Threat actors are abusing the special-use .arpa DNS namespace—intended for internet infrastructure and reverse-DNS lookups—to make phishing infrastructure harder for email security gateways and reputation systems to evaluate. The activity leverages reverse-DNS conventions (IPv4 in-addr.arpa and IPv6 ip6.arpa) but uses atypical forward-lookups (e.g., A/AAAA records) and non-standard hostnames under .arpa, which can slip past controls that treat .arpa traffic as benign or “internal plumbing.”
Reporting attributed the technique to observations shared by Infoblox, noting it combines legacy DNS assumptions with modern IPv6 usage to reduce detection efficacy for “basic scam-type” phishing, with concern it may be applicable to more targeted operations. Defensive guidance highlighted that legitimate in-addr.arpa names follow a strict IP-derived format ending in the suffix, so any .arpa query that is not a PTR-style reverse lookup or does not match expected naming patterns should be blocked or at least alerted on, and organizations should review DNS/email filtering logic to ensure .arpa is not implicitly trusted.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Reporting on Infoblox's findings highlighted that defenders should flag or block .arpa queries using atypical hostnames or A/AAAA lookups instead of expected PTR-style reverse lookups. The guidance emphasized that .arpa abuse is harder to assess because the namespace lacks normal registered-domain metadata such as WHOIS and domain age.
Infoblox reported that the phishing links were short-lived and used a traffic distribution system to filter targets and redirect non-targets to legitimate sites. The same activity also involved reputable infrastructure providers, dangling CNAME hijacking, and subdomain shadowing, including more than 100 hijacked CNAME instances tied to well-known organizations.
Infoblox identified a phishing campaign using IPv6 reverse-DNS names under ip6.arpa to create phishing URLs that can evade domain reputation checks and some email security gateways. The attackers controlled IPv6 address space and reverse-DNS zones, then placed non-PTR records such as A records on reverse-DNS hostnames to direct victims to phishing infrastructure.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.