216.73.216.6

Pulling the Threads on the Phish of Troy Hunt

· Published 29/03/2025 19:24 · Modified 31/03/2025 09:26

Export JSON

Essential information

Published
29/03/2025 19:24
Modified
31/03/2025 09:26
Tags
2025-03-29 dns pivoting infrastructure discovery mailchimp phishing threat intelligence troy hunt validin
Related entities
1 intrusion sets (apt), 6 techniques (mitre)

Description

A sophisticated attack targeted , compromising his account. The analysis reveals connections to the Scattered Spider group through domain pivoting. Using 's DNS, host response, and registration data, dozens of related domain names were uncovered. The investigation exposed a fake Cloudflare turnstile and bogus registration details. Pivoting on various features led to the discovery of multiple related domains and IP addresses. The attack's tactics strongly resemble those of Scattered Spider, including the reuse of previously used domains. The findings demonstrate the power of 's databases for uncovering adversary infrastructure and strengthening .

External references