Silent Push Tracks a Large Phishing Operation Using Fast-Flux Infrastructure

· Original article ↗

Summary

Silent Push says a fast-flux service query exposed thousands of live phishing domains, including a Canada-focused banking campaign using cloaking and rotating DNS infrastructure. Researchers detail credential theft, callback lures, and detection approaches.

Key points

  • Researchers bought access to a fast-flux service and traced its provider-controlled DNS delegation layer, identifying thousands of live phishing domains.
  • One cluster spans nearly 2,000 domains, roughly 90% impersonating Canadian organizations. Traffic-distribution cloaking shows security scanners and foreign visitors a 404 page.
  • A sample domain resolved to 20 IP addresses across 13 ASNs over 90 days; the Canadian campaign’s activity was doubling month over month, according to Silent Push.
  • The banking phishing kit uses single-use links and live operator monitoring to capture keystrokes, test stolen credentials, and direct victims through additional verification pages.
  • A second cluster uses fake fraud hotlines and cloned login forms to steal credentials, then delivers a malicious Windows executable through a password-protected ZIP after a live one-time code is entered.
  • The operation also targets banks and other brands in the U.K., U.S., Australia, and Europe, as well as telecom, tax, fintech, and crypto services.
  • The article recommends DNS analytics for high IP/ASN diversity, low TTLs, and inconsistent geolocation, alongside monitoring fast-flux infrastructure and confirmed abuse-tolerant networks.

Article Details

Attack Vectors
  • Phishing domains use fast-flux DNS to rotate across IP addresses and networks, frustrating IP-based blocking.
  • A Canada-focused banking operation uses Keitaro to profile visitors and show phishing pages to selected victims while returning 404 responses to many scanners and researchers.
  • The banking phishing kit captures keystrokes before form submission; an operator then directs victims through fake OTP and verification pages while testing stolen credentials against the real bank.
  • A callback-phishing cluster combines fake fraud-support pages and cloned login forms with live operators. After an operator issues a one-time code, a site offers a purported security-verification executable in a password-protected ZIP.
Defensive Notes
  • Develop DNS-level fast-flux detection using IP and ASN diversity, low TTLs, and inconsistent IP geolocation; verify that Protective DNS providers block fast-flux behavior.
  • Flag domains when they delegate to identified fast-flux nameservers and track their rotating IP pools.
  • Block confirmed bulletproof or abuse-tolerant infrastructure and monitor other networks appearing in fast-flux rotations.

Indicators of compromise

TypeIndicatorContext
DOMAINcanada-post11[.]comCanada Post lure domain shown resolving across 20 IPs and 13 ASNs in the identified fast-flux phishing infrastructure.
DOMAINetranferts[.]comDomain shown hosting a fake Interac e-Transfer deposit page in the phishing operation.

MITRE ATT&CK

Threat Actors

Vendors

Products

Countries

Industries

Related Articles