Palo Alto Networks reported widespread abuse of cybersquatting domains that imitate major brands including Facebook, Apple, Amazon, Netflix, Microsoft, Samsung, Walmart, and Wells Fargo to conduct phishing, malware delivery, command-and-control, technical support fraud, reward scams, re-bill scams, and parked-domain monetization. In one month of observation, researchers identified 13,857 squatting domains—about 450 per day—with 2,595 classified as malicious and 5,104 as suspicious or high risk, showing how frequently newly registered lookalike domains are weaponized against consumers.
The activity used multiple squatting techniques, including typosquatting, combosquatting, homograph-squatting, soundsquatting, bitsquatting, and level-squatting, and often targeted profitable sectors such as search, social media, shopping, finance, and banking. Examples included secure-wellsfargo[.]org for phishing, samsungeblyaiphone[.]com for Azorult malware distribution, microsoft-store-drm-server[.]com for C2 activity, microsoft-alert[.]club for a technical support scam, and netflixbrazilcovid[.]com for a re-bill scam; researchers also found that more than half of the malicious or high-risk domains were not detected by any VirusTotal vendors during the comparison window, underscoring significant detection gaps and the need for continuous monitoring of newly registered domains and passive DNS data.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks reported detecting 13,857 squatting domains in December 2019, averaging about 450 per day. Of those, 2,595 were classified as malicious and 5,104 as suspicious or high risk.
The report states that Azorult, a credential and payment-card information stealer later distributed via a squatting domain, has been active since 2016.
On February 3, the same campaign used microsoft-sback-server[.]com, which shared infrastructure and SSL behavior with the earlier Microsoft-themed squatting domain.
The campaign then used microsoft-store-drm-server[.]com from January 31 to February 2; Palo Alto Networks linked malware samples communicating with this squatting domain.
The same short-lived command-and-control campaign moved to stt-box[.]com from January 29 to 31 as part of its rotating squatting-domain infrastructure.
A command-and-control campaign using squatting domains employed store-in-box[.]com from January 27 to 28 before rotating to other lookalike domains.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.