Security researchers identified 10 web addresses weeks before they were even registered, then observed them launch as gateways to an AliExpress-themed phishing operation. EfficientIP Research Labs spotted the potential .cyou domains on June 9 in customer DNS traffic using its AI-driven domain generation algorithm detection engine and added them to its DNS threat intelligence feed. The domains were registered three weeks later on July 2 and began pointing to IP addresses the same day. Tracing their DNS and redirect patterns brought researchers to a fake AliExpress site promoting a malicious browser extension.

All 10 domains used the same structure—one number followed by five lowercase letters—and shared the same registration date. They pointed to three IP addresses within a single subnet. EfficientIP described them as DGA-style, though it cautioned the pattern by itself doesn't prove a domain generation algorithm created them. None of the domains actually hosted the phishing lure. Instead, each routed visitors through a tracking layer carrying campaign, click, or affiliate parameters, which EfficientIP said allows an operator to swap out exposed domains without rebuilding the entire campaign. The .cyou top-level domain provided additional context. EfficientIP cited Cloudflare research showing that 62% of emails from .cyou in 2023 were malicious, while emphasizing the domain ending alone doesn't make a site dangerous. An Interisle Phishing Landscape 2025 study found 77% of phishing domains were maliciously registered and 37% were purchased through bulk-registration services.

The chain ended at a site using a zero instead of the letter "o" in "shop," promoting a browser extension modeled after Alitools, a legitimate shopping-assistant brand. It claims more than 500,000 users and pushes visitors to click "Add to Browser." Multiple security services had flagged the site as malicious or unsafe, including ANY.RUN, whose sandbox marked it as phishing on May 22—weeks before the redirect domains appeared. According to the report, visitors faced the risk of credential and payment theft and exposure of their browsing activity through the extension, while the tracking parameters could generate affiliate revenue for the operator. Christophe Girard, cyber AI and big data R&D manager at EfficientIP, told Infosecurity the team couldn't confirm how many individual people reached the final site, but they could confirm users across eight different telecom operators in multiple geographies accessed it.

Because such domains have little history, reputation-based controls may not have classified them yet when the first visitors arrived, EfficientIP said. This explains why the early detection matters: traditional security tools that rely on domain reputation miss newly registered addresses during their most active phishing window. The tracking layer architecture lets attackers burn through entry-point domains rapidly while preserving the core phishing infrastructure, making each disposable address harder to block in advance. EfficientIP advised blocking the domains and IP addresses and searching DNS and proxy logs for past connections. Where users engaged with the site, it recommended resetting credentials, contacting card issuers, and removing the extension. Predictive detection may shift the advantage back toward defenders, but only if organizations can act on intelligence before malicious actors complete registration and deployment.