logo

FBI shares massive list of 42,000 LabHost phishing domains

ID: 6be996ff-742f-52d6-9a93-10ef04242d29

STIX ID: report--6be996ff-742f-52d6-9a93-10ef04242d29

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2025-04-30

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

The FBI published a historical list of 42,000 domains associated with LabHost, a major phishing-as-a-service platform dismantled in April 2024; LabHost provided sophisticated, customizable phishing kits (including 2FA bypass and automated SMS interactions), is estimated to have stolen ~1,000,000 credentials and ~500,000 payment card records, and had roughly 10,000 customers before takedown. The domain list is shared to enable blocklisting, retrospective detection, and threat analysis, but the FBI warns the list has not been fully validated and is historical in nature.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.