Threats Tagged 'domain spoofing'
View all threats tagged with 'domain spoofing'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'domain spoofing'
Click on any threat for detailed analysis and mitigation recommendations
The hospitality and travel sector experienced a dramatic surge in cyberattacks, with organizations facing an average of 2,291 weekly attacks in May 2026, representing a 24% year-over-year increase and a cumulative 122% rise since 2023. Cybercriminals registered 47,318 travel-related domains in May 2026 alone, with one in every 112 classified as malicious or suspicious. Three coordinated bulk-registration campaigns were identified, including sequential hotel-lure domains, American Express and Lloyds Travel Choice impersonations, and widespread Fora Travel brand abuse across 108 TLDs. Active phishing operations target major platforms including Booking.com, Airbnb, and Skyscanner through lookalike domains designed to harvest credentials and payment information. These attacks deliberately intensify during peak summer booking season when travelers are distracted and eager for deals, exploiting the industry's high volume of personal and financial data processing. Join the discussion | AlienVault OTX General | 06/15/2026, 14:53:05 UTC Added: 06/15/2026, 17:15:21 UTC |
A sophisticated phishing campaign targeting LinkedIn users has been identified. The attack uses fake LinkedIn message notifications to lure victims into clicking on malicious links. The emails closely mimic legitimate LinkedIn communications, including spoofed display names and formatting. Upon clicking, users are redirected to a convincing but fraudulent LinkedIn login page designed to steal credentials. The phishing page uses a deceptive domain name similar to 'LinkedIn' to further trick users. This campaign demonstrates the evolving tactics of cybercriminals in exploiting human trust and curiosity. The analysis emphasizes the importance of vigilance, source verification, and caution when interacting with seemingly routine notifications. Join the discussion | AlienVault OTX General | 03/31/2026, 16:14:20 UTC Added: 03/31/2026, 18:53:15 UTC |
Storm-0249, a seasoned initial access broker, has evolved from mass phishing to sophisticated post-exploitation tactics. The group now abuses legitimate Endpoint Detection and Response processes, particularly SentinelOne's SentinelAgentWorker.exe, through DLL sideloading. This allows them to conceal malicious activity as routine operations, bypass defenses, and maintain persistence. Their new tactics include Microsoft domain spoofing, curl-to-PowerShell piping, and fileless execution. Storm-0249's ability to weaponize trusted processes and conduct stealthy reconnaissance poses significant challenges for security teams. The group's evolution represents a broader trend in the ransomware-as-a-service ecosystem, lowering the technical barrier for attackers and accelerating the spread of ransomware across sectors. Join the discussion | AlienVault OTX General | 12/10/2025, 09:17:43 UTC Added: 12/10/2025, 09:27:44 UTC |
Following Hurricane Melissa's devastation in Jamaica in October 2025, cybercriminals launched a series of online scams exploiting the disaster. These scams included phishing campaigns, fake charity websites, and fraudulent financial-relief portals impersonating legitimate aid organizations. Attackers used social engineering tactics to prey on victims' compassion and urgency, often deploying scams within hours of the hurricane. A prominent example involved a cryptocurrency donation site with fabricated transaction data and static images to appear authentic. Numerous fraudulent domains soliciting cryptocurrency donations were identified. While primarily targeting individuals, these scams undermine trust in digital charity platforms and complicate legitimate relief efforts. European organizations involved in disaster relief, financial services, or public awareness campaigns should be vigilant. The threat is medium severity due to social engineering reliance and no direct system exploitation. Mitigation requires enhanced awareness, domain monitoring, and collaboration between cybersecurity entities and relief organizations. Join the discussion | AlienVault OTX General | 11/14/2025, 02:36:40 UTC Added: 11/14/2025, 11:37:02 UTC |
Showing 1 to 4 of 4 results