Why Phishers Love New TLDs Like .shop, .top and .xyz
ID: e61b2d5f-a90b-5c8f-a46c-4ca3147e67a7
STIX ID: report--e61b2d5f-a90b-5c8f-a46c-4ca3147e67a7
Feed Name: Krebs on Security
An Interisle Consulting study finds phishing rose nearly 40% from September 2023 to August 2024, driven by heavy abuse of inexpensive, loosely regulated new gTLDs (e.g., .shop, .top, .xyz) and large-scale use of subdomain providers like blogspot.com, pages.dev, and weebly.com. While .com and .net dominate total registrations, new gTLDs accounted for about 37% of reported cybercrime domains; the U.S. Postal Service was the most-phished brand, aided by widely distributed postal-service phishing kits tied to a seller known as Chenlun. The report warns that ICANN’s plan to add more gTLDs without stricter verification may worsen abuse and recommends subdomain services limit automated, high-volume account creation to mitigate phishing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
