Find notable cyber news and cases, enriched with sources, timelines, and signals.

AliExpress-themed phishing operation using disposable redirect domains

Campaign
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

An AliExpress-themed phishing campaign surfaced through 10 disposable .cyou domains that were flagged before registration and later redirected visitors to a fake shopping-assistant lure. The infrastructure used a tracking layer with campaign, click, and affiliate parameters, letting the operator swap exposed domains without rebuilding the operation. Users faced risk of credential and payment theft and browsing-activity exposure if they reached the lure. The pattern shows a reusable redirect-and-replacement setup designed to keep the phishing flow alive.

Related Happenings

Blocking disposable phishing domains and log-hunting for prior exposure

Defensive Guidance
H score26 First: 25.09.2026 11:30 Last: 25.09.2026 11:30 Sources 1

How related: EfficientIP advised blocking the domains and IP addresses and searching DNS and proxy logs for past connections.

About this happening: EfficientIP recommended blocking disposable phishing domains and IPs after tracking AliExpress-themed entry points that could expose users to credential, payment, and br...

LastPass and Bitwarden users targeted by fake-security-notice phishing campaign

Campaign
H score31 First: 14.07.2026 18:31 Last: 14.07.2026 18:31 Sources 1

About this happening: An ongoing phishing campaign is using fake security notices to lure LastPass and Bitwarden users to fraudulent websites, creating immediate credential theft risk f...

Forg365-ForgCookie alliance reshapes ransomware ecosystem operations

Threat Actor Meta
H score37 First: 09.07.2026 17:39 Last: 09.07.2026 17:39 Sources 1

About this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...

TikTok for Business phishing campaign using Turnstile and reverse proxy

Campaign
H score31 First: 26.03.2026 16:09 Last: 26.03.2026 16:09 Sources 1

About this happening: A phishing campaign is targeting TikTok for Business accounts and uses Cloudflare Turnstile to block automated analysis before exposing a reverse-proxy credential-...

Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations

Threat Actor Meta
H score82 First: 05.03.2026 08:51 Last: 05.03.2026 08:51 Sources 1

About this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...

Latest development: 17.05.2026 17:43

eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.

Timeline

  1. 25.09.2026 11:30 1 articles · 2h ago

    ANY.RUN tags lookalike shopping-assistant site as phishing

    Detection Ioc Update

    ANY.RUN sandbox tagged a lookalike shopping-assistant site as phishing on May 22, giving an early warning for a lure used in an AliExpress-themed phishing campaign.

    Show sources
  2. 25.09.2026 11:30 1 articles · 2h ago

    EfficientIP flags 10 disposable .cyou domains before registration

    Campaign Scope Update

    EfficientIP Research Labs identified 10 potential .cyou domains on June 9, added them to its DNS threat intelligence feed, and noted that the names shared a short digit-plus-five-lowercase-letters format and a common registration pattern.

    Show sources
  3. 25.09.2026 11:30 2 articles · 2h ago

    Disposable .cyou domains begin resolving and lead to fake AliExpress site

    Exploitation Observed

    On July 2, the 10 .cyou domains were registered and began resolving to IP addresses in one subnet, and DNS and redirect tracing led to a fake AliExpress site that used a tracking layer with campaign, click, and affiliate parameters.

    Show sources