👋 Hey there,
Happy Sunday!
🚨 News
Massive Hijack of Trusted Brands' Subdomains for Spam Campaign
- Operation "SubdoMailing" Unveiled: Researchers have identified a massive ad fraud campaign named "SubdoMailing," leveraging over 8,000 legitimate internet domains and 13,000 subdomains to send up to five million emails per day. The campaign exploits abandoned subdomains and domains of well-known companies for malicious emails.
- Tactics for Bypassing Security: The fraudulent operation exploits SPF and DKIM email policies to bypass spam filters, utilizing the trusted nature of the hijacked domains. Tactics include CNAME hijacking and SPF record exploitation, where attackers register external domains no longer in use, pointed to by CNAME records or SPF "include:" configurations of target domains.
- Sophisticated Exploitation Techniques: The attackers craft emails using images instead of text to evade text-based filters, employ click-redirects for malicious content delivery, and leverage legitimate email services like SendGrid for distribution. This complex operation indicates a high level of resource investment and sophistication.
- Challenges and Implications for Email Security: This operation highlights the limitations of conventional email security measures, such as SPF, DKIM, and DMARC, against sophisticated phishing tactics. The reliance on domain reputation is inadequate, pointing to the necessity for advanced detection technologies that can identify and mitigate such sophisticated threats.
Savvy Seahorse Gang Exploits DNS CNAME Records for Financial Scams
- The Surprising Threat: I recently stumbled upon an article about Savvy Seahorse, a DNS threat actor who has been using CNAME records for financial scams since at least August 2021. They leverage DNS CNAME records to create a traffic distribution system (TDS) for sophisticated campaigns, enabling them to control who has access to content and dynamically update IP addresses. This technique has allowed the actor to evade detection by the security industry.
- Targeted Attacks & Techniques: Savvy Seahorse's campaigns involve Facebook ads, dedicated hosting, and regular IP address changes. They use wildcard DNS entries for a large number of independent campaigns and a secondary HTTP-based TDS server for validating victim information and applying geofencing. The actor has been operating for at least a year, with approximately 4.2k base domains using the 'b36cname[.]site' CNAME.
- Impact & Severity: The Savvy Seahorse campaigns have resulted in over $4.6 billion in stolen funds from victims in the US alone. The actor targets Russian, Polish, Italian, German, Czech, Turkish, French, Spanish, and English speakers while excluding Ukraine and a handful of other countries.
- Recommendations: To mitigate the risk of falling victim to such campaigns, I recommend monitoring for the IOCs and ensuring security tools can detect and alert on similar campaigns. Regularly update security tools, monitor for unusual DNS activity, and stay vigilant for new phishing or investment scams.