Daily Threat Brief - Wednesday, 12 August 2026
TLP:CLEAR · Estate: 89 campaigns tracked · 468,804 unique domains · 84.6% online
Automated campaign intelligence from Webamon. Here's what our sensors saw across tracked phishing and malware-delivery estates in the last 24 hours.
📊 By the numbers (last 24h)
41 campaigns with activity
5,829 new malicious domains observed
1,119 domains taken offline (NXDOMAIN, double-checked)
6,012 infrastructure changes (new IPs / ASNs / cert issuers)
1,661 new page-title lures
185 emerging clusters live on the radar
🔍 What moved today
🔺 Fastest-growing — Chinese Gambling Portal Cluster (Dafa 6622 / Sun City / Vegas) added 1,304 new domains — active registration and rotation in progress.
🔻 Takedowns — 741 domains in Rolling sqllq[.]com subdomain phishing now resolve NXDOMAIN — takedowns/expiry confirmed by double-checked DNS.
🔁 Infra rotation — Brazilian 'Plataforma Oficial' Betting Kit Family moved onto 3,086 new IPs, and china k8 phishing portal onto 2,117 new IPs — evasion or re-hosting behaviour; refresh blocklists.
🎭 Lure refresh — Brazilian 'Plataforma Oficial' Betting Kit Family deployed 1,197 new page titles; Brazilian Casino Affiliate Network (Fortune Tiger kit) rotated in 286 — templates are being cycled.
🎯 Campaigns worth a look
Fake CAPTCHA Gate Network (Verifying you are human) — 7,209 domains, 100% online, with 256 new domains added this window and fresh nrd_20260811 tagging: newly registered infrastructure going live fast behind a human-verification gate.
Document-Lure Credential Phishing (DocuSign/OneDrive/Excel) — small (204 domains) but busy: 40 infrastructure changes and 3 new lures against enterprise document brands.
📡 On the radar — emerging clusters
185 clusters are live (110 critical, 75 high) — unattributed infrastructure large enough to promote to tracked campaigns. Sharpest 24h growth:
scripts cluster — 6,490 domains, +764 in a day (016213[.]cc)
tech cluster — 5,861 domains, +6 (01490242b[.]com)
ssl cluster — 9,888 domains, +2 (2rnkablo[.]com)
See the full brief and every tracked campaign live in the Webamon console → https://t.co/XUqv7kB0X0
Full Pdf Brief is available daily from 12:00UTC on our DTB Github Repo → https://t.co/WtUOYKzPDu
Researcher License - $15/month VS $45/month - For as long as your subscription is active. NEWSLETTER - At checkout page
Daily Threat Brief - Tuesday, 11 August 2026
TLP:CLEAR · Estate: 85 campaigns tracked · 454,693 unique domains · 84.4% online
⭐ New campaign spotlight - verificator[.]cc ClickFix → Femo IT bulletproof estate
We've added a new tracked campaign this window: Femo IT (AS214351) Bulletproof Phishing Estate + verificator[.]cc ClickFix — 624 domains, 62% still online (386), first seen 3 January 2026, active today.
It started from a single Win + R screenshot search that surfaced a fake-Cloudflare ClickFix loader on verificator[.]cc - a cloned "Just a moment…" gate that poisons the clipboard with a fileless irm …/verify.ps1 | iex PowerShell command. Pivoting the loader's cert-SAN fingerprint onto its ASN fingerprint exposed the host beneath: Femo IT Solutions Limited, AS214351 (Germany) - a single bulletproof network where every tracked domain contacts only this ASN. It runs at least six parallel operations at once: hotel/PMS credential phishing (Rezlynx, Newbook, D-EDGE, DIRS21, Guestline), banking (SoFi, Navy Federal, E*TRADE), crypto-exchange spoofs (ChangeNOW, ff-exchange), gaming skin scams, fake-YouTube copyright lures, and the ClickFix info-stealer delivery itself.
OSINT associates AS214351 with the defhost brand (defhost[.]co) and a broad malicious-tooling set (Lumma, StealC, Rhadamanthys, RedLine, Evilginx/EvilGoPhish, Meduza and more) consistent with a bulletproof host renting to many actors. New-domain volume is surging in August (16–22/day). The estate is now re-checked every 4 hours as a single tracked record.
📊 By the numbers (last 24h)
49 campaigns with activity
4,664 new malicious domains observed
910 domains went offline (NXDOMAIN, double-checked)
2,431 infrastructure changes (new IPs / ASNs / cert issuers)
1,569 new page-title lures
193 emerging clusters live on the radar
🔍 What moved today
🔺 Fastest-growing — Chinese Gambling Portal Cluster (Dafa 6622 / Sun City / Vegas) added 1,040 new domains — active registration and rotation in progress.
🔻 Takedowns — 433 domains in Rolling sqllq[.]com subdomain phishing now resolve NXDOMAIN — takedowns/expiry confirmed by double-checked DNS.
🔁 Infra rotation — china k8 phishing portal moved onto 938 new IPs, and Brazilian 'Plataforma Oficial' Betting Kit Family onto 802 — evasion or re-hosting behaviour; refresh blocklists.
🎭 Lure refresh — Brazilian 'Plataforma Oficial' Betting Kit Family deployed 1,060 new page titles; Brazilian Casino Affiliate Network (Fortune Tiger kit) added 285 and 0007bet Gambling Cert Farm 188 — templates are being cycled.
🎯 Campaigns worth a look
Fake CAPTCHA Gate Network (Verifying you are human) — 7,051 domains, 100% online, with 399 new domains this window across compromised-looking business names.
ClickFix Fake-Cloudflare Challenge Malware Delivery — smaller at 397 domains, but 99 infrastructure changes against 29 new domains: heavy re-hosting on a malware-delivery estate.
📡 On the radar — emerging clusters
193 clusters are live (111 critical, 82 high) — unattributed infrastructure large enough to promote to tracked campaigns. Sharpest 24h growth:
ssl cluster — 7,915 domains, +788 in a day ("CNAME Cross-User Banned | Cloudflare")
ssl cluster — 9,248 domains, +412 ("Attention Required! | Cloudflare")
ssl cluster — 7,351 domains, +374 ("Just a moment...")
See the full brief and every tracked campaign live in the Webamon console → https://t.co/XUqv7kB0X0
Full Pdf Brief is available daily from 12:00UTC on our DTB Github Repo → https://t.co/WtUOYKzPDu
Researcher License - $15/month VS $45/month - For as long as your subscription is active. NEWSLETTER - At checkout page
Daily Threat Brief - Monday, 10 August 2026
TLP:CLEAR · Estate: 84 campaigns tracked · 448,932 unique domains · 84.5% online
Automated campaign intelligence from Webamon. Here's what our sensors saw across tracked phishing and malware-delivery estates in the last 24 hours.
📊 By the numbers (last 24h)
44 campaigns with activity
6,830 new malicious domains observed
961 domains went offline (NXDOMAIN, double-checked)
2,674 infrastructure changes (new IPs / ASNs / cert issuers)
1,730 new page-title lures
188 emerging clusters live on the radar
🔍 What moved today
🔺 Fastest-growing — Chinese Gambling Portal Cluster (Dafa 6622 / Sun City / Vegas) added 1,572 new domains — active registration and rotation in progress.
🔻 Takedowns — 505 domains in Rolling sqllq[.]com subdomain phishing now resolve NXDOMAIN — takedowns/expiry confirmed by double-checked DNS.
🔁 Infra rotation — Brazilian 'Plataforma Oficial' Betting Kit Family moved onto 912 new IPs, while china k8 phishing portal shifted onto 873 new IPs across 1 new ASN — re-hosting behaviour; refresh blocklists.
🎭 Lure refresh — Brazilian 'Plataforma Oficial' Betting Kit Family deployed 830 new page titles; 0007bet Gambling Cert Farm rotated in 576 — content templates being cycled.
🎯 Campaigns worth a look
Fake CAPTCHA Gate Network (Verifying you are human) — 6,652 domains, 100% online, with 453 added in this window and new .xyz and .site TLDs in play.
ClickFix Fake-Cloudflare Challenge Malware Delivery — smaller at 368 domains, but 70 infrastructure changes in 24h against just 14 new domains: rotation over growth.
📡 On the radar — emerging clusters
188 clusters are live (92 critical, 96 high) — unattributed infrastructure large enough to promote to tracked campaigns. Sharpest 24h growth:
tech cluster — 8,825 domains, +1,802 in a day (00006060[.]com)
scripts cluster — 5,616 domains, +1,341 (l43dks[.]top)
See the full brief and every tracked campaign live in the Webamon console → https://t.co/XUqv7kB0X0
Full Pdf Brief is available daily from 12:00UTC on our DTB Github Repo → https://t.co/WtUOYKzPDu
Monthly Researcher License - £10pm for as long as your subscription lasts VS £35pm
Researcher license gives you full console access to all our tracked campaigns.
NEWSLETTER - At checkout
https://t.co/uBU9nkgDF4
Daily Threat Brief - Sunday, 09 August 2026
TLP:CLEAR · Estate: 84 campaigns tracked · 441,591 unique domains · 84.5% online
Automated campaign intelligence from Webamon. Here's what our sensors saw across tracked phishing and malware-delivery estates in the last 24 hours.
📊 By the numbers (last 24h)
49 campaigns with activity
7,865 new malicious domains observed
887 domains went offline (NXDOMAIN, double-checked)
3,537 infrastructure changes (new IPs / ASNs / cert issuers)
1,789 new page-title lures
179 emerging clusters live on the radar
🔍 What moved today
🔺 Fastest-growing — Chinese Gambling Portal Cluster (Dafa 6622 / Sun City / Vegas) added 1,948 new domains — active registration/rotation in progress.
🔻 Takedowns — 423 domains in Rolling sqllq[.]com subdomain phishing are now NXDOMAIN — takedowns/expiry confirmed by double-checked DNS.
🔁 Infra rotation — china k8 phishing portal moved onto 1,126 new IPs, and Brazilian 'Plataforma Oficial' Betting Kit Family onto 1,074 — evasion or re-hosting; refresh blocklists.
🎭 Lure refresh — 0007bet Gambling Cert Farm deployed 809 new page titles — content templates are being rotated.
🎯 Campaigns worth a look
ClickFix Fake-Cloudflare Challenge Malware Delivery — 354 domains, 43 new this window and 107 infrastructure changes off just 330 scans: a small estate churning hosting fast.
Fake CAPTCHA Gate Network (Verifying you are human) — 578 new domains, 6,199 total and 100% online, now expanding into new TLDs (.email, .be).
📡 On the radar — emerging clusters
179 clusters are live (89 critical, 90 high) — unattributed infrastructure large enough to promote to tracked campaigns. Sharpest 24h growth:
tech cluster — 8,362 domains, +1,224 (00006060[.]com)
ssl cluster — 9,494 domains, +1,013 ("Just a moment...")
See the full brief and every tracked campaign live in the Webamon console → https://t.co/XUqv7kB0X0
Full PDF Brief is available daily from 12:00 UTC on our DTB GitHub Repo → https://t.co/WtUOYKzPDu
Daily Threat Brief - Saturday, 08 August 2026
TLP:CLEAR · Estate: 84 campaigns tracked · 433,491 unique domains · 84.4% online
Automated campaign intelligence from Webamon. Here's what our sensors saw across tracked phishing and malware-delivery estates in the last 24 hours.
📊 By the numbers (last 24h)
48 campaigns with activity
9,000 new malicious domains observed
544 domains went offline (NXDOMAIN, double-checked)
4,680 infrastructure changes (new IPs / ASNs / cert issuers)
1,437 new page-title lures
175 emerging clusters live on the radar
🔍 What moved today
🔺 Fastest-growing — Chinese Gambling Portal Cluster (Dafa 6622 / Sun City / Vegas) added 1,982 new domains — active registration and rotation in progress.
🔻 Takedowns — 255 domains in Rolling sqllq[.]com subdomain phishing now resolve NXDOMAIN — takedowns/expiry confirmed by double-checked DNS.
🔁 Infra rotation — china k8 phishing portal moved onto 1,478 new IPs, and Brazilian 'Plataforma Oficial' Betting Kit Family onto 1,221 — evasion or re-hosting behaviour; refresh blocklists.
🎭 Lure refresh — 0007bet Gambling Cert Farm deployed 419 new page titles; Brazilian Casino Affiliate Network (Fortune Tiger kit) rotated in 408 — content templates being cycled.
🎯 Campaigns worth a look
Fake CAPTCHA Gate Network (Verifying you are human) — 5,621 domains, 100% online, with 757 added this window. Paired with ClickFix Fake-Cloudflare Challenge Malware Delivery (137 infra changes across 311 domains), the fake-verification gate remains an active malware-delivery front end.
📡 On the radar — emerging clusters
175 clusters are live (80 critical, 95 high) — unattributed infrastructure large enough to promote to tracked campaigns. Sharpest 24h growth:
dom cluster — 7,368 domains, +1,025 (100mocks[.]com)
tech cluster — 6,649 domains, +902 (0002302[.]pro)
See the full brief and every tracked campaign live in the Webamon console → https://t.co/XUqv7kB0X0
Full Pdf Brief is available daily from 12:00UTC on our DTB Github Repo → https://t.co/WtUOYKzPDu
Daily Threat Brief - Friday, 07 August 2026
NEW COMMUNITY BLOG: Operation Credit Mirage pt2
TLP:CLEAR · Estate: 76 campaigns tracked · 410,432 unique domains · 83.6% online
Automated campaign intelligence from Webamon. Here's what our sensors saw across tracked phishing and malware-delivery estates in the last 24 hours.
📊 By the numbers (last 24h)
36 campaigns with activity
2,770 new malicious domains observed
667 domains went offline (NXDOMAIN, double-checked)
1,319 infrastructure changes (new IPs / ASNs / cert issuers)
1,156 new page-title lures
167 emerging clusters live on the radar
🔍 What moved today
🔺 Fastest-growing — Rolling subdomain phishing added 738 new domains — active registration and rotation in progress.
🔻 Takedowns — 384 domains in the same sqllq[.]com estate now resolve NXDOMAIN — takedowns/expiry confirmed by double-checked DNS.
🔁 Infra rotation — china k8 phishing portal moved onto 474 new IPs, while the 2026 World Cup Chinese Gambling Doorway Network shifted onto 335 new IPs across 10 new ASNs — re-hosting behaviour; refresh blocklists.
🎭 Lure refresh — Brazilian Casino Affiliate Network (Fortune Tiger kit) deployed 304 new page titles; 0007bet Gambling Cert Farm rotated 282 and Chinese Cloaking Loader (Xitong Jiazai) 238.
🎯 Campaigns worth a look
Fake CAPTCHA Gate Network (Verifying you are human) — 610 new domains in a single window across a 4,864-domain estate that is 100% online. Zero attrition, pure growth.
ClickFix Fake-Cloudflare Challenge Malware Delivery — small but busy: 278 domains, 36 new, and 128 infrastructure changes in 24h.
📡 On the radar — emerging clusters
167 clusters are live (62 critical, 105 high) — unattributed infrastructure large enough to promote to tracked campaigns. Sharpest 24h growth:
asn cluster — 9,045 domains, +1,167 in a day (020gfhs[.]com)
tech cluster — 5,116 domains, +782 (000[.]rich)
ssl cluster — 6,373 domains, +645 ("Just a moment...")
ssl cluster — 8,588 domains, +619 ("Just a moment...")
See the full brief and every tracked campaign live in the Webamon console → https://t.co/XUqv7kB0X0
Full Pdf Brief is available daily from 12:00UTC on our DTB Github Repo → https://t.co/WtUOYKzPDu
Today is the last day of Q2 pricing for Webamon. All campaigns access available in console via Researcher License. Research Lab includes console + api campaigns access
https://t.co/fTqJtVQnuI
Daily Threat Brief - Thursday, 06 August 2026
NEW COMMUNITY BLOG: Casino factory: anatomy of a network of 18,445 web assets built for crypto fraud
TLP:CLEAR · Estate: 75 campaigns tracked · 407,912 unique domains · 83.7% online
Automated campaign intelligence from Webamon. Here's what our sensors saw across tracked phishing and malware-delivery estates in the last 24 hours.
📊 By the numbers (last 24h)
43 campaigns with activity
4,820 new malicious domains observed
942 domains went offline (NXDOMAIN, double-checked)
1,665 infrastructure changes (new IPs / ASNs / cert issuers)
1,281 new page-title lures
162 emerging clusters live on the radar
🔍 What moved today
🔺 Fastest-growing — Rolling sqllq[.]com subdomain phishing added 1,476 new domains — active registration and rotation in progress.
🔻 Takedowns — 407 domains in the same sqllq[.]com estate now resolve NXDOMAIN — takedowns/expiry confirmed by double-checked DNS.
🔁 Infra rotation — china k8 phishing portal moved onto 1,128 new IPs, and Fake CAPTCHA Gate Network (Verifying you are human) onto 28 new IPs — refresh blocklists.
🎭 Lure refresh — Chinese Cloaking Loader (Xitong Jiazai) deployed 385 new page titles; Brazilian Fake-Content Cloaking Bet Funnel rotated 264 and 0007bet Gambling Cert Farm 257.
🎯 Campaigns worth a look
ClickFix Fake-Cloudflare Challenge Malware Delivery — 242 domains, 79% online, with 47 new domains and 124 infrastructure changes in a single window. Small estate, very high churn.
0149 Mark Six Lottery Nav Portal Network — 542 new domains across 8,039 tracked, 100% online and nothing offline.
📡 On the radar — emerging clusters
162 clusters live (47 critical, 115 high) — unattributed infrastructure large enough to promote to tracked campaigns. Sharpest 24h growth:
asn cluster — 5,640 domains, +1,212 in a day (073752[.]com)
ssl cluster — 4,242 domains, +972 ("Just a moment...")
ssl cluster — 5,714 domains, +939 ("Just a moment...")
dom cluster — 4,204 domains, +619 (069reselling[.]com)
See the full brief and every tracked campaign live in the Webamon console → https://t.co/XUqv7kB0X0
Full Pdf Brief is available daily from 12:00UTC on our DTB Github Repo → https://t.co/WtUOYKzPDu
Daily Threat Brief - Wednesday, 05 August 2026
TLP:CLEAR · Estate: 75 campaigns tracked · 402,288 unique domains · 83.7% online
Automated campaign intelligence from Webamon. Here's what our sensors saw across tracked phishing and malware-delivery estates in the last 24 hours.
📊 By the numbers (last 24h)
38 campaigns with activity
2,441 new malicious domains observed
798 domains went offline (NXDOMAIN, double-checked)
327 infrastructure changes (new IPs / ASNs / cert issuers)
2,048 new page-title lures
153 emerging clusters live on the radar
🔍 What moved today
🔺 Fastest-growing — Rolling sqllq[.]com subdomain phishing added 931 new domains — active registration/rotation in progress.
🔻 Takedowns — 424 domains in the same sqllq[.]com estate now resolve to NXDOMAIN — takedowns/expiry confirmed by double-checked DNS.
🔁 Infra rotation — china k8 phishing portal moved onto 137 new IPs, and Fake CAPTCHA Gate Network onto 31 — re-hosting behaviour; refresh blocklists.
🎭 Lure refresh — Chinese Cloaking Loader (Xitong Jiazai) deployed 716 new page titles — content templates are being cycled.
🎯 Campaigns worth a look
Fake CAPTCHA Gate Network (Verifying you are human) — 3,780 domains, 100% online, 604 new this window across 33 infra changes. A fully live, fast-expanding gate estate.
ClickFix Fake-Cloudflare Challenge Malware Delivery — small (195 domains) but churning hard: 20 infra changes and 4 new tags in 24h.
Document-Lure Credential Phishing (DocuSign/OneDrive/Excel) — 173 domains, 21 infra changes and 4 new lures — enterprise credential theft, actively re-hosted.
📡 On the radar — emerging clusters
153 clusters live (34 critical, 118 high) — unattributed infrastructure large enough to promote to tracked campaigns. Sharpest 24h growth:
ssl cluster — 8,042 domains, +210 in a day (01800agregados[.]com)
asn cluster — 4,689 domains, +52 (0302onabike[.]com)
dom cluster — 3,274 domains, +21 (0055xing[.]com)
See the full brief and every tracked campaign live in the Webamon console → https://t.co/XUqv7kB0X0
Full PDF brief is available daily from 12:00UTC on our DTB GitHub Repo → https://t.co/WtUOYKzPDu
Daily Threat Brief - Tuesday, 04 August 2026
NEW BLOG POST: Most Targeted Brands: Impersonation by Vertical and Region
TLP:CLEAR · Estate: 75 campaigns tracked · 399,745 unique domains · 83.8% online
Automated campaign intelligence from Webamon. Here's what our sensors saw across tracked phishing and malware-delivery estates in the last 24 hours.
📊 By the numbers (last 24h)
39 campaigns with activity
1,984 new malicious domains observed
989 domains went offline (NXDOMAIN, double-checked)
257 infrastructure changes (new IPs / ASNs / cert issuers)
3,236 new page-title lures
150 emerging clusters live on the radar
🔍 What moved today
🔺 Fastest-growing — Rolling sqllq[.]com subdomain phishing added 547 new domains — active registration and rotation in progress.
🔻 Takedowns — 649 domains in the same sqllq[.]com estate now resolve to NXDOMAIN — takedowns/expiry confirmed by double-checked DNS.
🔁 Infra rotation — china k8 phishing portal shifted onto 61 new IPs across 8 new ASNs, while Chinese com[.]cn SEO Doorway Family (007/001 games-sports) moved onto 43 new IPs — re-hosting behaviour; refresh blocklists.
🎭 Lure refresh — Chinese Cloaking Loader (Xitong Jiazai) deployed 1,073 new page titles — content templates are being cycled.
🎯 Campaigns worth a look
Gambling Infra ASN+SSL Pair (.vip/.cc) — 9,488 domains, 75% online, with 400 new domains, 181 offline and 10 infra changes in a single window: high-churn hosting that blocklists will struggle to keep pace with.
0149 Mark Six Lottery Nav Portal Network — 207 new domains and 4 new IPs across a 7,274-domain, 100% online estate.
📡 On the radar — emerging clusters
150 clusters are live (31 critical, 118 high) — unattributed infrastructure large enough to promote to tracked campaigns. Sharpest 24h growth:
ssl cluster — 7,629 domains, +210 in a day (01800agregados[.]com)
tech cluster — 5,598 domains, +188 (01490242b[.]com)
dom cluster — 3,254 domains, +186 (00899[.]top)
See the full brief and every tracked campaign live in the Webamon console → https://t.co/XUqv7kB0X0
Full Pdf Brief is available daily from 12:00UTC on our DTB Github Repo → https://t.co/WtUOYKzPDu
Daily Threat Brief - Monday, 03 August 2026
COMMUNITY THREAT HUNTER BLOG POST
Operation Credit Mirage: Large-Scale Financial Phishing Infrastructure Targeting Brazilian
https://t.co/zaW1ZaKIMy
TLP:CLEAR · Estate: 75 campaigns tracked · 396,824 unique domains · 84.0% online
Automated campaign intelligence from Webamon. Here's what our sensors saw across tracked phishing and malware-delivery estates in the last 24 hours.
📊 By the numbers (last 24h)
37 campaigns with activity
2,724 new malicious domains observed
736 domains went offline (NXDOMAIN, double-checked)
313 infrastructure changes (new IPs / ASNs / cert issuers)
4,177 new page-title lures
144 emerging clusters live on the radar
🔍 What moved today
🔺 Fastest-growing — Gambling Infra ASN+SSL Pair (.vip/.cc) added 809 new domains this window — active registration/rotation in progress.
🔻 Takedowns - 476 domains in Rolling sqllq[.]com subdomain phishing now resolve NXDOMAIN — takedowns/expiry confirmed by double-checked DNS.
🔁 Infra rotation - Chinese com[.]cn SEO Doorway Family (007/001 games-sports) moved onto 104 new IPs, and 1gom Vietnamese Betting Network onto 40 — evasion or re-hosting behaviour; refresh blocklists.
🎭 Lure refresh - Chinese Cloaking Loader (Xitong Jiazai) deployed 1,078 new page titles — content templates are being rotated.
🎯 Campaigns worth a look
Rolling sqllq[.]com - 92,666 domains, 51% online, with 762 new domains added while 476 dropped offline in the same window: churn on a scale that defeats static blocklists.
Gambling Affiliate Registration Redirect Network (Meteverse /app/register.php) - 31,346 domains at 100% online, 170 added today. Nothing offline, nothing rotating — a stable, fully live estate.
Document-Lure Credential Phishing (DocuSign/OneDrive/Excel) - small (166 domains) but freshly registered: 2 new domains and 2 infra changes, tagged nrd_20260801/02.
📡 On the radar — emerging clusters
144 clusters are live (29 critical, 115 high) - unattributed infrastructure large enough to promote to tracked campaigns. Sharpest 24h growth:
ssl cluster — 7,218 domains, +369 in a day (01800agregados[.]com)
asn cluster — 4,423 domains, +118 (0302onabike[.]com)
tech cluster — 5,401 domains, +69 (01490242b[.]com)
See the full brief and every tracked campaign live in the Webamon console → https://t.co/XUqv7kB0X0
Full Pdf Brief is available daily from 12:00UTC on our DTB Github Repo → https://t.co/WtUOYKzPDu
The Maritime Economy Under Three Simultaneous Chokepoint Crises - published 2nd August 2026
Daily Threat Brief - Sunday, 02 August 2026
TLP:CLEAR · Estate: 75 campaigns tracked · 394,740 unique domains · 84.1% online
Automated campaign intelligence from Webamon. Here's what our sensors saw across tracked phishing and malware-delivery estates in the last 24 hours.
📊 By the numbers (last 24h)
36 campaigns with activity
2,747 new malicious domains observed
585 domains went offline (NXDOMAIN, double-checked)
210 infrastructure changes (new IPs / ASNs / cert issuers)
3,662 new page-title lures
132 emerging clusters live on the radar
🔍 What moved today
🔺 Fastest-growing — Rolling sqllq[.]com subdomain phishing added 756 new domains — active registration and rotation in progress.
🔻 Takedowns — 330 domains in the same estate now resolve NXDOMAIN, with the campaign sitting at just 51% online across 91,904 domains.
🔁 Infra rotation — Chinese https://t.co/5X6vro0Z4L SEO Doorway Family (007/001 games-sports) moved onto 69 new IPs, while 0149 Mark Six Lottery Nav Portal Network shifted onto 9 new IPs across 3 new ASNs — refresh blocklists.
🎭 Lure refresh — Chinese Cloaking Loader (Xitong Jiazai) deployed 1,110 new page titles alongside 289 new domains — content templates are being cycled.
🎯 Campaigns worth a look
Gambling Infra ASN+SSL Pair (.vip/.cc) — 607 new domains and 205 offline in a single window across an 8,279-domain estate (76% online): heavy churn on both ends.
Brazilian Fake-Content Cloaking Bet Funnel — 254 new domains and 1,045 new page-title lures, spanning Portuguese and French-language templates.
📡 On the radar — emerging clusters
132 clusters live (26 critical, 106 high) — unattributed infrastructure large enough to promote to tracked campaigns. Sharpest 24h growth:
ssl cluster — 6,611 domains, +362 in a day (007mansion[.]com)
asn cluster — 4,176 domains, +126 (0302onabike[.]com)
tech cluster — 5,386 domains, +110 (01014949[.]com)
See the full brief and every tracked campaign live in the Webamon console → https://t.co/XUqv7kB0X0
Full Pdf Brief is available daily from 12:00UTC on our DTB Github Repo → https://t.co/WtUOYKzPDu
Daily Threat Brief - Saturday, 01 August 2026
TLP:CLEAR · Estate: 75 campaigns tracked · 390,939 unique domains · 84.1% online
Automated campaign intelligence from Webamon. Here's what our sensors saw across tracked phishing and malware-delivery estates in the last 24 hours.
📊 By the numbers (last 24h)
26 campaigns with activity
2,017 new malicious domains observed
897 domains taken offline (NXDOMAIN, double-checked)
63 infrastructure changes (new IPs / ASNs / cert issuers)
2,785 new page-title lures
136 emerging clusters live on the radar
Estate liveness: online 330,185 (84.1%) · offline 62,362 (15.9%) · unchecked 2,386
🔍 What moved today
🔺 Fastest-growing — Rolling sqllq[.]com subdomain phishing added 591 new domains — active registration and rotation in progress.
🔻 Takedowns — 453 domains in the same estate now resolve NXDOMAIN — takedowns/expiry confirmed by double-checked DNS.
🔁 Infra rotation — ClickFix Fake-Cloudflare Challenge Malware Delivery moved onto 17 new IPs across 3 new ASNs — evasion or re-hosting behaviour; refresh blocklists.
🎭 Lure refresh — Chinese Cloaking Loader (Xitong Jiazai) deployed 1,112 new page titles — content templates are being cycled.
🎯 Campaigns worth a look
0149 Mark Six Lottery Nav Portal Network — 422 new domains and two new IPs (117.187.133.33, 183.60.255.95) across a 6,994-domain, 100%-online estate.
Brazilian Fake-Content Cloaking Bet Funnel — 185 new domains, 702 new lures and 9 infra changes; cloaked content swapping at pace.
Gambling Infra ASN+SSL Pair (.vip/.cc) — 97 new domains against 307 offline; churn rather than growth.
📡 On the radar — emerging clusters
136 clusters are live (25 critical, 111 high) — unattributed infrastructure large enough to promote to tracked campaigns. Sharpest 24h growth:
tech cluster — 5,322 domains, +377 in a day (01014949[.]com)
ssl cluster — 5,865 domains, +351 (007mansion[.]com)
ssl cluster — 8,221 domains, +228 (2rnkablo[.]com)
See the full brief and every tracked campaign live in the Webamon console → https://t.co/XUqv7kB0X0
Full Pdf Brief is available daily from 12:00UTC on our DTB Github Repo → https://t.co/WtUOYKzPDu
login-bankofengland[.]com - is live and phishing - registered 20260728
Dunno why put page title is hard coded in Russian
Официальный банк Великобритании / Official Bank of Great Britain
Pivoting on the IP shows more being hosted on this server
bnk-england[.]com registered yesterday and is live
Pivoting on the ASN fingerprint from the scan gives 116x unique domains all fraud in nature
The links fingerprint surfaces the 2x Bank of England incidents above and good for tracking
G'Luck
https://t.co/SUE0SRcAII