New Report Exposes Top TLDs and Registrars Hosting Phishing Sites

Phishing Landscape 2024: Cheap Domains and Emerging Threats

The latest research reveals a significant shift in phishing tactics, with cybercriminals increasingly targeting inexpensive domains to conduct their malicious activities. Interisle’s “Phishing Landscape 2024” report provides an in-depth analysis of the top-level domains (TLDs) and registrars most frequently exploited in phishing attacks.

This comprehensive study examined approximately 1.9 million phishing attacks occurring between May 2023 and April 2024, offering critical insights into the evolving strategies of phishers.

The End of an Era: Freenom’s Impact on the Phishing Ecosystem

The timeframe of this research is particularly noteworthy, as it began shortly after Freenom, a domain registrar known for offering free country code domain registrations, ceased its operations. Freenom had long been a favorite among phishers due to its accessibility and lack of stringent verification processes. Its closure forced cybercriminals to seek alternative avenues for registering domains, leading to a notable shift in their preferred TLDs and registration methods.

The Rise of Cheap TLDs and Free Subdomains

Interisle’s report highlights a significant surge in the use of cheap new TLDs and free subdomains by phishers. The study found that a staggering 42% of all domains reported for phishing were registered in new TLDs, a substantial increase from the 25% reported in the previous year. This demonstrates a clear preference for TLDs that offer low-cost registrations and minimal oversight.

Furthermore, the use of subdomains, such as those offered by Blogspot and similar platforms, also experienced a significant uptick. The report documented over 450,000 reported subdomain names used in phishing attacks, representing 24% of all phishing incidents. This indicates that phishers are increasingly leveraging the legitimacy and established reputation of these platforms to disguise their malicious activities.

.com: A Giant Among Giants

While the .com TLD had the highest absolute number of phishing domains reported, its overall percentage of abuse remained relatively low when considering the sheer size of the .com zone, which encompasses over 150 million registered domains. This suggests that while .com is a popular target due to its widespread recognition, the proportion of malicious domains within the .com namespace is relatively small compared to other TLDs.

.top: A Hotspot for Phishing Activity

The .top TLD was specifically singled out in the report as a significant source of phishing activity. With over 100,000 phishing domains reported on a domain base of under 3 million, .top exhibits a disproportionately high rate of abuse. The situation surrounding .top has become so concerning that ICANN (Internet Corporation for Assigned Names and Numbers) recently issued a breach notice to the company overseeing the .top domain registry.

The Most Phished TLDs: A Ranking of Risk

Interisle’s analysis extended beyond simply identifying the most frequently used TLDs for phishing. The report also calculated the percentage of domains within each TLD that were used for malicious purposes. This metric provides a more accurate representation of the risk associated with specific TLDs.

The top five TLDs with the highest percentage of domains used for phishing were:

  1. .lol
  2. .bond
  3. .support
  4. .top
  5. .sbs

The Price of Vulnerability: The Link Between Cost and Abuse

A common thread connecting these TLDs is their low pricing. As illustrated in Interisle’s report, the TLDs with the highest phishing rates are typically available for significantly less than more established and reputable TLDs.

Chart showing list of most-phished top level domains compared to price
Source: Interisle Phishing Landscape 2024

The report revealed that all but three of the 35 generic TLDs (gTLDs) with the highest phishing rates were available for under $5 per year. Furthermore, ten of these TLDs could be registered for under $1, and 27 were available for less than $2. This stark correlation between low cost and high abuse underscores the importance of affordable domain security measures.

The Reputational Risk for TLD Operators

Interisle’s report emphasizes that high rates of phishing can have detrimental consequences for TLD operators, stating:

High scores are a liability for registry operators. High yearly phishing domain scores erode the reputation of a TLD. Risk-averse organizations have resorted to blocklisting entire TLDs, and some blocklist providers and security companies assign increased risk scores to TLDs with poor reputations.

In essence, TLDs with a high prevalence of phishing activity risk being blacklisted by security companies and organizations, which can significantly impact their legitimacy and trustworthiness. This can lead to decreased adoption and ultimately harm the long-term viability of the TLD.

Registrar Accountability: Identifying Sources of Abuse

In addition to analyzing TLDs, the report also identified domain name registrars with a high rate of abuse. This is crucial because registrars play a significant role in verifying the legitimacy of domain registrations and preventing malicious actors from acquiring domains for phishing purposes.

The report highlighted NiceNIC as a particularly egregious offender, with an astonishing 45% of its 100,000 gTLD domain names under management being reported for phishing. Other top registrars with high abuse rates included URL Solutions, Aceville, WebNic, and OwnRegistrar.

Combating Phishing: A Collective Responsibility

The findings of the “Phishing Landscape 2024” report underscore the urgent need for a collaborative effort to combat phishing. This includes:

  • Increased vigilance from TLD operators: Implementing stricter registration policies, monitoring for suspicious activity, and taking swift action against malicious domains.
  • Enhanced accountability for registrars: Improving verification processes, collaborating with security organizations to identify and suspend phishing domains, and implementing anti-abuse measures.
  • Improved user awareness: Educating internet users about the dangers of phishing and how to identify and avoid falling victim to these attacks.
  • Technological advancements: Developing and deploying advanced technologies, such as machine learning and artificial intelligence, to detect and prevent phishing attacks in real-time.

By working together, stakeholders can create a safer online environment and mitigate the ever-growing threat of phishing.

The full report is available here.