The report says hackers use URL domain name shortening service to convert to .us top-level domain name to perform phishing.
CTOnews.com, Nov. 24, Infoblox, a network security company, recently released a security blog saying that hackers used the .us top-level domain name to carry out phishing and malware attacks.
The researchers found that the URL address shortening service labeled "Prolific Puma" has been running for more than three years and can shorten URL addresses to 3-7 short addresses, which are used by online anglers and malware distributors.
According to Infoblox, more than 55% of the domain names created by the shortening service have been used since May 2023. For top-level domain names in the United States, several new domain names are registered every day.
.us top-level domain names are usually sold to major companies and government agencies in the United States, and are mainly sold by web domain name registrars such as GoDaddy. Infoblox noticed that more than 2000 malicious domain names were privately registered through NameSilo.
A link to the original report is attached to CTOnews.com, which can be read in depth by users who are interested in security.