A DNS Deep Dive into the LabHost PhaaS Infrastructure

A DNS Deep Dive into the LabHost PhaaS Infrastructure

The FBI issued a warning about the LabHost phishing-as-a-service campaign, revealing over 42,000 related indicators of compromise. An extensive DNS investigation uncovered additional typosquatting domains, IP addresses, and subdomains associated with the campaign. #LabHost #PhishingAsAService #IASC

Keypoints

  • The FBI identified 42,515 domain IoCs related to the LabHost PhaaS campaign, with 42,401 domains analyzed after cleaning.
  • An additional 1,661 typosquatting domains linked to the campaign were discovered, raising the total analyzed to 44,062 domains.
  • These domains targeted 18 well-known brands, including Scotia Bank, Amazon, Netflix, Apple, and Spotify.
  • DNS traffic analysis showed 11,009 unique client IP addresses querying 163 domains with over 74,000 DNS requests during April-May 2025.
  • 3,319 domains were listed in the First Watch Malicious Domains Data Feed, mostly created months to years before the FBI warning.
  • Analysis revealed 61,727 subdomains with common service-related strings such as www, mail, and cpanel among the LabHost domains.
  • A total of 1,346 unique IP addresses resolved from the domains, dispersed across 41 countries with the U.S. and Germany topping the list.

MITRE Techniques

  • [T1586] Compromise Infrastructure – Use of typosquatting domains mimicking well-known brands to facilitate phishing campaigns (β€œnet new typosquatting domains akin to the IoCs”).
  • [T1071] Application Layer Protocol – Mass DNS queries observed from over 11,000 unique IP addresses querying malicious domains (β€œ74,617 DNS requests based on Internet Abuse Signal Collective (IASC) DNS traffic data”).
  • [T1598] Phishing – Deployment of phishing-as-a-service campaign through the use of extensive domain and subdomain infrastructure (β€œLabHost phishing-as-a-service (PhaaS) campaign”).

Indicators of Compromise

  • [Domain ] LabHost-related domains and typosquatting domains – 42,401 FBI listed domains and 1,661 additional typosquatting domains totaling 44,062 domains.
  • [IP Address ] Resolved IPs from malicious domains – 1,346 unique IP addresses distributed globally, including IPv4 and IPv6 addresses.
  • [Subdomain ] Common subdomains found in campaign domains – 61,727 subdomains including www, mail, webmail, cpanel, webdisk, smtp.


Read more: https://circleid.com/posts/a-dns-deep-dive-into-the-labhost-phaas-infrastructure