← All news

phishing

1.5M Malicious Domains, Built Like a Factory

2026-06-12

Researchers digging through VirusTotal data from January to May 2026 tallied roughly 1.5 million malicious domains, each flagged by at least five independent scanning engines. Nine in ten were registered fresh by attackers. The remainder were older legitimate sites that had been hijacked and repurposed.

The median domain didn't show up on VirusTotal until about two months after registration. A third were caught within a week. That's not a lot of warning time when a campaign can be live and harvesting credentials from day one.

A surprisingly concentrated supply chain

The eye-catching part isn't the volume. It's how few hands the work passes through. Four registrars handled more than a third of attacker-created domains between them. The top ten accounted for close to 60 percent. The humble .com extension covered around a third of the total, with the cheap-and-cheerful options, .top, .cc and .xyz, picking up much of the rest.

Hosting was even more lopsided. Eight of the ten busiest IP addresses in the dataset were Cloudflare reverse-proxy endpoints. Two of those endpoints were each fronting more than 230,000 attack domains on their own. AWS sat near the top of the list too.

Bulk manufacturing, not artisanal cybercrime

The registration patterns make the operation impossible to mistake for anything else. More than three-quarters of attack domains turned up in batches of five or more sharing the same registrar and the same creation date. The biggest single batch was over two thousand domains registered with one registrar in a single day, with names following short alphanumeric patterns that only an automated script would bother producing.

This isn't a hobbyist registering a lookalike domain over a cup of coffee. It's an assembly line, optimised for cost per domain and turnaround time.

Who attackers want to be

The brand impersonation data is unusually clean. A few names dominate, and they line up neatly with the accounts most worth stealing:

  • WhatsApp appeared in close to 20,000 attack domains, far ahead of every other brand.
  • Google, for the email and identity payoff.
  • Coinbase, for the crypto wallets.
  • Bet365, for the gambling balances sitting in user accounts.

The traffic distribution within the dataset is also wildly skewed. One single domain pulled in more than two billion queries on its own, suggesting a small group of very busy names do most of the actual damage while the rest churn quietly in the background.

The chokepoints are the point

An assembly line has weak spots that an artisan operation doesn't. A handful of registrars. A handful of extensions. A handful of networks. That concentration is awkward for the platforms hosting the abuse, and useful for everyone trying to stay ahead of it.

For anyone running awareness training or phishing simulations, the brand list is a ready-made shortlist of what's most likely to land in your people's inboxes this quarter. If your simulated lures don't already include a WhatsApp account-recovery message and a Coinbase login warning, they probably should.

1.5M Malicious Domains, Built Like a Factory | RiskSense