Fake support scammers, regardless of the initial ruse, typically trick victims into installing remote access tools, often describing it as a security or verification check.
Many use ConnectWise ScreenConnect, a legitimate tool, hosted on their own domains. They may even jazz things up with custom branding, sometimes changing the brand during the lifetime of the domain, though they really need to avoid heavily compressed images - that fake Apple support site looks janky!
Helpfully these scammers seem to follow a standard process for the DNS, allowing us to identify their consistencies:
- Registration through NameSilo
- Protection provided by Cloudflare
- Alphanumeric RDGA domains favouring TLDs '.cfd', '.sbs', '.top' and '.xyz'*
- Keyword RDGA domains, using words like 'care', 'help' and 'support', with TLDs '.help', '.live' and '.online'
Recent examples:
- 'cmonline[.]help'
- 'jxcr-ui1[.]top'
- 'jdsfrw-11[.]top'
- 'ntfre-8e[.]xyz'
- 'wlop10[.]top'
* We're working with our friends at XYZ.com to take down offending domains using TLDs under their control.
#cybercrime #cybersecurity #dns #infoblox #infobloxthreatintel #infosec #scam #supportscam #threatintel #threatintelligence