logo

The .gov Illusion: Inside the 16,800-Domain “Operation Trust Trap” Campaign

ID: 92ea322f-3ef7-5632-8c54-dfa38f0becf8

STIX ID: report--92ea322f-3ef7-5632-8c54-dfa38f0becf8

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-04-28

Date Updated: 2026-04-28

Author: Ddos

...
...

Cyble Research and Intelligence Labs (CRIL) uncovered “Operation Trust Trap,” a large-scale phishing campaign of ~16,800 rapidly rotating domains that mimic government URLs via subdomain trust injection and hyphen manipulation to harvest credentials and payment data; the campaign is US‑centric (targeting state services like DMVs and toll systems) with international lures and an infrastructure hosted on Tencent/Alibaba Cloud, and CRIL observed a cluster consistent with APT36 activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.