EfficientIP Detects AliExpress Phishing Domains Before Registration
Share
EfficientIP Research Labs has identified ten phishing domains targeting AliExpress users weeks before they were officially registered. The domains, which utilised the .cyou top-level domain, were first flagged on 9 June 2026 using an AI-driven domain generation algorithm (DGA) detection engine.
The domains were subsequently registered and began resolving to IP addresses on 2 July. The phishing operation used these domains as disposable entry points, redirecting visitors through a tracking layer that allowed operators to rotate exposed domains without needing to rebuild the campaign.
The campaign concluded at a fraudulent website that used a zero in place of the “o” in “shop” to mimic a legitimate service. This site promoted a fake browser extension styled after the legitimate shopping assistant, Alitools. Researchers warned that installing the extension could lead to the theft of login credentials, the exposure of payment information, and the unauthorised monitoring of user browsing activity.
Christophe Girard, cyber AI & bigdata R&D manager at EfficientIP, confirmed that the phishing site had been accessed by users across eight different telecom operators in multiple geographies.
To mitigate the risk, EfficientIP advised organisations to block the identified domains and IP addresses and to check DNS and proxy logs for historical connections. Users who may have interacted with the site are urged to reset their credentials, contact their card issuers, and remove the malicious extension immediately.




Leave a Reply