EfficientIP Research Labs said it identified the potential .cyou domains on June 9 and added them to its DNS threat intelligence feed.
From detection to live phishing chain: June 9 to July 2
EfficientIP tracked a set of ten .cyou names weeks before they appeared on the internet. According to the company, the domains were flagged on June 9 and were subsequently registered and began resolving to IP addresses on July 2. Tracing DNS and redirect activity led researchers to a single AliExpress-themed phishing destination.
Ten disposable entry points, DGA-style pattern
All ten domains followed the same format — one digit and five lowercase letters — and shared a registration date. EfficientIP described the set as DGA-style, while noting that the pattern alone does not prove a domain generation algorithm produced them. The domains resolved to three IP addresses in a single subnet.
None of the ten domains hosted the lure directly. Instead, each sent visitors through a tracking layer that carried campaign, click or affiliate parameters. EfficientIP highlighted that this structure allows an operator to replace exposed domains without rebuilding the campaign: change the disposable entry points, keep the tracking layer and the redirects intact.
That disposability is consequential because such names have little or no history; EfficientIP said reputation-based controls may not yet have classified them when the first visitors arrive.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildThe lookalike shopping assistant and early flags
The redirect chain ended at a site that used a zero in place of the "o" in "shop," promoting a browser extension styled after Alitools, a legitimate shopping-assistant brand. The page claims more than 500,000 users and urges visitors to click "Add to Browser."
Several security services had already flagged the site as malicious or unsafe. ANY.RUN's sandbox tagged the destination as phishing on May 22 — a point the report stresses because that detection predates the July activation of the redirect domains, meaning the early warning applied to the destination before the disposable entry points went live.
EfficientIP presented the harms from the chain as potential rather than confirmed: visitors risked credential and payment theft, exposure of browsing activity through the extension, and the tracking parameters could earn the operator affiliate revenue. The research report explicitly states it found no victims or losses and does not describe exactly how people were led to the domains or what the extension actually does.
Recommendations from EfficientIP and remaining investigative gaps
EfficientIP advised blocking the identified domains and IP addresses and searching DNS and proxy logs for past connections. Where users engaged with the site, the company recommended resetting credentials, contacting card issuers and removing the extension.
Not all technical details in the report are explained: the research does not describe how the names were spotted before registration. Infosecurity has reached out to EfficientIP for details on that point.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: EfficientIP's findings underline the limits of reputation-based controls for newly minted domains and the operational advantage of disposable entry points tied to tracking layers. The report's concrete steps — blocking the domains and IP addresses named by EfficientIP and searching DNS and proxy logs for prior connections — are the actions the firm recommended.
- Procurement and enterprise application leaders: The incident highlights how lookalike browser extensions can be used to impersonate a well-known shopping-assistant brand. Enterprises should be prepared to investigate extensions that claim large user bases and verify that marketplace claims map to legitimate vendor artifacts before permitting deployments.
- End users and general public: Where engagement with the site occurred, EfficientIP recommended removing the extension, resetting account credentials and contacting card issuers if payment data may have been exposed.
The case is notable for two linked observations: the relatively early sandbox detection of the final phishing site (ANY.RUN on May 22) and the prior flagging of the disposable .cyou names on June 9 — followed by their registration and activation on July 2. The unanswered technical question — how the pre-registration names were identified — is a concrete next step for follow-up and for defenders hoping to replicate early-warning capabilities. Infosecurity has contacted EfficientIP for further details.
Source: Infosecurity — Researchers Identify AliExpress Phishing Domains Before Registration




