A massive advertising fraud campaign, dubbed “SubdoMailing,” uses over 8,000 legitimate internet domains and 13,000 subdomains to send millions of emails daily.

Attackers steal abandoned subdomains and domains belonging to well-known companies and send the malicious emails. Their goal is to generate revenue through scams and malvertising.
Hackers from trusted companies so that emails bypass spam filters and pass through other security checks as legitimate and not as spam.
For example, the attackers used domains of the following companies for the malicious SubdoMailing campaign: MSN, VMware, McAfee, The Economist, Cornell University, CBS, NYC.gov, PWC, Pearson, Better Business Bureau, Unicef, ACLU, Symantec, Java.net, Marvel, and eBay.
See also: Bitwarden: New auto-fill option reduces the risk of credential phishing
These companies have nothing to do with the malicious emails but help hackers, as these names lend legitimacy to the fraudulent messages.
The malicious emails in the SubdoMailing campaign contain embedded buttons that lead users to a series of redirects, generating revenue for the threat actors through ad serving. Ultimately, the user ends up with fake gifts, security scans, surveys, or affiliate scams.
The scam was discovered by researchers at Guardio Labs, who reported that the operation has been ongoing since 2022.
Violation of legitimate domains for malicious emails
Guardio Labs' investigation began with the identification of unusual patterns in email metadata, which led to the discovery of a massive subdomain hijacking operation.

According to researchers, attackers use various methods to make their emails appear legitimate, including abusing SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail) and DMARC (Domain-based Message Authentication, Reporting, and Conformance) protocols.
See also: Organizations receive spear phishing emails with EU-related topics
These policies are used to prove that the sender of an email is legitimate.
As we mentioned earlier, the SubdoMailing campaign targets domains and subdomains of trusted organizations, attempting to compromise them primarily through CNAME hijacking and SPF record exploitation.
In CNAME attacks, attackers look for subdomains of trusted companies with CNAME records that point to external domains that are no longer registered. They then register these domains themselves through the NameCheap.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The second method involves examining SPF records of domains that use the “ include :” configuration option that points to external domains that are no longer registered. The include option is used to import allowed email senders from the external domain, which is now under the threat actor’s control .
Attackers register the domains and then change the SPF records to authorize their own malicious email servers. This makes their malicious emails appear to come from a trusted domain.
SubdoMailing: A massive advertising fraud campaign
Guardio Labs researchers believe that a group called “ResurrecAds” is behind the campaign, which frequently searches for domains that can be compromised.
Attackers are constantly updating domains, SMTP servers, and IP addresses. Guardio Labs says that SubdoMailing uses nearly 22,000 unique IPs.
See also: SNS Sender Malware distributes Phishing SMS via Amazon
Currently, the campaign operates through SMTP servers configured to spread malicious emails across a vast network of 8,000 domains and 13,000 subdomains.
Over 5,000,000 emails are sent daily.
Guardio Labs has created a monitoring website that can allow domain owners to identify if their brand is being used by hackers as part of the SubdoMailing campaign.

Phishing / spam emails: How to protect yourself?
One of the most effective methods of protecting yourself from phishing emails is to use reliable security software. These programs work constantly to detect and remove suspicious emails before they even reach inbox .
It is also important to regularly update your computer's software and operating system . These updates often include new protections against recent phishing techniques.
Education is also a powerful ally against phishing . Learn to recognize the signs of a dangerous email, such as spelling mistakes, unusual email addresses , and requests for personal information.
Finally, never open attachments or click on links in emails you are not expecting. If an email seems suspicious, it is best to contact the sender immediately to confirm its authenticity.
Source: www.bleepingcomputer.com
