Brands under phishing attack - 6 brands, 24 impersonating domains observed
MalwareAnalyzer by Cyble has observed 24 distinct domains impersonating 6 brands across public URL scans. Each brand page lists the impersonating domains with verdicts, phishing kits and sighting windows, plus any malware evidenced against those domains. The domains impersonate these brands; none belong to them. Counts describe this platform's corpus, not the internet.
| Brand | Impersonating domains | Flagged | Scans | Kits | Last observed |
|---|---|---|---|---|---|
| Binance | 11 | 11 | 13 | binance / crypto exchange kit | 2026-08-23 |
| 4 | 4 | 7 | meta / facebook login kit | 2026-08-20 | |
| 3 | 3 | 3 | blackeye, google account clone, meta / facebook login kit | 2026-08-21 | |
| Paypal | 2 | 2 | 11 | generic paypal harvester | 2026-08-23 |
| Gmail | 2 | 2 | 2 | 2026-08-20 | |
| Microsoft | 2 | 2 | 2 | generic office365 harvester, u-admin (uadmin) | 2026-08-22 |
Flagged counts domains whose scans produced a malicious or suspicious verdict. These are point-in-time observations from URL scans; a domain listed on a brand page may since have been taken down, and absence is not evidence of safety.
Questions about brand impersonation
- Which brand is impersonated the most?
- In this corpus, Binance: 11 distinct impersonating domains across 13 scans. That measures what this platform scanned, not global prevalence.
- Does a brand being listed here mean it was breached?
- No. These are third-party sites pretending to BE the brand to steal credentials or payments. The brand is the victim of the impersonation, and none of the listed domains belong to it.
- Why is a well-known brand missing from this list?
- Detection is bounded by the tracked-brand catalog and by what has been scanned, and a hub only exists once two or more distinct impersonating domains are observed. An absent brand is untracked, not unattacked - absence is never evidence of safety.
- How is impersonation decided?
- A page must CLAIM the brand identity (title, kit fingerprint or a look-alike domain) in a credential or checkout context, while failing to prove it operates for the brand (certificate organisation, official apex). A page that merely mentions a brand is not counted.
Scan a URL · How URL scanning works · Latest analyzed threats