Skip to content
Researchers Identify AliExpress Phishing Domains Before Registration

Researchers Identify AliExpress Phishing Domains Before Registration

Infosecurity-Magazine • September 25, 2026

Security researchers have reported flagging 10 web addresses weeks before they were registered, then watching them go live as entry points to an AliExpress-themed phishing site.

EfficientIP Research Labs said it identified the potential .cyou domains on June 9 in customer DNS traffic using its AI-driven domain generation algorithm (DGA) detection engine and added them to its DNS threat intelligence feed. They were subsequently registered and began resolving to IP addresses on July 2. Tracing their DNS and redirect activity led researchers to a fake AliExpress site.

Ten Disposable Entry Points

All 10 domains followed the same format of one digit and five lowercase letters, shared a registration date and resolved to three IP addresses in one subnet. EfficientIP called them DGA-style, but said the pattern alone does not prove a domain generation algorithm produced them.

None hosted the lure. Each sent visitors through a tracking layer carrying campaign, click or affiliate parameters, which EfficientIP said lets an operator replace exposed domains without rebuilding the campaign.

Because such domains have little history, EfficientIP said, reputation-based controls may not yet have classified them when the first visitors arrive.

The .cyou top-level domain adds context rather than proof. EfficientIP cited Cloudflare research which found that 62% of emails from .cyou in 2023 were malicious, while stressing that the ending alone does not make a site dangerous.

An Interisle Phishing Landscape 2025 study found 77% of phishing domains were maliciously registered and 37% were bought through bulk-registration services.

A Lookalike Shopping Assistant

The chain ended at a site using a zero in place of the "o" in "shop," promoting a browser extension styled after Alitools, a legitimate shopping-assistant brand.

It claims more than 500,000 users and urges visitors to click "Add to Browser."

Several security services had flagged the site as malicious or unsafe, including ANY.RUN, whose sandbox tagged it as phishing on May 22. That predates the redirect domains by weeks, so the early warning applies to the entry points rather than the site itself.

EfficientIP said visitors risked credential and payment theft and exposure of browsing activity through the extension, while the tracking parameters could earn the operator affiliate revenue.

Christophe Girard, cyber AI & bigdata R&D manager at EfficientIP, told Infosecurity , "We cannot confirm how many individual people reached the final site, but we can confirm that it was accessed by users across eight different telecom operators in multiple geographies."

EfficientIP advised blocking the domains and IP addresses and searching DNS and proxy logs for past connections. Where users engaged with the site, it recommended resetting credentials, contacting card issuers and removing the extension.

Article updated on September 25 to include Girard .

DNS Attacks on the Rise, Costing $1 Million Each News 4 June 2021

DNS Attacks on the Rise, Costing $1 Million Each

Nearly Three-Quarters of Firms Suffer Downtime from DNS Attacks News 1 June 2022

Nearly Three-Quarters of Firms Suffer Downtime from DNS Attacks

Two-Fifths of Euro Firms Suffer DNS-Linked Data Theft News 8 June 2018

Two-Fifths of Euro Firms Suffer DNS-Linked Data Theft

DNS Attack Costs Soar 105% in UK News 17 May 2018

DNS Attack Costs Soar 105% in UK

Governments Lose Millions to DNS Attacks Each Year News 19 November 2019

Governments Lose Millions to DNS Attacks Each Year

What’s Hot on Infosecurity Magazine?

ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day

Ransomware Attacks Reach Record High for 2026

Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records

North Korean Attackers Hit 30,000 Devices and Steal $10.7m

Hundreds of Leaked GitHub App Keys Still Authenticate

ShinyHunters Claim Hack of Rival Ransomware Gang Clop

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

ShinyHunters Claim Hack of Rival Ransomware Gang Clop

Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records

CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready

New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code

ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day

AI-Driven Cloud Threats and Defenses: Securing AI-Powered Environments

Your Security Awareness Programme Isn't Failing, It's Just Not Relevant

From APIs to Agents: How to Secure AI at Enterprise Scale

Frontier AI: How Cyber Defenders Can Harness the Defender’s Window

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Securing M365 Data and Identity Systems Against Modern Adversaries

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

Extracted Entities

Attack Types (1)

MITRE ATT&CK (1)

Platforms (1)