DomainGuard

Threats

A running catalog of phishing and brand-impersonation techniques attacking the open internet, documented so defenders can recognize and stop them. How each works, when we first saw it, and whether attackers are still using it today.

A large-scale campaign leveraging deceptive Chrome extensions with over 900,000 installs. These extensions request broad permissions to scrape the DOM of AI chat interfaces, stealing proprietary prompts, session tokens, and active tab URLs, which are then exfiltrated to attacker-controlled C2 servers.

Full write-up

A high-pressure social engineering attack impersonating Booking.com and other travel services. Victims are led to a fake BSOD page that instructs them to run a 'fix' command. The payload leverages MSBuild.exe to bypass execution policies and deploy DCRat malware.

Full write-up

A sophisticated T-Mobile smishing kit that fingerprints victims and logs clicks before presenting a fake payment interface. Captured data includes credit card numbers, CVV codes, and SMS OTPs, often used for unauthorized wallet provisioning or account takeover.

Full write-up

A ClickFix-family lure dressed as a Cloudflare 'I am not a robot' challenge. JavaScript silently writes a PowerShell command to the clipboard while the page tells the user to open Windows Terminal as admin, paste, and press Enter. The pasted command fetches and executes an attacker-controlled binary.

Full write-up

Impersonating a company from a free webmail account instead of a registered domain. Attackers register lookalike Gmail accounts and set the username, the part before @gmail.com where people normally put their own name, to a company name or domain ([email protected]) or the real name of an employee, so the address itself reads as someone the target trusts. Free and compromised webmail accounts are the most common launch point for business email compromise, and the attack leaves no domain to register, monitor, or take down.

Full write-up

Attackers buy paid search ads on brand keywords, then route the click to a lookalike domain hosting a phishing page. Because the ad sits above the organic results, it intercepts traffic before users ever see the legitimate site.

Full write-up

A lookalike domain is registered to pass for a brand's legitimate domain: a typo variant, a homoglyph swap, a brand-plus-word combination, or a missing-dot doppelganger. Attackers weaponize them for credential phishing, invoice fraud, malicious ads, and malware staging. Detection during the parked window between registration and weaponization is the defender's best lead time.

Full write-up