Guardio Labs has identified a sophisticated phishing campaign called Operation SubdoMailing, involving the manipulation of over 8,000 hijacked subdomains from reputable brands.

Description

This campaign, attributed to threat actor “ResurrecAds,” exploits the trust associated with domains like eBay, VMware [1] [2] [3] [4], and others to send millions of spammy and malicious phishing emails daily. By impersonating trusted brands, the campaign evades email-security measures and leverages stolen resources to deceive users.

Conclusion

The SubdoMailing Checker tool developed by Guardio researchers helps organizations detect domain compromise and combat this evolving threat in the digital advertising ecosystem. It is crucial for organizations to stay vigilant and implement robust security measures to protect against such sophisticated phishing campaigns.

References

[1] https://www.hackread.com/resurrecads-attack-hijack-brand-spam-subdomailing/
[2] https://www.443news.com/2024/02/resurrecads-attack-hijacks-brand-names-spreads-spam-via-subdomailing/
[3] https://www.prnewswire.com/il/news-releases/guardio-labs-uncovers-thousands-of-compromised-domains-used-to-send-mass-malicious-emails-302071035.html
[4] https://www.darkreading.com/application-security/ebay-vmware-mcafee-sites-hijacked-sprawling-phishing-operation