Threats Tagged 'domain generation'
View all threats tagged with 'domain generation'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'domain generation'
Click on any threat for detailed analysis and mitigation recommendations
This intelligence report details a hybrid cryptocurrency investment scam campaign targeting users in Asia, particularly Japan. The scam combines malvertising techniques to attract victims with pig butchering tactics using AI-powered chatbots for sustained engagement. Victims are lured through social media ads impersonating financial experts, directed to lure websites, and then to messaging apps where automated bots manipulate them into making increasingly large investments. The campaign uses over 23,000 domains, many generated algorithmically, and shows signs of expanding globally. This approach represents a scalable, automated evolution of traditional investment fraud methods, potentially transforming labor-intensive scams into more efficient operations. Join the discussion | AlienVault OTX General | 02/19/2026, 15:26:29 UTC Added: 02/19/2026, 17:46:12 UTC |
This report details two interconnected malware campaigns targeting Chinese-speaking users in 2025, using large-scale brand impersonation to deliver Gh0st RAT variants. The first campaign, active from February to March, mimicked three brands across over 2,000 domains. The second campaign, starting in May, impersonated over 40 applications with more sophisticated infection chains. Both campaigns used cloud infrastructure for payload delivery and DLL side-loading for evasion. The adversary demonstrated an evolving operational playbook, advancing from simple droppers to complex multi-stage infections. The campaigns' infrastructure remained active for months, indicating a persistent and well-resourced threat actor focused on Chinese-speaking targets globally. MediumMalware Join the discussion | AlienVault OTX General | 11/15/2025, 05:58:39 UTC Added: 11/17/2025, 09:32:29 UTC |
Showing 1 to 2 of 2 results