Threat Research Report: Malicious Domain Activity During the Los Angeles Wildfires
ID: 690c779e-85c3-5c55-8e1d-ae698bbcc10a
STIX ID: report--690c779e-85c3-5c55-8e1d-ae698bbcc10a
Feed Name: BforeAI
Researchers identified a short-lived, large-scale phishing and fraud campaign exploiting the 2025 Los Angeles wildfires: 119 domains registered in a six-day window (8–13 Jan 2025) using disaster-related keywords and largely .com TLDs (58% registered via GoDaddy). The domains and associated content target emotional triggers and recovery themes (relief funds, insurance claims, cleanup services), enabling financial scams, PII harvesting, and fake GoFundMe pages using recycled images to deceive donors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
