The Spamhaus Project

@spamhaus@infosec.exchange
1.3K Followers
20 Following
525 Posts
Spamhaus strengthens trust and safety for the Internet. Advocating for change through sharing reliable intelligence and expertise. As the authority on IP and domain reputation data, we are trusted across the industry because of our strong ethics, impartiality, and quality of actionable data. This data not only protects but also provides signal and insight across networks and email worldwide. 
With over two decades of experience, our researchers and threat hunters focus on exposing malicious activity to make the internet a better place for everyone. A wide range of industries, including leading global technology companies, use Spamhaus' data; currently protecting over 4.5 billion mailboxes worldwide.
Websitehttps://www.spamhaus.org
Threat Intel Communityhttps://submit.spamhaus.org
LinkedInhttps://www.linkedin.com/company/the-spamhaus-project
Twitterhttps://twitter.com/spamhaus

📢 SERVICE UPDATE | We’ve added a new troubleshooting feature to the IP & Domain Reputation Checker, built specifically for senders whose IP addresses appear on the Combined Spam Sources (CSS) Blocklist.

If your IP is listed, this enhanced support feature helps you quickly identify the root cause of the issue and provides actionable guidance on how to resolve it.

Learn more here ⤵️
https://www.spamhaus.org/resource-hub/ip-and-domain-reputation-checker/spamhaus-reputation-checker-troubleshoot-your-listing/

#IPChecker #RemovalRequest

Love letter ❤️ from a threat actor 🕵️exploiting React2Shell vulnerability (CVE-2025-55182) to spread #Mirai malware ⤵️

fuckoffurlhaus 😂

Payload URLs 🌐:
https://urlhaus.abuse.ch/host/45.153.34.201/

Mirai botnet C2s 📡:
marvisxoxo .st (ISTanCo 🇷🇸)
45.156.87 .231:23789 (AS51396 PFCLOUD 🇩🇪)

Malware sample 📄:
https://bazaar.abuse.ch/sample/9a84057ceb444e73f6f8733eda2fbd0db46fd9a6e182179256289558871427d6/

Over the last 30 days, we’ve seen increases in nine out of ten countries in the Top 10 hosting IPs associated with exploited devices. The most significant increase was in 🇬🇧 The United Kingdom (#5), with a +41% ⬆️ and 299,284 detections.

Meanwhile, the only country in the Top 10 that decreased was 🇷🇺 Russia (#9), with a negligible -2% ⬇️ and 95,950 detections.

Find the full list and more #ReputationStatistics here:
👉 https://www.spamhaus.org/reputation-statistics/countries/exploit/

#IPs #Countries #ThreatIntel

If there’s data you’d like to share but you’re unsure whether we can accept it, get in touch here 👉https://contact-center.spamhaus.org/?from=threat-intel

#Community #SharingData #ThreatIntelligence

The Spamhaus Project

We’d like to shout out a new entry on the IP leaderboard: “Sin Piedad” 📣🤩

Over the last 30 days, they’ve submitted a massive 132,945 IPs, placing them at #3 in the Top 10 - thank you for your support and contributions. 🙏

Whether you have just one IP or a regular stream of hundreds, you can make a difference.

Share your IPs, domains, URLs, or raw source data with the Spamhaus Threat Intel Portal here 👉 https://submit.spamhaus.org/submit

Your IP is clean… until suddenly it isn’t. You've unknowingly been pulled into a residential proxy network. 😱 These networks continue to pull in unsuspecting IPs, and the repercussions can be messy - degraded reputation, service disruption, and the risk of landing on a blocklist.

If you’ve just discovered your IP was listed because of residential proxy abuse, you’re not alone. To help, we’ve put together a simple FAQ explaining what happened and how to fix it.

First, let's start with how this happened:
➡️ https://www.spamhaus.org/faqs/residential-proxies/#residential-proxy-recommendations

Then follow the steps to fix it:
➡️ https://www.spamhaus.org/faqs/residential-proxies/#what-steps-can-i-take-to-fix-the-issue

#ResidentialProxies #Support #TicketDesk

❄️ As winter settles in and the temperatures drop, we’re seeing a rise in a UK-based “winter heating allowance” phishing scam. First spotted earlier this year, this campaign sends text messages posing as the Department for Work and Pensions (DWP), claiming the recipient has not yet submitted applied for this year’s allowance.

📄 See article - https://www.theguardian.com/money/2025/jul/27/scam-watch-winter-fuel-allowance-u-turn-news-scammers

Recently, we’ve observed a surge in related domains appearing on the Spamhaus Domain Blocklist, suggesting the campaign is resurfacing. Many of these domains begin with “uk-” and containing keywords like “winterfuelling,” “fuelgrant,” “fuelhelp,” “energyassist,” or similar terms.

Have you received a phishing attempt? Share it with us here 👉 https://submit.spamhaus.org

Keep an eye out for suspicious messages this winter 🕵️

Wishing you a warm and cozy Christmas from all of us at Spamhaus 🎄✨

Winter fuel allowance: the scammers pounce on government U-turn

Fraudsters send out texts claiming to be from the Department for Work and Pensions urging pensioners to apply for a £300 payment

The Guardian

📢 ISPs & Hosts | Following last month's Endgame 3.0 announcement, if you've received a notification, and are yet to take action, here's what you need to do:

👉 Go to this remediation webpage: https://www.spamhaus.org/endgame-3
👉 Enter the access code included in the email.
👉 Download the list of infected machines
👉 Verify each infected machine, and where necessary, contact the owner and ask them to run antivirus and malware removals tools, and reset their passwords for any online services they may have accessed from them (there's a ready-made email template for you to use on the remediation webpage 😀)

Thank you again to everyone who is part of this important effort 🙏

#Trustandsafety #Endgame3 #Takedown

Endgame takedown | Remediation data and support | Spamhaus

The Spamhaus Project

🎉 Massive shout out to URLhaus Top Contributor “geenensp”

First seen April 13th 2020 and since then, they’ve shared an unbelievable 844,345 malware URLs!! 😮 Over the last 30 days, they have shared 8,902 URLs, firmly securing their position at the top of the leaderboard 💪

URLhaus simply wouldn't exist without the help of awesome contributors like this who report malware URLs everyday 🙏

URLhaus ➡️ https://urlhaus.abuse.ch/
Stats ➡️ https://urlhaus.abuse.ch/statistics/

📢 In case you missed it….we recently published a detailed piece on the 'Anatomy of Bulletproof Hosts' - exploring how these services are evolving and what it means for the threat landscape.

In this blog, we cover:

- The decline of monolithic bulletproof hosts
- The shift toward separation of liabilities
- The growing abuse of trusted services
- And what’s next for the threat ecosystem

👉 Read the full post here: https://www.spamhaus.org/resource-hub/bulletproof-hosting/the-anatomy-of-bulletproof-hosting-past-present-future-/