EFFICIENTIP Research Labs reported identifying 10 potential AliExpress-themed phishing domains on 9 June 2026, weeks before they were registered. The .cyou domains were added to the company’s DNS threat-intelligence feed, then registered and began resolving to IP addresses on 2 July. All followed a similar one-digit-and-five-letter format, shared a registration date and resolved to three addresses in the same subnet. EfficientIP described the pattern as DGA-style, while stressing that this alone does not prove an algorithm generated the domains.
The domains did not host the phishing lure directly. Instead, they redirected visitors through a tracking layer containing campaign, click and affiliate parameters before leading to a lookalike shopping site. The site substituted a zero for the “o” in “shop” and promoted a browser extension styled after the legitimate Alitools shopping assistant, claiming more than 500,000 users and urging visitors to select “Add to Browser”.
ANY.RUN had already classified the site as phishing on 22 May, although that finding predates the redirect domains and does not establish when the campaign began. EfficientIP said the extension could potentially expose credentials, payment details and browsing activity, while affiliate tracking could generate revenue for the operator; it reported no confirmed victims or losses.
The researchers recommended blocking the domains and IP addresses, checking DNS and proxy logs for previous connections, resetting credentials, contacting card issuers and removing the extension where users interacted with the site. EfficientIP has not explained how the domains were identified before registration.