DNS, DHCP & IP Address Management appliances
For Microsoft DNS & DHCP servers
For open source DNS & DHCP servers
Cloud-based visualization of analytics across DDI architecture
Manage multi-vendor cloud DNS servers centrally
RIR Declaration Management and Automation
Automated network device configuration and management
Centralized visibility over all your clouds
A single source of truth for your network automation
Why DDI is an Obvious Starting Point
DNS Threat Intelligence for proactive defense
Intelligence Insights for Threat Detection and Investigation
Adaptive DNS security for service continuity and data protection
Improve Application Access Control to prevent spread of attacks
Protect users and block DNS-based malware activity
Carrier-grade DNS DDoS attack protection
Optimize application delivery performance from the edge
for Proactive Network Security
Visibility, analytics and micro segmentation for effective Zero Trust strategy
Enable work from anywhere by controlling access, security and data privacy
Simplify management and control costs across AWS, Azure and GCP environments
Policy enforcement, risk management, and automation for simplifying compliance
Risk-free migration to reduce DDI complexity and cost
Move risk-free to improve performance, security and costs
Automate management, unify control and strengthen security of connected devices
Protect your network against all DNS attacks, data exfiltration and ransomware
Enable zero touch operations for network management and security
Improve resiliency, deployment velocity and user experience for SD-WAN projects
Integrated DNS, DHCP, IPAM services to simplify, automate and secure your network.
Simplify design, deployment and management of critical DDI services for telcos
Optimize administration and security of critical DDI services for healthcare
Simplify and automate management of critical DDI services for finance
Simplify and automate management of critical DDI services for higher education
Simplify and automate management of critical DDI services for retail
Simplify Management and Automation for Network Operations Teams
Elevate SecOps Efficiency by Simplifying Threat Response
Enable DevOps practices to deliver consistent network operations.
Open architecture for DDI integration
Technology partnerships for network security & management ecosystems
Extend security perimeters and strengthen network defenses
Submit requests for temporary licenses
Submit access requests for EfficientIP knowledge platforms
Submit membership requests for EfficientIP Community
Strengthen your network security with insights from the Forrester 2025 Study on DNS Security.
Customer-centric DDI project delivery and training
Acquire the skills needed to manage EfficientIP SOLIDserver™
Identify vulnerabilities with an assessment of your DNS traffic
Test your protection against data breaches via DNS
Dedicated representation for your organization inside EfficientIP
Explore content which helps manage and automate your network and cloud operations
Read content which strengthens protection of your network, apps, users and data
Learn how to enhance your app delivery performance to improve resilience and UX
See all your assets in one place
This enterprise-grade cloud platform allows you to improve visibility, enhance operational efficiency, and optimize network performance effortlessly.
Who we are and what we do
Meet the team of leaders guiding our global growth
Technology partnerships for network security and management ecosystems
Make your cloud projects successful with insights from the 2025 EMA Hybrid Multi-cloud Report.
Discover the benefits of the SmartPartner global channel program
Become a part of the innovation
The latest updates, release information, and global events
EfficientIP Research Labs traced ten coordinated domains to an AliExpress phishing campaign, showing how DNS patterns and shared infrastructure can reveal malicious activity before reputation-based controls catch up.
September 24, 2026 | Written by: Christophe Girard | DNS Security
Summary
Tags
Client Query FilteringCyberthreatDNS FilteringDNS SecurityData TheftPhishingThreat Intelligence
EfficientIP Research Labs uncovered an AliExpress phishing campaign designed to lure people to a convincing fake shopping site. On June 9, researchers identified ten potential web addresses before they were registered and added them to DNS Threat Pulse. On July 2, the addresses became active, and their shared naming patterns and infrastructure linked them to the same campaign.
The campaign directed visitors through a series of links to a fake AliExpress-themed site. It used familiar branding, a lookalike name and an “Add to Browser” prompt encouraging visitors to install a shopping-assistant extension. Several independent security services classified the destination as malicious or unsafe.
If successful, the campaign could have led to credential theft, payment fraud or exposure of browsing activity and other sensitive information through an untrusted browser extension. What makes the research noteworthy is its timing: DNS intelligence identified the ten domains before they were registered or had established reputations. This earlier visibility gives security teams more time to investigate the wider campaign, protect users and reduce potential business impact.
The AliExpress phishing campaign uncovered by EfficientIP Research Labs shows how attackers combine disposable domains, tracking infrastructure and convincing brand imitation. Rather than relying on one phishing link, the campaign used multiple entry domains that could be replaced as they were detected.
On June 9, 2026, EfficientIP Research Labs identified ten potential [.]cyou domains and added them to DNS Threat Pulse (DTP) feed, even though they had not yet been registered. On July 2, the domains were registered and began resolving to IP addresses, turning those early indicators into active threat infrastructure. Each followed the same format: one digit followed by five lowercase letters. Tracing their DNS and redirect activity led to alish0p[.]com, a polished shopping site designed to appear associated with AliExpress.
The investigation shows why defenders need to look beyond the final phishing page. Naming patterns, shared infrastructure and DNS activity can reveal the wider operation and help identify related threats earlier.
Simplify & Secure Your Network
Our goal is to help companies face the challenges of modern infrastructures and digital transformation.
A victim could encounter one of the [.]cyou domains through a phishing email, SMS message, advertisement, social media post or QR code. The link would redirect the visitor through a tracking intermediary before delivering the fake AliExpress-themed site.
The observed infrastructure suggests three potential routes to harm:
These are potential outcomes based on the observed site and infrastructure. They should not be presented as confirmed victim losses without supporting evidence.
The investigation began with ten domains:
1cvvts[.]cyou, 2nftgz[.]cyou, 3gftdw[.]cyou, 3hfllr[.]cyou, 5kcivu[.]cyou, 5kvicu[.]cyou, 6nygmf[.]cyou, 7cbuyw[.]cyou, 9fkjsk[.]cyou and 9rqqca[.]cyou.
All ten shared the same registration date and naming structure. They also resolve to three observed IP addresses within the same subnet: 46.8.9[.]220, 46.8.9[.]222 and 46.8.9[.]223.
Together, these relationships strongly suggest coordinated infrastructure rather than unrelated registrations. Finding one domain in DNS logs therefore provides immediate pivots into the rest of the cluster.
The format, one digit followed by five lowercase letters, resembles output from a Domain Generation Algorithm, or DGA. Attackers use DGAs to produce large numbers of random-looking domains that can be activated, discarded and replaced quickly.
The pattern alone does not prove that a DGA generated these domains. “DGA-style domains” is therefore the more accurate description. Combined with their registration, hosting and redirect relationships, however, the pattern becomes a useful detection signal.
For another example of how these patterns can reveal dormant infrastructure, see AI-Driven DGA Detection Uncovers a Dormant Infostealer.
Cloudflare’s analysis of unwanted email found that 62% of email observed from the [.]cyou top-level domain in 2023 was classified as malicious. The TLD ranked among the three with the highest proportion of malicious email.
This does not make every [.]cyou domain dangerous. It does mean that a newly registered, random-looking [.]cyou domain that immediately redirects elsewhere deserves closer investigation.
A victim first reaches one of the newly registered [.]cyou domains. Because the domain has little history, reputation-based controls may not yet have classified it.
Instead of hosting the fake page directly, the domain sends the visitor through a tracking layer containing campaign, click, bid or affiliate parameters. This intermediary can record the interaction and select the next destination.
Separating the entry domain from the final site allows the operator to replace exposed domains, change destinations and measure traffic without rebuilding the campaign.
The visitor ultimately reaches alish0p[.]com, a site promoting an AliExpress shopping-assistant browser tool. The page appears to imitate “Alitools,” a legitimate shopping-assistant brand, using professional design, reassuring security language and a claim that it is trusted by more than 500,000 shoppers.
The lookalike domain uses a zero in place of the letter “o” in “shop.” On a mobile screen or shortened preview, “alish0p” can resemble “alishop,” creating an apparent connection to AliExpress or Alibaba.
A prominent “Add to Browser” button reinforces the lure. There is no evidence in the research reviewed that AliExpress was involved in or endorsed the site.
At the time of the EfficientIP Research Labs review, several independent security platforms had flagged alish0p[.]com:
These verdicts support treating the site as malicious or unsafe. They do not confirm which information the operator collected or how individual victims were affected.
The Interisle Phishing Landscape 2025 study found that 77% of domains used in phishing attacks were maliciously registered. It also found that 37% of phishing domains were acquired through bulk-registration services.
This model is scalable: attackers can register domains in batches, use them as temporary entry points and rotate them after detection. Tracking infrastructure separates those domains from the final lure, making the operation more adaptable.
Blocking one URL therefore addresses only one part of the campaign. Defenders need to identify the naming, registration, hosting and DNS relationships that reveal connected infrastructure. Read more about the role of Protective DNS in phishing protection.
Indicators marked Malicious were directly observed in the campaign or independently confirmed as harmful. Those marked Suspicious share the same subnet as the observed infrastructure but were not directly linked to the campaign; they should be treated as investigation pivots rather than confirmed threats.
Blocking known indicators is necessary, but identifying the next domain requires broader DNS visibility.
DNS Threat Pulse provides curated intelligence covering phishing, malware, DGA and newly observed domains. Client Query Filtering supports granular DNS policies based on user, device, IP address or network context.
The DNS Intelligence Center provides a unified view of DNS traffic insights for threat detection and investigation. Together, these capabilities support 360° DNS Security by helping defenders connect early DNS signals to practical prevention and response.
The EfficientIP Research Labs investigation shows how ten coordinated domains can support a larger phishing operation. Disposable entry points, tracking infrastructure and a convincing fake site serve different purposes, but DNS evidence connects them.
Blocking the current indicators is the immediate priority. Recognizing the pattern provides the longer-term advantage: it helps security teams find related infrastructure, investigate exposed users and detect similar campaigns before attackers rotate to another batch of domains.
A DGA domain is generated automatically by a Domain Generation Algorithm. Attackers use DGAs to produce random-looking domains and rotate infrastructure when existing domains are blocked. The [.]cyou domains in this investigation follow a DGA-style pattern, but the naming pattern alone does not confirm that a DGA created them.
Disposable domains gave the AliExpress phishing campaign multiple replaceable entry points. They redirected visitors through tracking infrastructure rather than hosting the fake site directly, allowing the operator to rotate exposed links while preserving the wider campaign.
Review DNS, proxy, browser and endpoint activity associated with the user and device. If the user entered credentials or payment information, reset passwords, revoke sessions, contact the card issuer and monitor for fraud. Any browser extension installed through the site should be removed and investigated.
Discover how the 2026 DNS Threat Intelligence Report reveals early DNS signals, staged infrastructure, and patterns that can help security teams detect phishing campaigns sooner.
Talk to an expert
Summarize
Networks
Explore content highlighting the value EfficientIP solutions bring to your network