Phishing Trends: May - July 2024
Phishing in 2024 shows no sign of a slowdown. We processed just slightly more than1M reports from our phishing feeds in the 3-month period ending July 31, 2024, a third straight reporting period where our collection exceeded 1M. We observe small decreases in most measurements of resources that phishers exploit to perpetrate crimes. See the measurements at Key Statistics, TLD, Registrar, and Hosting Networks for a fuller picture.
Runaway phishing in the new gTLDs
Phishing domains reported decreased by 9% during the May - July 2024 period.
While phishing domains in .TOP decreased 34%, phishers appear to have moved on to .BOND. .RU, .ICU and .CFD which all increased by more than 125%. Since the beginning of program, phishers have migrated to and from dozens of new gTLDs that offer free, cheap, or open registration policies.
Often, phishers register domains across several new gTLDs for a given phishing campaign to make their campaigns resillient to blocklisting or takedowns. Offering cybercriminals more new gTLDs of similar pricing and policy will expand an already fertile greenfield for abuse.
Phishers have firmly concentrated their registration efforts in the new gTLDs. For the period, more domain names were reported for phishing in the thirteen new gTLDs in this period's top 20 than were reported in the .COM TLD. Why is this comparison important?
.COM has nearly 155M domains under management. Combined, the 13 phishiest new gTLDs have only 18M domains under management, which is approximately one-eighth of .COM.
The percent of Phishing Domains in the combined 13 phishiest new gTLDs is 118% of those in .COM (185,486/157,053).
This is a pronounced escalation over the worrisome increase we reported in our Phishing Landscape 2024 study.
Phishing Domains Reported: 13 new gTLDs vs .COM TLD
TLD(s) | Phishing Domain Reported | Domains Under Management in TLD (DUM) | Percent of DUM |
.COM | 157,053 | 154,941,634 | .010% |
Sum of .TOP, .XYZ, .BOND, .LOL, .SHOP, .ONLINE, .SBS, .SITE, .ICU, .CFD, .TODAY, .LIVE, .BUZZ (13 new gTLDs in May - July Top 20 | 185,486 | 17,986,252 | .125% |
Changes in hosting behavior
Cloudflare continues to top the list of hosting networks with the most phishing attacks. Phishers exploited several small hosting networks in this quarter:
SEDO GmbH
Weebly, Inc.
Limenet
Komkov Vadim Aleksandrovich
PROSPERO llc
These ASNs had astronomically phishing scores, which is the ratio of phishing attacks to IPv4 addresses reported for hosting phishing attacks in the ASN (see Phishing Activity in Hosting Networks).
Impersonated Brands
United States Postal Service and Facebook were the most impersonated brands this reporting period. Meta, AT&T, Microsoft, and Netflix were also among the top targets. We also saw an increase in Crypto/Wallet phishing over prior period(s).
USPS is the brand most frequently found as an exact match string in phishing domains. Registry, registrar and subdomain operators could use this to experiment with a "filter for string, delay delegation pending investigation" process.
Impersonated Brands
Brand | Domains Reported by Feed for Targeting Brand | Domains Containing Exact Match of Brand in Name | Domains Reported by Feed -OR- Containing Exact Match of Brand |
United States Postal Service, USPS | 7,614 | 13,029 | 18,679 |
2,965 | 319 | 3,310 |
Phishing from Subdomain Providers
Phishing from user accounts at subdomain providers decreased but still accounts for more than 10% of phishing attacks reported during the May - July 2024 period.
Phishing Activity in Subdomain Providers
May 1, 2024 - July 31, 2024
Ranking of Subdomain Providers by Phishing Attacks (May to July 2024)
Rank | Subdomain Provider |
Domains | Phishing Attacks ▼ |
Malicious Phishing ttacks |
Percent Malicious |
1 | Cloudflare | pages.dev trycloudflare.com workers.dev |
15,022 | 5,369 | 29% |
2 | appspot.com blogspot.com blogspot.xx on 66 ccTLDs doubleclick.net firebaseapp.com googleapis.com page.link web.app |
11,621 | 5,654 | 49% | |
3 | Weebly | weebly.com weeblysite.com |
10,172 | 6,077 | 60% |
4 | DuckDNS | duckdns.org | 7,141 | 6,804 | 95% |
5 | Github | github.io | 7,075 | 2,079 | 29% |
6 | Vercel | vercel.app | 4,549 | 3,030 | 67% |