/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Infoblox discovers a threat actor that has provided link shortening services to cybercriminals for over four years, registering ~75K domains since April 2022

Ionut Ilascu / BleepingComputer :

BleepingComputer Ionut Ilascu

Context & Ripple Effects

The report identifies infrastructure-as-a-service behind criminal campaigns rather than a single intrusion: a link-shortening provider paired with large-scale domain registration can give multiple customers a reusable distribution layer. Earlier research found that many newly registered cybersquatted domains were malicious, underscoring why domain-registration patterns are a useful security signal for detecting malicious domain operations.

It also fits a broader DNS-abuse record in the coverage, from state-backed domain hijacking to later reporting on DNS configuration flaws used to commandeer registered domains. The common issue is that domain and DNS control remain high-leverage points for both attackers and defenders.

First-order effects

  • Infoblox’s finding gives defenders a defined cluster of roughly 75,000 registered domains and an associated service model to investigate, block, or monitor for phishing and malware-delivery activity.
  • Cybercriminal customers of the identified provider risk losing a layer that obscures or redirects victims to malicious destinations if its domains and links are broadly detected or disrupted.

Second-order effects

  • DNS-security vendors, registrars, and hosting providers may need to place more weight on infrastructure relationships—shared registration behavior and redirect networks—rather than evaluating suspicious domains one at a time.
  • A reusable short-link service lowers setup friction for many criminal campaigns; identifying it can let defenders disrupt multiple downstream operations through a common dependency.

Third-order effects

  • If such services continue to be identified as shared infrastructure, cyber defense is likely to shift further toward ecosystem-level takedowns and graph-based detection of domains, DNS, and redirect chains rather than campaign-by-campaign response.
  • The pattern strengthens the case that domain-abuse controls must account for both newly registered domains and compromised or misconfigured ones, though the most effective responsibility split among registrars, DNS operators, and security vendors remains unsettled.

The trend: Cybercrime infrastructure is becoming a more important enforcement and defense target because shared domain, DNS, and redirect services can support many campaigns at once.

Discussion

  • Infoblox Blog Infoblox Blog on x
    Prolific Puma: Shadowy Link Shortening Service Enables Cybercrime