DomainTools recently published their latest blog exploring how threat actors are taking advantage of this growing retail sector and how their activity can be “clustered” to help organizations defend themselves. The various clusters include:
- E-commerce Domain Fraud
- Brand Impersonation for Financial Fraud
- Success Sadly Has a Thousand Cousins
The retail sector faces not only the broader threats that businesses more generally face such as ransomware, phishing, and BEC, but threats that try to leverage brand loyalty.
You can read more via this blog post: https://www.domaintools.com/resources/blog/retail-targeted-campaigns-domain-fraud-brand-impersonation-and-ponzi-schemes/.
New Chenlun/Sinkinto01 TTPs Development to Use Amazon & USPS Lures in Smishing Attacks
Posted in Commentary with tags Domain Tools on October 29, 2024 by itnerdDomainTools has published new research on the development of phishing attacks to gather personal information attributed to the threat actor Chenlun/Sinkinto01, which continued after DomainTools’ original investigation in December 2023.
After analyzing related domains, DomainTools noticed interesting evolutions in their tactics, techniques, and procedures (TTPs). Chenlun has expanded to use Amazon and the previously identified United States Postal Office (USPS) lures.
DomainTools domain-related data allowed researchers to identify a preference for using subdomains with short life cycles on older apex-level domains. Both subdomains and apex-level domains indicate using a domain generation algorithm (DGA) as an obfuscation method.
DomainTools identified redirect domains used after visiting the domain mentioned in the SMS message to further obfuscate the path traveled by the victim before being asked for personal information.
Last year, DomainTools published research on a phishing campaign that targeted individuals by using SMS messages to impersonate the USPS. The original article details the likely responsible threat actor, Chenlun/Sinkinto01.
You can read the details here.
Leave a comment »