logo

The .vu Surge: How Threat Actors Are Exploiting Vanuatu's Domain Extension

ID: 7bb16073-f738-5cfb-afd7-6f74798f82e2

STIX ID: report--7bb16073-f738-5cfb-afd7-6f74798f82e2

Feed Name: KnowBe4 Blog

Threat Score
70/100

Date Published: 2026-08-28

Date Updated: 2026-08-28

Author: KnowBe4 Threat Lab

...
...

KnowBe4 Threat Lab observed a large, active phishing campaign (April–July 2026) that abused 1,660 short-lived .vu domains to host credential-harvesting and MFA-relay pages, delivering at least 28,167 malicious emails by separating clean sender domains from embedded .vu payload links; the report details campaign phases, registrars, sample IOCs, targeted sectors, and recommended defensive actions including blocking .vu at mail/DNS layers and retroactive hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.