Security2 publishers2 min readPublished
EfficientIP flagged ten .cyou domains 23 days before they fed a phishing site impersonating Alitools
EfficientIP put ten .cyou domains on its threat feed June 9, 23 days before they went live as redirects to a fake AliExpress site. The chain was designed to outrun reputation scoring, though its landing page had carried a phishing verdict since May 22.
The Watch · Security desk

What happened
- EfficientIP Research Labs listed ten .cyou domains in its DNS threat intelligence feed on June 9, and they were registered and began resolving on July 2.
- All ten used one digit plus five lowercase letters, shared a registration date and resolved to three IP addresses in a single subnet.
- None of the ten hosted the lure; each passed visitors through a tracking layer carrying campaign, click or affiliate parameters.
- The chain ended at a lookalike shop site with a zero in place of the 'o', pushing a browser extension styled after the Alitools shopping assistant.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Checking where a redirect chain ends would have stopped this campaign on a verdict that already existed, with no need to predict the entry names.
- constraint An operator who can rotate entry domains without rebuilding keeps name-level blocklists one batch behind unless the feed can list names before registration.
- cost Containing this batch costs defenders a blocklist update for ten names and their addresses plus a search of DNS and proxy logs for past hits.
Whether the early warning can be repeated depends on how EfficientIP chose the names before anyone registered them. Infosecurity has asked the company to explain [16]. The domains went live 23 days after they entered the feed [1]. EfficientIP called the batch DGA-style. It also said the shared format alone does not prove a domain generation algorithm produced it [5].
The ten were disposable entry points. According to EfficientIP, the tracking layer lets an operator replace exposed domains without rebuilding the campaign [6]. Because new domains have little history, the company said, reputation-based controls may not have classified them when the first visitors arrive [7].
That evasion case rests on how the chain was built, and it covers only the first hop. ANY.RUN's sandbox tagged the landing site as phishing on May 22 [12]. That was 18 days before EfficientIP listed the entry domains [3] and 41 days before they resolved [2]. Several other services had also marked the site malicious or unsafe [12]. The research reports no victims or losses, and it does not say how people reached the domains or what the extension does [14].
One set of ten says little about whether a single operator is changing tactics over time. It does fit a supply pattern that has already been measured. Interisle's Phishing Landscape 2025 study found 77% of phishing domains were maliciously registered and 37% were bought through bulk-registration services [9]. EfficientIP cited Cloudflare research finding that 62% of email from .cyou in 2023 was malicious, while stressing that the ending alone does not make a site dangerous [8]. A blanket .cyou block would also hit the 38% of that email Cloudflare did not class as malicious [4].
The lure page claims more than 500,000 users and asks visitors to click "Add to Browser" [11]. EfficientIP described the harms as potential: credential and payment theft, exposure of browsing activity through the extension, and affiliate revenue for the operator from the tracking parameters [13]. For users who engaged with the site, it recommended resetting credentials, contacting card issuers and removing the extension [15].
What to watch
- EfficientIP's reply to Infosecurity on how it identified the ten names before they were registered.
- A fresh batch of one-digit, five-letter .cyou names resolving into the same subnet would show the operator rotating entry points.
- Any analysis of what the Alitools-styled extension does once installed, or the first report of victims.