Silent Push Tracks a Large Phishing Operation Using Fast-Flux Infrastructure

Summary
Silent Push says a fast-flux service query exposed thousands of live phishing domains, including a Canada-focused banking campaign using cloaking and rotating DNS infrastructure. Researchers detail credential theft, callback lures, and detection approaches.
Key points
- Researchers bought access to a fast-flux service and traced its provider-controlled DNS delegation layer, identifying thousands of live phishing domains.
- One cluster spans nearly 2,000 domains, roughly 90% impersonating Canadian organizations. Traffic-distribution cloaking shows security scanners and foreign visitors a 404 page.
- A sample domain resolved to 20 IP addresses across 13 ASNs over 90 days; the Canadian campaign’s activity was doubling month over month, according to Silent Push.
- The banking phishing kit uses single-use links and live operator monitoring to capture keystrokes, test stolen credentials, and direct victims through additional verification pages.
- A second cluster uses fake fraud hotlines and cloned login forms to steal credentials, then delivers a malicious Windows executable through a password-protected ZIP after a live one-time code is entered.
- The operation also targets banks and other brands in the U.K., U.S., Australia, and Europe, as well as telecom, tax, fintech, and crypto services.
- The article recommends DNS analytics for high IP/ASN diversity, low TTLs, and inconsistent geolocation, alongside monitoring fast-flux infrastructure and confirmed abuse-tolerant networks.
Article Details
- Attack Vectors
- Phishing domains use fast-flux DNS to rotate across IP addresses and networks, frustrating IP-based blocking.
- A Canada-focused banking operation uses Keitaro to profile visitors and show phishing pages to selected victims while returning 404 responses to many scanners and researchers.
- The banking phishing kit captures keystrokes before form submission; an operator then directs victims through fake OTP and verification pages while testing stolen credentials against the real bank.
- A callback-phishing cluster combines fake fraud-support pages and cloned login forms with live operators. After an operator issues a one-time code, a site offers a purported security-verification executable in a password-protected ZIP.
- Defensive Notes
- Develop DNS-level fast-flux detection using IP and ASN diversity, low TTLs, and inconsistent IP geolocation; verify that Protective DNS providers block fast-flux behavior.
- Flag domains when they delegate to identified fast-flux nameservers and track their rotating IP pools.
- Block confirmed bulletproof or abuse-tolerant infrastructure and monitor other networks appearing in fast-flux rotations.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | canada-post11[.]com | Canada Post lure domain shown resolving across 20 IPs and 13 ASNs in the identified fast-flux phishing infrastructure. |
| DOMAIN | etranferts[.]com | Domain shown hosting a fake Interac e-Transfer deposit page in the phishing operation. |
MITRE ATT&CK
T1056.001 · KeyloggingThe Canadian banking phishing kit sends a victim's keystrokes to an operator before form submission.T1566.004 · Spearphishing VoiceFake fraud-hotline pages route victims to live operators who engage them by phone as part of the callback-phishing operation.T1568.001 · Fast Flux DNSPhishing domains rapidly rotate DNS resolutions across changing pools of IP addresses and networks.
Threat Actors
Vendors
Products
KeitaroEvery domain in the Canadian operation sits behind Keitaro, a commercial traffic distribution system (TDS).Silent Push Indicators of Future Attack (IOFA®) feedsIOFA feeds: Exclusive to Enterprise clients, Silent Push Indicators of Future Attack (IOFA®) feeds for this fast-flux infrastructure – including the Fastflux, Dnspod Domains, and IPs feeds – are available via API andTotal ViewLoading one of the Canada Post lure domains into Total View’s Infrastructure Variance tab shows the domain resolving to 20 different IPs across 13 ASNs over a 90-day window; each bar below is a separate network the same
Countries
AustraliaBehind the same fast-flux layer, we found bank look-alikes in the U.K., the U.S., Australia, and Europe, plus telecom providers, tax authorities, email marketing platforms, and crypto brands.CanadaFrom a single query in our platform, we identified thousands of live phishing domains, including a large, Canada-first banking campaign that hides behind commercial traffic-distribution cloaking.United KingdomBehind the same fast-flux layer, we found bank look-alikes in the U.K., the U.S., Australia, and Europe, plus telecom providers, tax authorities, email marketing platforms, and crypto brands.United StatesYalishanda was advertising custom encrypted proxy infrastructure, decoy traffic, and abuse-proof hosting on behalf of Media Land, a bulletproof hosting provider sanctioned by the U.S.
Industries
BankingFrom a single query in our platform, we identified thousands of live phishing domains, including a large, Canada-first banking campaign that hides behind commercial traffic-distribution cloaking.CryptocurrencyEmail marketingBehind the same fast-flux layer, we found bank look-alikes in the U.K., the U.S., Australia, and Europe, plus telecom providers, tax authorities, email marketing platforms, and crypto brands.Financial TechnologyGovernmentPostal servicesTelecommunications