Infoblox Threat Intel
Prolific Puma
Prolific Puma is a threat actor that uses algorithmically generated domains to create shortened links for other malicious actors. The short links help bad actors to evade detection while they distribute phishing, scams and malware. Prolific Puma is the first actor to be identified as a malicious link shortening service. They register hundreds to thousands of new domains daily and notably abuse the .US TLD.
- Operating since: At least January 2020
- Infoblox discovered: March 2022
- Infoblox published: October 2023
- Prevalence: Uncommon