https://krebsonsecurity.com/2023/09/why-is-us-being-used-to-phish-so-many-of-us/ Advertisement [5] Advertisement [10] Krebs on Security Skip to content * Home * About the Author * Advertising/Speaking Why is .US Being Used to Phish So Many of Us? September 1, 2023 9 Comments [dotUS-b] Domain names ending in ".US" -- the top-level domain for the United States -- are among the most prevalent in phishing scams, new research shows. This is noteworthy because .US is overseen by the U.S. government, which is frequently the target of phishing domains ending in .US. Also, .US domains are only supposed to be available to U.S. citizens and to those who can demonstrate that they have a physical presence in the United States. .US is the "country code top-level domain" or ccTLD of the United States. Most countries have their own ccTLDs: .MX for Mexico, for example, or .CA for Canada. But few other major countries in the world have anywhere near as many phishing domains each year as .US. That's according to The Interisle Consulting Group, which gathers phishing data from multiple industry sources and publishes an annual report on the latest trends. Interisle's newest study examined six million phishing reports between May 1, 2022 and April 30, 2023, and found 30,000 .US phishing domains. .US is overseen by the National Telecommunications and Information Administration (NTIA), an executive branch agency of the U.S. Department of Commerce. However, NTIA currently contracts out the management of the .US domain to GoDaddy, by far the world's largest domain registrar. Under NTIA regulations, the administrator of the .US registry must take certain steps to verify that their customers actually reside in the United States, or own organizations based in the U.S. But Interisle found that whatever GoDaddy was doing to manage that vetting process wasn't working. "The .US 'nexus' requirement theoretically limits registrations to parties with a national connection, but .US had very high numbers of phishing domains," Interisle wrote. "This indicates a possible problem with the administration or application of the nexus requirements." Dean Marks is executive director and legal counsel for a group called the Coalition for Online Accountability, which has been critical of the NTIA's stewardship of .US. Marks says virtually all European Union member state ccTLDs that enforce nexus restrictions also have massively lower levels of abuse due to their policies and oversight. "Even very large ccTLDs, like .de for Germany -- which has a far larger market share of domain name registrations than .US -- have very low levels of abuse, including phishing and malware," Marks told KrebsOnSecurity. "In my view, this situation with .US should not be acceptable to the U.S. government overall, nor to the US public." Marks said there are very few phishing domains ever registered in other ccTLDs that also restrict registrations to their citizens, such as .HU (Hungary), .NZ (New Zealand), and .FI (Finland), where a connection to the country, a proof of identity, or evidence of incorporation are required. "Or .LK (Sri Lanka), where the acceptable use policy includes a 'lock and suspend' if domains are reported for suspicious activity," Marks said. "These ccTLDs make a strong case for validating domain registrants in the interest of public safety." Sadly, .US has been a cesspool of phishing activity for many years. As far back as 2018, Interisle found .US domains were the worst in the world for spam, botnet (attack infrastructure for DDOS etc.) and illicit or harmful content. Back then, .US was being operated by a different contractor. In response to questions from KrebsOnSecurity, GoDaddy said all .US registrants must certify that they meet the NTIA's nexus requirements. But this appears to be little more than an affirmative response that is already pre-selected for all new registrants. Attempting to register a .US domain through GoDaddy, for example, leads to a U.S. Registration Information page that auto-populates the nexus attestation field with the response, "I am a citizen of the United States." Other options include, "I am a permanent resident of the US," and "My primary domicile is in the US." It currently costs just $4.99 to obtain a .US domain through GoDaddy. GoDaddy said it also conducts a scan of selected registration request information, and conducts "spot checks" on registrant information. "We conduct regular reviews, per policy, of registration data within the Registry database to determine Nexus compliance with ongoing communications to registrars and registrants," the company said in a written statement. GoDaddy says it "is committed to supporting a safer online environment and proactively addressing this issue by assessing it against our own anti-abuse mitigation system." "We stand against DNS abuse in any form and maintain multiple systems and protocols to protect all the TLDs we operate," the statement continued. "We will continue to work with registrars, cybersecurity firms and other stakeholders to make progress with this complex challenge." Interisle found significant numbers of .US domains were registered to attack some of the United States' most prominent companies, including Bank of America, Amazon, Apple, AT&T, Citi, Comcast, Microsoft, Meta, and Target. "Ironically, at least 109 of the .US domains in our data were used to attack the United States government, specifically the United States Postal Service and its customers," Interisle wrote. ".US domains were also used to attack foreign government operations: six .US domains were used to attack Australian government services, six attacked Great's Britain's Royal Mail, one attacked Canada Post, and one attacked the Denmark Tax Authority." The NTIA recently published a proposal that would allow GoDaddy to redact registrant data from WHOIS registration records. The current charter for .US specifies that all .US registration records be public. Interisle argues that without more stringent efforts to verify a United States nexus for new .US domain registrants, the NTIA's proposal will make it even more difficult to identify phishers and verify registrants' identities and nexus qualifications. The NTIA has not yet responded to requests for comment. Interisle sources its phishing data from several places, including the Anti-Phishing Working Group (APWG), OpenPhish, PhishTank, and Spamhaus. For more phishing facts, see Interisle's 2023 Phishing Landscape report (PDF). This entry was posted on Friday 1st of September 2023 11:38 AM A Little Sunshine The Coming Storm Web Fraud 2.0 Coalition for Online Accountability Dean Marks GoDaddy Interisle Consulting Group National Telecommunications and Information Administration U.S. Department of Commerce Post navigation - U.S. Hacks QakBot, Quietly Removes Botnet Infections 9 thoughts on "Why is .US Being Used to Phish So Many of Us?" 1. Eric September 1, 2023 In my experience, GoDaddy is not a serious company and should not be entrusted with anything resembling due diligence. Reply - 2. Nance Gordon September 1, 2023 "Also, .US domains are only supposed to be available to U.S. citizens and to those who can demonstrate that they have a physical presence in the United States." Nothing a pay-to-play contract with one of Hunter's "consulting" firms can't fix... Reply - 1. BrianKrebs Post authorSeptember 1, 2023 SHOW US THE LAPTOP! Reply - 3. mark September 1, 2023 Oh, wonderful. When I relocated from Chicago to the DC metro area in '09, I broke down, registered a domain, and bought hosting. I'm not a business, nor an organization, and I had no idea what state/commonwealth/district I'd wind up in... so I chose .us. Reply - 4. Andrew September 1, 2023 Some clarity around the .us previously being operated by another contractor...GoDaddy acquired Neustar's registry business, which is how it ended up with the contract. Reply - 5. Cory Booth September 1, 2023 My issue with .us is they won't let you use domain privacy. So it's a non-stop parade of phone calls wanting to "help me with my site" Reply - 6. Moike September 1, 2023 The phishers have probably been using stolen credit cards with a US address, a Gmail address and an anonymous US proxy IP address. It gives a few months for the phishing domain to live until the stolen credit card is detected. Those attributes alone cannot filter out US residents. Reply - 1. BrianKrebs Post authorSeptember 1, 2023 I asked GoDaddy about whether they used credit card data as one of the factors in determining nexus. According to them, it is not. Here's what they said in response: "As the usTLD Administrator/Registry Operator, GoDaddy Registry does not process customer orders or hold credit card data." Reply - 7. Mark Bennett September 1, 2023 Does anybody really think that youtu.be is based in Belgium? ME is Montenegro and I've seen US companies use that as a TLD. Reply - Leave a Reply Cancel reply Your email address will not be published. Required fields are marked * [ ] [ ] [ ] [ ] [ ] [ ] [ ] Comment * [ ] Name * [ ] Email * [ ] Website [ ] [Post Comment] [ ] [ ] [ ] [ ] [ ] [ ] [ ] D[ ] Advertisement [7] Advertisement Mailing List Subscribe here Search KrebsOnSecurity Search for: [ ] [Search] Recent Posts * Why is .US Being Used to Phish So Many of Us? * U.S. Hacks QakBot, Quietly Removes Botnet Infections * Kroll Employee SIM-Swapped for Crypto Investor Data * Tourists Give Themselves Away by Looking Up. So Do Most Network Intruders. * Karma Catches Up to Global Phishing Service 16Shop Spam Nation Spam Nation A New York Times Bestseller! Thinking of a Cybersecurity Career? Thinking of a Cybersecurity Career? Read this. All About Skimmers All About Skimmers Click image for my skimmer series. Story Categories * A Little Sunshine * All About Skimmers * Ashley Madison breach * Breadcrumbs * Data Breaches * DDoS-for-Hire * Employment Fraud * How to Break Into Security * Internet of Things (IoT) * Latest Warnings * Ne'er-Do-Well News * Other * Pharma Wars * Ransomware * Russia's War on Ukraine * Security Tools * SIM Swapping * Spam Nation * Target: Small Businesses * Tax Refund Fraud * The Coming Storm * Time to Patch * Web Fraud 2.0 The Value of a Hacked PC valuehackedpc Badguy uses for your PC Badguy Uses for Your Email Badguy Uses for Your Email Your email account may be worth far more than you imagine. Donate to Krebs On Security Most Popular Posts * Sextortion Scam Uses Recipient's Hacked Passwords (1076) * Online Cheating Site AshleyMadison Hacked (798) * Sources: Target Investigating Data Breach (620) * Trump Fires Security Chief Christopher Krebs (534) * Why Paper Receipts are Money at the Drive-Thru (530) * Cards Stolen in Target Breach Flood Underground Markets (445) * Reports: Liberty Reserve Founder Arrested, Site Shuttered (416) * Was the Ashley Madison Database Leaked? (376) * DDoS-Guard To Forfeit Internet Space Occupied by Parler (374) * True Goodbye: 'Using TrueCrypt Is Not Secure' (363) Why So Many Top Hackers Hail from Russia [computered-580x389] Category: Web Fraud 2.0 Criminnovations Innovations from the Underground [shreddedID-copy-285x189] ID Protection Services Examined Is Antivirus Dead? Is Antivirus Dead? The reasons for its decline The Growing Tax Fraud Menace The Growing Tax Fraud Menace File 'em Before the Bad Guys Can Inside a Carding Shop Inside a Carding Shop A crash course in carding. Beware Social Security Fraud Beware Social Security Fraud Sign up, or Be Signed Up! How Was Your Card Stolen? How Was Your Card Stolen? Finding out is not so easy. Krebs's 3 Rules... Krebs's 3 Rules... ...For Online Safety. (c) Krebs on Security - Mastodon