Security News

Researchers Spot AliExpress Phishing Domains Weeks Before They Went Live

Infosecurity Magazine · 25 Sept 2026
Key Takeaway Train staff to be wary of shopping-related browser extensions and links from unfamiliar or newly seen domains, since brand-new websites can bypass standard reputation-based filtering.

Security researchers at EfficientIP Research Labs identified 10 web addresses on June 9, weeks before they were even registered, and added them to a DNS threat intelligence feed. The domains, all using the .cyou top-level domain and following a similar naming pattern, went live on July 2 and began redirecting visitors through a tracking layer to a fake AliExpress shopping site.

The fake site used a lookalike domain (replacing a letter with a zero) and promoted a browser extension styled after a legitimate shopping-assistant brand, claiming over 500,000 users. Researchers warned that visitors could risk having credentials, payment details or browsing activity exposed, while the redirect structure allows the operator to swap out exposed domains without rebuilding the whole campaign. Notably, one of the destination sites had already been flagged as phishing by a security sandbox weeks before the redirect domains appeared, though the report does not confirm any actual victims or financial losses.

The research highlights a broader trend: newly registered domains often slip past reputation-based security filters because they lack any history to be judged against, giving attackers a short window to operate undetected.

phishing DNS security domain abuse browser extensions threat intelligence

Summarised by CISO AI from Infosecurity Magazine. We link back to every original so you can read it yourself.