logo

The assembly line behind 1.5 million malicious domains

ID: 9d60715b-044f-55c7-ad38-c5ab4a7d6541

STIX ID: report--9d60715b-044f-55c7-ad38-c5ab4a7d6541

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-06-12

Date Updated: 2026-06-12

Author: Anamarija Pogorelec

...
...

A research analysis of >1.5M VirusTotal-flagged domains (Jan–May 2026) found attackers registered most domains in bulk, used automated name patterns, and activated them quickly; registrations and traffic are highly concentrated across a few registrars, TLDs, and hosting providers (notably Cloudflare and AWS). The study highlights brand-impersonation (WhatsApp, Google, Coinbase), extreme DNS-query skew where a handful of domains account for most exposure, and recommends rate-limiting same-day bulk registrations, automated abuse pipelines with large providers, and sinkholing the highest-traffic domains first.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.