Threat reportPhishingTL-2026-0154

.arpa TLD Abuse — IPv6 Reverse DNS Phishing, Dangling CNAME Hijacking via Hurricane Electric and Cloudflare

mediumACTIVE

.arpa TLD Abuse (TL-2026-0154), also tracked as .arpa TLD Phishing, is a medium-severity phishing campaign, first published 2026-02-28. It has no confirmed attribution, affects Hurricane Electric IPv6 Tunnel Broker, maps to 19 MITRE ATT&CK techniques (T1036.005, T1056.003, T1071.001), and is covered by 9 detection rules and 21 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
19MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
21Indicators of compromise

Key facts for TL-2026-0154

Threat ID
TL-2026-0154
Also known as
.arpa TLD Phishing, IPv6 Reverse DNS Phishing, ip6.arpa Abuse
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
Last reviewed
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
government, education, telecommunications, media, retail, healthcare, financial
Target regions
Global
Detection rules
9
Indicators of compromise
21

Malware and tooling in .arpa TLD Abuse

Malware and tooling: Cloudflare, Hurricane Electric

How .arpa TLD Abuse works

Multiple unattributed threat actors are abusing the .arpa top-level domain — specifically ip6.arpa reverse DNS zones — for large-scale phishing and malware distribution. The novel technique weaponizes IPv6 reverse DNS domains as phishing links that bypass security controls due to implicit trust in IANA-managed infrastructure TLDs.

Infoblox Threat Intelligence research published February 26, 2026 reveals a novel, previously unreported phishing technique abusing the .arpa top-level domain (TLD). The .arpa TLD is managed by IANA exclusively for infrastructure purposes — in-addr.arpa for IPv4 reverse DNS and ip6.arpa for IPv6 reverse DNS — and is not intended to host user-facing content.

The attack works through coordinated abuse of two services: (1) acquiring free IPv6 tunnel address space from providers like Hurricane Electric, which grants administrative control over the corresponding ip6.arpa reverse DNS zone, and (2) finding DNS providers that allow adding A records (instead of expected PTR records) for these reverse DNS domains. The threat actors discovered that certain DNS providers, including Cloudflare, allow claiming ownership of .arpa domains without proper validation.

The resulting ip6.arpa reverse DNS domains resolve to IP addresses (typically Cloudflare edge network) hosting phishing content. To evade detection, actors prepend randomly generated 10-character subdomains to each FQDN, making each phishing link unique. These domains bypass security tools that rely on reputation scoring, registration information, and policy blocklists — because .arpa domains have implicitly clean reputation, no registration information, and are rarely blocked by policy.

Phishing emails impersonate major brands using image-only HTML that hides the malicious link. Victims click the image, their device resolves the .arpa domain, and they are fingerprinted and redirected through traffic distribution systems (TDSs) to fraudulent survey/gift card phishing pages. The campaigns require mobile devices and residential IP addresses for full redirection. Links are active for only a few days.

In parallel, the same toolkit (active since at least 2017) abuses dangling CNAME records of high-profile organizations. Over 100 instances of hijacked CNAMEs from government agencies, universities, telecommunications companies, media organizations, and retailers were identified. Some hijacked subdomains have been abused for years — one shadow subdomain has operated since 2020 without detection. Notable examples include publicnoticessites[.]com (expired, providing content for 120+ newspaper websites — 8 CNAMEs hijacked), hobsonsms[.]com (expired, providing university account services — 3 university CNAMEs hijacked), and hyfnrsx1[.]com (recently expired, subdomains serving global food/beverage companies — hijacked January 2026).

Previously reported dangling CNAME attacks (Abusix, August 2024) documented hijacks against UC San Diego, UCLA, Georgetown University, Vodafone Italy, Heriot-Watt University, and dozens more organizations. The Hazy Hawk threat actor (tracked by Infoblox since December 2023) performs similar cloud resource hijacking against CDC, alabama.gov, berkeley.edu, deloitte.com, and other high-profile targets using abandoned Azure, AWS, Cloudflare, and other cloud service endpoints.

MITRE ATT&CK techniques used in TL-2026-0154

defense-evasion

T1036.005 Match Legitimate Resource Name or Location; T1127 Trusted Developer Utilities Proxy Execution

collection

T1056.003 Web Portal Capture; T1213 Data from Information Repositories

command-and-control

T1071.001 Web Protocols; T1071.004 DNS; T1090.003 Multi-hop Proxy

discovery

T1082 System Information Discovery

execution

T1204.001 Malicious Link

defense-impairment

T1553.002 Code Signing

initial-access

T1566.002 Spearphishing Link

resource-development

T1583.001 Domains; T1583.002 DNS Server; T1583.006 Web Services; T1584.001 Domains; T1584.002 DNS Server; T1608.005 Link Target

reconnaissance

T1590.002 DNS; T1596.001 DNS/Passive DNS

Affected products and versions in .arpa TLD Abuse

  • Hurricane Electric — IPv6 Tunnel Broker
    Vulnerable versions: All — free IPv6 tunnel service grants .arpa zone control
  • Cloudflare — DNS and Tunnel Services
    Vulnerable versions: DNS allows A record creation for .arpa domains; tunnels used for hosting
  • Multiple DNS Providers — DNS Hosting
    Vulnerable versions: Providers that allow .arpa domain ownership claims without validation

Remediation for .arpa TLD Abuse

Immediate actions

  • Block A record queries for ip6.arpa and in-addr.arpa domains at DNS resolver level
  • Add detection rules for .arpa domains in email hyperlinks — these should never appear in legitimate email content
  • Block known phishing domains: actinismoleil[.]sbs, cablecomparison[.]shop, cheapperfume[.]shop, drumsticks[.]store, fightingckmelic[.]makeup
  • Block known TDS domains: dulcetoj[.]com, golandof[.]com, politeche[.]com, taktwo[.]com, toindom[.]com
  • Audit organizational DNS records for dangling CNAMEs pointing to expired or unregistered domains

Workarounds

  • Configure DNS resolvers to refuse A/AAAA queries for .arpa TLD subdomains
  • Email security gateways should treat .arpa links as suspicious by default
  • Network security tools should flag any HTTP/HTTPS traffic to ip6.arpa or in-addr.arpa resolved domains

Longer-term hardening

  • Implement DNS monitoring for A/AAAA record queries to .arpa TLD — alert on any resolution to non-PTR records
  • Deploy CNAME monitoring to detect dangling records before they can be hijacked
  • Implement email gateway rules to flag or block messages containing .arpa domain links
  • DNS providers should validate and reject A record creation for .arpa namespace domains
  • Regularly audit cloud service endpoints and remove DNS records for decommissioned resources
  • Implement Certificate Transparency monitoring for certificates issued to organizational subdomains

Weaknesses (CWE) in .arpa TLD Abuse

CWE-350, CWE-451, CWE-807

Timeline of .arpa TLD Abuse

  • Same phishing toolkit used in .arpa abuse campaigns observed active since at least 2017 (Infoblox assessment)
  • Earliest known shadow subdomain abuse — one subdomain has operated since 2020 without detection (Infoblox)
  • Hazy Hawk cloud resource hijacking first observed by Infoblox — targets CDC, government, universities, major corporations
  • Abusix publishes report on dangling CNAME attacks documenting 50+ hijacked subdomains of universities, government, and corporations
  • Same hijacked CNAMEs observed consistently in phishing emails since September 2025 — some used in 100+ emails per day
  • Domain hyfnrsx1[.]com expires — subdomains serving global food/beverage companies hijacked, observed in phishing emails starting January 2026
  • Infoblox notifies DNS providers where .arpa domain ownership claims were not properly validated
  • Infoblox publishes 'Abusing .arpa: The TLD That Isn't Supposed to Host Anything' — first public documentation of .arpa TLD abuse for phishing at scale
  • Threat published to Threadlinqs Intelligence Platform as TL-2026-0154
  • As of 2026-05-29, this technique-based phishing/DNS-abuse threat remains active: no CVE to patch, and both vectors persist post-disclosure. Infoblox/CloudSEK confirm ongoing .arpa/ip6.arpa abuse (incl. a second Frankfurt-ASN campaign), and Hazy Hawk's dangling-CNAME hijacking escalated to MIT, Harvard, Stanford and 30+ universities in April 2026.

Sources cited for .arpa TLD Abuse

Detection coverage for TL-2026-0154

As of 2026-02-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0154 across Splunk SPL, Microsoft KQL and Sigma, covering 21 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
21 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats