Phishing Trends: May - July 2024

Phishing in 2024 shows no sign of a slowdown. We processed just slightly more than1M reports from our phishing feeds in the 3-month period ending July 31, 2024, a third straight reporting period where our collection exceeded 1M. We observe small decreases in most measurements of resources that phishers exploit to perpetrate crimes. See the measurements at Key Statistics, TLD, Registrar, and Hosting Networks for a fuller picture.

Runaway phishing in the new gTLDs

Phishing domains reported decreased by 9% during the May - July 2024 period.

While phishing domains in .TOP decreased 34%, phishers appear to have moved on to .BOND. .RU, .ICU and .CFD which all increased by more than 125%. Since the beginning of program, phishers have migrated to and from dozens of new gTLDs that offer free, cheap, or open registration policies.

Often, phishers register domains across several new gTLDs for a given phishing campaign to make their campaigns resillient to blocklisting or takedowns. Offering cybercriminals more new gTLDs of similar pricing and policy will expand an already fertile greenfield for abuse.

Phishers have firmly concentrated their registration efforts in the new gTLDs. For the period, more domain names were reported for phishing in the thirteen new gTLDs in this period's top 20 than were reported in the .COM TLD. Why is this comparison important?

  1. .COM has nearly 155M domains under management. Combined, the 13 phishiest new gTLDs have only 18M domains under management, which is approximately one-eighth of .COM.

  2. The percent of Phishing Domains in the combined 13 phishiest new gTLDs is 118% of those in .COM (185,486/157,053).

This is a pronounced escalation over the worrisome increase we reported in our Phishing Landscape 2024 study.

Phishing Domains Reported: 13 new gTLDs vs .COM TLD

TLD(s) Phishing
Domain
Reported
Domains Under
Management in
TLD (DUM)
Percent
of DUM
.COM 157,053 154,941,634 .010%
Sum of .TOP, .XYZ, .BOND, .LOL, .SHOP, .ONLINE,
.SBS, .SITE, .ICU, .CFD, .TODAY, .LIVE, .BUZZ
(13 new gTLDs in May - July Top 20
185,486 17,986,252 .125%

Changes in hosting behavior

Cloudflare continues to top the list of hosting networks with the most phishing attacks. Phishers exploited several small hosting networks in this quarter:

  • SEDO GmbH

  • Weebly, Inc.

  • Limenet

  • Komkov Vadim Aleksandrovich

  • PROSPERO llc

These ASNs had astronomically phishing scores, which is the ratio of phishing attacks to IPv4 addresses reported for hosting phishing attacks in the ASN (see Phishing Activity in Hosting Networks).

Impersonated Brands

United States Postal Service and Facebook were the most impersonated brands this reporting period. Meta, AT&T, Microsoft, and Netflix were also among the top targets. We also saw an increase in Crypto/Wallet phishing over prior period(s).

USPS is the brand most frequently found as an exact match string in phishing domains. Registry, registrar and subdomain operators could use this to experiment with a "filter for string, delay delegation pending investigation" process.

Impersonated Brands

Brand Domains Reported by Feed
for Targeting Brand
Domains Containing
Exact Match of
Brand in Name
Domains Reported by Feed
-OR-
Containing Exact Match of Brand
United States Postal Service, USPS 7,614 13,029 18,679
Facebook 2,965 319 3,310

Phishing from Subdomain Providers

Phishing from user accounts at subdomain providers decreased but still accounts for more than 10% of phishing attacks reported during the May - July 2024 period.

Phishing Activity in Subdomain Providers
May 1, 2024 - July 31, 2024

Ranking of Subdomain Providers by Phishing Attacks (May to July 2024)

Rank Subdomain
Provider
Domains Phishing
Attacks ▼
Malicious
Phishing
ttacks
Percent
Malicious
1 Cloudflare pages.dev
trycloudflare.com
workers.dev
15,022 5,369 29%
2 Google appspot.com
blogspot.com
blogspot.xx on 66 ccTLDs
doubleclick.net
firebaseapp.com
googleapis.com
page.link
web.app
11,621 5,654 49%
3 Weebly weebly.com
weeblysite.com
10,172 6,077 60%
4 DuckDNS duckdns.org 7,141 6,804 95%
5 Github github.io 7,075 2,079 29%
6 Vercel vercel.app 4,549 3,030 67%