< ciso
brief />
Tag Banner

All news with #domain impersonation tag

58 articles

How to Spot Suspicious and Risky Websites

🔎 This article explains how many websites fall into a gray area between legitimate services and outright scams, outlining common deceptive practices and how they harm users. It describes schemes such as hidden subscription traps, counterfeit or non-delivered goods, fraudulent crypto and investment platforms, and fake middlemen charging inflated fees. The piece also highlights dangerous fake browser extensions and recommends using Kaspersky security solutions, including the Kaspersky Protection browser extension and Kaspersky Premium, to detect, block, and warn about sites with uncertain trust.
read more →

Fake recruiter phishing targets corporate mobile logins

🔍 Researchers at Zimperium’s zLabs uncovered recruitment-themed phishing campaigns that target corporate credentials on mobile devices by presenting full-screen counterfeit login pages and rejecting personal email domains to prioritize enterprise accounts. The activity, linked to RecruitTrap, impersonated major employers and persisted across cloud, hosting and domain-parking providers, exposing gaps in URL blocklists. Zimperium recommends securing mobile identity touchpoints and dynamically inspecting network traffic to detect credential harvesting.
read more →

Weedhack malware spread via fake Minecraft clients

🛡️ McAfee Labs found ongoing campaigns distributing the Weedhack malware by impersonating popular Minecraft clients and hosting convincing lookalike sites. The attacks use SEO poisoning, Discord and file-hosting links to redirect victims and deploy multi-stage JAR payloads that collect system data and disable security protections. Threat actors even used an AI site builder to create believable malicious domains that outrank legitimate sources.
read more →

CubePilot suffers DNS hijack disrupting drone services

🛡️ CubePilot, an Australian drone flight-controller maker, reported a DNS hijacking on July 24 that redirected traffic to attacker-controlled infrastructure and allowed issuance of TLS certificates for all cubepilot.org subdomains. The firm regained domain control the same day, revoked the fraudulent certificates, preserved evidence, and informed authorities. Critical services including OEM portals, the community forum, and documentation remain offline while the company investigates and advises caution around credentials and recent firmware downloads.
read more →

Lawsuit Claims App Store Hosted Fake Bitcoin Wallet

🔒 Three plaintiffs allege they lost about $1.8 million in Bitcoin after installing a fraudulent Sparrow Wallet app from the App Store. The July 24 complaint accuses Apple of inadequate app review and monitoring, saying the malicious app impersonated the legitimate desktop-only Sparrow Wallet and prompted users to enter seed phrases. Victims reported the fraudulent app to Apple, which later removed impersonating apps and terminated developer accounts, but plaintiffs say warnings had been issued to Apple over a year earlier.
read more →

ChatGPT Enters Top 10 Most Impersonated Brands

🛡️ OpenAI’s ChatGPT has appeared in the top 10 most impersonated brands in phishing attacks for the first time in Q2 2026, according to Check Point. The report highlights a fake “ChatGPT Plus payment failed” email that mimicked an OpenAI billing notice to steal full credit card details. Microsoft remains the most impersonated brand, followed by LinkedIn, with Google, Apple and Amazon also in the top five. Check Point recommends inline phishing prevention, AI-powered detection and consolidated email/workspace protection to mitigate brand phishing.
read more →

LastPass and Bitwarden Users Targeted by Phishing Alerts

🔔 LastPass warns of an active phishing campaign using fake corporate-style security notices that redirect recipients to fraudulent landing pages impersonating DocuSign. The emails, claiming to announce policy updates, come from addresses like hello@lastpassnewsletter.com and lead to domains such as lastpasscompliance[.]com, which have been flagged as malicious. Bitwarden users have received similar messages from hello@bitwardennewsletter.com redirecting to bitwardencompliance[.]com. LastPass confirms its systems were not breached and urges users to never share their master password and to report suspicious messages to abuse@lastpass.com.
read more →

OnlyFans DMCA Requests Reveal Compromised Domains

🔎 Armed with copyright law and internet scanning, OnlyFans creators and specialized vendors have been using DMCA takedowns to identify and remove unauthorized adult-content listings that appear on high-authority government and education websites. By tracking requests in Google’s Transparency Report and the Lumen database, researchers mapped thousands of compromised .gov and .edu domains used by traffic distribution systems (TDS) and parasite SEO. This trend has grown rapidly since 2020 as decentralized content ownership increased detection coverage and vendor capabilities.
read more →

Google sues scammers leveraging Gemini AI

🛡️ Google has filed suit against a group called Outsider Enterprise, accused of running phishing-as-a-service via Telegram using Gemini to create convincing fake sites. The operation reportedly offered nearly 300 scam templates impersonating Google, YouTube, and agencies like New York’s E‑ZPass. Google coordinated with carriers and used on‑device protections in Google Messages to block many malicious texts. The company hopes legal action and technical defenses will curb the campaign.
read more →

Phishing campaign impersonates Interpol to spread ransomware

🛡️ Cybercriminals are impersonating Interpol in a phishing campaign aimed at small businesses across Europe, Asia, the Middle East and North America. The emails claim to be from the 'Cybercrime Investigation Unit' and urge recipients to open a password-protected Proton Drive file supposedly containing evidence. The file leads to an executable disguised as a video that deploys ransomware and instructs victims to contact attackers via Tox rather than listing a ransom.
read more →

Phantom squatting: AI-hallucinated domains abused

🛡️ Palo Alto Networks' Unit 42 warns attackers are registering AI-hallucinated domains and using them for phishing and malware distribution. The report shows models invent millions of links, many unregistered, and attackers are preemptively purchasing and cloning brand sites. Because new domains lack reputation data, they evade blocklists until damage is done. Unit 42 documents several real-world cases and offers mitigation steps for defenders and users.
read more →

Phantom Squatting: LLMs Enabling Web Domain Attacks

🛡️ Unit 42 found that large language models (LLMs) commonly hallucinate plausible web domains for real brands, and adversaries are registering these nonexistent domains to intercept AI-generated traffic. This phenomenon, called phantom squatting, poses a supply chain risk and was observed across multiple sectors. Researchers predicted adversary registrations 18–51 days in advance and discovered over 13,229 malicious URLs plus ~250,000 unregistered hallucinated domains.
read more →

Scammers Exploit Venezuela Earthquake Registrations

🧭Researchers uncovered 212 domains registered within five days of the Venezuela earthquake, many claiming to offer aid, donations, or rescue services. While some registrations may be legitimate, 93% hid registrant contact details and several solicit Bitcoin with no verifiable accountability. The pattern mirrors past disaster-driven scams; donors are advised to use known charity sites and avoid new or crypto-only donation pages.
read more →

Pre-positioned cyber threats around FIFA 2026 event

⚠️ Check Point Research found that cybercriminals pre-built and partially deployed fraud infrastructure targeting FIFA World Cup 2026 before the June 11 kickoff, focusing on financial services, transportation, hospitality, and gambling. Pre-tournament research highlighted weak DMARC enforcement among partners, a 60x surge in fake sportsbook apps concentrated on Google Play, and large volumes of lookalike travel and hotel domains created two months prior. Check Point's exposure, brand protection, and dark web monitoring capabilities flagged the activity and report rapid remediation metrics.
read more →

Fraudulent OpenAI organization invites target security firms

🔔 Push Security discovered a campaign where attackers create fraudulent OpenAI tenants impersonating real companies and send legitimate-looking invites to employees. The invites originate from OpenAI notification addresses, pass authentication checks, and assign recipients Owner privileges within the fake organization. Attackers used Gmail accounts to pose as company executives and even attached a billing card to the tenant, likely to reduce suspicion. Push Security warns employees could be tricked into submitting sensitive data into the workspace and advises verification and monitoring of SaaS memberships.
read more →

Prime Day 2026: Surge in Amazon-Themed Scams

🛡️ Check Point Research warns that Amazon Prime Day (June 23–26, 2026) is generating a large pre-event surge in phishing, fake storefronts, and domain-squatting operations. Between December 2025 and May 2026, thousands of Amazon-themed domains were registered, with many already flagged as malicious. Attackers are building multi-TLD campaigns, regional IDN spoofs, and convincing counterfeit product pages to steal credentials and payments.
read more →

FTC: Record $3.5B Lost to Imposter Scams in 2025

📰 The FTC reports Americans lost $3.5 billion to imposter scams in 2025, with these schemes comprising nearly one in three fraud reports. Scammers used texts, calls, emails, social media, and search results, with social platforms driving over $2.1 billion in losses. Business and government impersonators caused the largest harms, and the FTC has pursued enforcement under its Impersonation Rule to seek redress.
read more →

Aged-domain acquisition enables phishing bypasses

🔒 Phishing operators increasingly buy or hijack aged legitimate domains to bypass enterprise email filters that weight domain age heavily. The author documents a Sneaky2FA campaign using a decade-old domain takeover revealed via certificate transparency logs, illustrating gaps in reputation scoring. Detection should include hosting-pattern stability, subdomain wordlist anomaly, and CT log monitoring to catch these rapid repurposings.
read more →

FIFA World Cup 2026: Rising ticket and streaming scams

🛡️ Security researchers and law enforcement warn that FIFA-themed fraud is already targeting World Cup 2026 fans ahead of the June 11 kickoff. Threat actors have registered thousands of lookalike domains, deployed phishing kits that clone FIFA's login pages, and hidden banking trojans inside pirate streaming apps. Scams include counterfeit ticket sales, fake merchandise shops, malicious streaming apps that install banking malware, and social-media ad campaigns driving victims to phishing pages.
read more →

Pre-positioned Cyber Threats Targeting FIFA 2026

🛡️ Check Point Research and Exposure Management tracked a year-long rise in coordinated cyber threats aimed at FIFA World Cup 2026. Attackers have pre-positioned infrastructure across finance, travel and hospitality, and gambling, with active domains, fake apps, and social schemes ready to scale. The report highlights escalating fraud, domain impersonation, mobile-app impersonation, B2B spoofing risks, and potential operational impacts like ransomware and DDoS.
read more →