Shreshta Blog

We uncover badness.

Threat Intelligence

Open Resolvers: Understanding security risks and best practices

An “open resolver” is a DNS server that accepts and resolves a domain name recursively for anyone on the internet. In this blog post, we will share the security risks of open resolvers and best practices. At the time of writing, there were 192920 open resolvers in India with recursion enabled. While most of these …

Open Resolvers: Understanding security risks and best practices Read More »

Phishing email impersonating income tax luring users to download malware

Threat actors targeting Indian citizens

Security researchers at Shreshta have identified a phishing campaign targeting Indian citizens.   Executive Summary The Income Tax Department (also referred to as IT Department or ITD) is a government agency undertaking direct tax collection of the Government of India. It functions under the Department of Revenue of the Ministry of Finance. The main responsibility of …

Threat actors targeting Indian citizens Read More »

Phishing targeting bank of Philippines

Threat actors targeting Union Bank of Philippines users

Security researchers at Shreshta have identified a phishing campaign targeting Indian citizens. Threat actors targeting Union Bank of Philippines users with a phishing campaign   Executive Summary The Union Bank of the Philippines, Inc., more commonly known as UnionBank, is one of the universal banks in the Philippines and the ninth-largest bank in the country by assets.1   …

Threat actors targeting Union Bank of Philippines users Read More »

Phishing targeting metamask users

Phishing targeting MetaMask users

Security researchers at Shreshta , using our threat intelligence platform SDINET, have identified a phishing website targeting MetaMask users. A phishing campaign targeting MetaMask users has been doing the rounds on the internet. About MetaMask MetaMask is a software cryptocurrency wallet used to interact with the Ethereum blockchain. It allows users to access their Ethereum wallet …

Phishing targeting MetaMask users Read More »

Phishing website targeting Indiana Department of Workforce Development

Phishing campaign targeting Indiana Department of Workforce Development’s (DWD) Uplink

On the 21st of January, security researchers at Shreshta IT, had uncovered a phishing website impersonating the Indiana Department of Workforce Uplink website. During further investigations, we discovered a more extensive phishing campaign. About Indiana Department of Workforce Development’s (DWD) Uplink is the name of the Indiana Department of Workforce Development’s automated self-service unemployment Insurance …

Phishing campaign targeting Indiana Department of Workforce Development’s (DWD) Uplink Read More »