VYPR
researchPublished Sep 25, 2026· 1 source

Researchers Proactively Flag AliExpress Phishing Domains Before Registration

EfficientIP researchers have developed a novel method to identify and flag AliExpress phishing domains before they are officially registered, enabling earlier mitigation of malicious campaigns.

Security researchers have successfully identified and flagged ten web addresses weeks before their official registration, subsequently observing them being activated as entry points for AliExpress-themed phishing campaigns. This proactive approach, developed by EfficientIP Research Labs, aims to disrupt threat actors by intercepting malicious infrastructure before it becomes fully operational.

The identified domains, all utilizing the .cyou top-level domain, shared a common format and registration date, resolving to a small cluster of IP addresses. While EfficientIP noted their similarity to domains generated by Domain Generation Algorithms (DGAs), they stopped short of definitively attributing their creation to such methods. Each domain acted as a disposable entry point, redirecting users through a tracking layer that included campaign and affiliate parameters. This design allows operators to easily swap out compromised domains without needing to rebuild the entire phishing infrastructure.

EfficientIP highlighted that domains with little to no history often evade reputation-based security controls, making them particularly dangerous in their initial stages. The use of the .cyou TLD, while not inherently malicious, has been associated with a high percentage of malicious emails, according to Cloudflare research. Similarly, a study by Interisle found that a significant portion of phishing domains are maliciously registered or purchased in bulk, underscoring the need for advanced detection methods.

The phishing chain ultimately led to a fake AliExpress website that mimicked a legitimate shopping assistant brand, Alitools. This fraudulent site urged visitors to install a browser extension, posing as a "shopping assistant." While several security services had already flagged the site as malicious in sandbox environments, the threat actor's use of pre-registration domain flagging meant that the entry points themselves were identified and neutralized before widespread exploitation could occur.

Users who interact with such phishing sites risk credential theft, payment information compromise, and exposure of their browsing activity through malicious extensions. The tracking parameters embedded in the redirect layer also present an opportunity for threat actors to generate affiliate revenue. While the research identified the mechanism and potential harms, it did not report any confirmed victims or financial losses, nor did it detail how users were initially directed to these domains or the specific functionality of the malicious extension.

To combat this threat, EfficientIP recommended blocking the identified domains and IP addresses, and urged organizations to search their DNS and proxy logs for any past connections. For users who may have engaged with the malicious site, the advice included resetting credentials, contacting credit card issuers, and removing any installed extensions. The exact methodology used by EfficientIP to spot these domains prior to their registration remains undisclosed, with the company having been contacted for further details.

This development underscores the evolving tactics of cybercriminals in the phishing landscape, particularly their reliance on disposable infrastructure and the exploitation of new TLDs. The proactive detection method employed by EfficientIP represents a significant step forward in disrupting these campaigns at an earlier stage, potentially saving numerous users from falling victim to credential harvesting and other malicious activities.

Synthesized by Vypr AI