By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Neglected Domains Used in Malspam to Evade SPF and DMARC Security Protections
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Neglected Domains Used in Malspam to Evade SPF and DMARC Security Protections
Tech News

Neglected Domains Used in Malspam to Evade SPF and DMARC Security Protections

By Viral Trending Content 8 Min Read
Share
SHARE
Neglected Domains

Cybersecurity researchers have found that bad actors are continuing to have success by spoofing sender email addresses as part of various malspam campaigns.

Faking the sender address of an email is widely seen as an attempt to make the digital missive more legitimate and get past security mechanisms that could otherwise flag it as malicious.

While there are safeguards such as DomainKeys Identified Mail (DKIM), Domain-based Message Authentication, Reporting and Conformance (DMARC), and Sender Policy Framework (SPF) that can be used to prevent spammers from spoofing well-known domains, it has increasingly led them to leverage old, neglected domains in their operations.

In doing so, the email messages are likely to bypass security checks that rely on the domain age as a means to identify spam.

DNS threat intelligence firm, in a new analysis shared with The Hacker News, discovered that threat actors, including Muddling Meerkat and others, have abused some of its own old, disused top-level domains (TLDs) that haven’t been used to host content for nearly 20 years.

“They lack most DNS records, including those that are typically used to check the authenticity of a sender domain, e.g., Sender Policy Framework (SPF) records,” the company said. “The domains are short and in highly reputable TLDs.”

Cybersecurity

One such campaign, active since at least December 2022, involves distributing email messages with attachments containing QR codes that lead to phishing sites. It also instructs recipients to open the attachment and use the AliPay or WeChat apps on their phones to scan the QR code.

The emails employ tax-related lures written in Mandarin, while also locking the QR code documents behind a four-digit password included in the email body in different ways. The phishing site, in one case, urged users to enter their identification and card details, and then make a fraudulent payment to the attacker.

“Although the campaigns do use the neglected domains we see with Muddling Meerkat, they appear to broadly spoof random domains, even ones that do not exist,” Infoblox explained. “The actor may use this technique to avoid repeated emails from the same sender.”

The company said it also observed phishing campaigns that impersonate popular brands like Amazon, Mastercard, and SMBC to redirect victims to fake login pages using traffic distribution systems (TDSes) with an aim to steal their credentials. Some of the email addresses that have been identified as using spoofed sender domains are listed below –

  • ak@fdd.xpv[.]org
  • mh@thq.cyxfyxrv[.]com
  • mfhez@shp.bzmb[.]com
  • gcini@vjw.mosf[.]com
  • iipnf@gvy.zxdvrdbtb[.]com
  • zmrbcj@bce.xnity[.]net
  • nxohlq@vzy.dpyj[.]com

A third category of spam relates to extortion, wherein email recipients are asked to make a $1800 payment in Bitcoin to delete embarrassing videos of themselves that were recorded using a purported remote access trojan installed on their systems.

“The actor spoofs the user’s own email address and challenges them to check it and see,” Infoblox The email tells the user that their device has been compromised, and as proof, the actor alleges that the message was sent from the user’s own account.”

The disclosure comes as legal, government and construction sectors have been targeted by a new phishing campaign dubbed Butcher Shop that aims to steal Microsoft 365 credentials since early September 2024.

The attacks, per Obsidian Security, abuse trusted platforms like Canva, Dropbox DocSend, and Google Accelerated Mobile Pages (AMPs) to redirect users to the malicious sites. Some of the other channels include emails and compromised WordPress sites.

“Before displaying the phishing page, a custom page with a Cloudflare Turnstile is shown to verify that the user is, in fact, human,” the company said. “These turnstiles make it harder for email protection systems, like URL scanners, to detect phishing sites.”

In recent months, SMS phishing campaigns have been observed impersonating law enforcement authorities in the U.A.E. to send fake payment requests for non-existent traffic violations, parking violations, and license renewals. Some of the bogus sites set up for this purpose have been attributed to a known threat actor called Smishing Triad.

Banking customers in the Middle East have also been targeted by a sophisticated social engineering scheme that impersonates government officials in phone calls and employs remote access software to steal credit card information and one-time passwords (OTPs).

The campaign, assessed to be the work of unknown native Arabic speakers, has been found to be primarily directed against female consumers who have had their personal data leaked via stealer malware on the dark web.

“The scam specifically targets individuals who have previously submitted commercial complaints to the government services portal, either through its website or mobile app, regarding products or services purchased from online merchants,” Group-IB said in an analysis published today.

Cybersecurity

“The fraudsters exploit the victims’ willingness to cooperate and obey their instructions, hoping to receive refunds for their unsatisfactory purchases.”

Another campaign identified by Cofense involves sending emails claiming to be from the United States Social Security Administration that embed a link to download an installer for the ConnectWise remote access software or direct the victims to credential harvesting pages.

The development comes as generic top-level domains (gTLDs) such as .top, .xyz, .shop, .vip, and .club have accounted for 37% of cybercrime domains reported between September 2023 and August 2024, despite holding only 11% of the total domain name market, according to a report from the Interisle Consulting Group.

These domains have become lucrative for malicious actors due to low prices and a lack of registration requirements, thereby opening doors for abuse. Among the gTLDs widely used for cybercrime, 22 offered registration fees of less than $2.00.

Threat actors have also been discovered advertising a malicious WordPress plugin called PhishWP that can be used to create customizable payment pages mimicking legitimate payment processors like Stripe to steal personal and financial data via Telegram.

“Attackers can either compromise legitimate WordPress websites or set up fraudulent ones to install it,” SlashNext said in a new report. “After configuring the plugin to mimic a payment gateway, unsuspecting users are lured into entering their payment details. The plugin collects this information and sends it directly to attackers, often in real-time.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

How to Follow the Trajectory of Comet 3I/Atlas

The Mummy 4 Is Heading to Cinemas, But Will It Be A Box Office Success?

Vibe-Coded Malicious VS Code Extension Found with Built-In Ransomware Capabilities

Stryker recognises outstanding young women in STEM through WISE UP Technological Awards

Sipeed NanoCluster Raspberry Pi CM4 CM5 Case Review 2025

TAGGED: Cyber Security, Cybercrime, Cybersecurity, email security, Internet, Malspam, phishing, social engineering, Spoofing, Threat Intelligence
Share This Article
Facebook Twitter Copy Link
Previous Article Amazon to pay fine, continue to implement safety measures at Colorado warehouses to settle hazardous working condition claims
Next Article Israeli Strike in West Bank Kills 3, Including Children
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Square Enix’s UK and US Offices Are Being Hit With Lay-Offs Affecting Over 100 Employees
Gaming News
How to Follow the Trajectory of Comet 3I/Atlas
Tech News
Who is Michelle Agyemang? England's Lioness star named 2025 European Golden Girl
Sports
Gen Alpha won’t ever have to write an email when they join the workforce, new research reveals—they’ll be sending voice notes to their boss instead
Business
BingX AI arena debuts, bringing competitive AI trading in copy trading
Crypto
Is A Ripple IPO Coming? Garlinghouse Shares New Insights
Crypto
Record pay deal for Elon Musk as Tesla bets on robots
World News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Square Enix’s UK and US Offices Are Being Hit With Lay-Offs Affecting Over 100 Employees

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Square Enix’s UK and US Offices Are Being Hit With Lay-Offs Affecting Over 100 Employees
November 7, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?