Blocking disposable phishing domains and log-hunting for prior exposure
Defensive Guidance
Summary
Hide ▲
Show ▼
EfficientIP recommended blocking disposable phishing domains and IPs after tracking AliExpress-themed entry points that could expose users to credential, payment, and browsing-data theft. The guidance also calls for DNS and proxy log review to find prior connections before the domains are reconfigured or replaced. That helps defenders catch exposure quickly when low-history domains have not yet been classified by reputation systems.
Related Happenings
AliExpress-themed phishing operation using disposable redirect domains
Campaign
H score30
First: 25.09.2026 11:30
Last: 25.09.2026 11:30
Sources 1
How related:
Each sent visitors through a tracking layer carrying campaign, click or affiliate parameters, which EfficientIP said lets an operator replace exposed domains without rebuilding the campaign.
About this happening:
An AliExpress-themed phishing campaign surfaced through 10 disposable .cyou domains that were flagged before registration and later redirected visitors to a fake shopping-...
AliExpress-themed phishing operation using disposable redirect domains
CampaignHow related: Each sent visitors through a tracking layer carrying campaign, click or affiliate parameters, which EfficientIP said lets an operator replace exposed domains without rebuilding the campaign.
About this happening: An AliExpress-themed phishing campaign surfaced through 10 disposable .cyou domains that were flagged before registration and later redirected visitors to a fake shopping-...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor Meta
H score37
First: 09.07.2026 17:39
Last: 09.07.2026 17:39
Sources 1
About this happening:
Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Forg365-ForgCookie alliance reshapes ransomware ecosystem operations
Threat Actor MetaAbout this happening: Forg365 is a phishing-as-a-service (PhaaS) operation built to steal Microsoft 365 accounts with AiTM and device-code phishing, increasing credential-theft risk...
Ip6.arpa reverse-DNS phishing campaign using IPv6 tunneling
Campaign
H score34
First: 08.03.2026 16:12
Last: 08.03.2026 16:12
Sources 1
About this happening:
A phishing campaign is abusing ip6.arpa reverse DNS and IPv6 tunneling to slip past domain reputation checks and email security gateways, making malicious links ha...
Ip6.arpa reverse-DNS phishing campaign using IPv6 tunneling
CampaignAbout this happening: A phishing campaign is abusing ip6.arpa reverse DNS and IPv6 tunneling to slip past domain reputation checks and email security gateways, making malicious links ha...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor Meta
H score82
First: 05.03.2026 08:51
Last: 05.03.2026 08:51
Sources 1
About this happening:
Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Tycoon 2FA-Storm-1747 ecosystem shift changes threat-actor operations
Threat Actor MetaAbout this happening: Tycoon 2FA is a commercial phishing-as-a-service ecosystem that moved from adversary-in-the-middle credential harvesting into device-code phishing after a March...
Latest development: 17.05.2026 17:43
eSentire says Tycoon2FA now uses device-code phishing to target Microsoft 365 accounts, with invoice-themed lure emails carrying Trustifi click-tracking URLs that redirect through Trustifi, Cloudflare Workers, obfuscated JavaScript layers, and a fake Microsoft CAPTCHA page before sending victims to microsoft.com/devicelogin. The kit also adds anti-analysis defenses, including detection of Selenium, Puppeteer, Playwright, and Burp Suite, plus blocks for security vendors, VPNs, sandboxes, AI crawlers, and cloud providers.
Timeline
-
25.09.2026 11:30 1 articles · 2h ago
ANY.RUN tags AliExpress-lookalike shopping-assistant site as phishing
Detection Ioc UpdateANY.RUN's sandbox tagged a lookalike shopping-assistant site as phishing on May 22; the site used a zero in place of the "o" in "shop" and promoted a browser extension styled after Alitools.
Show sources
- Researchers Identify AliExpress Phishing Domains Before Registration — www.infosecurity-magazine.com — 25.09.2026 11:30
-
25.09.2026 11:30 1 articles · 2h ago
EfficientIP flags 10 potential .cyou domains before registration
Initial DisclosureEfficientIP Research Labs identified 10 potential .cyou domains on June 9 and added them to its DNS threat intelligence feed, treating them as disposable entry points tied to the AliExpress-themed phishing activity.
Show sources
- Researchers Identify AliExpress Phishing Domains Before Registration — www.infosecurity-magazine.com — 25.09.2026 11:30
-
25.09.2026 11:30 1 articles · 2h ago
Ten .cyou domains register and resolve to phishing infrastructure
Campaign Scope UpdateOn July 2, the 10 .cyou domains were registered and began resolving to three IP addresses in one subnet, and DNS and redirect tracing led researchers to a fake AliExpress site.
Show sources
- Researchers Identify AliExpress Phishing Domains Before Registration — www.infosecurity-magazine.com — 25.09.2026 11:30
-
25.09.2026 11:30 2 articles · 2h ago
EfficientIP advises blocking phishing domains and hunting DNS and proxy logs
Mitigation Patch UpdateEfficientIP advised blocking the domains and IP addresses and searching DNS and proxy logs for past connections, warning that users who engaged with the lure should reset credentials, contact card issuers, and remove the extension.
Show sources
- Researchers Identify AliExpress Phishing Domains Before Registration — www.infosecurity-magazine.com — 25.09.2026 11:30
- Researchers Identify AliExpress Phishing Domains Before Registration — www.infosecurity-magazine.com — 25.09.2026 11:30