HomeSecuritySubdoMailing: New spam campaign uses hacked company domains

SubdoMailing: New spam campaign uses hacked company domains

A massive advertising fraud campaign, dubbed “SubdoMailing,” uses over 8,000 legitimate internet domains and 13,000 subdomains to send millions of emails daily.

SubdoMailing: New spam campaign uses hacked company domains

Attackers steal abandoned subdomains and domains belonging to well-known companies and send the malicious emails. Their goal is to generate revenue through scams and malvertising.

Hackers from trusted companies so that emails bypass spam filters and pass through other security checks as legitimate and not as spam.

For example, the attackers used domains of the following companies for the malicious SubdoMailing campaign: MSN, VMware, McAfee, The Economist, Cornell University, CBS, NYC.gov, PWC, Pearson, Better Business Bureau, Unicef, ACLU, Symantec, Java.net, Marvel, and eBay.

See also: Bitwarden: New auto-fill option reduces the risk of credential phishing

These companies have nothing to do with the malicious emails but help hackers, as these names lend legitimacy to the fraudulent messages.

The malicious emails in the SubdoMailing campaign contain embedded buttons that lead users to a series of redirects, generating revenue for the threat actors through ad serving. Ultimately, the user ends up with fake gifts, security scans, surveys, or affiliate scams.

The scam was discovered by researchers at Guardio Labs, who reported that the operation has been ongoing since 2022.

Violation of legitimate domains for malicious emails

Guardio Labs' investigation began with the identification of unusual patterns in email metadata, which led to the discovery of a massive subdomain hijacking operation.

SubdoMailing campaign

According to researchers, attackers use various methods to make their emails appear legitimate, including abusing SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail) and DMARC (Domain-based Message Authentication, Reporting, and Conformance) protocols.

See also: Organizations receive spear phishing emails with EU-related topics

These policies are used to prove that the sender of an email is legitimate.

As we mentioned earlier, the SubdoMailing campaign targets domains and subdomains of trusted organizations, attempting to compromise them primarily through CNAME hijacking and SPF record exploitation.

In CNAME attacks, attackers look for subdomains of trusted companies with CNAME records that point to external domains that are no longer registered. They then register these domains themselves through the NameCheap.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The second method involves examining SPF records of domains that use the “ include :” configuration option that points to external domains that are no longer registered. The include option is used to import allowed email senders from the external domain, which is now under the threat actor’s control .

Attackers register the domains and then change the SPF records to authorize their own malicious email servers. This makes their malicious emails appear to come from a trusted domain.

SubdoMailing: A massive advertising fraud campaign

Guardio Labs researchers believe that a group called “ResurrecAds” is behind the campaign, which frequently searches for domains that can be compromised.

Attackers are constantly updating domains, SMTP servers, and IP addresses. Guardio Labs says that SubdoMailing uses nearly 22,000 unique IPs.

See also: SNS Sender Malware distributes Phishing SMS via Amazon

Currently, the campaign operates through SMTP servers configured to spread malicious emails across a vast network of 8,000 domains and 13,000 subdomains.

Over 5,000,000 emails are sent daily.

Guardio Labs has created a monitoring website that can allow domain owners to identify if their brand is being used by hackers as part of the SubdoMailing campaign.

SubdoMailing: New spam campaign uses hacked company domains

Phishing / spam emails: How to protect yourself?

One of the most effective methods of protecting yourself from phishing emails is to use reliable security software. These programs work constantly to detect and remove suspicious emails before they even reach inbox .

It is also important to regularly update your computer's software and operating system . These updates often include new protections against recent phishing techniques.

Education is also a powerful ally against phishing . Learn to recognize the signs of a dangerous email, such as spelling mistakes, unusual email addresses , and requests for personal information.

Finally, never open attachments or click on links in emails you are not expecting. If an email seems suspicious, it is best to contact the sender immediately to confirm its authenticity.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS