CyberSecurity SEE

Researchers Identify Phishing Domains for AliExpress Ahead of Registration

Researchers Identify Phishing Domains for AliExpress Ahead of Registration

Security Researchers Warn of Preemptive Phishing Scheme Targeting AliExpress Users

In a concerning development for online shoppers, security researchers have identified a sophisticated phishing campaign linked to AliExpress that took root in a peculiarly short timeframe. EfficientIP Research Labs reported that it flagged ten web addresses weeks before they were officially registered. The researchers tracked these domains as they became active entry points to a fraudulent site that misleadingly mimicked AliExpress.

On June 9, EfficientIP harnessed its advanced AI-driven domain generation algorithm (DGA) detection engine to spot potential phishing domains embedded within customer DNS traffic. Following this initial detection, these domains were incorporated into the company’s DNS threat intelligence feed. By July 2, they were officially registered and began resolving to specific IP addresses. Investigating the DNS records and redirection activities led researchers directly to a counterfeit AliExpress platform.

The Mechanics of the Phishing Campaign

All ten identified domains exhibited a formulaic structure of a single digit followed by five lowercase letters. They shared the same registration date and resolved to three IP addresses contained within one subnet. While EfficientIP labeled them as DGA-style domains, they emphasized that the correlation in structure alone does not definitively indicate that a domain generation algorithm was at play.

Notably, none of these domains hosted their phishing lure directly. Instead, they funneled visitors through a tracking layer that contained various campaign parameters, such as click or affiliate tracking. EfficientIP explained that this method allows phishing operators to change out exposed domains without needing to reconfigure the entire campaign. Due to the low historical footprint of these domains, traditional reputation-based controls were likely ineffective at the time those initial visitors arrived.

The nature of the .cyou top-level domain adds an additional layer of analysis but does not serve as a conclusive indicator of malicious intent. EfficientIP referenced findings from Cloudflare, which reported that 62% of emails associated with the .cyou domain in 2023 were categorized as malicious. However, they did caution that the domain’s suffix alone should not be the sole factor in deeming a website dangerous.

Further emphasizing the gravity of the situation, a study by Interisle titled "Phishing Landscape 2025" revealed that a staggering 77% of phishing domains were registered with malicious intent. More notably, 37% of these domains were acquired through bulk registration services.

Deceptive Tactics and User Risks

The phishing campaign culminated at a site that employed a zero in place of the letter "o" in "shop," promoting a browser extension fraudulently branded as Alitools, which is a legitimate shopping assistant with a claimed user base exceeding 500,000. Visitors to the site were urged to click an "Add to Browser" button, further facilitating the potential for fraud.

Several cybersecurity firms had already flagged the site as hazardous or phishing-related. For instance, ANY.RUN identified it as phishing on May 22, well ahead of the registration of the redirect domains, indicating that there was pre-existing awareness concerning the site.

According to Christophe Girard, the cyber AI and Big Data R&D manager at EfficientIP, users who interacted with the fraudulent site faced serious risks including credential theft, payment fraud, and the unwanted exposure of browsing behaviors through the malicious extension. Moreover, the embedded tracking parameters offer operators an avenue for potential affiliate revenue.

Girard commented to Infosecurity, "While we cannot determine the exact number of users who accessed the fraudulent site, we can confirm that access occurred across eight different telecom operators in several geographical locations." This highlights the widespread nature of the threat, making it imperative for users to exercise caution when browsing.

In response to this alarming phishing scheme, EfficientIP has recommended that organizations and individuals block the malicious domains and associated IP addresses. They also advise searching DNS and proxy logs for any previous connections to the fraudulent sites. For individuals who may have engaged with the site, they recommend immediate action—including resetting account passwords, notifying credit card issuers, and removing the fraudulent browser extension.

With the rapid evolution of cyber threats and increasingly sophisticated tactics employed by cybercriminals, this incident serves as a critical reminder for online shoppers to remain vigilant and prioritize their cybersecurity hygiene. As phishing attempts continue to proliferate, awareness and proactive measures are necessary to safeguard personal information and financial security.

Source link

Exit mobile version