Hackers hijack .arpa domain for phishing scams

Attackers have exploited the .arpa internet domain to host malicious websites and deliver phishing links. They use IPv6 and hidden .arpa addresses to disguise URLs and steal user credentials. The scheme was reported by TechRadar on March 2, 2026.

The .arpa domain, a core part of the internet infrastructure, has been hijacked by hackers for phishing purposes. According to TechRadar, attackers are leveraging IPv6 technology alongside hidden .arpa addresses to create undetectable malicious websites and domains. These disguised URLs lead users to phishing pages designed to secretly capture credentials.

The exploit allows hackers to host scams in places where they are difficult to spot, evading typical detection methods. No specific victims or scale of the attack were detailed in the report. TechRadar's coverage highlights the vulnerability in this foundational domain, which is used for internet address resolution.

This incident underscores ongoing risks in internet security, particularly with emerging protocols like IPv6. Users are advised to remain vigilant against suspicious links, though no further preventive measures were outlined in the source.

Verwandte Artikel

Illustration depicting hackers hijacking Linux Snap Store apps to steal cryptocurrency recovery phrases, featuring a compromised Ubuntu laptop and digital seed phrase theft.
Bild generiert von KI

Attackers hijack Linux Snap Store apps to steal crypto phrases

Von KI berichtet Bild generiert von KI

Cybercriminals have compromised trusted Linux applications on the Snap Store by seizing expired domains, allowing them to push malware that steals cryptocurrency recovery phrases. Security experts from SlowMist and Ubuntu contributor Alan Pope highlighted the attack, which targets established publisher accounts to distribute malicious updates impersonating popular wallets. Canonical has removed the affected snaps, but calls for stronger safeguards persist.

Major VPN providers such as NordVPN, ExpressVPN, and Proton VPN are facing attacks through typosquatting, where fake domains mimic their official sites. A report indicates that 14 percent of these imitation domains are malicious. Users are advised to take precautions to avoid falling victim to these scams.

Von KI berichtet

Digital squatting has reached new heights as hackers increasingly impersonate brands through domain attacks. This form of cyber impersonation takes various shapes to deceive users and organizations. The trend highlights ongoing challenges in online security.

Russian state-sponsored hackers quickly weaponized a newly patched Microsoft Office flaw to target organizations in nine countries. The group, known as APT28, used spear-phishing emails to install stealthy backdoors in diplomatic, defense, and transport entities. Security researchers at Trellix attributed the attacks with high confidence to this notorious cyber espionage unit.

Von KI berichtet

Security researchers, first reporting via TechRadar in December 2025, warn WhatsApp's 3 billion users of GhostPairing—a technique tricking victims into linking attackers' browsers to their accounts, enabling full access without breaching passwords or end-to-end encryption.

Ethereum's daily transactions reached an all-time high of over 2.8 million on January 16, largely driven by a widespread address poisoning scam. These attacks, which involve sending tiny crypto amounts from deceptive addresses, are intensifying amid recent network upgrades. Security experts warn that without improved wallet safeguards, users remain vulnerable to significant losses.

Von KI berichtet

A new cybercrime platform known as 1Campaign allows hackers to run malicious Google Ads while evading the company's screening process. This development is raising concerns in the cybersecurity community. The platform's emergence highlights ongoing challenges in online advertising security.

 

 

 

Diese Website verwendet Cookies

Wir verwenden Cookies für Analysen, um unsere Website zu verbessern. Lesen Sie unsere Datenschutzrichtlinie für weitere Informationen.
Ablehnen