Threat Actors Register Over 26,000 Domains to Imitate Brands and Deceive Users

Threat Actors Register Over 26,000 Domains to Imitate Brands and Deceive Users

Massive Surge in Fake Domains Targets Users with Sophisticated Smishing Campaigns

In March 2025 alone, cybercriminals registered over 26,000 domains designed to impersonate trusted brands and government agencies—marking a dramatic escalation in digital deception tactics.

These rogue domains are being used in advanced smishing (SMS phishing) campaigns, where victims receive text messages containing links to fake websites that mimic legitimate services. The goal? Trick users into handing over sensitive information or making fraudulent payments.

To boost credibility, attackers are crafting domain names that blend real brand names with suspicious subdomains. This subtle manipulation gives just enough visual legitimacy to fool users at a glance.

This isn’t a new tactic—it’s a significant expansion of a trend that gained momentum in early 2024. Since the FBI’s initial warning last April, researchers have now identified over 91,500 root domains used in similar attacks.

The campaign’s targets are carefully chosen: services where users expect timely, actionable messages—such as delivery updates, toll payment notices, and government alerts.

According to researchers at Palo Alto Networks, more than 75% of these domains were registered through a single registrar—Hong Kong-based Dominet (HK) Limited—pointing to a highly coordinated campaign, likely run by a single threat group.

Their telemetry data reveals the scale of the operation: over 31 million domain queries were logged in just the last quarter, a clear sign of the campaign’s reach and effectiveness.

One of the reasons this tactic works so well is its short-lived nature. Nearly 70% of traffic to these domains happens within a week of registration, allowing attackers to slip under the radar before defenses catch up.

Domain Patterns: Deceptively Simple

The domains typically follow four predictable naming conventions, all designed to appear legitimate. Examples include structures like:

  • com-[random string].[TLD]
  • gov-[random string].[TLD]

For instance:

  • A domain like gov-mfc.com was used to create the deceptive URL hxxps://driveky.gov-mfc.com/pay, spoofing Kentucky’s driving services.
  • Another, com-ic1.top, was used as hxxps://usps.com-ic1.top/us, impersonating the U.S. Postal Service.

Security experts suggest that blocking Newly Registered Domains (NRDs) for at least a month can intercept around 85% of this malicious traffic. However, attackers are adapting quickly.

They’re now using cloaking techniques that display different content depending on the visitor—making it harder for both end-users and automated systems to detect malicious intent.

As activity continues to surge in 2025, it’s clear that threat actors are investing more resources and growing bolder with their tactics. This evolving threat demands continued vigilance, smarter detection strategies, and global cooperation to slow the momentum of these large-scale deception campaigns.

More Articles & Posts