AliExpress-themed phishing operation using disposable redirect domains
Campaign
Summary
Hide ▲
Show ▼
An AliExpress-themed phishing campaign surfaced through 10 disposable .cyou domains that were flagged before registration and later redirected visitors to a fake shopping-assistant lure. The infrastructure used a tracking layer with campaign, click, and affiliate parameters, letting the operator swap exposed domains without rebuilding the operation. Users faced risk of credential and payment theft and browsing-activity exposure if they reached the lure. The pattern shows a reusable redirect-and-replacement setup designed to keep the phishing flow alive.
Related Happenings
Blocking disposable phishing domains and log-hunting for prior exposure
Defensive Guidance
H score26
First: 25.09.2026 11:30
Last: 25.09.2026 11:30
Sources 1
How related:
EfficientIP advised blocking the domains and IP addresses and searching DNS and proxy logs for past connections.
About this happening:
EfficientIP recommended blocking disposable phishing domains and IPs after tracking AliExpress-themed entry points that could expose users to credential, payment, and br...
Blocking disposable phishing domains and log-hunting for prior exposure
Defensive GuidanceHow related: EfficientIP advised blocking the domains and IP addresses and searching DNS and proxy logs for past connections.
About this happening: EfficientIP recommended blocking disposable phishing domains and IPs after tracking AliExpress-themed entry points that could expose users to credential, payment, and br...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
Campaign
H score31
First: 14.07.2026 18:31
Last: 14.07.2026 18:31
Sources 1
About this happening:
An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
LastPass and Bitwarden users targeted by fake-security-notice phishing campaign
CampaignAbout this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
TikTok for Business phishing campaign using Turnstile and reverse proxy
Campaign
H score31
First: 26.03.2026 16:09
Last: 26.03.2026 16:09
Sources 1
About this happening:
A phishing campaign is targeting TikTok for Business accounts and uses Cloudflare Turnstile to block automated analysis before exposing a reverse-proxy credential-...
TikTok for Business phishing campaign using Turnstile and reverse proxy
CampaignAbout this happening: A phishing campaign is targeting TikTok for Business accounts and uses Cloudflare Turnstile to block automated analysis before exposing a reverse-proxy credential-...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor Meta
H score82
First: 05.03.2026 08:51
Last: 05.03.2026 08:51
Sources 1
About this happening:
Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Latest development: 17.05.2026 17:43
eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.
Timeline
-
25.09.2026 11:30 1 articles · 2h ago
ANY.RUN tags lookalike shopping-assistant site as phishing
Detection Ioc UpdateANY.RUN sandbox tagged a lookalike shopping-assistant site as phishing on May 22, giving an early warning for a lure used in an AliExpress-themed phishing campaign.
Show sources
- Researchers Identify AliExpress Phishing Domains Before Registration — www.infosecurity-magazine.com — 25.09.2026 11:30
-
25.09.2026 11:30 1 articles · 2h ago
EfficientIP flags 10 disposable .cyou domains before registration
Campaign Scope UpdateEfficientIP Research Labs identified 10 potential .cyou domains on June 9, added them to its DNS threat intelligence feed, and noted that the names shared a short digit-plus-five-lowercase-letters format and a common registration pattern.
Show sources
- Researchers Identify AliExpress Phishing Domains Before Registration — www.infosecurity-magazine.com — 25.09.2026 11:30
-
25.09.2026 11:30 2 articles · 2h ago
Disposable .cyou domains begin resolving and lead to fake AliExpress site
Exploitation ObservedOn July 2, the 10 .cyou domains were registered and began resolving to IP addresses in one subnet, and DNS and redirect tracing led to a fake AliExpress site that used a tracking layer with campaign, click, and affiliate parameters.
Show sources
- Researchers Identify AliExpress Phishing Domains Before Registration — www.infosecurity-magazine.com — 25.09.2026 11:30
- Researchers Identify AliExpress Phishing Domains Before Registration — www.infosecurity-magazine.com — 25.09.2026 11:30