Back Infosecurity-Magazine Researchers Identify AliExpress Phishing Domains Before Registration
Security researchers have reported flagging 10 web addresses weeks before they were registered, then watching them go live as entry points to an AliExpress-themed phishing site.
EfficientIP Research Labs said it identified the potential .cyou domains on June 9 in customer DNS traffic using its AI-driven domain generation algorithm (DGA) detection engine and added them to its DNS threat intelligence feed. They were subsequently registered and began resolving to IP addresses on July 2. Tracing their DNS and redirect activity led researchers to a fake AliExpress site.
Ten Disposable Entry Points
All 10 domains followed the same format of one digit and five lowercase letters, shared a registration date and resolved to three IP addresses in one subnet. EfficientIP called them DGA-style, but said the pattern alone does not prove a domain generation algorithm produced them.
None hosted the lure. Each sent visitors through a tracking layer carrying campaign, click or affiliate parameters, which EfficientIP said lets an operator replace exposed domains without rebuilding the campaign.
Because such domains have little history, EfficientIP said, reputation-based controls may not yet have classified them when the first visitors arrive.
The .cyou top-level domain adds context rather than proof. EfficientIP cited Cloudflare research which found that 62% of emails from .cyou in 2023 were malicious, while stressing that the ending alone does not make a site dangerous.
An Interisle Phishing Landscape 2025 study found 77% of phishing domains were maliciously registered and 37% were bought through bulk-registration services.
A Lookalike Shopping Assistant
The chain ended at a site using a zero in place of the "o" in "shop," promoting a browser extension styled after Alitools, a legitimate shopping-assistant brand.
It claims more than 500,000 users and urges visitors to click "Add to Browser."
Several security services had flagged the site as malicious or unsafe, including ANY.RUN, whose sandbox tagged it as phishing on May 22. That predates the redirect domains by weeks, so the early warning applies to the entry points rather than the site itself.
EfficientIP said visitors risked credential and payment theft and exposure of browsing activity through the extension, while the tracking parameters could earn the operator affiliate revenue.
Christophe Girard, cyber AI & bigdata R&D manager at EfficientIP, told Infosecurity , "We cannot confirm how many individual people reached the final site, but we can confirm that it was accessed by users across eight different telecom operators in multiple geographies."
EfficientIP advised blocking the domains and IP addresses and searching DNS and proxy logs for past connections. Where users engaged with the site, it recommended resetting credentials, contacting card issuers and removing the extension.
Article updated on September 25 to include Girard .
DNS Attacks on the Rise, Costing $1 Million Each News 4 June 2021
DNS Attacks on the Rise, Costing $1 Million Each
Nearly Three-Quarters of Firms Suffer Downtime from DNS Attacks News 1 June 2022
Nearly Three-Quarters of Firms Suffer Downtime from DNS Attacks
Two-Fifths of Euro Firms Suffer DNS-Linked Data Theft News 8 June 2018
Two-Fifths of Euro Firms Suffer DNS-Linked Data Theft
DNS Attack Costs Soar 105% in UK News 17 May 2018
DNS Attack Costs Soar 105% in UK
Governments Lose Millions to DNS Attacks Each Year News 19 November 2019
Governments Lose Millions to DNS Attacks Each Year
What’s Hot on Infosecurity Magazine?
ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day
Ransomware Attacks Reach Record High for 2026
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
North Korean Attackers Hit 30,000 Devices and Steal $10.7m
Hundreds of Leaked GitHub App Keys Still Authenticate
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
ShinyHunters Claim Hack of Rival Ransomware Gang Clop
Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
CRA Reporting Rules Take Effect: How to Ensure Your Organization is Ready
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day
AI-Driven Cloud Threats and Defenses: Securing AI-Powered Environments
Your Security Awareness Programme Isn't Failing, It's Just Not Relevant
From APIs to Agents: How to Secure AI at Enterprise Scale
Frontier AI: How Cyber Defenders Can Harness the Defender’s Window
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Securing M365 Data and Identity Systems Against Modern Adversaries
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
