Infoblox Threat Intel reported a previously unreported phishing technique that abuses the infrastructure-focused .arpa TLD—normally used for reverse DNS mapping—to host and deliver phishing content in ways that can bypass common enterprise controls. Threat actors obtain control of IPv6 address space via free IPv6 tunnel services, then exploit DNS management weaknesses at some providers to create records that should not exist for reverse-DNS zones (e.g., creating A records instead of expected PTR records). This results in long, reverse-DNS-style domains under ip6.arpa that resolve and can serve malicious content, while appearing “infrastructure-like” and therefore less likely to be blocked by reputation-based defenses.
The observed campaigns use malspam impersonating major consumer brands and typically present a single image containing an embedded hyperlink, obscuring the unusual .arpa destination from the user. Clicking the image sends victims through a Traffic Distribution System (TDS) that fingerprints traffic (including device targeting such as mobile) and then redirects to fraudulent pages. Reporting emphasized that because .arpa is critical to Internet operations and is rarely treated as a web-hosting namespace, defenders may have blind spots in URL filtering, domain reputation, and DNS policy enforcement when attackers weaponize ip6.arpa-style hostnames.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
CloudSEK reported that large-scale scanning of 127,906 IPv6 prefixes uncovered 384 suspicious ip6.arpa zones delegated to Cloudflare nameservers and confirmed two zones as actively malicious. In addition to infrastructure overlapping with the earlier Infoblox-observed activity, the researchers identified a separate active campaign using the zone 0.d.7.2.7.0.1.b.e.0.a.2.ip6.arpa on IONOS infrastructure in Frankfurt, Germany.
Infoblox publicly disclosed the campaign and explained how attackers used .arpa, IPv6 address space, traffic distribution systems, and short-lived redirect chains to bypass common security controls. The report also linked the activity to related techniques such as dangling CNAME hijacking and subdomain shadowing, and shared indicators and defensive recommendations.
Infoblox Threat Intel identified a previously unreported phishing technique that abuses the .arpa namespace and IPv6 reverse-DNS names under ip6.arpa to host or route victims to phishing content. The campaign used free IPv6 tunnel services, unexpected DNS record creation, and infrastructure-looking hostnames to evade reputation and registration-based defenses.
Infoblox observed some hijacked CNAMEs being used consistently from September 2025 as part of the same broader evasion ecosystem tied to the phishing activity. In some cases, expired service domains enabled takeover of many dependent subdomains belonging to trusted organizations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 22 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
6 references tracked. Mallory keeps watching after this page renders.
cloudsek.com
Open sourcecloudsek.com
Open sourcehackread.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourceinfoblox.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.