Phishers always look for the effective ways to distribute phish email, lure victims
to scam web sites, and shield their online scams from discovery and takedown.
Phishers make considerable efforts to maintain these shields, and have repeatedly
adjusted their attack methods in response to each improvement in antiphishing
measures. Domain names have played an increasingly important role in phishing
attacks for some time, and they remain a tactical area of great interest to phishers.
This advisory discusses how phishers now use what we call subdomain registries to
provide safe harbors for malicious and criminal activities. The advisory also
discusses measures individuals and organizations can consider if they opt to make
these harbors less attractive and effective to phishers.

I wrote this November 2008 APWG advisory with colleagues Rod Rasmussen and Greg Aaron. I’ve posted it here since the original URL is broken.


Leave a Reply

Your email address will not be published. Required fields are marked *