Phishing Schemes Abuse .arpa TLD and IPv6 Tunnels to Evade Detection
Infoblox Threat Intel has identified a sophisticated phishing campaign that leverages the .arpa top-level domain (TLD) and IPv6 tunnels to bypass enterprise security controls. This method circumvents traditional domain reputation checks, posing new…
Infoblox Threat Intel has identified a sophisticated phishing campaign that leverages the .arpa top-level domain (TLD) and IPv6 tunnels to bypass enterprise security controls. This method circumvents traditional domain reputation checks, posing new challenges for network defense systems.
The .arpa domain is reserved for internal internet infrastructure, primarily used for reverse DNS mapping. However, threat actors are exploiting vulnerabilities in the DNS record management systems of certain providers.
By utilizing free IPv6 tunnel services, attackers gain control over specific IPv6 address blocks. Instead of creating reverse DNS pointer (PTR) records, they generate standard A records for these .arpa subdomains. This results in fully qualified domain names that security tools inherently trust.
The attack sequence often starts with emails impersonating major brands. These emails contain a hyperlinked image that, when clicked, redirects the user through a Traffic Distribution System (TDS) to deliver a malicious payload. This campaign also exploits dangling CNAME hijacking by compromising abandoned subdomains of reputable entities.
According to Infoblox, weaponizing the .arpa namespace transforms core internet infrastructure into a phishing delivery mechanism. Due to the clean reputation of reverse DNS domains, standard security tools are ineffective in detection. Organizations are advised to treat DNS infrastructure as a potential attack surface and implement specialized filtering for unusual record additions in the .arpa namespace.
Indicator Description
This method circumvents traditional domain reputation checks, posing new challenges for network defense systems.
<10 random letters>.5.2.1.6.3.0.0.0.7.4.0.1.0.0.2[.]ip6[.]arpa IPv6 reverse DNS domain with DGA subdomain
<10 random letters>.1.9.5.0.9.1.0.0.0.7.4.0.1.0.0.2[.]ip6[.]arpa IPv6 reverse DNS domain with DGA subdomain
<10 random letters>.8.1.9.5.0.9.1.0.0.0.7.4.0.1.0.0.2[.]ip6[.]arpa IPv6 reverse DNS domain with DGA subdomain
actinismoleil[.]sbs Malicious phishing domain
cablecomparison[.]shop Malicious phishing domain
dulcetoj[.]com TDS domain
publicnoticessites[.]com Domain with a subdomain acting as a hijacked CNAME
Organizations are urged to implement monitoring measures for DNS infrastructure to identify and mitigate potential threats.
Based on reporting by Cyber Security News.
