Description

An extensive ad fraud scheme named "SubdoMailing" is exploiting over 8,000 legitimate internet domains and 13,000 subdomains, sending up to five million emails daily to generate revenue through scams and malvertising. The campaign, dubbed "SubdoMailing," involves hijacking abandoned subdomains and domains of well-known companies to send malicious emails. Leveraging the trust associated with these domains, the threat actors evade spam filters and exploit SPF and DKIM email policies to appear legitimate. Notable brands affected include MSN, VMware, McAfee, The Economist, and many others, inadvertently lending credibility to fraudulent emails. Clicking on embedded buttons leads users through redirections, generating revenue for threat actors via fraudulent ad views. Ultimately, users encounter fake giveaways, security scans, surveys, or affiliate scams. Guardio Labs researchers Nati Tal and Oleg Zaytsev discovered the campaign, ongoing since 2022, by detecting anomalous email metadata patterns, unveiling a vast subdomain hijacking operation. A case study involving a falsely authorized email by MSN demonstrates attackers' tactics to appear legitimate, including SPF, DKIM, and DMARC protocol abuses. The campaign targets reputable organizations' domains and subdomains, primarily through CNAME hijacking and SPF record exploitation. Threat actors scan for subdomains with CNAME records pointing to defunct external domains and register these domains themselves. They also exploit SPF records, commandeering control over domains pointed to by "include:" configurations. By registering and modifying SPF records, attackers make their emails seem to originate from reputable domains like MSN. Guardio Labs attributes the operation to a threat actor dubbed "ResurrecAds," systematically scanning for hijackable domains and constantly refreshing a vast network of domains, SMTP servers, and IP addresses to sustain the operation's scale and complexity. The campaign employs nearly 22,000 unique IPs, including residential proxies, to disseminate fraudulent emails globally. Guardio Labs has developed a SubdoMailing checker site to help domain owners identify and mitigate abuse.