EfficientIP Research Labs identified 10 prospective .cyou domains before registration that were later activated as entry points for an AliExpress-themed phishing campaign. Registered domains began resolving on July 2 and directed users through a tracking layer to a fraudulent shopping-assistant site impersonating the Alitools brand, where operators promoted a deceptive browser extension.
The disposable-domain infrastructure enabled the operators to rotate hosting and evade reputation-based controls. The campaign could expose victims to credential and payment-card theft, browsing-activity collection, and affiliate-revenue fraud, although no confirmed victims or financial losses have been reported. Organizations should block the identified domains and associated IPs, review DNS and proxy logs for access, and reset credentials, monitor payment cards, and remove extensions on affected endpoints.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
The ten .cyou domains were registered and began resolving to three IP addresses in one subnet. DNS and redirect tracing showed they routed visitors through a tracking layer to a fraudulent AliExpress-themed shopping-assistant site promoting a browser extension.
EfficientIP Research Labs identified ten prospective .cyou domains matching a one-digit, five-lowercase-letter pattern before the domains were registered. The domains were later linked to an AliExpress-themed phishing campaign.
ANY.RUN tagged the fraudulent shopping-assistant destination site as phishing before the disposable redirect domains were registered.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.