216.73.216.6

DNS Used to Hide Fake Investment Platform Schemes

· Published 19/02/2026 15:26 · Modified 19/02/2026 18:12

Export JSON

Essential information

Published
19/02/2026 15:26
Modified
19/02/2026 18:12
Tags
2026-02-19 cname records dns abuse domain generation algorithm facebook ads geofencing investment scams traffic distribution system
Related entities
1 intrusion sets (apt), 49 others

Description

Savvy Seahorse, a DNS threat actor, employs sophisticated techniques to lure victims into fake investment platforms through . They use DNS to create a , enabling dynamic IP address updates and evasion of detection. The campaigns target multiple languages and involve fake ChatGPT and WhatsApp bots. Victims are convinced to create accounts, make deposits, and unknowingly transfer funds to Russian banks. The actor has been operating since August 2021, using dedicated hosting and frequently changing IP addresses. Their infrastructure includes approximately 4,200 base domains with linked to subdomains of b36cname[.]site. The campaigns are short-lived, typically lasting 5-10 days per subdomain.

External references