Skip to content
AliExpress Phishing Campaign Exposed with Early DNS Detection

AliExpress Phishing Campaign Exposed with Early DNS Detection

First seen 25 Sep 2026, 11:24 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 25, 2026 at 13:25 UTC
  • •Ten phishing domains linked to AliExpress were identified before registration.
  • •The campaign used a convincing fake shopping site to steal user credentials.
  • •DNS intelligence enabled early detection, allowing for proactive security measures.

EfficientIP Research Labs identified ten .cyou domains linked to an AliExpress phishing campaign before their registration on June 9, 2026. The domains became active on July 2, directing users to a fraudulent AliExpress-themed site that promoted a malicious browser extension. The campaign utilized a phishing redirect chain and familiar branding to deceive users, posing risks of credential theft and payment fraud. The domains followed a specific naming pattern and shared infrastructure, which allowed for early detection through DNS intelligence. This early identification provided security teams with a crucial opportunity to mitigate potential impacts before the domains were classified as malicious. The research highlights the importance of monitoring DNS activity for early threat detection.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-09
Domains identified before registration
EfficientIP flagged ten potential .cyou domains in DNS traffic using its detection engine.
EfficientIP
2026-07-02
Domains became active
The flagged domains were registered and began resolving to IP addresses, linking them to a phishing campaign.
EfficientIP
2026-09-25
Research published
EfficientIP released findings on the phishing campaign, emphasizing the importance of DNS monitoring for threat detection.
EfficientIP

More articles in this cluster (2)