.arpa TLD Abuse — IPv6 Reverse DNS Phishing, Dangling CNAME Hijacking via Hurricane Electric and Cloudflare — Threadlinqs Intelligence
As of 2026-05-30, .arpa TLD Abuse — IPv6 Reverse DNS Phishing, Dangling CNAME Hijacking via Hurricane Electric and Cloudflare is a medium-severity phishing threat attributed to a N/A-nexus actor, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 21 indicators of compromise.
Threat ID: TL-2026-0154 · Severity: MEDIUM · Status: ACTIVE · Category: PHISHING
Attribution: N/A · FINANCIAL
Multiple unattributed threat actors are abusing the .arpa top-level domain — specifically ip6.arpa reverse DNS zones — for large-scale phishing and malware distribution. The novel technique weaponizes
Infoblox Threat Intelligence research published February 26, 2026 reveals a novel, previously unreported phishing technique abusing the .arpa top-level domain (TLD). The .arpa TLD is managed by IANA exclusively for infrastructure purposes — in-addr.arpa for IPv4 reverse DNS and ip6.arpa for IPv6 reverse DNS — and is not intended to host user-facing content.
The attack works through coordinated abuse of two services: (1) acquiring free IPv6 tunnel address space from providers like Hurricane Electric, which grants administrative control over the corresponding ip6.arpa reverse DNS zone, and (2) finding DNS providers that allow adding A records (instead of expected PTR records) for these reverse DNS domains. The threat actors discovered that certain DNS providers, including Cloudflare, allow claiming ownership of .arpa domains without proper validation.
The resulting ip6.arpa reverse DNS domains resolve to IP addresses (typically Cloudflare edge network) hosting phishing content. To evade detection, actors prepend randomly generated 10-character subdomains to each FQDN, making each phishing link unique. These domains bypass security tools that rely on reputation scoring, registration information, and policy blocklists — because .arpa domains have implicitly clean reputation, no registration information, and are rarely blocked by policy.
Phishing emails impersonate major brands using image-only HTML that hides the malicious link. Victims click the image, their device resolves the .arpa domain, and they are fingerprinted and redirected through traffic distribution systems (TDSs) to fraudulent survey/gift card phishing pages. The campaigns require mobile devices and residential IP addresses for full redirection. Links are active for only a few days.
In parallel, the same toolkit (active since at least 2017) abuses dangling CNAME records of high-profile organizations. Over 100 instances of hijacked CNAMEs from government agencies, universities, telecommunications companies, media organizations, and retailers were identified. Some hijacked subdomains have been abused for years — one shadow subdomain has operated since 2020 without detection. Notable examples include publicnoticessites[.]com (expired, providing content for 120+ newspaper websites — 8 CNAMEs hijacked), hobsonsms[.]com (expired, providing university account services — 3 university CNAMEs hijacked), and hyfnrsx1[.]com (recently expired, subdomains serving global food/beverage companies — hijacked January 2026).
Previously reported dangling CNAME attacks (Abusix, August 2024) documented hijacks against UC San Diego, UCLA, Georgetown University, Vodafone Italy, Heriot-Watt University, and dozens more organizations. The Hazy Hawk threat actor (tracked by Infoblox since December 2023) performs similar cloud resource hijacking against CDC, alabama.gov, berkeley.edu, deloitte.com, and other high-profile targets using abandoned Azure, AWS, Cloudflare, and other cloud service endpoints.
Weaknesses (CWE)
CWE-350, CWE-451, CWE-807
Target sectors: government, education, telecommunications, media, retail, healthcare, financial
Target regions: Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 21 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, MEDIUM, threat intelligence, cybersecurity, T1566.002, T1583.001, T1583.002, T1583.006, T1584.001, T1584.002, T1608.005, T1204.001, T1036.005, T1127