Skip to content

AliExpress Phishing Campaign: What EfficientIP Research Labs Uncovered

EfficientIP Research Labs traced ten coordinated domains to an AliExpress phishing campaign, showing how DNS patterns and shared infrastructure can reveal malicious activity before reputation-based controls catch up.

September 24, 2026 | Written by: Christophe Girard |

Summary

Aliexpress Phishing Campaign Uncovered by Efficientip Research Labs

Key Findings

  • EfficientIP Research Labs identified ten potential [.]cyou domains before registration. Their activation on July 2 led researchers to uncover an AliExpress phishing campaign.
  • The domains formed a phishing redirect chain leading through tracking infrastructure to a fake AliExpress site.
  • The campaign created potential risks to credentials, payment information and browser activity, while DNS evidence provided earlier warning signs.

Executive Summary

EfficientIP Research Labs uncovered an AliExpress phishing campaign designed to lure people to a convincing fake shopping site. On June 9, researchers identified ten potential web addresses before they were registered and added them to DNS Threat Pulse. On July 2, the addresses became active, and their shared naming patterns and infrastructure linked them to the same campaign.

The campaign directed visitors through a series of links to a fake AliExpress-themed site. It used familiar branding, a lookalike name and an “Add to Browser” prompt encouraging visitors to install a shopping-assistant extension. Several independent security services classified the destination as malicious or unsafe.

If successful, the campaign could have led to credential theft, payment fraud or exposure of browsing activity and other sensitive information through an untrusted browser extension. What makes the research noteworthy is its timing: DNS intelligence identified the ten domains before they were registered or had established reputations. This earlier visibility gives security teams more time to investigate the wider campaign, protect users and reduce potential business impact.

Introduction

The AliExpress phishing campaign uncovered by EfficientIP Research Labs shows how attackers combine disposable domains, tracking infrastructure and convincing brand imitation. Rather than relying on one phishing link, the campaign used multiple entry domains that could be replaced as they were detected.

On June 9, 2026, EfficientIP Research Labs identified ten potential [.]cyou domains and added them to DNS Threat Pulse (DTP) feed, even though they had not yet been registered. On July 2, the domains were registered and began resolving to IP addresses, turning those early indicators into active threat infrastructure. Each followed the same format: one digit followed by five lowercase letters. Tracing their DNS and redirect activity led to alish0p[.]com, a polished shopping site designed to appear associated with AliExpress.

The investigation shows why defenders need to look beyond the final phishing page. Naming patterns, shared infrastructure and DNS activity can reveal the wider operation and help identify related threats earlier.

Simplify & Secure Your Network

Our goal is to help companies face the challenges of modern infrastructures and digital transformation.

The Suspected Fraud and Potential Harm

A victim could encounter one of the [.]cyou domains through a phishing email, SMS message, advertisement, social media post or QR code. The link would redirect the visitor through a tracking intermediary before delivering the fake AliExpress-themed site.

The observed infrastructure suggests three potential routes to harm:

  • Credential and payment theft: Visitors attempting to sign in or purchase a product could expose passwords, personal information or payment-card details.
  • Browser extension risks: The site encouraged visitors to install a shopping-assistant tool. An untrusted extension could expose browsing activity or other sensitive information.
  • Potential affiliate fraud: Tracking parameters may allow the operator to record clicks or receive referral revenue if visitors are eventually sent to legitimate product pages.

These are potential outcomes based on the observed site and infrastructure. They should not be presented as confirmed victim losses without supporting evidence.

What EfficientIP Research Labs Uncovered

The Coordinated Domain Cluster

The investigation began with ten domains:

1cvvts[.]cyou, 2nftgz[.]cyou, 3gftdw[.]cyou, 3hfllr[.]cyou, 5kcivu[.]cyou, 5kvicu[.]cyou, 6nygmf[.]cyou, 7cbuyw[.]cyou, 9fkjsk[.]cyou and 9rqqca[.]cyou.

All ten shared the same registration date and naming structure. They also resolve to three observed IP addresses within the same subnet: 46.8.9[.]220, 46.8.9[.]222 and 46.8.9[.]223.

Together, these relationships strongly suggest coordinated infrastructure rather than unrelated registrations. Finding one domain in DNS logs therefore provides immediate pivots into the rest of the cluster.

DGA-Style Domains

The format, one digit followed by five lowercase letters, resembles output from a Domain Generation Algorithm, or DGA. Attackers use DGAs to produce large numbers of random-looking domains that can be activated, discarded and replaced quickly.

The pattern alone does not prove that a DGA generated these domains. “DGA-style domains” is therefore the more accurate description. Combined with their registration, hosting and redirect relationships, however, the pattern becomes a useful detection signal.

For another example of how these patterns can reveal dormant infrastructure, see AI-Driven DGA Detection Uncovers a Dormant Infostealer.

Why [.]cyou Deserves Attention

Cloudflare’s analysis of unwanted email found that 62% of email observed from the [.]cyou top-level domain in 2023 was classified as malicious. The TLD ranked among the three with the highest proportion of malicious email.

This does not make every [.]cyou domain dangerous. It does mean that a newly registered, random-looking [.]cyou domain that immediately redirects elsewhere deserves closer investigation.

How the Phishing Campaign Works

Disposable Entry Domains and Tracking Redirects

A victim first reaches one of the newly registered [.]cyou domains. Because the domain has little history, reputation-based controls may not yet have classified it.

Instead of hosting the fake page directly, the domain sends the visitor through a tracking layer containing campaign, click, bid or affiliate parameters. This intermediary can record the interaction and select the next destination.

Separating the entry domain from the final site allows the operator to replace exposed domains, change destinations and measure traffic without rebuilding the campaign.

Fake AliExpress Site and Lookalike Branding

Alitools Smart Shopping Assistant for Aliexpress with Price History Similar Product Finder and Seller Ratings

The visitor ultimately reaches alish0p[.]com, a site promoting an AliExpress shopping-assistant browser tool. The page appears to imitate “Alitools,” a legitimate shopping-assistant brand, using professional design, reassuring security language and a claim that it is trusted by more than 500,000 shoppers.

The lookalike domain uses a zero in place of the letter “o” in “shop.” On a mobile screen or shortened preview, “alish0p” can resemble “alishop,” creating an apparent connection to AliExpress or Alibaba.

A prominent “Add to Browser” button reinforces the lure. There is no evidence in the research reviewed that AliExpress was involved in or endorsed the site.

Independent Security Verdicts

At the time of the EfficientIP Research Labs review, several independent security platforms had flagged alish0p[.]com:

PlatformVerdictDetail
ANY.RUN SandboxMalicious activityAnalyzed May 22, 2026 — tagged: phishing
ScamAdviserVery likely unsafeTrust score: 0/100
GridinsoftPotentially MaliciousIndependent flag
DNSFilterMaliciousFlagged within last 30 days
Hybrid AnalysisThreat score: 100/100AV detection: 50%

These verdicts support treating the site as malicious or unsafe. They do not confirm which information the operator collected or how individual victims were affected.

The Bigger Picture: A Growing Phishing Playbook

The Interisle Phishing Landscape 2025 study found that 77% of domains used in phishing attacks were maliciously registered. It also found that 37% of phishing domains were acquired through bulk-registration services.

This model is scalable: attackers can register domains in batches, use them as temporary entry points and rotate them after detection. Tracking infrastructure separates those domains from the final lure, making the operation more adaptable.

Blocking one URL therefore addresses only one part of the campaign. Defenders need to identify the naming, registration, hosting and DNS relationships that reveal connected infrastructure. Read more about the role of Protective DNS in phishing protection.

What Security Teams Should Do Now

  • Block confirmed domains: Add the ten [.]cyou domains and alish0p[.]com to DNS, proxy and email controls.
  • Review observed IP activity: Search for connections to 46.8.9[.]220, 46.8.9[.]222 and 46.8.9[.]223. Assess broader subnet blocking against ownership, business need and potential collateral impact.
  • Search historical logs: Review DNS, proxy, browser and endpoint activity for the confirmed indicators. A match should trigger investigation of the associated user and device.
  • Contain potential exposure: Reset passwords, revoke sessions and contact the card issuer if a user entered credentials or payment details. Remove and investigate any browser extension installed through the site.
  • Hunt related infrastructure: Search for domains with similar naming patterns, registration dates, nameservers, redirect parameters and hosting relationships.
  • Report the site: Submit alish0p[.]com to Google Safe Browsing, URLhaus, PhishTank and the relevant national or regional CERT.
  • Reduce future exposure: Consider controls for newly registered domains, context-aware DNS filtering and user awareness around unusual spellings in branded links.

Indicators of Compromise

Indicators marked Malicious were directly observed in the campaign or independently confirmed as harmful. Those marked Suspicious share the same subnet as the observed infrastructure but were not directly linked to the campaign; they should be treated as investigation pivots rather than confirmed threats.

IndicatorTypeRoleVerdict
1cvvts[.]cyouDomainDGA RedirectorMalicious
2nftgz[.]cyouDomainDGA RedirectorMalicious
3gftdw[.]cyouDomainDGA RedirectorMalicious
3hfllr[.]cyouDomainDGA RedirectorMalicious
5kcivu[.]cyouDomainDGA RedirectorMalicious
5kvicu[.]cyouDomainDGA RedirectorMalicious
6nygmf[.]cyouDomainDGA RedirectorMalicious
7cbuyw[.]cyouDomainDGA RedirectorMalicious
9fkjsk[.]cyouDomainDGA RedirectorMalicious
9rqqca[.]cyouDomainDGA RedirectorMalicious
alish0p[.]comDomainPhishing / Fake ShopMalicious
46.8.9[.]220IP AddressShared host for [.]cyou redirector domains — consider blocking /24Malicious
46.8.9[.]221IP AddressSame subnet as observed infrastructure — investigation pivotSuspicious
46.8.9[.]222IP AddressShared host for [.]cyou redirector domains — consider blocking /24Malicious
46.8.9[.]223IP AddressShared host for [.]cyou redirector domains — consider blocking /24Malicious
46.8.9[.]224IP AddressSame subnet as observed infrastructure — investigation pivotSuspicious
46.8.9[.]225IP AddressSame subnet as observed infrastructure — investigation pivotSuspicious
46.8.9[.]226IP AddressSame subnet as observed infrastructure — investigation pivotSuspicious
46.8.9[.]227IP AddressSame subnet as observed infrastructure — investigation pivotSuspicious
46.8.9[.]228IP AddressSame subnet as observed infrastructure — investigation pivotSuspicious
46.8.9[.]229IP AddressSame subnet as observed infrastructure — investigation pivotSuspicious

How EfficientIP Can Help Detect Similar Campaigns Earlier

Blocking known indicators is necessary, but identifying the next domain requires broader DNS visibility.

DNS Threat Pulse provides curated intelligence covering phishing, malware, DGA and newly observed domains. Client Query Filtering supports granular DNS policies based on user, device, IP address or network context.

The DNS Intelligence Center provides a unified view of DNS traffic insights for threat detection and investigation. Together, these capabilities support 360° DNS Security by helping defenders connect early DNS signals to practical prevention and response.

Conclusion

The EfficientIP Research Labs investigation shows how ten coordinated domains can support a larger phishing operation. Disposable entry points, tracking infrastructure and a convincing fake site serve different purposes, but DNS evidence connects them.

Blocking the current indicators is the immediate priority. Recognizing the pattern provides the longer-term advantage: it helps security teams find related infrastructure, investigate exposed users and detect similar campaigns before attackers rotate to another batch of domains.

FAQ

Detect Phishing Campaigns Earlier

Discover how the 2026 DNS Threat Intelligence Report reveals early DNS signals, staged infrastructure, and patterns that can help security teams detect phishing campaigns sooner.

Talk to an expert

Summarize

Networks