A malicious actor has found a new way to bypass phishing detection defenses: It manipulates the .arpa top-level domain (TLD) and IPv6-to-IPv4 tunnel to host phishing content on domains that shouldn’t resolve to an IP address. For the uninitiated, the .arpa domain is an Address and Routing Parameters Area domain that is intended solely for internet infrastructure purposes.
See also: Europe Banks: Mandatory refunds to phishing victims?

It is primarily used to map IP addresses to domains by providing reverse records. However, according to a report by Infoblox, a malicious actor discovered a vulnerability in at least one provider's DNS record management control that allows them to create A records for reverse DNS names instead of adding the expected PTR records.
“From there,” Infoblox says, “they can do whatever they want to the hosting provider. It’s a pretty clever trick.” Infoblox first discovered the trick when it was used against a US-based DNS provider called Hurricane Electricand a content delivery provider called CloudFlare. It also confirmed that other providers have been abused and that it has notified them of the issue.
The tactic “can certainly bypass a significant number of security platforms,” Dave Mitchell, senior director of threat research at Infoblox, said in an interview. “I think it’s definitely a risk.” So far, Infoblox has seen two types of consumer-oriented spam: One group pretends to come from major department store brands, supermarkets and hardware chains, offering a gift for completing a survey.
Other lures claim that the victim's subscription to an online service or anti‑malware software has been terminated, or that the cloud storage quota has been exceeded, and they must pay to restore the service. But Mitchell said there is no reason why the tactic could not be used for spear‑phishing attacks against businesses.
See also: Microsoft: Phishing attacks via OAuth are evolving

In the examples found by Infoblox, the attacker obtained addresses for an IPV6 tunnel to IPV4 from Hurricane Electric as part of a free service offered by the provider. The service's customers are allowed to set DNS in the distributed space to a DNS provider.
What is supposed to happen then is that an IT department or individual uses this space to create a DNS zone to map IP addresses to names – jones.com, smith.org, etc.But in these attacks, the hacker turned to CloudFlare name servers, added the IPV6 .arpa distributions, and instead of just creating reverse DNS records, he created forward DNS records that went to malicious websites.
This tactic will not necessarily work with all providers due to the way they have configured their systems, Mitchell said.
All DNS and IPV6 providers must ensure that their services are not abused in this way, Mitchell said.
IPv6 tunnel providers must ensure they verify the customers requesting the service, specifying what the addresses they receive are used for — something Mitchell admits may not be easy. DNS providers must ensure they only allow the creation of a DNS record for legitimate purposes.
CSOs and domain and network administrators should be aware that even if they have DNS protection or next-generation firewalls, the .arpa domain is always configured to be trusted. They should understand whether their current security controls will detect abuse. A firewall rule that says “Show me any DNS traffic going to 'IP6.arpa'” will help, as will tracing where web traffic from that link is going.
See also: Starkiller: New phishing kit bypasses MFA

And administrators should check whether their organization's email security vendors are flagging these flows within email messages. Gateway providers should look for and quarantine long chains ending in .ip6.arpa that are embedded in images or HTTP links, Mitchell added. Corporate networks should already be deploying DNS monitoring as a primary network detection and defense resource, said Johannes Ullrich, dean of research at the SANS Institute. This should make it easy to alert and potentially block suspicious entries.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
