• Home
  • Domains
  • Internet & Tech
  • Security & Privacy
  • Google & Search
  • Editorial Praise
  • Contact

Strategic Revenue - Domain and Internet News

Internet news authored by John Colascione

Register Domain Names

  • Isn’t Print Dead?
  • Killer Acquisition
  • New gTLD Death
  • Online Censorship
  • Gullible Domainers
  • You’re A Loser
You are here: Home / Domain Names / “Prolific Puma” Created 75k Unique Domain Names Since April 2022 Used for Scams

“Prolific Puma” Created 75k Unique Domain Names Since April 2022 Used for Scams

November 2, 2023 By John Colascione Leave a Comment

*** Here Is A List Of Some Of The Best Domain Name Resources Available ***






SANTA CLARA, CA – Researchers from security vendor Infoblox have uncovered an actor known as “Prolific Puma” that has been revealed as having provided link shortening services for countless cyber criminals for a span of time of at least four years or longer, an act that has likely been responsible for an immense number of scams targeting innocent people. 

As an example of how Prolific Puma lives up to the “prolific” part of their name, the actor reportedly registers thousands of domains on the U.S. top-level domain (usTLD) every month – having created 75,000 unique domain names since April 2022 – which cybercriminals then utilize to assist with spreading phishing, cyber-scams, and malware. 

Shortened links, such as those from bit.ly, make it easy to type in a web address quickly but difficult to determine where the web browser will actually take you. Criminals often utilize shortened URLs to direct victims to phishing sites or initiate a download of malicious software onto their device. 

Infoblox notes that they first came across Prolific Puma approximately 6 months ago, having been alerted to their activity after detecting a registered domain generation algorithm (RDGA) that they said was utilized to create domain names for their link shortening service. From there, Infoblox were able to track down Prolific Puma’s network utilizing DNS detectors, observing it grow and evolve as it assisted more and more individuals and organizations to commit internet-based crimes. 

What is a DGA and/or RDGA?

DGAs are algorithms that typically reside within the malware distributed by threat actors. These algorithms are programmed to generate any number of pseudorandom domain names, and the malware cycles through them to find one that enables it to communicate with the attacker’s C2. This allows for the attacker to evade detection and blocking mechanisms by offering alternative domains that can quickly replace any that may be deemed malicious or blocklisted. Before the invention of DGAs, IP addresses or domain names were hardcoded into the malware and were quickly thwarted once the malware was discovered..

Source: https://blogs.infoblox.com/cyber-threat-intelligence/rdgas-the-new-face-of-dgas/

While some of the links created by Prolific Puma lead directly to a specific page, many instead weave a complex series of redirects – some of which utilize shortened links themselves – before finally landing on their shady final destination. 

Meet "Prolific Puma," the secretive threat actor behind a dangerous link shortening service with thousands of malicious domains used for phishing and #malware distribution.

Learn how this operation evades detection: https://t.co/qWRxtUEfy9#cybersecurity #hacking

— The Hacker News (@TheHackersNews) November 1, 2023

“We eventually captured several instances of shortened links redirecting to final landing pages that were phishing and scam sites,” Infoblox said, stating that it is believed that multiple actors were using Prolific Puma’s service due to the inconsistency in what the shortened links would lead to. 

Shenanigans like this, a new (kinda novel) twist on the age-old DGA problem, make an increasingly strong case for domain allowlisting.

There are ways to do this balancing user needs with security concerns, and the friction is worth it for high-risk orgs.https://t.co/Wq7QnPAcND

— Keith (@kwm) November 1, 2023

The shortened links were delivered via a variety of methods, spanning e-mail, social media, advertisements, and even text messages. In order to keep a low profile and avoid detection, Prolific Puma would often allow their newly created domains to sit dormant for several weeks while making several DNS queries to grow their reputation.

John Colascione 2024
John Colascione

About The Author: John Colascione is Chief Executive Officer of Internet Marketing Services Inc. He specializes in Website Monetization, is a Google AdWords Certified Professional, authored a ‘how to’ book called ”Mastering Your Website‘, and is a key player in several Internet related businesses through his search engine strategy brand Searchen Networks®

Filed Under: Domain Names, Security Issues Tagged With: Algorithm, Algorithmic, Algorithms, Criminals, Cyber-security, Cybersecurity, Data Security, DNS, DNS Detectors, Domain, Domain Name, Domain Names, Email Scams, Infoblox, Internet Security, IP Address, IP addresses, Malware, Phishing, Phishing Scam, Phishing Scams, Prolific Puma, RDGA, Research, Scam, Scammers, Scams, Security, Security Analysis, Security Breach, Security Vulnerabilities, Top, Top Level Domain, usTLD

*** Here Is A List Of Some Of The Best Domain Name Resources Available ***






Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search This Site

by: John Colascione

John Colascione

Best Site for Things to Do While Visiting Florida
John Colascione is Chief Executive of Internet Marketing Services Inc. He specializes in Website Monetization, authored a book called Mastering Your Website, and is a key player in several Internet businesses through his brand SEARCHEN®

#Indiana.com

GEO domain name

Follow Me

John Colascione Twitter

The First Fiction Horror Story Based Entirely On An Internet Domain Name

The First Fiction Horror Story Based Entirely On An Internet Domain Name
A cyber thriller where the countdown to death is always ticking…

USED CARS ENTERPRISE

auto buyers market
Auto Buyers Market – Shop Used Cars by Participating Dealers at autobuyersmarket.com

In The News

  • DNJournal: New Book From Veteran Domainer
  • From Brandable to Exact-Match Geo Domain
  • InnovateLI: Two Deals, One Very Interesting Digital
  • Internet Commerce Association: John Colascione
  • NamesCon: Featured Attendee: John Colascione
  • Long Island Media Inc, SmartCEO, Future 50
  • Speakers, Name Summit, John Colascione
  • Speakers, Real Estate Summit, John Colascione
  • 24 Leading Domain Experts Analyze 2017

Popular Stories

Did DuckDuckGo Just Acquire Premium Domain “Duck.com” from Google?

New gTLD? Not So Fast; History Suggests New ‘Right of the Dots’ Could = Total Failure

Could Domain Investing Industry End with Legal Provision for Domain “Hoarding”

Websites and Domain Names to Become Insignificant within 20 Years or Less

Does the Domain Industry Suffer From Own Versions of Trumpted “Fake News” Stories?

Quotes to Follow

quote icon The domain name is equivalent to Gold. It is the only packaged item which is globally tax-free, portable, with value that is universal across different cultures. quote icon – Frank Schilling

quote icon Domains have and will continue to go up in value faster than any other commodity ever known to man. quote icon – Rick Schwartz

quote icon  Google knows you, your friends, your likes, what entertains you, where you are in the world at any given time. Google will soon predict your next action, your next thought, based on a collaboration of thoughts past. quote icon – John Colascione

Like These Headlines?

Enter your email address:

Delivered by FeedBurner

T.L.D. Brokerage

Domain Brokers

Master of My Domain: The Power of the Publisher – Reality of Digital Journalism

WEST PALM BEACH, FL - There’s a power that comes with publishing that most people will never fully understand - unless they’ve had the experience of pushing the button and watching their words go … [Read More...]

Google’s Search Market Share Dips Below 90% for First Time in Decade

MOUNTAIN VIEW, CA - Google's global search engine market share fell below 90% in the final quarter of 2024, marking the first time since 2015 that it has dipped under this threshold. Regional … [Read More...]

Aflac Hit by Sophisticated Cyberattack: What Victims, Businesses Need to Know

COLUMBUS, GA - Aflac Incorporated, a leading supplemental insurance provider, disclosed that its U.S. systems suffered a cyberattack on June 12, 2025, potentially exposing sensitive customer data. The … [Read More...]

Domaining blog recommended by Domaining.com

Copyright © 2010-2025 StrategicRevenue.com - Property of Internet Marketing Services Inc.   FeedBurner: RSS
By using this site you agree to our Terms of Service and Privacy Policy. If you do not agree, please exit the service.