Infosecurity Magazine iconInfosecurity MagazineSep 25, 2026 ~4 min source read

Researchers flagged AliExpress-themed phishing domains weeks before registration

EfficientIP detected 10 DGA-style.cyou domains in June, added them to DNS threat feeds, then watched them be registered and used as disposable entry points to a fake AliExpress lookalike pushing a malicious browser extension.

Share this story

Send the public story page.

Useful takeaways from this story.

EfficientIP identified 10 domains with a one-digit + five-letter pattern on June 9 and added them to its DNS threat feed before they were registered on July 2.

All 10 domains resolved to three IPs in the same subnet and redirected visitors through a tracking layer to a fake AliExpress-style site promoting a malicious browser extension.

If users engaged with the site or installed the extension, steps include removing the extension, resetting credentials, and contacting card issuers if payment information may have been exposed.

The useful part

EfficientIP Research Labs said it identified the potential.cyou domains on June 9 in customer DNS traffic using its AI-driven domain generation algorithm (DGA) detection engine and added them to its DNS threat intelligence feed. They were subsequently registered and began resolving to IP addresses on July 2. Tracing their DNS and redirect activity led researchers to a fake AliExpress site.

How it works

  • Ten Disposable Entry Points All 10 domains followed the same format of one digit and five lowercase letters, shared a registration date and resolved to three IP addresses in one subnet.
  • Each sent visitors through a tracking layer carrying campaign, click or affiliate parameters, which EfficientIP said lets an operator replace exposed domains without rebuilding the campaign.
  • It claims more than 500,000 users and urges visitors to click "Add to Browser." Several security services had flagged the site as malicious or unsafe, including ANY.RUN, whose sandbox tagged it as phishing...
  • Where users engaged with the site, it recommended resetting credentials, contacting card issuers and removing the extension.
  • Opinion 12 November 2025 1 Japanese Railway Operators Hit with Weekend Cyber Attacks News 29 September 2026 2 Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk News 25 September...

What to take from it

Because such domains have little history, EfficientIP said, reputation-based controls may not yet have classified them when the first visitors arrive. EfficientIP said visitors risked credential and payment theft and exposure of browsing activity through the extension, while the tracking parameters could earn the operator affiliate revenue. Critical Infrastructure Braces for Sweeping New Cyber Reporting Rules News Feature 28 September 2026 4 Deepfakes Are Becoming a Costly Reality for Businesses, Report Warns News 28 September 2026 5 Citrix Patches Critical Zero Days Under Active Exploitation News 28 September 2026 6 Who Authorized That Agent?

Example or evidence

  • Researchers Identify AliExpress Phishing Domains Before Registration.
  • EfficientIP called them DGA-style, but said the pattern alone does not prove a domain generation algorithm produced them.
  • An Interisle Phishing Landscape 2025 study found 77% of phishing domains were maliciously registered and 37% were bought through bulk-registration services.
  • That predates the redirect domains by weeks, so the early warning applies to the entry points rather than the site itself.

Details worth keeping

The.cyou top-level domain adds context rather than proof. Hundreds of Malicious Domains Registered Ahead of Prime Day A Lookalike Shopping Assistant The chain ended at a site using a zero in place of the "o" in "shop," promoting a browser extension styled after Alitools, a legitimate shopping-assistant brand. Article updated on September 25 to include Girard comments.

Related coverage

  • Gbhackers: A surge of lookalike domains targeting users of TypeSafe AI's newly launched Jev decision model, with roughly 670 "jev"-branded domains obtaining TLS certificates within eight days of the product's debut.
  • Bleepingcomputer: A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. [...]
  • Jpost: BrandShield also identified 5,878 fake or suspicious domains involving the luxury Swiss watch brand Omega SA, alongside 5,134 linked to NIKE, 4,987 to Labubu, and 4,041 to Apple's iPhone.
  • Esecurityplanet: 119,000 Fake Shops Are Mimicking Real Brands to Steal Card Details
  • Theregister: Used by crims to compromise 12K+ email inboxes across 10K+ global orgs

More context around this story.

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app