The .vu Surge: How Threat Actors Are Exploiting Vanuatu's Domain Extension
ID: 7bb16073-f738-5cfb-afd7-6f74798f82e2
STIX ID: report--7bb16073-f738-5cfb-afd7-6f74798f82e2
Feed Name: KnowBe4 Blog
Threat Score
KnowBe4 Threat Lab observed a large, active phishing campaign (April–July 2026) that abused 1,660 short-lived .vu domains to host credential-harvesting and MFA-relay pages, delivering at least 28,167 malicious emails by separating clean sender domains from embedded .vu payload links; the report details campaign phases, registrars, sample IOCs, targeted sectors, and recommended defensive actions including blocking .vu at mail/DNS layers and retroactive hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
