Gmail phishing and impersonation - 2 domains observed
MalwareAnalyzer by Cyble has observed 2 distinct domains impersonating Gmail across 2 URL scans. 2 of them carry a malicious or suspicious verdict. None of these domains belong to Gmail; they are sites impersonating it, detected by comparing a page's claimed identity against evidence of who actually operates it.
Lookalike domains impersonating Gmail
The domain itself is the deception on these: a homograph, typosquat or a Gmail brand token built into the name, on infrastructure Gmail does not operate.
| Domain | Worst verdict | Evidence | Scans | First seen | Last seen | Kit |
|---|---|---|---|---|---|---|
| cpanel.gmailvip.site | malicious | brand token in domain | 1 | 2026-08-20 | 2026-08-20 | |
| www.orgmailbridge.com | suspicious | brand token in domain | 1 | 2026-08-20 | 2026-08-20 |
Malware observed hosted on or communicating with these domains
None yet. That is the honest state, not a gap in the page: credential-harvesting phishing mostly collects logins rather than serving executables, so a domain can be actively hostile with no malware ever hosted on it. This section fills in only when a sample's runtime traffic, extracted configuration or download provenance evidences one of these domains - a hostname merely appearing inside a file's bytes is listed separately below and never counted here.
How impersonation is detected
A page's CLAIMED identity (its title, og:site_name, favicon and phishing-kit
fingerprint) is compared against evidence of who actually operates it: the certificate subject
organisation, the RDAP registrant and the announcing network. A free domain-validated certificate
asserts nothing about ownership, and that asymmetry is itself the signal. A page on Gmail's
own apex with a matching certificate organisation is treated as the real property, not an
impersonation, which is why this list does not include Gmail's own sites.
These are point-in-time observations. A domain listed here may since have been taken down, and absence from this list is not evidence a domain is safe.
Questions about Gmail phishing
- How many domains are impersonating Gmail?
- 2 distinct domains, seen across 2 public URL scans, of which 2 currently carry a malicious or suspicious verdict.
- How can I tell a fake Gmail site from the real one?
- Compare what the page CLAIMS against who demonstrably operates it: the certificate subject organisation, the domain's registrant and the network announcing its address. A free domain-validated certificate proves control of the name and nothing about ownership, and that asymmetry is the signal - a real Gmail property does not need to borrow the brand's look.
- Is a domain safe if it is not listed here?
- No. This lists what MalwareAnalyzer has scanned, not the whole internet, and a domain taken down yesterday still appears. Absence is not evidence of safety - scan the specific URL.
All brands under attack · Scan a URL · Latest analyzed threats · How URL scanning works