Fake AV Moving From .co.cc To .cz.cc
ID: 651f912d-51f8-573f-88ba-47eb70ceb9e6
STIX ID: report--651f912d-51f8-573f-88ba-47eb70ceb9e6
Feed Name: Zscaler Security Research Blog
Threat Score
The blog post describes a campaign of fake antivirus (fake AV) websites hosted as free subdomains—primarily on co.cc and increasingly on cz.cc—where attackers leverage free DNS/hosting to distribute malicious content. The author notes that co.cc has begun removing reported malicious sites within 24 hours, but attackers are migrating to other providers, sustaining the threat and risking infection of unaware users.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
