Cybercriminals Using Novel DNS Hijacking Technique for Investment Scams

Share:

A new DNS threat actor dubbed Savvy Seahorse is leveraging sophisticated techniques to entice targets into fake investment platforms and steal funds.

“Savvy Seahorse is a DNS threat actor who convinces victims to create accounts on fake investment platforms, make deposits to a personal account, and then transfers those deposits to a bank in Russia,” Infoblox said in a report published last week.

Targets of the campaigns include Russian, Polish, Italian, German, Czech, Turkish, French, Spanish, and English speakers, indicating that the threat actors are casting a wide net in their attacks.

Users are lured via ads on social media platforms like Facebook, while also tricking them into parting with their personal information in return for alleged high-return investment opportunities through fake ChatGPT and WhatsApp bots.

The financial scam campaigns are notable for using DNS canonical name (CNAME) records to create a traffic distribution system (TDS), thereby allowing threat actors to evade detection since at least August 2021.

A CNAME record is used to map a domain or subdomain to another domain (i.e., an alias) instead of pointing to an IP address. One advantage with this approach is that when the IP address of the host changes, only the DNS A record for the root domain needs to be updated.

Savvy Seahorse leverages this technique to its advantage by registering several short-lived subdomains that share a CNAME record (and thus an IP address). These specific subdomains are created using a domain generation algorithm (DGA) and are associated with the primary campaign domain.

The ever-changing nature of the domains and IP addresses also makes the infrastructure resistant to takedown efforts, allowing the threat actors to continuously create new domains or alter their CNAME records to a different IP address as their phishing sites are disrupted.

While threat actors like VexTrio have used DNS as a TDS, the discovery marks the first time CNAME records have been used for such purposes.

Victims who end up clicking the links embedded on Facebook ads are urged to provide their names, email addresses, and phone numbers, after which they are redirected to the bogus trading platform for adding funds to their wallets.

“An important detail to note is the actor validates the user’s information to exclude traffic from a predefined list of countries, including Ukraine, India, Fiji, Tonga, Zambia, Afghanistan, and Moldova, although their reasoning for choosing these specific countries is unclear,” Infoblox noted.

The development comes as Guardio Labs revealed that thousands of domains belonging to legitimate brands and institutions have been hijacked using a technique called CNAME takeover to propagate spam campaigns.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:56 pm, Jun 21, 2025
weather icon 30°C
L: 28° | H: 31°
overcast clouds
Humidity: 41 %
Pressure: 1016 mb
Wind: 8 mph S
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 97%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:43 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
28° | 31°°C 0.73 mm 73% 10 mph 51 % 1016 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 26°°C 1 mm 100% 15 mph 78 % 1014 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
15° | 23°°C 0.2 mm 20% 15 mph 81 % 1016 mb 0 mm/h
Tue Jun 24 10:00 pm
weather icon
14° | 23°°C 0 mm 0% 13 mph 78 % 1016 mb 0 mm/h
Wed Jun 25 10:00 pm
weather icon
18° | 27°°C 0.38 mm 38% 11 mph 82 % 1013 mb 0 mm/h
Today 4:00 pm
weather icon
30° | 30°°C 0 mm 0% 8 mph 41 % 1016 mb 0 mm/h
Today 7:00 pm
weather icon
28° | 29°°C 0 mm 0% 10 mph 39 % 1015 mb 0 mm/h
Today 10:00 pm
weather icon
23° | 26°°C 0.73 mm 73% 7 mph 51 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 19°°C 1 mm 100% 7 mph 77 % 1013 mb 0 mm/h
Tomorrow 4:00 am
weather icon
16° | 16°°C 0 mm 0% 10 mph 78 % 1013 mb 0 mm/h
Tomorrow 7:00 am
weather icon
17° | 17°°C 0 mm 0% 10 mph 67 % 1014 mb 0 mm/h
Tomorrow 10:00 am
weather icon
23° | 23°°C 0 mm 0% 12 mph 48 % 1014 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
26° | 26°°C 0 mm 0% 14 mph 33 % 1013 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€89,925.85
-1.84%
Ethereum(ETH)
€2,102.08
-4.53%
Tether(USDT)
€0.87
0.01%
XRP(XRP)
€1.84
-2.18%
Solana(SOL)
€122.21
-3.93%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.139398
-5.81%
Shiba Inu(SHIB)
€0.000010
-4.59%
Pepe(PEPE)
€0.000009
-5.12%
Peanut the Squirrel(PNUT)
€0.218233
13.10%
Scroll to Top