New TLDs Like .shop, .top And .xyz Attracting Phishers

New TLDs Like .shop, .top And .xyz Attracting Phishers

A significant surge in phishing attacks has been unveiled by a recent study conducted by Interisle Consulting, with a nearly 40% increase in the year ending August 2024.

The research highlights that much of this growth is concentrated in a small number of new generic top-level domains (gTLDs), such as .shop, .top, and .xyz.

These new gTLDs, which command just 11% of the market for new domains, accounted for approximately 37% of cybercrime domains reported between September 2023 and August 2024.

This disproportionate representation in cybercrime activities is attributed to the attractive features these domains offer to scammers, including rock-bottom prices and minimal registration requirements.

Security analysts at KrebsonSecurity observed that the spammers and cybercriminals are gravitating towards these new gTLDs due to their low-cost or free registration options and the lack of stringent account or identity verification processes.

Leveraging 2024 MITRE ATT&CK Results for SME & MSP Cybersecurity Leaders – Attend Free Webinar

Technical Analysis

It’s been found that among the gTLDs with the highest cybercrime domain scores, nine offered registration fees under $1, and nearly two dozen had fees below $2.00. In contrast, the most affordable .com domain was priced at $5.91.

While traditional domains like .com and .net still make up about half of all registered domains and account for just over 40% of cybercrime domains, the rapid rise of new gTLDs in phishing activities is concerning.

Top 5 new gTLDs, ranked by cybercrime domains reported (Source – KrebsonSecurity)

The Internet Corporation for Assigned Names and Numbers (ICANN), which oversees the domain name industry, is paradoxically moving forward with plans to introduce even more gTLDs, with applications for new ones expected to open in 2026.

John Levine, president of the Coalition Against Unsolicited Commercial Email (CAUCE), warns that adding more TLDs without stricter registration policies will likely expand opportunities for cybercriminals.

He criticizes ICANN’s approach, suggesting that the organization is behaving more like a domain speculator trade association than a neutral nonprofit regulator.

The rapid increase of phishing domains within new gTLDs is eroding user trust and posing significant security risks.

To combat this growing threat, experts recommend implementing digital identity verification programs, deploying automated systems to screen for suspicious registration patterns, and creating “Trusted Reporter” programs to facilitate swift suspension of identified phishing resources.

The upcoming round of new gTLDs in 2026 will likely reignite debates on how to encourage a more diverse online ecosystem while safeguarding against the misuse of these domains by malicious actors.

Analyse Advanced Malware & Phishing Analysis With ANY.RUN Black Friday Deals : Get up to 3 Free Licenses.

The post New TLDs Like .shop, .top And .xyz Attracting Phishers appeared first on Cyber Security News.

Tags

About Author

Chad Barr

Chad Barr is a visionary and executive leader, blending over two decades of expertise with a unique ability to demystify complex technical concepts. As a cybersecurity leader, prolific author, and director at AccessIT Group, Chad has empowered organizations across diverse industries to build resilient security frameworks. His engaging writing, speaking engagements, and thought leadership inspire proactive cybersecurity practices, making him a trusted voice in the ever-evolving digital landscape.

My Books

Cybersecurity News

  • Major Vulnerabilities Patched in SonicWall, Palo Alto Expedition, and Aviatrix Controllers
    by [email protected] (The Hacker News) on January 9, 2025 at 5:29 pm

    Palo Alto Networks has released software patches to address several security flaws in its Expedition migration tool, including a high-severity bug that an authenticated attacker could exploit to access sensitive data. “Multiple vulnerabilities in the Palo Alto Networks Expedition migration tool enable an attacker to read Expedition database contents and arbitrary files, as well as create and

  • 5 Benefits Of A Malware Sandbox For Business Security
    by Balaji N on January 9, 2025 at 5:27 pm

    Imagine an employee receiving an email that looks completely legitimate, maybe it’s a fake invoice or a shipping update. They click on the attachment, and just like that, your network could be infected with ransomware, sensitive customer data stolen, or your entire system brought to a halt. It’s a nightmare scenario, but one that happens The post 5 Benefits Of A Malware Sandbox For Business Security appeared first on Cyber Security News.

  • Rapid Cyber Incident Response: Why Speed, Quality, and the Right Tools Matter
    by Kaaviya Ragupathy on January 9, 2025 at 4:48 pm

    As you probably know by now, it doesn’t really matter how big in size your business is, you’re going to be up against the risk of cyberattacks in some form or another. These can range in scope and scale with threats such as ransomware and phishing campaigns right through insider threats and advanced persistent attacks. The post Rapid Cyber Incident Response: Why Speed, Quality, and the Right Tools Matter appeared first on Cyber Security News.

  • Criminal IP Launches Real-Time Phishing Detection Tool on Microsoft Marketplace
    by Kaaviya Ragupathy on January 9, 2025 at 4:32 pm

    Criminal IP, a globally recognized Cyber Threat Intelligence (CTI) solution by AI SPERA, has launched its Criminal IP Malicious Link Detector add-in on the Microsoft Marketplace. This cutting-edge tool provides real-time phishing email detection and URL blocking for Microsoft Outlook, adding an essential layer of email security in the face of increasing cyber threats. Generative AI advancements The post Criminal IP Launches Real-Time Phishing Detection Tool on Microsoft Marketplace appeared first on Cyber Security News.

  • New AI Challenges Will Test CISOs & Their Teams in 2025
    by Josh Lemos on January 9, 2025 at 3:00 pm

    CISOs need to recognize the new threats AI can present — while also embracing AI-powered solutions to stay ahead of those threats.

Categories