisfactionlab[.]de :no_entry:️ assessmentevaluationreport[.]com :no_entry:️ duemineral[.]uk https://www.infoblox.com/blog/threat-intelligence/the-procurement-trap-inside-an-aitm-campaign-targeting-global-institutions/ #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm #rdga
Inside a Global Procurement-Themed AiTM Phishing Campaign
Infoblox Blog

Inside a Global Procurement-Themed AiTM Phishing Campaign

Researchers discover a phishing campaign targeting global enterprises and agencies using multiple AiTM phishing kits to bypass MFA and steal sessions.

2
0
0
0
Open post
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange
· 6mo ago

Poisonseed has successfully phished enterprise email accounts for over a year to further their crypto seed phrase poisoning attacks. 🎣 ✉️ 💸

It's been one year since @troyhunt@infosec.exchange's Mailchimp phishing incident (https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/) which resulted in threat actors downloading his entire email list and creating an API key likely in an attempt to send mass emails from his account.

Before we get into some fresh domains you can hunt, here's a bit of background on this ongoing threat...

The threat actors behind this campaign are seemingly associated with The Com / Scattered Spider threat actors and use a compromised email account to send CRM phishing emails and also crypto seed phrase poisoning / crypto phishing emails. They essentially compromise a CRM to send more CRM phishing emails from it – a supply chain compromise that just keeps spreading -- very clever! The threat actors are targeting Mailchimp, Sendgrid, ActiveCampaign and allegedly other CRM providers.

We've had some great writeups in the last year on this threat including:

Validin: "Pulling the Threads on the Phish of Troy Hunt" @ https://www.validin.com/blog/pulling_threads_on_phishing_campaign

Silent Push: "PoisonSeed Campaign Targets CRM and Bulk Email Providers in Supply Chain Spam Operation" https://www.silentpush.com/blog/poisonseed/

NViso: "Shedding Light on PoisonSeed’s Phishing Kit" https://blog.nviso.eu/2025/08/12/shedding-light-on-poisonseeds-phishing-kit/

Domain Tools: "Newly Identified Domains Likely Linked to Continued Activity from PoisonSeed E-Crime Actor" https://dti.domaintools.com/research/newly-identified-domains-likely-linked-to-continued-activity-from-poisonseed-e-crime-actor

Over the last year, Poisonseed have successfully phished *dozens* of major organizations, seemingly with no or minimal public disclosures about these incidents from impacted organizations. And while we don't share victim details, we have a breakdown of the industries who have been impacted by the CRM phishing campaigns (essentially every major industry):

A Sneaky Phish Just Grabbed my Mailchimp Mailing List
Troy Hunt

A Sneaky Phish Just Grabbed my Mailchimp Mailing List

You know when you're really jet lagged and really tired and the cogs in your head are just moving that little bit too slow? That's me right now, and the penny has just dropped that a Mailchimp phish has grabbed my credentials, logged into my account and exported

2
0
3
0
Open post
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange
· 7mo ago
Replying to
This is the same toolkit, but for a different campaign, that was used to create the Thanksgiving scam we mentioned in a previous post. https://infosec.exchange/@InfobloxThreatIntel/115611651417357684
infosec.exchange
1
0
1
0
Open post
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange
· 2mo ago
Interesting scam story with support and commentary from one of our researchers. Quoting Zach Edwards from his highlights of the story: A bunch of NFL players were targeted in an ecommerce investment scam and likely lost millions of dollars to a 24-year old guy based in the U.S.. The threat actor(s) behind it created multiple Shopify stores and were creating numerous “manual orders” on Shopify for bulk orders and then marking them as paid. The victims were given admin credentials on those Shopify stores so that when they logged in they could see the revenue growth and orders, and unless you drilled into the order details, you may not have any clue that something was wrong. #scam #cybercrime #cybersecurityhttps://www.barrons.com/articles/nfl-players-shopify-fake-stores-4d90d418?st=ZVjTeu
barrons.com
0
0
0
0
Open post
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange
· 1mo ago
Season's Scammings 🔅 🎄 We've been tracking a cluster of personal loan phishing sites that work hard to look like independent lenders — different brands, different domains, even deliberately varied infrastructure. Look closely enough, though, and the seams show. Similar underlying templates. The same technology stack. And passive DNS tying their thousands of domains back to the same operator. The sites present as loan applications. Name, address, employment details, financial history. And then, at the final step: your Social Security Number. No real company name. No regulatory disclosure. Just a form — and your most sensitive personal data sent off to who-knows-where for who-knows-what. A significant portion of the domains are seasonal — Christmas cash, Thanksgiving funds, Black Friday loans. Financially stretched consumers, at exactly the moment they're most likely to reach for a quick fix. ⛔ mychristmaswallet[.]com ⛔ cashzillaloans[.]com ⛔ personalreliefwallet[.]com ⛔ thanksgivingcash-5k[.]com ⛔ christmascashhelp-direct[.]com #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #scam
0
0
0
0
Open post
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange
· 1w ago
Quiz time: which of these domains is impersonating Apple? quizearny[.]shop, rewardquiz[.]org look like generic quiz sites. applerewards[.]net is more obvious. All of them belong to a cluster serving identical Apple impersonation content, prompting victims to claim an Apple gift card reward by handing over their personal details. testar[.]ink, "to test", was the first to be created, nearly a month before the others went live, which may say something about how this campaign got started. What makes this cluster more interesting is what happens after you click the "Claim Your Apple Reward" button on the initial page. Different locations, different device types, different destinations. Classic TDS. This cluster is a good reminder that brand impersonation lives in the page content, not just the domain name. A quiz site with no Apple in its name can be just as dangerous as an obvious lookalike. #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #axur #lookalike #scam #tds
0
0
9
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:08:52 UTC