<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Interisle Insights]]></title><description><![CDATA[Interisle's partners are experienced practitioners with extensive track records in cybersecurity and cybercrime research, Internet infrastructure and technology, mobility and wireless, policy and governance, patents, and standards development. ]]></description><link>https://interisle.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!2WC-!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Finterisle.substack.com%2Fimg%2Fsubstack.png</url><title>Interisle Insights</title><link>https://interisle.substack.com</link></image><generator>Substack</generator><lastBuildDate>Mon, 29 Jun 2026 09:38:32 GMT</lastBuildDate><atom:link href="https://interisle.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Interisle Consulting Group]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[interisle@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[interisle@substack.com]]></itunes:email><itunes:name><![CDATA[Interisle Consulting Group]]></itunes:name></itunes:owner><itunes:author><![CDATA[Interisle Consulting Group]]></itunes:author><googleplay:owner><![CDATA[interisle@substack.com]]></googleplay:owner><googleplay:email><![CDATA[interisle@substack.com]]></googleplay:email><googleplay:author><![CDATA[Interisle Consulting Group]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Phishing Landscape 2026 – Six Years of Phishing, Six Years of Growth]]></title><description><![CDATA[Colin Strutt]]></description><link>https://interisle.substack.com/p/phishing-landscape-2026-six-years</link><guid isPermaLink="false">https://interisle.substack.com/p/phishing-landscape-2026-six-years</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Thu, 25 Jun 2026 13:09:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-0Ab!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27431472-9063-404a-bd73-80708ea60381_1062x450.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In previous years, Interisle published comprehensive annual reports on phishing. This year, we&#8217;re taking a different approach and showing just the significant results of our analysis as a series of posts. Our fall study will include additional insights, findings and recommendations.</p><p>You can refer to previous full reports (such as <a href="https://interisle.net/s/phishinglandscape2025.pdf">Phishing Landscape 2025</a>) for more details about our methodology and definitions of terms.</p><p>In the <a href="https://interisle.substack.com/p/phishing-landscape-2026-summary-findings">previous post</a>, we looked at the key results and compared them to those of the previous year.</p><p>In this post we look at the growth of phishing each quarter since our first (2020) Phishing Landscape report &#8211; both the number of phishing attacks and the number of domains used for phishing.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-0Ab!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27431472-9063-404a-bd73-80708ea60381_1062x450.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-0Ab!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27431472-9063-404a-bd73-80708ea60381_1062x450.png 424w, https://substackcdn.com/image/fetch/$s_!-0Ab!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27431472-9063-404a-bd73-80708ea60381_1062x450.png 848w, https://substackcdn.com/image/fetch/$s_!-0Ab!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27431472-9063-404a-bd73-80708ea60381_1062x450.png 1272w, https://substackcdn.com/image/fetch/$s_!-0Ab!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27431472-9063-404a-bd73-80708ea60381_1062x450.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-0Ab!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27431472-9063-404a-bd73-80708ea60381_1062x450.png" width="1062" height="450" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/27431472-9063-404a-bd73-80708ea60381_1062x450.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:450,&quot;width&quot;:1062,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:120541,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/203546656?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27431472-9063-404a-bd73-80708ea60381_1062x450.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-0Ab!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27431472-9063-404a-bd73-80708ea60381_1062x450.png 424w, https://substackcdn.com/image/fetch/$s_!-0Ab!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27431472-9063-404a-bd73-80708ea60381_1062x450.png 848w, https://substackcdn.com/image/fetch/$s_!-0Ab!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27431472-9063-404a-bd73-80708ea60381_1062x450.png 1272w, https://substackcdn.com/image/fetch/$s_!-0Ab!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27431472-9063-404a-bd73-80708ea60381_1062x450.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cWFq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffffec6-957c-49f0-9b9a-d9f8a8b98a0a_976x652.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cWFq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffffec6-957c-49f0-9b9a-d9f8a8b98a0a_976x652.png 424w, https://substackcdn.com/image/fetch/$s_!cWFq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffffec6-957c-49f0-9b9a-d9f8a8b98a0a_976x652.png 848w, https://substackcdn.com/image/fetch/$s_!cWFq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffffec6-957c-49f0-9b9a-d9f8a8b98a0a_976x652.png 1272w, https://substackcdn.com/image/fetch/$s_!cWFq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffffec6-957c-49f0-9b9a-d9f8a8b98a0a_976x652.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cWFq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffffec6-957c-49f0-9b9a-d9f8a8b98a0a_976x652.png" width="976" height="652" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6ffffec6-957c-49f0-9b9a-d9f8a8b98a0a_976x652.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:652,&quot;width&quot;:976,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:943806,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/203546656?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffffec6-957c-49f0-9b9a-d9f8a8b98a0a_976x652.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cWFq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffffec6-957c-49f0-9b9a-d9f8a8b98a0a_976x652.png 424w, https://substackcdn.com/image/fetch/$s_!cWFq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffffec6-957c-49f0-9b9a-d9f8a8b98a0a_976x652.png 848w, https://substackcdn.com/image/fetch/$s_!cWFq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffffec6-957c-49f0-9b9a-d9f8a8b98a0a_976x652.png 1272w, https://substackcdn.com/image/fetch/$s_!cWFq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ffffec6-957c-49f0-9b9a-d9f8a8b98a0a_976x652.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">AI generated Image</figcaption></figure></div><div class="callout-block" data-callout="true"><p style="text-align: center;"><span data-color="#0b5394" style="color: rgb(11, 83, 148);">It is tempting to only look at the drop off from the peak over the last three quarters and conclude that phishing attacks are in decline. But from measurements we&#8217;ve compiled since 2020, you can see a that reports of phishing attacks numbers &#8211; as well as the numbers of domain names used for phishing &#8211; exhibit a distinct and repeatable &#8220;peaks and valleys&#8221; behavior, but over time, there has been a 6-fold growth in both measurements.</span></p></div><p>In the next post in this series, we&#8217;ll look at how the different types of TLDs are affected by phishing.</p>]]></content:encoded></item><item><title><![CDATA[Phishing Landscape 2026 – Summary Findings]]></title><description><![CDATA[Colin Strutt]]></description><link>https://interisle.substack.com/p/phishing-landscape-2026-summary-findings</link><guid isPermaLink="false">https://interisle.substack.com/p/phishing-landscape-2026-summary-findings</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Wed, 24 Jun 2026 13:04:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!okI4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b759ba1-6c66-4011-a507-6ec48013be42_711x662.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In previous years, Interisle published comprehensive annual reports on phishing. This year, we&#8217;re taking a different approach and showing just the significant results of our analysis as a series of posts. Our fall study will include additional insights, findings and recommendations.</p><p>In this first post in the series, we look at the key results and compare them to those of the previous year.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5lCp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb06f4702-5d10-4be5-b8d5-5994f9922c0e_832x537.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5lCp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb06f4702-5d10-4be5-b8d5-5994f9922c0e_832x537.png 424w, https://substackcdn.com/image/fetch/$s_!5lCp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb06f4702-5d10-4be5-b8d5-5994f9922c0e_832x537.png 848w, https://substackcdn.com/image/fetch/$s_!5lCp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb06f4702-5d10-4be5-b8d5-5994f9922c0e_832x537.png 1272w, https://substackcdn.com/image/fetch/$s_!5lCp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb06f4702-5d10-4be5-b8d5-5994f9922c0e_832x537.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5lCp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb06f4702-5d10-4be5-b8d5-5994f9922c0e_832x537.png" width="832" height="537" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b06f4702-5d10-4be5-b8d5-5994f9922c0e_832x537.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:537,&quot;width&quot;:832,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:79346,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/203387464?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb06f4702-5d10-4be5-b8d5-5994f9922c0e_832x537.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5lCp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb06f4702-5d10-4be5-b8d5-5994f9922c0e_832x537.png 424w, https://substackcdn.com/image/fetch/$s_!5lCp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb06f4702-5d10-4be5-b8d5-5994f9922c0e_832x537.png 848w, https://substackcdn.com/image/fetch/$s_!5lCp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb06f4702-5d10-4be5-b8d5-5994f9922c0e_832x537.png 1272w, https://substackcdn.com/image/fetch/$s_!5lCp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb06f4702-5d10-4be5-b8d5-5994f9922c0e_832x537.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!okI4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b759ba1-6c66-4011-a507-6ec48013be42_711x662.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!okI4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b759ba1-6c66-4011-a507-6ec48013be42_711x662.png 424w, https://substackcdn.com/image/fetch/$s_!okI4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b759ba1-6c66-4011-a507-6ec48013be42_711x662.png 848w, https://substackcdn.com/image/fetch/$s_!okI4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b759ba1-6c66-4011-a507-6ec48013be42_711x662.png 1272w, https://substackcdn.com/image/fetch/$s_!okI4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b759ba1-6c66-4011-a507-6ec48013be42_711x662.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!okI4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b759ba1-6c66-4011-a507-6ec48013be42_711x662.png" width="711" height="662" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1b759ba1-6c66-4011-a507-6ec48013be42_711x662.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:662,&quot;width&quot;:711,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1052441,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/203387464?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b759ba1-6c66-4011-a507-6ec48013be42_711x662.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!okI4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b759ba1-6c66-4011-a507-6ec48013be42_711x662.png 424w, https://substackcdn.com/image/fetch/$s_!okI4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b759ba1-6c66-4011-a507-6ec48013be42_711x662.png 848w, https://substackcdn.com/image/fetch/$s_!okI4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b759ba1-6c66-4011-a507-6ec48013be42_711x662.png 1272w, https://substackcdn.com/image/fetch/$s_!okI4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1b759ba1-6c66-4011-a507-6ec48013be42_711x662.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Image created by Meta AI</figcaption></figure></div><div class="callout-block" data-callout="true"><h3 style="text-align: center;">Insufficient effort is being applied across the industry to reduce phishing; instead, <br>phishing continues to grow at an alarming rate.</h3></div><p>Refer to previous full reports (such as <a href="https://interisle.net/s/phishinglandscape2025.pdf">Phishing Landscape 2025</a>) for more details about our methodology and definitions of terms.</p>]]></content:encoded></item><item><title><![CDATA[Domain Name Email Verification is Contact Validation, not Authentication ]]></title><description><![CDATA[Dave Piscitello]]></description><link>https://interisle.substack.com/p/domain-name-email-verification-is</link><guid isPermaLink="false">https://interisle.substack.com/p/domain-name-email-verification-is</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Tue, 23 Jun 2026 13:03:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!47uF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0c6182-4488-42cd-8c0f-a6fc6d7f3b5d_1408x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>To comply with ICANN and European Union NIS2 requirements, gTLD domain registrars must verify registrant email addresses. This <a href="https://www.icann.org/resources/pages/contact-verification-2013-05-03-en">owner email verification</a> process was a topic of considerable discussion prior to and during the recent ICANN meeting. Virtually every accredited registrar has a FAQ page explaining this process, and nearly every registrar has an opinion of its utility or futility.</p><p>Certain registrars want the policy left as it is. <a href="https://opensrs.com/blog/does-whois-verification-timing-affect-dns-abuse-rates/">Others</a> want the 15 days shortened and used as an anti-abuse measure. Yet others question whether tightening email verification would reduce DNS abuse. Some community members propose that registrars should only be allowed to activate domains once email verification is complete. (I can only imagine the registrar reaction&#8230;)</p><p>ICANN is caught in a &#8220;failing to see the forest for the trees&#8221; situation: neither the findings nor the proposals address the real registrant verification issue.</p><h3>Your verification succeeded but it didn&#8217;t prove identity</h3><p><strong>Verification is a method for establishing authenticity or integrity of a (user) identity</strong>, and in the domain registration context, the identity of a registrant. As formulated in the article, the question under debate assumes that email is a method that authenticates a registrant.</p><p><strong>An email address verificaton is not proof of identity:</strong> <strong>it&#8217;s a confirmation of control of an email inbox</strong>. It only proves that someone (or automation) has access to that inbox <em>at that moment</em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!47uF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0c6182-4488-42cd-8c0f-a6fc6d7f3b5d_1408x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!47uF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0c6182-4488-42cd-8c0f-a6fc6d7f3b5d_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!47uF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0c6182-4488-42cd-8c0f-a6fc6d7f3b5d_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!47uF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0c6182-4488-42cd-8c0f-a6fc6d7f3b5d_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!47uF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0c6182-4488-42cd-8c0f-a6fc6d7f3b5d_1408x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!47uF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0c6182-4488-42cd-8c0f-a6fc6d7f3b5d_1408x768.png" width="1408" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/df0c6182-4488-42cd-8c0f-a6fc6d7f3b5d_1408x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2071241,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/202868843?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0c6182-4488-42cd-8c0f-a6fc6d7f3b5d_1408x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!47uF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0c6182-4488-42cd-8c0f-a6fc6d7f3b5d_1408x768.png 424w, https://substackcdn.com/image/fetch/$s_!47uF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0c6182-4488-42cd-8c0f-a6fc6d7f3b5d_1408x768.png 848w, https://substackcdn.com/image/fetch/$s_!47uF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0c6182-4488-42cd-8c0f-a6fc6d7f3b5d_1408x768.png 1272w, https://substackcdn.com/image/fetch/$s_!47uF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdf0c6182-4488-42cd-8c0f-a6fc6d7f3b5d_1408x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Image Created by Gemini</figcaption></figure></div><div class="callout-block" data-callout="true"><p style="text-align: center;"><em>You&#8217;ve knocked on the door. Someone answers, &#8220;Occupied!&#8221; <br>You now know the room is occupied. </em></p><p style="text-align: center;"><em>But you don&#8217;t know who the occupant is, <br>when they first occupied the room, or <br>whether their occupancy is permanent or transient.</em></p></div><h4><strong>Email verification: contact validation, nothing more</strong> </h4><p>Email verification can confirm that you reached out to a party or automation that controls an inbox and you received a response. That&#8217;s &#8220;contact-ability&#8221;. </p><p>Contact-ability is arguably the lowest bar you can set for any form of confirmation. It&#8217;s commonly used in &#8220;Email Before Download&#8221; arrangements to limit or track access to published content. It&#8217;s cheap to implement, scales well, but no cybersecurity professional would consider this an effective authentication method.</p><h3>The limitations of email <em>address </em>verification are numerous</h3><p><strong>An email address cannot be undeniably associated with a natural person (or organization).</strong> There is an exception case - when cryptographic signatures provide non-repudiable proof of origin - but the general public and domain registrars do not typically use secure email (e.g., S/MIME, PGP).</p><p><strong>No authority or government has established proof of identity criteria that must be met for its issuance of an email address. </strong>Anyone can create one or dozens of email addresses, free of charge. You don&#8217;t need proof of age, residence (nexus), incorporation, business presence or any legitimate evidence that the registrant is who they say they are.</p><p><strong>Temporary, disposable, or alias emails erode what little verification value one might attribute to an email address. </strong>Many email services offer temporary or disposable email addresses. These are purposely used for anonymity or deception, or as part of legitimate criminal investigations (undercover work).</p><h3>What cybersecurity professionals and investigators say about email verification</h3><p>We asked prominent criminal investigators to share how they use email addresses and unsurprisingly, they exploit the ability to create an unverifiable but acceptable persona. One investigator shared that:</p><blockquote><p>&#8220;As part of our research, I register accounts on hundreds of crypto investment scam websites a week. I own 20-ish domains and have a catch-all on all of them so that any email on any of the domains gets forwarded to my single webmail account that I share with my analysts&#8230; I have used thousands or possibly tens of thousands of emails to &#8220;Validate&#8221; myself on a huge variety of accounts.&#8221;</p></blockquote><p>A cybersecurity colleague spoke to us about an investigation performed for a client into the use of free or temporary email addresses as usernames for accounts that were subsequently used for malicious activities (phishing, service misuse):</p><blockquote><p>&#8220;We helped [them] map out a few hundred &#8216;free mail&#8217; and &#8216;tempmail&#8217; services that worked just like that. They found tens of thousands of accounts that were registered and &#8216;validated&#8217; using emails of that type, and various researchers have collected them into &#8220;block lists&#8221; (my favorite currently has 6,933 domains that are known to be (or to have been) temporary email domains. Sadly, @gmail.com is just as easy based on the proliferation of captcha solving services, both AI-based and human-based.&#8220;</p></blockquote><p>The last observation is significant.</p><p><strong>Automation or AI can respond to verification emails</strong>. A script or an AI agent can search for confirmation emails (by origin, for example). By coding or instructing the AI to parse the content as a human recipient would, they can generate the necessary response.</p><p>Finally, <strong>an email confirmation is an &#8220;instance in time&#8221; response</strong>. You cannot know if the party that uses an email address today is the same party that used that email account at the time when the registration account was created (or any time between). Cybercriminals have <a href="https://www.spamhaus.org/resource-hub/hijacking/expired-and-exploited-reviving-a-30-year-old-legacy-domain-for-hijacking/">hijacked IP address blocks</a> by re-registering expired domain names to create email addresses used as contact information for delegated IP address blocks. Attackers can also identify a high-value domain name, look up the historical registrant email address, register the domain of that email address, and attempt a password reset to hijack a domain registration account.</p><h2>Takeaway</h2><p>ICANN shouldn&#8217;t burden an already exhaustingly long policy development process with debates over the existing and flawed verification method, but instead should concentrate attention on a uniform and effective registrant authentication method. Quoting one of our frustrated public safety community members and first responder:</p><blockquote><p>&#8220;Investigators and criminals have known that email verification is a farce for years &#8230; do some honest verification work&#8221;.</p></blockquote>]]></content:encoded></item><item><title><![CDATA[Pig Butchering Part 4: Why Are Romance Scams So Effective?]]></title><description><![CDATA[Matt Piscitello]]></description><link>https://interisle.substack.com/p/pig-butchering-part-4-why-are-romance</link><guid isPermaLink="false">https://interisle.substack.com/p/pig-butchering-part-4-why-are-romance</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Thu, 18 Jun 2026 15:18:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!MFHn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfe6cd5a-376c-4bd3-9d95-e2176154f365_586x320.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Under normal social circumstances, building a relationship is an emotional investment and persistent commitment. They can often fail to work out for reasons beyond our control. Such investments clash with what we know about criminal activity, which often seeks the highest payout with the lowest effort and the least amount of risk. So why are romance scams so effective?</p><h4><strong>What contributes to successful romance scams?</strong></h4><p>As described earlier in this series, &#8220;<a href="https://www.icba.org/w/pig-butchering-crypto-scams-a-growing-concern">pig-butchering</a>&#8221; (from the Chinese &#8220;<em>sha zhu pan</em>&#8221;) involves contacting a potential victim through an engineered chance encounter and developing a long-term emotional bond with them. Once scammers are confident of this bond, they convince the victim to invest in a cryptocurrency, which is typically a fake crypto platform. They hook the victim with an initial profitable investment, then encourage the victim to invest again and again. The scammers abandon the victim and shut down their fake crypto exchange once the victim indicates that they have nothing more to invest.</p><h4>How are these scams both successful and scalable?</h4><p>The answer partly involves classic <a href="https://www.cisa.gov/news-events/news/avoiding-social-engineering-and-phishing-attacks">social engineering</a>, but another significant part involves the way people communicate in the modern age. Digital communications change the nature of relationship building significantly, offering a path through physical, social, and psychological barriers. <a href="https://pubmed.ncbi.nlm.nih.gov/27191792/">Online relationship building</a> promises the user a preferred amount of anonymity, which reduces the fear of judgment or rejection. They also allow users to choose and modify their profile to match the appearance they wish to display. They&#8217;re also advantageous in the sense that they create an avenue to cultivate relationships for people with little free time.</p><p>Additionally, online romance scams have spread rapidly alongside the development of social media and dating apps. These apps offer the opportunity to find your <a href="https://clinical-practice-and-epidemiology-in-mental-health.com/VOLUME/16/PAGE/24/FULLTEXT/">&#8220;perfect match&#8221;</a> that are backed by scientific algorithms and match users based on common values, interests, geography, and other preferences.</p><p>According to a 2024 <a href="https://www.statista.com/statistics/1481218/us-online-dating-service-users-scams-by-gender/#:~:text=According%20to%20a%202024%20survey%20conducted%20in%20the,women%20who%20used%20such%20services%20reported%20the%20same.">survey</a> conducted in the U.S., 53% of male online dating service users reported being a victim of a romance scam. Nearly the same percentage of women (47%) identified as victims. These numbers will only continue to evolve alongside social media and dating apps unless major steps are taken to first educate the public on these campaigns, create more effective and expedient avenues for remediation, and most importantly, stop the crime at its source.</p><p>While these are revolutionary and sometimes positive changes to the dating world, they also present a new pathway for criminality. Scammers lure in victims with three dynamics that are extremely attractive for the target.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MFHn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfe6cd5a-376c-4bd3-9d95-e2176154f365_586x320.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MFHn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfe6cd5a-376c-4bd3-9d95-e2176154f365_586x320.png 424w, https://substackcdn.com/image/fetch/$s_!MFHn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfe6cd5a-376c-4bd3-9d95-e2176154f365_586x320.png 848w, https://substackcdn.com/image/fetch/$s_!MFHn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfe6cd5a-376c-4bd3-9d95-e2176154f365_586x320.png 1272w, https://substackcdn.com/image/fetch/$s_!MFHn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfe6cd5a-376c-4bd3-9d95-e2176154f365_586x320.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MFHn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfe6cd5a-376c-4bd3-9d95-e2176154f365_586x320.png" width="586" height="320" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cfe6cd5a-376c-4bd3-9d95-e2176154f365_586x320.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:320,&quot;width&quot;:586,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:385769,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/202503903?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfe6cd5a-376c-4bd3-9d95-e2176154f365_586x320.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MFHn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfe6cd5a-376c-4bd3-9d95-e2176154f365_586x320.png 424w, https://substackcdn.com/image/fetch/$s_!MFHn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfe6cd5a-376c-4bd3-9d95-e2176154f365_586x320.png 848w, https://substackcdn.com/image/fetch/$s_!MFHn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfe6cd5a-376c-4bd3-9d95-e2176154f365_586x320.png 1272w, https://substackcdn.com/image/fetch/$s_!MFHn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcfe6cd5a-376c-4bd3-9d95-e2176154f365_586x320.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><strong>Image Created with Gemini</strong></figcaption></figure></div><p>Through fictitious profiles, scammers can develop relationships with their victims over the course of 6-8 months, build a deep emotional bond, and extort money through subtle manipulation. As we touched on in part three of our series, the ideal victim is one who both craves emotional connection and is thus more vulnerable to persuasion. In this state, their judgment is impaired by the notion that someone is attracted to them and craves their company.</p><p>The prevailing attitude surrounding scams of this nature is that they are easily avoided through common sense. But the reality is that these schemes are built upon subversion and deception, along with appropriately vulnerable targets.</p><p>Scammers rely on long-term psychological manipulation to build false emotional trust with victims as their first step. The scheme involves building unearned trust over weeks and months of casual, seemingly harmless conversations that create the illusion of daily life, hobbies, and family to establish themselves as friends or romantic partners to victims. They fabricate identities using attractive photos displaying luxurious lifestyles in order to appear successful, stable, and, most importantly, <a href="https://dfpi.ca.gov/news/insights/pig-butchering-how-to-spot-and-report-the-scam/">legitimate</a>.</p><p>Scammers also benefit from the relatively nascent state of cryptocurrency and are able to exploit the lack of familiarity that their targets have with it. This is important because the whole scam hinges on the scammer&#8217;s ability to create a convincing&#8212;but remember, fake&#8212;crypto exchange site. They are only successful because they create a convincing persona and a platform to operate.</p><p><strong>Staging the Investment</strong></p><p>Once the victim&#8217;s guard is sufficiently lowered, the scammer will initiate a test run. They broach the subject of their recent financial success casually, crediting a new and lucrative platform for almost as an afterthought. Since the scammers have established the illusion of this success with a myriad of pictures, this tricks the victims into believing the platform is legitimate. It worked for their new friend or partner, so&#8230; why not try it?</p><p>There are two important things to call out here:</p><p><strong>These Crypto Sites Are Always Fake.</strong> Crypto platforms have emerged rapidly in the last decade. Fake sites are typically very convincing impersonations of legit sites. In December 2025, the US Securities and Exchange Commission <a href="https://www.sec.gov/newsroom/press-releases/2025-144-sec-charges-three-purported-crypto-asset-trading-platforms-four-investment-clubs-scheme-targeted">filed charges</a> against several fake crypto exchanges, including Berge Blockchain Technology Co. Ltd. An <a href="https://archive.org">archive.org</a> copy of the fake exchange hosted at bergev[.]org illustrates how convincing fake exchanges are. [Note: Berge was eventually <a href="https://www.sec.gov/files/litigation/complaints/2025/comp-pr2025-144.pdf">shut down by the US SEC</a>.]</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!x6Pf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2b4794-f867-4994-ad9e-0abe57027736_676x356.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!x6Pf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2b4794-f867-4994-ad9e-0abe57027736_676x356.png 424w, https://substackcdn.com/image/fetch/$s_!x6Pf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2b4794-f867-4994-ad9e-0abe57027736_676x356.png 848w, https://substackcdn.com/image/fetch/$s_!x6Pf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2b4794-f867-4994-ad9e-0abe57027736_676x356.png 1272w, https://substackcdn.com/image/fetch/$s_!x6Pf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2b4794-f867-4994-ad9e-0abe57027736_676x356.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!x6Pf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2b4794-f867-4994-ad9e-0abe57027736_676x356.png" width="676" height="356" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eb2b4794-f867-4994-ad9e-0abe57027736_676x356.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:356,&quot;width&quot;:676,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:197166,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/202503903?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2b4794-f867-4994-ad9e-0abe57027736_676x356.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!x6Pf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2b4794-f867-4994-ad9e-0abe57027736_676x356.png 424w, https://substackcdn.com/image/fetch/$s_!x6Pf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2b4794-f867-4994-ad9e-0abe57027736_676x356.png 848w, https://substackcdn.com/image/fetch/$s_!x6Pf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2b4794-f867-4994-ad9e-0abe57027736_676x356.png 1272w, https://substackcdn.com/image/fetch/$s_!x6Pf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb2b4794-f867-4994-ad9e-0abe57027736_676x356.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>One way to establish exchange legitimacy is to <a href="https://www.cftc.gov/sites/default/files/LearnandProtect/SpotFraudSites.pdf">verify their compliance</a> with government regulation. Datavisor provides a <a href="https://www.datavisor.com/wiki/fake-cryptocurrency-exchanges">list of fake crypto exchanges</a> and explains how to avoid them. The list is helpful but the advice, more so.</p><p><strong>The Scheme Hinges on the Victim&#8217;s Decision. </strong>Importantly, the scammer will never directly push the victim to get into crypto. What they do instead is dangle the illusion of success in front of them until the offer is too tempting not to take. In this way, they avoid suspicion, because after all, they never forced you to do anything.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_Z_9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c64a515-2444-4fc7-9ee8-36a4280c79c4_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_Z_9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c64a515-2444-4fc7-9ee8-36a4280c79c4_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!_Z_9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c64a515-2444-4fc7-9ee8-36a4280c79c4_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!_Z_9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c64a515-2444-4fc7-9ee8-36a4280c79c4_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!_Z_9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c64a515-2444-4fc7-9ee8-36a4280c79c4_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_Z_9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c64a515-2444-4fc7-9ee8-36a4280c79c4_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8c64a515-2444-4fc7-9ee8-36a4280c79c4_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2354966,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/202503903?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c64a515-2444-4fc7-9ee8-36a4280c79c4_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_Z_9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c64a515-2444-4fc7-9ee8-36a4280c79c4_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!_Z_9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c64a515-2444-4fc7-9ee8-36a4280c79c4_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!_Z_9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c64a515-2444-4fc7-9ee8-36a4280c79c4_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!_Z_9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c64a515-2444-4fc7-9ee8-36a4280c79c4_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Image created with CoPilot</figcaption></figure></div><p>The initial investment that a victim makes will often yield a fast and high return. In isolation, this should normally be another tip-off to the victim, but when reinforced by the established relationship with the scammer, it instead draws them in deeper.</p><h2>How Criminals Sustain the Bleeding</h2><p>As the scheme progresses, the scammer shifts from relationship-building to siphoning money without raising suspicion. The scammers shift away from conventional social media or dating apps to encrypted messaging platforms, such as WhatsApp, Telegram, or WeChat. Criminals may also avoid live interaction, declining live video calls by blaming camera malfunctions, illness, bad hair day, pimples, or sudden emergencies as their cover. They will also decline meetups in real life and often engineer the victim&#8217;s desire to draw out more money from them.</p><p>At the same time that they avoid being discovered as frauds, the scammers will coach the victim through more fake investments. They will direct the victim towards the investments that have the best return (remember, these are fake) and encourage them when the returns aren&#8217;t as fruitful as the first one. If a victim&#8217;s bank or crypto exchange flags a transaction, the scammer will teach them how to lie about the purpose of the transfer. If a victim is slow to invest or starts to pull back, the scammer will turn around with a sudden reason why their relationship can&#8217;t continue without the investment. In this way, they hold both the farcical relationship and the victim hostage.</p><h2>The Rug-Pull</h2><p>In the <a href="https://www.huntress.com/cybersecurity-101/topic/pig-butchering-scam">final phase of the scam</a>, the scammer closes the fake investment platform, blocks the victim, and disappears with all the deposited funds. This often occurs when the victim has spent all their life savings or their pension and is now anxiously awaiting the promised returns.</p><p>When the victim attempts to withdraw their money, the fake platform may freeze their account unexpectedly. Attempts to visit the fake site may result in &#8220;temporarily unavailable&#8221; or other web server errors. The platform may demand an upfront payment of taxes, security deposits, or withdrawal fees. This is another bleed. These sums are usually smaller than the total that the victim has on the platform, to seem like a small obstacle to overcome for the rest of the money. Frustrating, but manageable &#8211; or so the victim believes. However, when the victim pays these abrupt fees, the money still won&#8217;t come. In fact, there&#8217;s another hindrance that requires more money to unlock their funds.</p><p>Eventually, when the victim is out of money or realizes they&#8217;re being scammed, the scammers disable the website or app, disconnect their phone numbers, and vanish with the stolen cryptocurrency.</p><p>Because the victim willingly purchased and transferred the cryptocurrency to the scammers, recovering the funds is incredibly difficult. The victim is left with catastrophic financial losses, deep emotional trauma, and worst of all, no sympathy from their friends and family.</p><h2>Beyond the Rug Pull: Be Wary of Recovery Scammers!</h2><p><a href="https://www.aarp.org/money/scams-fraud/recovery-scams/">Recovery scammers</a> target individuals who have already lost money to fraud, offering to recover stolen funds or secure a refund for an upfront fee. Often referred to as &#8220;recovery rooms&#8221; or advance fee fraud, these scams are a double-victimization where the perpetrators disappear with the new fees.</p><h2>Takeaways</h2><p>Romance scams are widespread. The scammers create plausible and attractive lures and authentic looking crypto exchange impersonation sites. They will bleed a victim to financial ruin.</p><h4>From the Editor</h4><p>If you&#8217;ve enjoyed the Pig-Butchering series, or if you&#8217;ve found it informative, please share (begin with <a href="https://interisle.substack.com/p/pig-butchering-scams-the-industrialization">Part 1</a>, <a href="https://interisle.substack.com/p/pig-butchering-part-2-anatomy-of">Part 2</a>, <a href="https://interisle.substack.com/p/pig-butchering-part-3-the-psychology">Part 3</a>). </p><p>But&#8230; more importantly! Warn your friends, colleagues, and family to be wary of any &#8220;chance encounters&#8221;, people who flaunt their earnings (overt or subtle) in social media or direct messaging apps and be skeptical of anyone who promises to help you lead a lucrative lifestyle if you&#8217;ll invest in cryptocurrency. And should someone you know fall victim to a romance scam, warn them to be wary of anyone who offers to help them recover their losses.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://interisle.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Interisle Insights is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p style="text-align: center;">Use the special offer <a href="https://interisle.substack.com/subscribe?coupon=8abeadd5">endromancscams</a> to <br>receive 40% off any subscription!</p><p></p>]]></content:encoded></item><item><title><![CDATA[Interisle Study Presented to ICANN Government Advisory Committee ]]></title><description><![CDATA[Dave Piscitello]]></description><link>https://interisle.substack.com/p/interisle-study-presented-to-icann</link><guid isPermaLink="false">https://interisle.substack.com/p/interisle-study-presented-to-icann</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Thu, 11 Jun 2026 15:02:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YoYt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f1def6f-e48a-42dc-955f-ed15648d383f_640x480.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On Wednesday, June 10, 2026, Karen Rose presented Interisle&#8217;s recently published study, <a href="https://interisle.net/insights/cybercriminaldomaindemand">Malicious Registrations in the Domain Name Market: An Analysis of 2025 gTLD Registrations and Cybercriminal Demand</a>, to the ICANN GAC (Government Advisory Committee) at <a href="https://www.icann.org/en/engagement-calendar/details/icann86-seville-policy-forum-2026-06-08">ICANN86 Seville Policy Forum</a>. The <a href="https://gac.icann.org/about">GAC advises ICANN</a> on public policy aspects of specific issues for which ICANN has responsibility, and DNS abuse has long been an issue of particular interest to the GAC.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YoYt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f1def6f-e48a-42dc-955f-ed15648d383f_640x480.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YoYt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f1def6f-e48a-42dc-955f-ed15648d383f_640x480.jpeg 424w, https://substackcdn.com/image/fetch/$s_!YoYt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f1def6f-e48a-42dc-955f-ed15648d383f_640x480.jpeg 848w, https://substackcdn.com/image/fetch/$s_!YoYt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f1def6f-e48a-42dc-955f-ed15648d383f_640x480.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!YoYt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f1def6f-e48a-42dc-955f-ed15648d383f_640x480.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YoYt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f1def6f-e48a-42dc-955f-ed15648d383f_640x480.jpeg" width="352" height="264" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9f1def6f-e48a-42dc-955f-ed15648d383f_640x480.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:640,&quot;resizeWidth&quot;:352,&quot;bytes&quot;:135341,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/201478747?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f1def6f-e48a-42dc-955f-ed15648d383f_640x480.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YoYt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f1def6f-e48a-42dc-955f-ed15648d383f_640x480.jpeg 424w, https://substackcdn.com/image/fetch/$s_!YoYt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f1def6f-e48a-42dc-955f-ed15648d383f_640x480.jpeg 848w, https://substackcdn.com/image/fetch/$s_!YoYt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f1def6f-e48a-42dc-955f-ed15648d383f_640x480.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!YoYt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9f1def6f-e48a-42dc-955f-ed15648d383f_640x480.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Karen&#8217;s representation to the GAC follows:</p><blockquote><p>Good morning. I&#8217;m Karen Rose of Interisle Consulting Group. I&#8217;m pleased to have the opportunity to share with you some findings from our most recent study.</p><p>Our work examined malicious domain name registrations made in 2025 in the gTLDs.</p><p>I&#8217;ll focus on two questions our research looked at: 1) how much cybercriminal demand drove new domain registrations last year, and 2) whether market incentives allow that demand to persist.</p><p>We used publicly and commercially available data for our research, including blocklists and domain registration data &#8211; and you can find our full methodology in our report.</p><p>Overall, our findings were sobering. We estimate that bad actors purchased 16.8 million gTLD domain names last year &#8212; That&#8217;s about 20 percent of all new registrations sold.</p><p>Put another way, as many as 1 out of every 5 domain names may have been purchased by bad actors to perpetrate phishing, malware, scams and other harmful attacks.</p><p>Imagine another industry where 1 out of every 5 products sold was being used to facilitate fraud, theft, or other serious crimes.</p><p>Few governments would consider that ordinary misuse. Policymakers would ask whether the rules, safeguards, and accountability mechanisms in that market were adequate to the scale of the problem &#8211; and if those measures were sufficiently protecting the public interest.</p><p>I think those same questions are relevant to DNS abuse policy discussions here, for the whole ICANN community.</p><p>Our study also found that abuse is highly concentrated among certain providers.</p><p>We found numerous registries and registrars where over half of all their registrations appeared to be purchased by bad actors.</p><p>At one registrar, 88 percent of its registrations were identified as malicious.</p><p>In one TLD we examined, nearly all of its registrations &#8211; some 100,000 &#8211; were associated with FUNNULL &#8211; a cybercriminal gang that powered scam farms across Southeast Asia.</p><p>Why does abuse exist at this scale? Economics and distorted incentives play a role.</p><p>Cybercriminals create sustained demand for domain names. They are high-volume, repeat buyers. And they buy millions of domains each year.</p><p>Fierce competition in the gTLD market has driven prices and profit margins down. Sales volume matters. Registrars provide tools that facilitate easy bulk registrations.</p><p>Some registries and registrars appear to derive commercial benefits from satisfying cybercriminal demand. Even when malicious registrations generate little revenue, tolerating abuse can still be commercially rational &#8212; especially when there are no obligations to prevent it.</p><p>While cybercriminals and some in the market may benefit from these transactions, the costs of cybercrime facilitated by domain abuse fall on victims, businesses, governments, and society at large.</p><p>In economic terms, this is a classic <em>negative externality</em> &#8211; a form of market failure that undermines the very benefits of competition.</p><p>Taken together, these findings make it hard to treat current levels of abuse as acceptable.</p><p>Importantly, our study also shows that abuse at this scale is <em>not</em> inevitable. Some registries and registrars managed to grow last year without attracting outsized levels of abuse, showing that provider practices and abuse choices make a difference.</p><p>And our case studies show that associated domain name checks can be a helpful mitigation step.</p><p>But we also need effective steps beyond mitigation. Steps that focus more on abuse prevention &#8211; and reducing the ability of bad actors to acquire domains in the first place.</p><p>This is especially urgent as ICANN prepares for the next round of new gTLDs. The introduction of new TLDs will further intensify competition and risks perpetuating current distortions in the market.</p><p>Measurably reducing DNS abuse needs to be our ultimate goal.</p><p>We look forward to engaging with the GAC and the community going forward.</p></blockquote><p>Interisle appreciates the active engagement of the GAC and its members on domain name abuse issues and thanks the committee for the invitation to contribute our findings and analysis to this important discussion.</p>]]></content:encoded></item><item><title><![CDATA[Cybercrime Reported in May 2026]]></title><description><![CDATA[Colin Strutt]]></description><link>https://interisle.substack.com/p/cybercrime-reported-in-may-2026</link><guid isPermaLink="false">https://interisle.substack.com/p/cybercrime-reported-in-may-2026</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Tue, 09 Jun 2026 13:56:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!GKRU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7a5d5a6-1dd8-4582-b121-eadc6f803abf_467x302.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Interisle publishes quarterly data about cybercrime activity - for phishing, malware, and spam - at the <a href="https://cybercrimeinfocenter.org">Cybercrime Information Center</a>.</p><p>Here we look at cybercrime activity for the month of May 2026. We point out anything that strikes us as particularly interesting in overall numbers as well as significant changes in ranking for Top Level Domains (TLDs), Registrars, and Hosting Networks.</p><h2>Overall numbers</h2><p>The May results showed a 27% increase in overall phishing reported compared to April.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1qd2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F425fff5d-c9e4-48a6-bebd-7f88710ee1d8_481x285.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1qd2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F425fff5d-c9e4-48a6-bebd-7f88710ee1d8_481x285.png 424w, https://substackcdn.com/image/fetch/$s_!1qd2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F425fff5d-c9e4-48a6-bebd-7f88710ee1d8_481x285.png 848w, https://substackcdn.com/image/fetch/$s_!1qd2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F425fff5d-c9e4-48a6-bebd-7f88710ee1d8_481x285.png 1272w, https://substackcdn.com/image/fetch/$s_!1qd2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F425fff5d-c9e4-48a6-bebd-7f88710ee1d8_481x285.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1qd2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F425fff5d-c9e4-48a6-bebd-7f88710ee1d8_481x285.png" width="481" height="285" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/425fff5d-c9e4-48a6-bebd-7f88710ee1d8_481x285.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:285,&quot;width&quot;:481,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:22962,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/201141611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F425fff5d-c9e4-48a6-bebd-7f88710ee1d8_481x285.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1qd2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F425fff5d-c9e4-48a6-bebd-7f88710ee1d8_481x285.png 424w, https://substackcdn.com/image/fetch/$s_!1qd2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F425fff5d-c9e4-48a6-bebd-7f88710ee1d8_481x285.png 848w, https://substackcdn.com/image/fetch/$s_!1qd2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F425fff5d-c9e4-48a6-bebd-7f88710ee1d8_481x285.png 1272w, https://substackcdn.com/image/fetch/$s_!1qd2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F425fff5d-c9e4-48a6-bebd-7f88710ee1d8_481x285.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Spam reported in May increased 35% compared to April.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Oh8S!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e5ae9c-4c22-4d72-9ed8-a501bfc3fa24_478x292.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Oh8S!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e5ae9c-4c22-4d72-9ed8-a501bfc3fa24_478x292.png 424w, https://substackcdn.com/image/fetch/$s_!Oh8S!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e5ae9c-4c22-4d72-9ed8-a501bfc3fa24_478x292.png 848w, https://substackcdn.com/image/fetch/$s_!Oh8S!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e5ae9c-4c22-4d72-9ed8-a501bfc3fa24_478x292.png 1272w, https://substackcdn.com/image/fetch/$s_!Oh8S!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e5ae9c-4c22-4d72-9ed8-a501bfc3fa24_478x292.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Oh8S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e5ae9c-4c22-4d72-9ed8-a501bfc3fa24_478x292.png" width="478" height="292" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d7e5ae9c-4c22-4d72-9ed8-a501bfc3fa24_478x292.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:292,&quot;width&quot;:478,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23125,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/201141611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e5ae9c-4c22-4d72-9ed8-a501bfc3fa24_478x292.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Oh8S!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e5ae9c-4c22-4d72-9ed8-a501bfc3fa24_478x292.png 424w, https://substackcdn.com/image/fetch/$s_!Oh8S!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e5ae9c-4c22-4d72-9ed8-a501bfc3fa24_478x292.png 848w, https://substackcdn.com/image/fetch/$s_!Oh8S!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e5ae9c-4c22-4d72-9ed8-a501bfc3fa24_478x292.png 1272w, https://substackcdn.com/image/fetch/$s_!Oh8S!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7e5ae9c-4c22-4d72-9ed8-a501bfc3fa24_478x292.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>While malware reported in May decreased 17% compared to April, it still represents an 11% increase over the monthly average for the 12 -month period.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!GKRU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7a5d5a6-1dd8-4582-b121-eadc6f803abf_467x302.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!GKRU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7a5d5a6-1dd8-4582-b121-eadc6f803abf_467x302.png 424w, https://substackcdn.com/image/fetch/$s_!GKRU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7a5d5a6-1dd8-4582-b121-eadc6f803abf_467x302.png 848w, https://substackcdn.com/image/fetch/$s_!GKRU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7a5d5a6-1dd8-4582-b121-eadc6f803abf_467x302.png 1272w, https://substackcdn.com/image/fetch/$s_!GKRU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7a5d5a6-1dd8-4582-b121-eadc6f803abf_467x302.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!GKRU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7a5d5a6-1dd8-4582-b121-eadc6f803abf_467x302.png" width="467" height="302" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b7a5d5a6-1dd8-4582-b121-eadc6f803abf_467x302.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:302,&quot;width&quot;:467,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23229,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/201141611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7a5d5a6-1dd8-4582-b121-eadc6f803abf_467x302.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!GKRU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7a5d5a6-1dd8-4582-b121-eadc6f803abf_467x302.png 424w, https://substackcdn.com/image/fetch/$s_!GKRU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7a5d5a6-1dd8-4582-b121-eadc6f803abf_467x302.png 848w, https://substackcdn.com/image/fetch/$s_!GKRU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7a5d5a6-1dd8-4582-b121-eadc6f803abf_467x302.png 1272w, https://substackcdn.com/image/fetch/$s_!GKRU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7a5d5a6-1dd8-4582-b121-eadc6f803abf_467x302.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Phishing</h2><div class="callout-block" data-callout="true"><h4 style="text-align: center;"><strong>Top-level Domains</strong></h4><p><strong>.CN increased 450%</strong> in phishing domains reported (.BOND increased 350%).</p><p><strong>.FORUM increased 750%</strong> in phishing domain score (.BOND increased 350% ).</p><p><strong>.CN increased over 900%</strong> in malicious phishing domains.</p><h4 style="text-align: center;">Registrars</h4><p>Phishing domains registered at <strong>Alibaba Cloud Computing (Beijing) increased 1,400%.</strong><br><br><strong>Xiamen 35.com&#8217;s phishing domain score increased12,875%</strong>. Nearly all of the phishing domains were maliciously registered.</p><h4 style="text-align: center;">Hosting Providers</h4><p><strong>Private Layer (AS51852) rose to the top of the ASN phishing attacks</strong> ranking with an increase over 7,700%.</p><p>Ten of the top 20 ASNs suffered increases in phishing attacks of over 1,000%.</p><p>Seven of the top 20 ASNs had increases in phishing attack scores of over 1,000%.</p></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FVfM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cbd676b-7862-4068-aec6-251bb62ec621_600x616.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FVfM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cbd676b-7862-4068-aec6-251bb62ec621_600x616.png 424w, https://substackcdn.com/image/fetch/$s_!FVfM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cbd676b-7862-4068-aec6-251bb62ec621_600x616.png 848w, https://substackcdn.com/image/fetch/$s_!FVfM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cbd676b-7862-4068-aec6-251bb62ec621_600x616.png 1272w, https://substackcdn.com/image/fetch/$s_!FVfM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cbd676b-7862-4068-aec6-251bb62ec621_600x616.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FVfM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cbd676b-7862-4068-aec6-251bb62ec621_600x616.png" width="600" height="616" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3cbd676b-7862-4068-aec6-251bb62ec621_600x616.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:616,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:75604,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/201141611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cbd676b-7862-4068-aec6-251bb62ec621_600x616.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FVfM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cbd676b-7862-4068-aec6-251bb62ec621_600x616.png 424w, https://substackcdn.com/image/fetch/$s_!FVfM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cbd676b-7862-4068-aec6-251bb62ec621_600x616.png 848w, https://substackcdn.com/image/fetch/$s_!FVfM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cbd676b-7862-4068-aec6-251bb62ec621_600x616.png 1272w, https://substackcdn.com/image/fetch/$s_!FVfM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3cbd676b-7862-4068-aec6-251bb62ec621_600x616.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Spam</h3><div class="callout-block" data-callout="true"><h4 style="text-align: center;">Top-level Domains</h4><p><strong>.HELP became the top-ranked TLD by spam domain score</strong> (a 350% increase).</p><p><strong>386,000 spam domains were reported in .COM</strong>, and 256,000 in .TOP.</p><p>Eighteen of the top 20 TLDs had increases in spam domains.</p><h4 style="text-align: center;">Registrars </h4><p>DynaDot (#1) and NameSilo (#2) top the rankings of domain registrars by spam domains reported.</p><p>Spam domains registered at Alibaba Cloud Computing (Beijing) grew over 11,500%.</p><p>Spam domains registered at MarkMonitor grew over 19,000%.</p><p>NameMart and Aceville continue top the rankings of domain registrars by spam domain score.</p><h4 style="text-align: center;">Hosting Providers</h4><p><strong>CNSERVERS rose to #2</strong> (behind Cloudflare in ASN rankings by IP addresses reported for spammed content or spambot hosting, and</p><p><strong>BGPNET PTE, unranked last month, rose to #5</strong>.</p></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SJlZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f47f437-5376-4334-9d85-1775bfd3e64e_667x557.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SJlZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f47f437-5376-4334-9d85-1775bfd3e64e_667x557.png 424w, https://substackcdn.com/image/fetch/$s_!SJlZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f47f437-5376-4334-9d85-1775bfd3e64e_667x557.png 848w, https://substackcdn.com/image/fetch/$s_!SJlZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f47f437-5376-4334-9d85-1775bfd3e64e_667x557.png 1272w, https://substackcdn.com/image/fetch/$s_!SJlZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f47f437-5376-4334-9d85-1775bfd3e64e_667x557.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SJlZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f47f437-5376-4334-9d85-1775bfd3e64e_667x557.png" width="667" height="557" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5f47f437-5376-4334-9d85-1775bfd3e64e_667x557.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:557,&quot;width&quot;:667,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:68697,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/201141611?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f47f437-5376-4334-9d85-1775bfd3e64e_667x557.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SJlZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f47f437-5376-4334-9d85-1775bfd3e64e_667x557.png 424w, https://substackcdn.com/image/fetch/$s_!SJlZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f47f437-5376-4334-9d85-1775bfd3e64e_667x557.png 848w, https://substackcdn.com/image/fetch/$s_!SJlZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f47f437-5376-4334-9d85-1775bfd3e64e_667x557.png 1272w, https://substackcdn.com/image/fetch/$s_!SJlZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5f47f437-5376-4334-9d85-1775bfd3e64e_667x557.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Malware</h2><p>The majority of malware reports from our feeds cite IP addresses rather than domain names.</p><p>There continues to be churn in the choice of ASNs that appear to be used for malware activity. Ten ASNs showed reduced malware (-4% to -36%) while ten ASNs showed increased malware (+7% to +120%).</p><h2>Be Prepared</h2><p>Check out the lists above and the tables of the worst TLDs, gTLD registrars, and hosting networks (ASNs) at the most recent <a href="https://www.cybercrimeinfocenter.org/phishing-activity">Phishing Activity</a>, <a href="https://www.cybercrimeinfocenter.org/malware-activity">Malware Activity</a>, and <a href="https://www.cybercrimeinfocenter.org/spam-activity">Spam Activity</a> pages to determine which represent the most risk to your organization. Network staff might consider blocking TLDs and ASNs that appear in our Phishing, Malware, and Spam &#8220;Favorites&#8221; tables to protect against inadvertent access to content that could result in harm, making exceptions only where there is a clear business case.</p><h2>Quarterly Results</h2><p>The quarterly spam results for March to May 2026 will be published on the <a href="https://www.cybercrimeinfocenter.org/spam-activity">Spam Activity</a> page at the Cybercrime Information Center.</p>]]></content:encoded></item><item><title><![CDATA[Pig Butchering Part 3: The Psychology of the Scam]]></title><description><![CDATA[Matt Piscitello]]></description><link>https://interisle.substack.com/p/pig-butchering-part-3-the-psychology</link><guid isPermaLink="false">https://interisle.substack.com/p/pig-butchering-part-3-the-psychology</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Fri, 05 Jun 2026 12:57:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!MBTg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85d9e460-52a7-4c8a-8a89-65a1283a26f4_747x406.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Online romance scams are psychological manipulation crimes. Scammers exploit a target&#8217;s loneliness, emotional needs, and trust by nurturing fake, intense romantic bonds with that target to eventually lure them into a fraudulent investment or a payment scheme.</p><p>In today&#8217;s article, we explore the psychology behind romance scams, particularly the ones driven toward pig butchering. We&#8217;ll look at tactics commonly used in these schemes - grooming, urgent crises, or &#8220;sunk cost fallacy&#8221; - to keep victims invested emotionally and financially.</p><h2>Psychological Tactics of Criminals</h2><p>The playbook for romance scams is simultaneously nefarious on the part of the criminal and devastating on the part of the victim. Romance scammers typically employ these tactics:</p><ul><li><p><strong>Love Bombing[1]:</strong> Scammers overwhelm their victims with affection and constant communication. This is intended to speed up the relationship and bait the hook.</p></li><li><p><strong>Grooming and Trust Building[2]:</strong> Scammers invest significant time (sometimes months) to build trust, adapting their false persona to the victim&#8217;s desires.</p></li><li><p><strong>Target (Victim) Isolation<sup>1</sup>:</strong> Scammers will attempt to estrange victims from friends and family. This makes the victim more vulnerable and reliant on the scammer.</p></li><li><p><strong>Urgency and Crisis[3][4]:</strong> Scammers fabricate emergencies (medical bills, travel costs, visa issues) that require immediate financial help.</p></li><li><p><strong>Sunk Cost Fallacy:</strong> Victims invest more money, time, and affection to justify the initial investment, or mitigate the loss.</p><h2>Psychological Vulnerabilities of Victims</h2><p>In addition to the psychological patterns of the criminal, it&#8217;s important to characterize the psychology used against the the victims<strong>[5]</strong>: </p><ul><li><p><strong>Loneliness and Grief:</strong> People who are newly widowed or isolated are prime targets: their emotional state increases their susceptibility to persuasion.</p></li><li><p><strong>High Need for Affection:</strong> Victims are often vulnerable to the kind of affection that a scammer will overwhelm them with. They are desperate for a romantic connection, making them easy to groom.</p></li><li><p><strong>Impulsivity and Sensitivity Seeking:</strong> People with impulsive tendencies may jump on opportunities quickly, whether for financial gain or romantic connection. They often fail to verify the identity of the person they are interacting with.</p></li><li><p><strong>Idealized Romance:</strong> Individuals who idealize potential partners or believe in &#8220;soulmates&#8221; are more easily manipulated.</p></li></ul><h2>Role of Technology and AI</h2><p>Criminal enterprises benefit from emerging technologies as much as legitimate enterprises do.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MBTg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85d9e460-52a7-4c8a-8a89-65a1283a26f4_747x406.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MBTg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85d9e460-52a7-4c8a-8a89-65a1283a26f4_747x406.png 424w, https://substackcdn.com/image/fetch/$s_!MBTg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85d9e460-52a7-4c8a-8a89-65a1283a26f4_747x406.png 848w, https://substackcdn.com/image/fetch/$s_!MBTg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85d9e460-52a7-4c8a-8a89-65a1283a26f4_747x406.png 1272w, https://substackcdn.com/image/fetch/$s_!MBTg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85d9e460-52a7-4c8a-8a89-65a1283a26f4_747x406.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MBTg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85d9e460-52a7-4c8a-8a89-65a1283a26f4_747x406.png" width="747" height="406" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/85d9e460-52a7-4c8a-8a89-65a1283a26f4_747x406.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:406,&quot;width&quot;:747,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:76973,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/200639296?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85d9e460-52a7-4c8a-8a89-65a1283a26f4_747x406.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MBTg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85d9e460-52a7-4c8a-8a89-65a1283a26f4_747x406.png 424w, https://substackcdn.com/image/fetch/$s_!MBTg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85d9e460-52a7-4c8a-8a89-65a1283a26f4_747x406.png 848w, https://substackcdn.com/image/fetch/$s_!MBTg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85d9e460-52a7-4c8a-8a89-65a1283a26f4_747x406.png 1272w, https://substackcdn.com/image/fetch/$s_!MBTg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85d9e460-52a7-4c8a-8a89-65a1283a26f4_747x406.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Psychological Influence is Present in Every Phase of the Scam</h2><p>In our second article[6], we cover the step-by-step mechanics of the scam. here, we&#8217;ll examine how scammers apply psychology in each phase of a romance scam. Unlike other mass-marketing fraud victims, these victims experienced a &#8216;double hit&#8217; of the scam: a financial loss and the loss of a relationship. For most, the loss of the relationship was more upsetting than their financial losses. Most victims are left inconsolable in the aftermath, which is compounded by a lack of understanding from friends and family due to the stigma surrounding victims of fraud.</p><p>Below, we break down each of those phases and look deeper into the psychology behind them:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gmtZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836765f0-aeb9-45a4-bcd4-8a691a293cc7_521x574.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gmtZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836765f0-aeb9-45a4-bcd4-8a691a293cc7_521x574.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gmtZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836765f0-aeb9-45a4-bcd4-8a691a293cc7_521x574.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gmtZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836765f0-aeb9-45a4-bcd4-8a691a293cc7_521x574.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gmtZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836765f0-aeb9-45a4-bcd4-8a691a293cc7_521x574.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gmtZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836765f0-aeb9-45a4-bcd4-8a691a293cc7_521x574.jpeg" width="619" height="681.9692898272552" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/836765f0-aeb9-45a4-bcd4-8a691a293cc7_521x574.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:574,&quot;width&quot;:521,&quot;resizeWidth&quot;:619,&quot;bytes&quot;:96218,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/200639296?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836765f0-aeb9-45a4-bcd4-8a691a293cc7_521x574.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gmtZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836765f0-aeb9-45a4-bcd4-8a691a293cc7_521x574.jpeg 424w, https://substackcdn.com/image/fetch/$s_!gmtZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836765f0-aeb9-45a4-bcd4-8a691a293cc7_521x574.jpeg 848w, https://substackcdn.com/image/fetch/$s_!gmtZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836765f0-aeb9-45a4-bcd4-8a691a293cc7_521x574.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!gmtZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F836765f0-aeb9-45a4-bcd4-8a691a293cc7_521x574.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Takeaway</h2><p>Pig Butchering scams merge the deep emotional manipulation of romance scams with the mechanics of fraudulent investment platforms. While traditional romance scammers ask for direct financial help, pig butchering scammers manipulate victims into believing they are building a wealthy future together.</p><p>In the next article, we&#8217;ll dive deeper into how and why crypto scams work so well.</p></li></ul><div><hr></div><p>[1] <a href="https://health.clevelandclinic.org/love-bombing">https://health.clevelandclinic.org/love-bombing</a></p><p>[2] <a href="https://pmc.ncbi.nlm.nih.gov/articles/PMC5806049/">https://pmc.ncbi.nlm.nih.gov/articles/PMC5806049/</a></p><p>[3] <a href="https://www.heraldopenaccess.us/openaccess/romance-scams-and-older-adults-a-health-and-social-care-perspective">https://www.heraldopenaccess.us/openaccess/romance-scams-and-older-adults-a-health-and-social-care-perspective</a></p><p>[4] <a href="https://academic.oup.com/cybersecurity/article/12/1/tyag003/8449214">https://academic.oup.com/cybersecurity/article/12/1/tyag003/8449214</a></p><p>[5] <a href="https://www.sciencedirect.com/org/science/article/pii/S1745017920000183">https://www.sciencedirect.com/org/science/article/pii/S1745017920000183</a></p><p>[6] <a href="https://interisle.substack.com/p/pig-butchering-part-2-anatomy-of">https://interisle.substack.com/p/pig-butchering-part-2-anatomy-of</a></p><p>[7] <a href="https://www.sciencedirect.com/org/science/article/pii/S1745017920000183">https://www.sciencedirect.com/org/science/article/pii/S1745017920000183</a></p>]]></content:encoded></item><item><title><![CDATA[Malicious Actors Accounted for as much as 20% of New Domain Name Registrations in 2025]]></title><description><![CDATA[Greg Aaron, Colin Strutt, and Karen Rose]]></description><link>https://interisle.substack.com/p/malicious-actors-accounted-for-as</link><guid isPermaLink="false">https://interisle.substack.com/p/malicious-actors-accounted-for-as</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Tue, 02 Jun 2026 17:32:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QN_j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaaaff-71a5-46d4-870f-afbe2e410e92_2500x1406.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>A new analysis by <a href="https://interisle.net/">Interisle Consulting Group</a> finds that cybercriminals registered a significant share of new domain name registrations in 2025, representing a substantial percentage of the generic Top-Level Domain (gTLD) market.</strong></p><p><strong>The study establishes that malicious actors purchased at least 10 percent of all newly registered gTLD domains in 2025, with projections indicating that the actual share may be closer to 20 percent.</strong></p><p><strong>In 2025, nearly 85 million gTLD domains were newly registered. As of mid-May 2026, 8.5 million of those domains &#8212; 10 percent &#8212; had been added to blocklists for malicious activity. Applying conservative projections for additional future blocklisting and associated domains registered by criminals not identified by blocklists, the study estimates that bad actors may have purchased 16.8 million domains, or 20 percent of gTLD registrations.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QN_j!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaaaff-71a5-46d4-870f-afbe2e410e92_2500x1406.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QN_j!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaaaff-71a5-46d4-870f-afbe2e410e92_2500x1406.webp 424w, https://substackcdn.com/image/fetch/$s_!QN_j!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaaaff-71a5-46d4-870f-afbe2e410e92_2500x1406.webp 848w, https://substackcdn.com/image/fetch/$s_!QN_j!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaaaff-71a5-46d4-870f-afbe2e410e92_2500x1406.webp 1272w, https://substackcdn.com/image/fetch/$s_!QN_j!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaaaff-71a5-46d4-870f-afbe2e410e92_2500x1406.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QN_j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaaaff-71a5-46d4-870f-afbe2e410e92_2500x1406.webp" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dacaaaff-71a5-46d4-870f-afbe2e410e92_2500x1406.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:264030,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/200315747?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaaaff-71a5-46d4-870f-afbe2e410e92_2500x1406.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QN_j!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaaaff-71a5-46d4-870f-afbe2e410e92_2500x1406.webp 424w, https://substackcdn.com/image/fetch/$s_!QN_j!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaaaff-71a5-46d4-870f-afbe2e410e92_2500x1406.webp 848w, https://substackcdn.com/image/fetch/$s_!QN_j!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaaaff-71a5-46d4-870f-afbe2e410e92_2500x1406.webp 1272w, https://substackcdn.com/image/fetch/$s_!QN_j!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdacaaaff-71a5-46d4-870f-afbe2e410e92_2500x1406.webp 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>The full study, </strong><em><strong>Malicious Registrations in the Domain Name Market</strong></em><strong>, is available at <a href="https://interisle.net/cybercriminaldomaindemand">https://interisle.net/cybercriminaldomaindemand</a></strong></p>]]></content:encoded></item><item><title><![CDATA[Phishing Trends: February 2026 – April 2026]]></title><description><![CDATA[Dave Piscitello]]></description><link>https://interisle.substack.com/p/phishing-trends-february-2026-april</link><guid isPermaLink="false">https://interisle.substack.com/p/phishing-trends-february-2026-april</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Tue, 26 May 2026 12:11:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!zDDA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0732ff28-9d55-462a-bf51-246dce31cf6f_991x595.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Results for <a href="https://www.cybercrimeinfocenter.org/phishing-activity-numbers-february-april-2026.htm">phishing activity</a> for the period February 1, 2025 &#8211; April 30, 2026, are available at the <a href="https://cybercrimeinfocenter.org/">Cybercrime Information Center</a>. They include Top 20 rankings of Top-level Domains, Domain Registrars, and Hosting Operators (by ASN) and aggregate <a href="https://www.cybercrimeinfocenter.org/records-repository">records</a> of all operators with phishing activity.</p><h2>Headline</h2><p>We observed decreases from the prior quarterly data in overall phishing attacks reported, unique domain names reported for phishing, and phishing attacks hosted at free or cheap web site services (subdomain resellers). We observed significant phishing activity in certain Top-level Domains with little or no prior history of abuse by phishers. Much of this unwelcomed growth can be traced to specific domain registrars.</p><h2>Top-level Domains: Weed Prevention Fails in .GARDEN</h2><p>The .GARDEN TLD was the big, little phishing story for this reporting period. The sorry numbers in the table show that nearly 1 in 5 domains registered were reported for phishing. We determined that essentially all of these were maliciously registered domains, and all were registered via Spaceship (Namecheap family of registrars).</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ulb8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8479219e-3f27-40d7-b6d8-59cb2638c169_818x133.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ulb8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8479219e-3f27-40d7-b6d8-59cb2638c169_818x133.png 424w, https://substackcdn.com/image/fetch/$s_!Ulb8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8479219e-3f27-40d7-b6d8-59cb2638c169_818x133.png 848w, https://substackcdn.com/image/fetch/$s_!Ulb8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8479219e-3f27-40d7-b6d8-59cb2638c169_818x133.png 1272w, https://substackcdn.com/image/fetch/$s_!Ulb8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8479219e-3f27-40d7-b6d8-59cb2638c169_818x133.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ulb8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8479219e-3f27-40d7-b6d8-59cb2638c169_818x133.png" width="818" height="133" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8479219e-3f27-40d7-b6d8-59cb2638c169_818x133.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:133,&quot;width&quot;:818,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:21517,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/199181581?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8479219e-3f27-40d7-b6d8-59cb2638c169_818x133.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ulb8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8479219e-3f27-40d7-b6d8-59cb2638c169_818x133.png 424w, https://substackcdn.com/image/fetch/$s_!Ulb8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8479219e-3f27-40d7-b6d8-59cb2638c169_818x133.png 848w, https://substackcdn.com/image/fetch/$s_!Ulb8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8479219e-3f27-40d7-b6d8-59cb2638c169_818x133.png 1272w, https://substackcdn.com/image/fetch/$s_!Ulb8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8479219e-3f27-40d7-b6d8-59cb2638c169_818x133.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>We confirmed through our colleagues at SURBL that .GARDEN and .BEER domains were used in credential stealing phishing attacks impersonating Walmart, Omaha Steaks, and Lowe&#8217;s.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dnk9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2ab1123-a7c5-40e0-ad81-38f6f88d12bf_967x207.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dnk9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2ab1123-a7c5-40e0-ad81-38f6f88d12bf_967x207.png 424w, https://substackcdn.com/image/fetch/$s_!dnk9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2ab1123-a7c5-40e0-ad81-38f6f88d12bf_967x207.png 848w, https://substackcdn.com/image/fetch/$s_!dnk9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2ab1123-a7c5-40e0-ad81-38f6f88d12bf_967x207.png 1272w, https://substackcdn.com/image/fetch/$s_!dnk9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2ab1123-a7c5-40e0-ad81-38f6f88d12bf_967x207.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dnk9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2ab1123-a7c5-40e0-ad81-38f6f88d12bf_967x207.png" width="967" height="207" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c2ab1123-a7c5-40e0-ad81-38f6f88d12bf_967x207.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:207,&quot;width&quot;:967,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:133621,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/199181581?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2ab1123-a7c5-40e0-ad81-38f6f88d12bf_967x207.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dnk9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2ab1123-a7c5-40e0-ad81-38f6f88d12bf_967x207.png 424w, https://substackcdn.com/image/fetch/$s_!dnk9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2ab1123-a7c5-40e0-ad81-38f6f88d12bf_967x207.png 848w, https://substackcdn.com/image/fetch/$s_!dnk9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2ab1123-a7c5-40e0-ad81-38f6f88d12bf_967x207.png 1272w, https://substackcdn.com/image/fetch/$s_!dnk9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2ab1123-a7c5-40e0-ad81-38f6f88d12bf_967x207.png 1456w" sizes="100vw"></picture><div></div></div></a></figure></div><h2>Small TLDs Under Siege</h2><p>.GARDEN was one of three small TLDs (under 100,000 registrations) that were targeted so aggressively that they joined the Top 20 ranking for this period.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zDDA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0732ff28-9d55-462a-bf51-246dce31cf6f_991x595.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zDDA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0732ff28-9d55-462a-bf51-246dce31cf6f_991x595.png 424w, https://substackcdn.com/image/fetch/$s_!zDDA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0732ff28-9d55-462a-bf51-246dce31cf6f_991x595.png 848w, https://substackcdn.com/image/fetch/$s_!zDDA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0732ff28-9d55-462a-bf51-246dce31cf6f_991x595.png 1272w, https://substackcdn.com/image/fetch/$s_!zDDA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0732ff28-9d55-462a-bf51-246dce31cf6f_991x595.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zDDA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0732ff28-9d55-462a-bf51-246dce31cf6f_991x595.png" width="991" height="595" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0732ff28-9d55-462a-bf51-246dce31cf6f_991x595.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:595,&quot;width&quot;:991,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:125543,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/199181581?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0732ff28-9d55-462a-bf51-246dce31cf6f_991x595.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zDDA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0732ff28-9d55-462a-bf51-246dce31cf6f_991x595.png 424w, https://substackcdn.com/image/fetch/$s_!zDDA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0732ff28-9d55-462a-bf51-246dce31cf6f_991x595.png 848w, https://substackcdn.com/image/fetch/$s_!zDDA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0732ff28-9d55-462a-bf51-246dce31cf6f_991x595.png 1272w, https://substackcdn.com/image/fetch/$s_!zDDA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0732ff28-9d55-462a-bf51-246dce31cf6f_991x595.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Domain Registrars: Spaceship Takes Off&#8230; But Not in a Good Way</h2><p>Registrar Spaceship rose 12 spots to claim #1 in our Top 20 rankings for phishing domains reported. Namecheap (locked in at #6) launched Spaceship in August 2023. According to Namecheap&#8217;s <a href="https://www.prnewswire.com/news-releases/namecheap-officially-reveals-plans-for-spaceship--its-next-generation-domain-registration--web-services-platform-301903001.html">press release</a>, the goal was &#8220;to empower users to get online faster and easier than ever before, bypassing the ingrained complexities often associated with domains and digital products.&#8221; Getting online faster and easier is certainly working out for some registrants; sadly, that includes too many cybercriminals. We determined that over 108,000 of the 110,000 phishing domains registered via Spaceship reported during this period were registered for malicious purposes.</p><p>NICENIC International didn&#8217;t cede the top spot quietly. With nearly 99,000 domains reported for phishing and only 238,000 registrations, this registrar had a terrifyingly high 4,158 phishing domain score for the period. We determined that, of the ~127,000 .COM domains that were malicious registrations: over 46,000 were registered via NICENIC. That&#8217;s nearly 20% of NICENIC&#8217;s overall registrations.</p><p>While GoDaddy appears in the Top 20 for phishing domains reported, their phishing domain score is a very respectable 2.5. Compared to GoDaddy, NICENIC&#8217;s numbers are embarrassingly bad.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!F7Zb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F065c8126-c1aa-4643-a838-c1b26321ce87_668x197.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!F7Zb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F065c8126-c1aa-4643-a838-c1b26321ce87_668x197.png 424w, https://substackcdn.com/image/fetch/$s_!F7Zb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F065c8126-c1aa-4643-a838-c1b26321ce87_668x197.png 848w, https://substackcdn.com/image/fetch/$s_!F7Zb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F065c8126-c1aa-4643-a838-c1b26321ce87_668x197.png 1272w, https://substackcdn.com/image/fetch/$s_!F7Zb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F065c8126-c1aa-4643-a838-c1b26321ce87_668x197.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!F7Zb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F065c8126-c1aa-4643-a838-c1b26321ce87_668x197.png" width="668" height="197" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/065c8126-c1aa-4643-a838-c1b26321ce87_668x197.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:197,&quot;width&quot;:668,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:30304,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/199181581?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F065c8126-c1aa-4643-a838-c1b26321ce87_668x197.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!F7Zb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F065c8126-c1aa-4643-a838-c1b26321ce87_668x197.png 424w, https://substackcdn.com/image/fetch/$s_!F7Zb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F065c8126-c1aa-4643-a838-c1b26321ce87_668x197.png 848w, https://substackcdn.com/image/fetch/$s_!F7Zb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F065c8126-c1aa-4643-a838-c1b26321ce87_668x197.png 1272w, https://substackcdn.com/image/fetch/$s_!F7Zb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F065c8126-c1aa-4643-a838-c1b26321ce87_668x197.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Hosting Networks: Cloudflare Is King of a Reshuffled Top 20 Mountain</h2><p>Cloudflare is again the unenviable #1. We&#8217;d love to see the IPv4 addresses cloaked by Cloudflare reverse proxy services so we could more accurately report the addresses actually hosting criminal content.</p><p>The Top 20 for this reporting period is a crazy reshuffle from the prior period.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zyiJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b76e2f-c04e-42ce-8e22-ac38d46b8ba5_942x550.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zyiJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b76e2f-c04e-42ce-8e22-ac38d46b8ba5_942x550.png 424w, https://substackcdn.com/image/fetch/$s_!zyiJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b76e2f-c04e-42ce-8e22-ac38d46b8ba5_942x550.png 848w, https://substackcdn.com/image/fetch/$s_!zyiJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b76e2f-c04e-42ce-8e22-ac38d46b8ba5_942x550.png 1272w, https://substackcdn.com/image/fetch/$s_!zyiJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b76e2f-c04e-42ce-8e22-ac38d46b8ba5_942x550.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zyiJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b76e2f-c04e-42ce-8e22-ac38d46b8ba5_942x550.png" width="942" height="550" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f0b76e2f-c04e-42ce-8e22-ac38d46b8ba5_942x550.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:550,&quot;width&quot;:942,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:88819,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/199181581?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b76e2f-c04e-42ce-8e22-ac38d46b8ba5_942x550.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zyiJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b76e2f-c04e-42ce-8e22-ac38d46b8ba5_942x550.png 424w, https://substackcdn.com/image/fetch/$s_!zyiJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b76e2f-c04e-42ce-8e22-ac38d46b8ba5_942x550.png 848w, https://substackcdn.com/image/fetch/$s_!zyiJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b76e2f-c04e-42ce-8e22-ac38d46b8ba5_942x550.png 1272w, https://substackcdn.com/image/fetch/$s_!zyiJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff0b76e2f-c04e-42ce-8e22-ac38d46b8ba5_942x550.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>It&#8217;s hard to distill or individualize what attracted phishers to these hosting providers. In some cases, e.g., Weebly, it may be free/cheap hosting. In others, e.g., Protocol Labs, it may be the opportunity to abuse Interplanetary File Service, IPFS, for bulletproofing properties. Phishers may be exploiting Sucuri because, like Cloudflare, it offers reverse-proxy (IP address obfuscation). Some of the Top 20 newcomers are operators that offer shared IP hosting, low cost, and have small abuse response capacity.</p><h2>Ball of Confusion</h2><p>The Temptations nailed the state of the world in 1970.</p><blockquote><p>Fear in the air, tension everywhere&#8230;</p><p>Great Googamooga<br>Can&#8217;t you hear me talking to you?</p><p>It&#8217;s a ball of confusion<br>That&#8217;s what the world is today, hey-hey</p></blockquote><p>&#8220;Fear in the air, tension everywhere&#8221; is now, &#8220;Fear in the air, phishing everywhere&#8221;.</p><p>It&#8217;s hard for us to make concrete recommendations when the landscape changes <em>this </em>dramatically and rapidly, especially when policy regimes and regulatory environments change so slowly. </p><p>Head down. Raise your shields.</p>]]></content:encoded></item><item><title><![CDATA[Uses and Abuses of US Telephone Numbers Today: Part 2]]></title><description><![CDATA[Fred Goldstein]]></description><link>https://interisle.substack.com/p/uses-and-abuses-of-us-telephone-numbers-f41</link><guid isPermaLink="false">https://interisle.substack.com/p/uses-and-abuses-of-us-telephone-numbers-f41</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Wed, 20 May 2026 13:01:54 GMT</pubDate><content:encoded><![CDATA[<p>As we noted in <a href="https://interisle.substack.com/p/uses-and-abuses-of-us-telephone-numbers">Part 1</a> of this series, a telephone number is not an address. It&#8217;s a name. It leads to a carrier that serves that number. But the local number assignment and portability system is not at all like the toll free (800) system. It evolved from the legacy of how telephone numbers used to work, with incremental changes that preserved backwards compatibility.</p><p>There was a time, of course, when dialed digits actually directed the switchboard operators and electromechanical switches in the early telephone network, but it&#8217;s all databases now. That&#8217;s why numbers are now portable between carriers, allowing customers to switch carriers while keeping their numbers. But that makes local numbers open to abuse too, not unlike 800 numbers.</p><h2>Telephone Number Assignment Today</h2><p>Many entities have the power to assign telephone numbers, a bit like the many registries who sell domain names on the Internet, though the numbers are supposed to be associated with a service. The FCC has authorized the North American Numbering Plan Administrator to manage the wholesale distribution of local number blocks. That FCC contract is now held by Somos Inc., the long-time 800-number administrator, who took over from Neustar in 2018.</p><h3>Geographic numbers are assigned by carriers</h3><p>The US telephone system is still centered around local exchange areas, called rate centers, which used to be used for distance-sensitive long distance billing. There are around 20,000 rate centers in the United States. In many cases wireline providers are still required to assign numbers with the location&#8217;s assigned rate center, so they need access to numbers associated with areas they serve.</p><p>State-certificated wireline telephone companies, FCC-licensed wireless carriers, and some VoIP providers are allowed to request geographic numbers that they can assign. They are given out in blocks of 1000 at a time. A 3-digit prefix code within an area code is assigned to a rate center and its ten thousands-blocks (i.e., the ten blocks 0xxx through 9xxx) may belong to different service providers. A new 3-digit prefix code is only opened when the thousands-blocks in a rate center run out.</p><p>Thousands-block assignment is based around the local number portability (LNP) system that was built after the Telecommunications Act of 1996. In essence it pre-ports 1000 numbers away from the telephone carrier that initially requested or held the prefix code. Before pooling was available, prefix codes were being exhausted rapidly by the growth of new competitive local carriers (CLECs). The need for new prefix codes led to many area code splits.</p><p>While pooling and thousands-block assignments dramatically reduced the need for new codes, area codes are no longer split. Instead, an exhausted area code is overlaid with a new one; for example, Boston&#8217;s 617 area code was overlaid with 857, though <em>only</em> after two splits (creating 508 and later 781) reduced its coverage area. The advantage? No one has to change their number anymore. The only disadvantage is that 7-digit local dialing is no longer possible in an overlaid area; like most of the country, all 10 digits are required. Of course with mobile phones and their widespread use of address-book calling, that&#8217;s hardly noticeable.</p><p>VoIP providers are not obligated to only assign numbers to users local to the rate center, and wireless providers aren&#8217;t either (after all, their users can roam anywhere). Numbers nominally associated with small rural rate centers (with few potential local users) are often assigned, then, to telemarketers, conference bridges, voice and fax mailboxes, and other users that need domestic numbers but don&#8217;t care where. Of course the call never goes anywhere near its rate center; carriers exchange traffic in regional centers called tandem offices, or, as VoIP providers do, over the Internet.</p><p>While Somos assigns the thousands blocks, the LNP database is now run by iconectiv, formerly Telcordia, previously Bellcore, and now owned by Koch Inc. Again this is a ministerial function carrying out policies dictated by the FCC. Originating telephone companies dip the call into the LNP database (iconectiv&#8217;s or one of several mirrors) and are directed towards a terminating carrier and an associated Location Routing Number, part of the phone number&#8217;s actual address.</p><h3>&#8230; but can be sold</h3><p>There&#8217;s now a business of buying and selling premium telephone numbers &#8220;individually&#8221;. Unlike 800-number brokerage, this is legal. The biggest player is probably Number Barn, a broker working with the major VoIP providers and CLECs that actually own the thousands blocks. So a carrier might pull a thousands-block and give the less desirable numbers to its regular or bulk customers while saving the -000, and combinations that spell out interesting words, for anyone who wants to pay. Some of the very desirable numbers, like the same 7 digits, so often seen being used by personal injury lawyers on billboards, may sell for about $50,000. One small carrier, FracTel, also seems to make it its business to order up new prefix codes that create the most valuable numbers, like 888 (for 888-8888) or 700 (for 700-0000).</p><p>Telemarketers and robocallers don&#8217;t always use real local numbers, as they&#8217;re not the ones receiving calls. There is a difference between those two categories, though. Legitimate telemarketing &#8211; calls made by real people &#8211; is not well loved but it&#8217;s legal. Telemarketers need a phone number to put in the Caller ID field. That can come from anywhere in the country. So they will often request a block of numbers from a CLEC or VoIP provider, and rotate through the numbers, returning them when they get put onto too many block lists. The carrier can then return the block to the available pool. This could of course be a problem for the customers of the next carrier that needs numbers in that rate center (often a cellular carrier) and who finds some of them still blocked here and there.</p><p>Robocallers often originate their calls outside of the United States and use shady VoIP service providers to enter the US network. The VoIP provider then labels the call with a domestic number, which is likely to be false. Often, it&#8217;s <em>neighborhooding</em>,<em> </em>showing a random number local to the called person that doesn&#8217;t even belong to a carrier involved with the call.</p><h2>STIR/SHAKEN helps a little</h2><p><a href="https://www.consumeraffairs.com/news/robocalls-fell-sharply-in-january-but-billions-still-reached-us-consumers-020926.html">Caller ID spoofing was rampant</a> before the industry came up with a secure protocol, STIR/SHAKEN, that allows originating carriers to attest that the originating number is valid. There are three levels of attestation that arrive with a call, at the terminating carrier, if it uses SIP, the VoIP call control standard:</p><p>&#183; A: Full attestation: <em>This is my customer. I gave them this telephone number.</em></p><p>&#183; B: Partial attestation: <em>This is my customer. This call originated on my network; however, I did not give them this telephone number.</em></p><p>&#183; C: Gateway attestation: <em>This call originated outside my network.</em></p><p>Only a call with A attestation can generally be trusted. Some phone carriers will then use the attestation in arriving calls to warn their customers of incoming spam calls or allow them to be blocked.</p><p>But while the FCC requires it to be used wherever practical, STIR/SHAKEN is not a panacea. For one thing, there may well be shady VoIP gateways that give an invalid A attestation to robocallers. It&#8217;s not legal but the FCC&#8217;s enforcement authority is quite limited, especially against foreigners and small LLCs that they may set up in the US. The FCC is starting to crack down on this, though, by adding wholesale &#8220;know your customer&#8221; rules for carriers to enforce, both for their customers and for other carriers that they accept calls from.</p><p>Many phones, especially landline, don&#8217;t display the attestation. An even bigger problem is that it only works on end-to-end, VOIP-to-VoIP calls. That does include 4G and 5G mobile networks, but it doesn&#8217;t include the legacy TDM telephone networks. In fact the major incumbent telephone carriers (such as AT&amp;T, Verizon, Lumen, Frontier, and Consolidated) refuse to allow many smaller carriers to interconnect using SIP, instead forcing them to connect via TDM links using Signaling System 7, which does not support STIR/SHAKEN, so the authentication method needed to mitigate robocalling isn&#8217;t carried end-to-end That&#8217;s even the case where they&#8217;ve upgraded their own networks to support SIP and IP carriage of voice. A docket pending at the FCC may in the future require them to allow competitors to connect with SIP, but that is likely to take a few years.</p><p>Unlike the Internet, the US telephone network is legally regulated by the FCC and to some extent the states, including the assignment of telephone numbers. But some of the regulations, however well intended, left open opportunities for abuse. Regulators, network operators, and customers all have a role in protecting their users and themselves from robocallers and other telephone frauds.</p>]]></content:encoded></item><item><title><![CDATA[Pig Butchering, Part 2: Anatomy of a Crypto Confidence Scam]]></title><description><![CDATA[Matt Piscitello]]></description><link>https://interisle.substack.com/p/pig-butchering-part-2-anatomy-of</link><guid isPermaLink="false">https://interisle.substack.com/p/pig-butchering-part-2-anatomy-of</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Fri, 15 May 2026 12:56:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!cr8y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1bbada1-0e1b-428f-a2c4-487ed8358985_778x424.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This article continues a series that explores a nefarious kind of cryptocurrency confidence and romance scam that criminals characterize as pig-butchering. We examine how these scammers establish trust with a target over time and then exploit that trust to lure their target into fraudulent investments.</p><h2>Chronology of a Long Scam</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cr8y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1bbada1-0e1b-428f-a2c4-487ed8358985_778x424.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cr8y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1bbada1-0e1b-428f-a2c4-487ed8358985_778x424.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cr8y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1bbada1-0e1b-428f-a2c4-487ed8358985_778x424.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cr8y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1bbada1-0e1b-428f-a2c4-487ed8358985_778x424.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cr8y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1bbada1-0e1b-428f-a2c4-487ed8358985_778x424.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cr8y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1bbada1-0e1b-428f-a2c4-487ed8358985_778x424.jpeg" width="778" height="424" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c1bbada1-0e1b-428f-a2c4-487ed8358985_778x424.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:424,&quot;width&quot;:778,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:183316,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/197848543?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1bbada1-0e1b-428f-a2c4-487ed8358985_778x424.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cr8y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1bbada1-0e1b-428f-a2c4-487ed8358985_778x424.jpeg 424w, https://substackcdn.com/image/fetch/$s_!cr8y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1bbada1-0e1b-428f-a2c4-487ed8358985_778x424.jpeg 848w, https://substackcdn.com/image/fetch/$s_!cr8y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1bbada1-0e1b-428f-a2c4-487ed8358985_778x424.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!cr8y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1bbada1-0e1b-428f-a2c4-487ed8358985_778x424.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>Image Generated by ChatGPT (5/4/2026)</em></p><p>Pig Butchering can be broken down into the following <a href="https://www.huntress.com/cybersecurity-101/topic/pig-butchering-scam">six steps</a>:</p><p>1. <strong>Chance Encounter</strong> Contact begins with an <em>accidental contact</em>: what appears to be a wrong-number text, connection request, or match on a dating app. The scammer&#8217;s profile is polished, often featuring an attractive, successful professional living in luxury abroad.</p><p>2. <strong>Building the Relationship:</strong> The scammer establishes trust by investing time and energy to build a relationship over weeks or months into what the target considers a uniquely meaningful connection.</p><p>3. <strong>Casual Investment Mention:</strong> When the scammer is confident that they have established trust, they make mention of substantial returns they&#8217;ve made on a cryptocurrency platform. They are not pushy. They frame it as something personal they can share with the target.</p><p>4. <strong>Guided First Investment:</strong> After the victim expresses curiosity, the scammer introduces the target to a <a href="https://dfpi.ca.gov/news/insights/pig-butchering-how-to-spot-and-report-the-scam/">crypto platform</a>. They encourage a small investment, and the platform is rigged so that that target sees immediate returns. The target is permitted to make a first small withdrawal to reinforce confidence in the investment opportunity. This is the &#8220;fattening of the pig&#8221; phase of the scam.</p><p>5. <strong>Escalating Deposits:</strong> Encouraged by initial gains, the victim deposits more: this is the &#8220;bleeding the pig&#8221; phase of the scam. The scammer will encourage the victim to invest everything they own (&#8220;bleeding the pig&#8221;).</p><p>6. <strong>The Exit:</strong> When the victim attempts a significant withdrawal, the platform invents obstacles &#8212; a tax requirement, a compliance hold, an anti-money-laundering fee. Each payment unlocks a new requirement. Eventually the platform either vanishes entirely or stops responding. The romantic contact disappears simultaneously. This is the &#8220;butchering&#8221; phase of the scam.</p><p>That&#8217;s how it works at a high level. But how do criminals actually pull it off? And how does it scale? How can someone pretend to be someone else for long enough to get money out of a victim? And how do they handle multiple victims?</p><h2>Chance Encounters</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Hgim!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d9d9a4b-1d56-4e0c-bc3f-8289fdd952e1_685x720.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Hgim!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d9d9a4b-1d56-4e0c-bc3f-8289fdd952e1_685x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Hgim!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d9d9a4b-1d56-4e0c-bc3f-8289fdd952e1_685x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Hgim!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d9d9a4b-1d56-4e0c-bc3f-8289fdd952e1_685x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Hgim!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d9d9a4b-1d56-4e0c-bc3f-8289fdd952e1_685x720.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Hgim!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d9d9a4b-1d56-4e0c-bc3f-8289fdd952e1_685x720.jpeg" width="685" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5d9d9a4b-1d56-4e0c-bc3f-8289fdd952e1_685x720.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:685,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:144091,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/197848543?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d9d9a4b-1d56-4e0c-bc3f-8289fdd952e1_685x720.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Hgim!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d9d9a4b-1d56-4e0c-bc3f-8289fdd952e1_685x720.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Hgim!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d9d9a4b-1d56-4e0c-bc3f-8289fdd952e1_685x720.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Hgim!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d9d9a4b-1d56-4e0c-bc3f-8289fdd952e1_685x720.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Hgim!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5d9d9a4b-1d56-4e0c-bc3f-8289fdd952e1_685x720.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em>Image Generated by ChatGPT (5/4/2026)</em></p><p><a href="https://www.phishingbox.com/glossary/pig-butchering">Contact begins</a> with what appears to be a wrong-number text, connection request, or match on a dating app. Scammers seek out potential victims using the Telegram and Signal apps as well.</p><p>The reach-out is casual, they act apologetically, and they start a friendly conversation to build rapport under the guise of &#8220;taking a sudden interest.&#8221;</p><p>The scammer&#8217;s profile is polished, often featuring a charming, attractive, successful professional living abroad. Their profile is usually designed in a way that appears legitimate without a keen eye or thorough inspection. Most importantly, the profile is designed to appeal to targets: someone the target admires and would be excited to know better.</p><div class="callout-block" data-callout="true"><p>Let&#8217;s dive deeper into the how the scam proceeds. The text posts and exchanges, photos,  and guides that we&#8217;ve scraped from the message platforms commonly used by the scammers illustrate the breadth and depth of the crypto confidence scam (under)world.</p></div>
      <p>
          <a href="https://interisle.substack.com/p/pig-butchering-part-2-anatomy-of">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Uses and Abuses of US Telephone Numbers Today ]]></title><description><![CDATA[Fred Goldstein]]></description><link>https://interisle.substack.com/p/uses-and-abuses-of-us-telephone-numbers</link><guid isPermaLink="false">https://interisle.substack.com/p/uses-and-abuses-of-us-telephone-numbers</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Tue, 12 May 2026 13:50:22 GMT</pubDate><content:encoded><![CDATA[<p>In this series, we will look at how telephone number assignments have evolved since the 1960s, accommodating competition and new applications, but also opening up opportunities for abuse and fraud.</p><h2>Once upon a time</h2><p>Once upon a time a telephone number was an address, belonging to a physical telephone line installed in a specific place. Numbers were assigned by local telephone companies and the most memorable numbers, often ending in 00, were saved for large multi-line business customers. Most telephone calls, at least outside of a limited local area, cost real money, so it wasn&#8217;t economical to make massive numbers of marketing calls hoping for an occasional bite.</p><p>It&#8217;s a different world today! While telephone competition has reduced the cost of a domestic call, and even some international calls, to zero, that has been accompanied by a large number of unwanted calls, both manned telemarketers and robocalls. The Federal Communications Commission has made some efforts to cut down on robocalling, but the telecriminals, often overseas, usually manage to defeat them.</p><p>Telephone numbers play an important role in these scams. Much of the time they&#8217;re not even used for their most obvious purpose, to <em>receive</em> calls, but to fill in the field that shows up as a recipient&#8217;s Caller ID. That primarily addresses the use of local numbers. Toll-free (codes reserved for &#8220;800 service&#8221; include 800 and, assigned sequentially as needed, 888, 877, etc. through 822) numbers are abused too, but primarily to receive calls intended for someone else. In this first part of a two-part series, we&#8217;ll look at the toll-free number business and how it can be abused.</p><h2>800 numbers became portable before geographic numbers</h2><p>When 800 numbers were first created in the 1960s, they were, like everything else in the telephone network, provided on a monopoly basis, mainly by AT&amp;T. In the 1980s, a few long distance competitors like MCI and Sprint were able to issue 800 numbers too, but using different prefix codes (e.g., 800-950 for MCI). Later, after seven local &#8220;Bell&#8221; carriers were split off from AT&amp;T and the long distance business became fully competitive, 800 numbers became portable &#8211; a customer could move them to their choice of carrier.</p><p>An 800 telephone number is no longer an <em>address</em>. It&#8217;s now a <em>name</em>. It leads to a carrier that serves that number. Hence it is really an entry in a database administered by a neutral party. For toll-free numbers that&#8217;s handled by Somos Inc. Somos itself descends from the Service Management System (SMS/800) created to administer 800 numbers when they first became portable. SMS/800 was originally owned by the seven Bell spinoffs when they were not allowed to provide long distance services. Somos now administers both the local number and 800 systems, but they are separate operations. Unlike domain names, telephone numbers are regulated both SMS/800 and NANPA (North American Numbering Plan Administrator) Somos businesses operate in the U.S. under strict FCC rules.</p><p>Somos doesn&#8217;t deal directly with users. On the SMS/800 side, they accredit Responsible Organizations, called RespOrgs, who assign toll-free numbers to users. RespOrgs pay SMS/800 about six cents per year per number. There are now hundreds of these, large and small, some inactive, and some who are rather shadowy.</p><h2>Who&#8217;s using all the 800 numbers?</h2><p>Given how few end users pay for telephone calls today, a toll-free number may seem almost like an anachronism. But they are essentially the only non-geographic numbers available to businesses, and thus they suggest that a business has a broad or nationwide scope. Some, of course, spell out a name on a keypad that still has letters on it, and these are often heavily advertised. They are also useful for large-scale customer calling, as the carriers who operate the services can dynamically distribute 8xx-number calls among different sites, route by time of day, and provide other value added services. Thousands of businesses make good use of these services.</p><p>But how did we end up with tens of millions of 8xx numbers in use, such that the FCC has gotten down to the 833 range? (After 822 there are no more 8xx codes left.) Unlike variable-length Internet domains, and for that matter, phone numbers in some parts of the world, American telephone numbers are a relatively small, fixed length of 10 digits length, behind country code 1. Yes, call centers do need these as nongeographic numbers, and that does account for several million numbers. And many small and medium-sized businesses still use them. On the other hand, it&#8217;s been a long time since pagers, which often used 800 numbers, have been popular.</p><p>One main answer to that seems to be misdial marketing, the telephone equivalent of typosquatting. Just as a company might claim intellectual property or copyrights to an Internet domain name that is close to a legitimate business&#8217; name, other players take, from a RespOrg, large numbers of 8xx numbers that are close to an actual company&#8217;s number. These may to be pointed towards phone sex lines, illegitimate businesses, or others who seek to victimize callers. This leads major 800-number users to also (defensively) grab as many nearby numbers as they can, to pick up the misdialed numbers themselves. A few RespOrgs even seem to specialize in this, notably Call Haven Partners. This practice is similar to how organizations defend brands by registering misspell domains. It&#8217;s cheap and legal, but more problematic since is accelerating the exhaustion of a fixed-length number.</p><p>What isn&#8217;t technically allowed is buying and selling 8xx numbers. Nor is &#8220;warehousing&#8221; them, when a RespOrg claims numbers that it doesn&#8217;t actually have a customer for. These rules give rise to workarounds, though, and deals are routinely made to obtain desired numbers.</p><p>Recognizing the value of these numbers, when the FCC opened 833 in 2019, they allowed the usual &#8220;land rush&#8221; to claim numbers. Several thousand were claimed by multiple parties, and they held a sealed-bid auction to allocate them. In the end, only a fraction of those received competitive bids and the auction proceeds totaled only a few hundred thousand dollars. It&#8217;s easier to play the numbers game when the numbers are practically free.</p><p>Hence the well-intentioned system of assigning toll-free telephone numbers has worked well enough for its major users but leaves that quite finite number space more heavily occupied than it should be, while customers can innocently reach malicious parties they never intended to. </p><p>In Part 2, we&#8217;ll look at how local telephone number assignments have evolved, and how they too can be abused.</p>]]></content:encoded></item><item><title><![CDATA[Allowlisting: Exception Handling for Blocked TLDs ]]></title><description><![CDATA[Dave Piscitello]]></description><link>https://interisle.substack.com/p/allowlisting-exception-handling-for</link><guid isPermaLink="false">https://interisle.substack.com/p/allowlisting-exception-handling-for</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Fri, 08 May 2026 13:03:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!S9r_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bc9af6-e6f6-4790-9165-51b462a208d4_990x445.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In this article, we discuss how to deal with blocklisting exception cases by using selective <em>allowlisting</em> to complement generalized blocklisting as part of an incident response.</p><h3>Applying Old School Firewall Best Practices to DNS blocklisting</h3><p>Like many first-generation firewall greybeards, I spent a fair bit of time testing and configuring network firewalls. The firewall admins whom I most respected were strong advocates of conservative outbound or <em>egress traffic filtering</em> policies. Over the years, I folded the accumulated wisdom of these admins into a <a href="https://www.securityskeptic.com/firewall-best-practices-egress-traffic-filtering/">egress traffic filtering best practices</a> article, where I explained how to establish the most secure egress traffic baseline:</p><p>The best way to configure egress traffic filtering policies is to begin with a DENY ALL outbound policy, packet filter, or firewall rule. This creates a &#8220;nothing leaves my network without explicit permission&#8221; security baseline. Next, add rules to allow authorized access to the external services identified in your egress traffic enforcement policy.</p><p>Explicit permission is the exception handling language for firewall traffic filtering, and you can apply it in cases where you&#8217;ve blocked a TLD.</p><p>In previous articles [<a href="https://interisle.substack.com/p/how-to-protect-against-phishy-top">1</a>][<a href="https://interisle.substack.com/p/how-to-protect-against-phishy-top=b41">2</a>], we explained that security conscious organizations sometimes choose to take extreme domain name blocklisting measures when they identify a threat and their tolerance for risk exceeds acceptable thresholds. In such scenarios, such organizations may employ stringent traffic filtering or blocklisting using their own security systems, but others may also use features of certain public, open resolvers to reduce risk. We then demonstrated how to block a TLD that is shown to exhibit significant cybercriminal activity, to reduce the threat surface.</p><h3>Allowlisting Scenario</h3><p>Since no one can practically begin by blocking the DNS entirely, blocking a TLD is essentially a baseline DENY ALL action on DNS traffic. But organizations should be prepared to handle exceptions should they make this choice.</p><p>For example, imagine that your healthcare organization falls victim to a malware attack that is disrupting critical services and is exfiltrating sensitive information. Your security team has <a href="https://www.securityskeptic.com/monitor-dns-traffic-and-you-just-might-catch-a-rat/">monitored outbound DNS traffic</a> and your event logs indicate that the infected systems are communicating with their command-control host using domains from a single TLD. Further analysis reveals that the domains appear to be part of a large network of registered domain names generated algorithmically (<a href="https://www.infoblox.com/blog/threat-intelligence/rdgas-the-next-chapter-in-domain-generation-algorithms/">RDGAs</a>). Containing and mitigating this threat quickly and thoroughly is your primary concern. You consult with your security team and staff and determine that no authorized or critical services are hosted at domains in this TLD so you and your team agree: blocklist it and continue with remediation and response.</p><p>With the command-control now unreachable from your network, you begin to identify infected devices from events in your DNS logs. As you restore services, you learn that you need to access one domain in this TLD to reach a supplier. You&#8217;re still remediating affected devices, so removing the block on the entire TLD at this time is premature.</p><p>In such a scenario, allowlisting is a practical option: this is a circumstance where explicit permission is appropriate for exception handling in traffic filtering or name resolution. Specifically, you can add an explicit ALLOW filter. This is the name resolution equivalent of what we called &#8220;punching a hole through your firewall&#8221;.</p><h3>How to Allowlist Domains</h3><p>In a previous <a href="https://interisle.substack.com/p/how-to-protect-against-phishy-top-b41">article</a>, we explained how to block a TLD using the <a href="https://nextdns.io">NextDNS</a> public, open resolver. NextDNS accommodates this via the <strong>Allowlist</strong> tab. In our allowlist scenario, we might add a single (wildcarded) domain:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!S9r_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bc9af6-e6f6-4790-9165-51b462a208d4_990x445.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!S9r_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bc9af6-e6f6-4790-9165-51b462a208d4_990x445.png 424w, https://substackcdn.com/image/fetch/$s_!S9r_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bc9af6-e6f6-4790-9165-51b462a208d4_990x445.png 848w, https://substackcdn.com/image/fetch/$s_!S9r_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bc9af6-e6f6-4790-9165-51b462a208d4_990x445.png 1272w, https://substackcdn.com/image/fetch/$s_!S9r_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bc9af6-e6f6-4790-9165-51b462a208d4_990x445.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!S9r_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bc9af6-e6f6-4790-9165-51b462a208d4_990x445.png" width="990" height="445" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3bc9af6-e6f6-4790-9165-51b462a208d4_990x445.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:445,&quot;width&quot;:990,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:71904,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/196894283?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bc9af6-e6f6-4790-9165-51b462a208d4_990x445.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!S9r_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bc9af6-e6f6-4790-9165-51b462a208d4_990x445.png 424w, https://substackcdn.com/image/fetch/$s_!S9r_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bc9af6-e6f6-4790-9165-51b462a208d4_990x445.png 848w, https://substackcdn.com/image/fetch/$s_!S9r_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bc9af6-e6f6-4790-9165-51b462a208d4_990x445.png 1272w, https://substackcdn.com/image/fetch/$s_!S9r_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3bc9af6-e6f6-4790-9165-51b462a208d4_990x445.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>With this exception filter in place, the organization should be able to reach the supply chain provider, but all other domains in the TLD remain blocked. While our previous articles only focused on using public, open resolvers, many security systems, e.g., firewalls, DNS servers or proxy devices, can accommodate both TLD blocking and exception handling.</p><h3>Summary</h3><p>In this post, we&#8217;ve used a compromise-and-breach scenario to explain what we mean by &#8220;extreme case&#8221; where blocking may be in play. In our scenario, a security team concluded that the welfare of the organization outweighed the benefits of universal domain resolvability, and the DENY ALL &#8220;staunched the bleeding&#8221; communications between the organization&#8217;s infected systems and the malware command-control were disrupted. The infected systems could be identified from DNS traffic logs and IT teams could begin malware removal, assess damage, and continue with restoring services. In this as in many scenarios, blocklisting is useful when employed temporarily. In persistent threat scenarios, it may be employed for as long as the threat condition persists.</p>]]></content:encoded></item><item><title><![CDATA[Cybercrime Reported in April 2026]]></title><description><![CDATA[Colin Strutt]]></description><link>https://interisle.substack.com/p/cybercrime-reported-in-april-2026</link><guid isPermaLink="false">https://interisle.substack.com/p/cybercrime-reported-in-april-2026</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Wed, 06 May 2026 15:09:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!SFYM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cfae50-63e9-414a-ad69-f6d784073b73_840x671.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Interisle publishes quarterly data about cybercrime activity (for phishing, malware, and spam) at the <a href="https://cybercrimeinfocenter.org">Cybercrime Information Center</a>.</p><p>Here we look at cybercrime activity for the month of April 2026. We point out anything that strikes us as particularly interesting in overall numbers as well as significant changes in ranking for Top Level Domains (TLDs), Registrars, and Hosting Networks.</p><h2>Overall numbers</h2><p>The April results showed a 27% increase in overall phishing reported compared to March.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!fSDF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832105dd-e3eb-4103-8e0d-7ebfd0d92ed1_488x298.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!fSDF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832105dd-e3eb-4103-8e0d-7ebfd0d92ed1_488x298.png 424w, https://substackcdn.com/image/fetch/$s_!fSDF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832105dd-e3eb-4103-8e0d-7ebfd0d92ed1_488x298.png 848w, https://substackcdn.com/image/fetch/$s_!fSDF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832105dd-e3eb-4103-8e0d-7ebfd0d92ed1_488x298.png 1272w, https://substackcdn.com/image/fetch/$s_!fSDF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832105dd-e3eb-4103-8e0d-7ebfd0d92ed1_488x298.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!fSDF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832105dd-e3eb-4103-8e0d-7ebfd0d92ed1_488x298.png" width="500" height="305.327868852459" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/832105dd-e3eb-4103-8e0d-7ebfd0d92ed1_488x298.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:298,&quot;width&quot;:488,&quot;resizeWidth&quot;:500,&quot;bytes&quot;:22849,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/196658827?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832105dd-e3eb-4103-8e0d-7ebfd0d92ed1_488x298.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!fSDF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832105dd-e3eb-4103-8e0d-7ebfd0d92ed1_488x298.png 424w, https://substackcdn.com/image/fetch/$s_!fSDF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832105dd-e3eb-4103-8e0d-7ebfd0d92ed1_488x298.png 848w, https://substackcdn.com/image/fetch/$s_!fSDF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832105dd-e3eb-4103-8e0d-7ebfd0d92ed1_488x298.png 1272w, https://substackcdn.com/image/fetch/$s_!fSDF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F832105dd-e3eb-4103-8e0d-7ebfd0d92ed1_488x298.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Spam reported in April increased 3% compared to March.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ewui!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31669add-7785-433c-8252-0d320e568d74_481x294.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ewui!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31669add-7785-433c-8252-0d320e568d74_481x294.png 424w, https://substackcdn.com/image/fetch/$s_!ewui!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31669add-7785-433c-8252-0d320e568d74_481x294.png 848w, https://substackcdn.com/image/fetch/$s_!ewui!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31669add-7785-433c-8252-0d320e568d74_481x294.png 1272w, https://substackcdn.com/image/fetch/$s_!ewui!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31669add-7785-433c-8252-0d320e568d74_481x294.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ewui!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31669add-7785-433c-8252-0d320e568d74_481x294.png" width="481" height="294" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/31669add-7785-433c-8252-0d320e568d74_481x294.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:294,&quot;width&quot;:481,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:22841,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/196658827?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31669add-7785-433c-8252-0d320e568d74_481x294.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ewui!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31669add-7785-433c-8252-0d320e568d74_481x294.png 424w, https://substackcdn.com/image/fetch/$s_!ewui!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31669add-7785-433c-8252-0d320e568d74_481x294.png 848w, https://substackcdn.com/image/fetch/$s_!ewui!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31669add-7785-433c-8252-0d320e568d74_481x294.png 1272w, https://substackcdn.com/image/fetch/$s_!ewui!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31669add-7785-433c-8252-0d320e568d74_481x294.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>While malware reported in April decreased 62% compared to March, it was still 10% over the amount reported in February.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Z_cc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f23a5e4-e37d-425e-9a69-dc7978684875_487x296.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Z_cc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f23a5e4-e37d-425e-9a69-dc7978684875_487x296.png 424w, https://substackcdn.com/image/fetch/$s_!Z_cc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f23a5e4-e37d-425e-9a69-dc7978684875_487x296.png 848w, https://substackcdn.com/image/fetch/$s_!Z_cc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f23a5e4-e37d-425e-9a69-dc7978684875_487x296.png 1272w, https://substackcdn.com/image/fetch/$s_!Z_cc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f23a5e4-e37d-425e-9a69-dc7978684875_487x296.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Z_cc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f23a5e4-e37d-425e-9a69-dc7978684875_487x296.png" width="487" height="296" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2f23a5e4-e37d-425e-9a69-dc7978684875_487x296.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:296,&quot;width&quot;:487,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:23156,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/196658827?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f23a5e4-e37d-425e-9a69-dc7978684875_487x296.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Z_cc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f23a5e4-e37d-425e-9a69-dc7978684875_487x296.png 424w, https://substackcdn.com/image/fetch/$s_!Z_cc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f23a5e4-e37d-425e-9a69-dc7978684875_487x296.png 848w, https://substackcdn.com/image/fetch/$s_!Z_cc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f23a5e4-e37d-425e-9a69-dc7978684875_487x296.png 1272w, https://substackcdn.com/image/fetch/$s_!Z_cc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f23a5e4-e37d-425e-9a69-dc7978684875_487x296.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Endpoint malware (targeting user devices) dropped by 56% and Malicious IP address malware (traffic injectors and attackware) dropped by 69% month over month. Internet of Things (IoT) malware increased by 6%.</p><h2>Phishing</h2><h4>TLDs</h4><ul><li><p>GARDEN, unranked in March, ranked in the Top 5 for phishing domains, phishing domain score, and malicious phishing domains</p></li><li><p>TOP grew over 750% in phishing domains and malicious phishing domains</p></li><li><p>BEER, WIN, and BOATS grew 1,200% in phishing domain score</p></li><li><p>CAM and TOP grew 700% in phishing domain score</p></li></ul><h4>Registrars</h4><ul><li><p>Spaceship (IANA ID 3862) increased 1,650% in phishing domains, 1,550% in phishing domain score, and 1,800% in malicious phishing domains</p></li><li><p>Unstoppable (IANA ID 4326) increased 1,100% in phishing domains, 950% in phishing domain score, and 900% in malicious phishing domains</p></li></ul><h4>Hosting Providers</h4><p>Five ASNs had a 10,000%+ growth in phishing attacks: </p><ul><li><p>Gigabit Hosting (AS55720)   </p></li><li><p>SpectralP (AS62068) </p></li><li><p>Advania Island (AS50613)</p></li><li><p>PLAY2GO (AS215439)   </p></li><li><p>Feo Prest (AS208137)</p></li></ul><h2>Spam</h2><h4>TLDs</h4><ul><li><p>GARDEN grew 33,000% spam domains, 16,000% spam domain score, and 36,000% in malicious spam domains</p></li><li><p>CO, MY, and TOP each grew 80% in spam domains</p></li><li><p>AUTOS grew 1,600% in spam domain score</p></li><li><p>BAR and TOWN each grew more than 600% in spam domain score, </p></li><li><p>WIKI and WIN each grew more than 450% in spam domain score</p></li><li><p>TOP grew 75% in malicious spam domains</p></li></ul><h4>Registrars</h4><ul><li><p>Realtime Register (IANA ID 839) increased 240% in spam domains</p></li><li><p>Spaceship (IANA ID 3862), NameMart (IANA ID 4162), and Cosmotown (IANA ID 1509) each grew more than 100% in spam domains</p></li><li><p>DOMAIN NAME (IANA ID 1527) grew 340% in spam domain score</p></li><li><p>Cosmotown (IANA ID 1509), Spaceship (IANA ID 3862), and Nicnames (IANA ID 4156) each grew over 100% in spam domain score</p></li><li><p>Four registrars had large growths in malicious spam domains: Realtime Register (320%), Spaceship (130%), NameMart (125%), and Cosmotown (130%)</p></li></ul><h4>Hosting Providers</h4><ul><li><p>Skycloud (AS7483) grew more than 34,000% in hosting spam content</p></li><li><p>CNSERVERS (AS40065) increased more than 200% and Dream Wave (AS18068) increased more than 190% in hosting spam content</p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SFYM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cfae50-63e9-414a-ad69-f6d784073b73_840x671.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SFYM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cfae50-63e9-414a-ad69-f6d784073b73_840x671.png 424w, https://substackcdn.com/image/fetch/$s_!SFYM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cfae50-63e9-414a-ad69-f6d784073b73_840x671.png 848w, https://substackcdn.com/image/fetch/$s_!SFYM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cfae50-63e9-414a-ad69-f6d784073b73_840x671.png 1272w, https://substackcdn.com/image/fetch/$s_!SFYM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cfae50-63e9-414a-ad69-f6d784073b73_840x671.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SFYM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cfae50-63e9-414a-ad69-f6d784073b73_840x671.png" width="840" height="671" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a8cfae50-63e9-414a-ad69-f6d784073b73_840x671.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:671,&quot;width&quot;:840,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:91880,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/196658827?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cfae50-63e9-414a-ad69-f6d784073b73_840x671.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SFYM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cfae50-63e9-414a-ad69-f6d784073b73_840x671.png 424w, https://substackcdn.com/image/fetch/$s_!SFYM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cfae50-63e9-414a-ad69-f6d784073b73_840x671.png 848w, https://substackcdn.com/image/fetch/$s_!SFYM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cfae50-63e9-414a-ad69-f6d784073b73_840x671.png 1272w, https://substackcdn.com/image/fetch/$s_!SFYM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa8cfae50-63e9-414a-ad69-f6d784073b73_840x671.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Malware</h2><p>The majority of malware reports from our feeds cite IP addresses rather than domain names.</p><p>There continues to be churn in the choice of ASNs that are reported for malware activity. Two ASNs were not ranked in the previous month, each having negligible malware in March but significant reports in April: Neterra (AS34224) and Weebly (AS27647). Amazon (AS14618) increased 170% and Shenzhen Tencent (AS45090) increased over 225% in reporting of hosting malware.</p><h2>Be Prepared</h2><p>Check out the lists above and the tables of the worst TLDs, gTLD registrars, and hosting networks (ASNs) at the most recent <a href="https://www.cybercrimeinfocenter.org/phishing-activity">Phishing Activity</a>, <a href="https://www.cybercrimeinfocenter.org/malware-activity">Malware Activity</a>, and <a href="https://www.cybercrimeinfocenter.org/spam-activity">Spam Activity</a> pages to determine which represent the most risk to your organization. </p><h2>Quarterly Results</h2><p>The quarterly phishing results for February to April 2026 will be published on the <a href="https://www.cybercrimeinfocenter.org/phishing-activity">Phishing Activity</a> page at the Cybercrime Information Center.</p>]]></content:encoded></item><item><title><![CDATA[Pig Butchering Scams: The Industrialization of Online Fraud]]></title><description><![CDATA[Matt Piscitello and Dave Piscitello]]></description><link>https://interisle.substack.com/p/pig-butchering-scams-the-industrialization</link><guid isPermaLink="false">https://interisle.substack.com/p/pig-butchering-scams-the-industrialization</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Tue, 28 Apr 2026 15:13:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!LiYi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d19391-3659-4e8f-aff7-cbe0de197aa3_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>This article is the first in a series that explores a particularly nefarious kind of romance scam called pig-butchering. Our goal with this series is to raise awareness of the nature, scale, and dangers of these scams.</p><h2>What is pig butchering?</h2><p>The term pig butchering is derived from a Chinese expression, &#8220;fattening a pig before you butcher it&#8221;. Criminals embraced this distasteful term to identify a form of online relationship and investment fraud where perpetrators cultivate fake romantic or social relationships with victims before persuading them to invest money into a fraudulent cryptocurrency or other investment scheme, or a request for money to assist with a medical or other emergency. Regrettably, <a href="https://dfpi.ca.gov/news/insights/pig-butchering-how-to-spot-and-report-the-scam/">pig butchering scam</a> is more popularly used than the more accurate term, <a href="https://www.ic3.gov/AnnualReport/Reports/2024_IC3Report.pdf">cryptocurrency confidence scam</a>, </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LiYi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d19391-3659-4e8f-aff7-cbe0de197aa3_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LiYi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d19391-3659-4e8f-aff7-cbe0de197aa3_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!LiYi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d19391-3659-4e8f-aff7-cbe0de197aa3_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!LiYi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d19391-3659-4e8f-aff7-cbe0de197aa3_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!LiYi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d19391-3659-4e8f-aff7-cbe0de197aa3_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LiYi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d19391-3659-4e8f-aff7-cbe0de197aa3_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d7d19391-3659-4e8f-aff7-cbe0de197aa3_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2354966,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/195746447?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d19391-3659-4e8f-aff7-cbe0de197aa3_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LiYi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d19391-3659-4e8f-aff7-cbe0de197aa3_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!LiYi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d19391-3659-4e8f-aff7-cbe0de197aa3_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!LiYi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d19391-3659-4e8f-aff7-cbe0de197aa3_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!LiYi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7d19391-3659-4e8f-aff7-cbe0de197aa3_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Pig butchering scams are so prolific &#8211; and the associated losses are so enormous - that some call it a <a href="https://www.group-ib.com/media-center/press-releases/scamdemic/">scamdemic</a>. Chainalysis reported that <a href="https://www.chainalysis.com/blog/2024-pig-butchering-scam-revenue-grows-yoy/">cryptocurrency scams received at least $9.9 billion on-chain in 2024</a>. The <a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">FBI Internet Crime Report</a> reported that in the US alone, complaint losses attributed to confidence and romance frauds exceeded $929M in 2025. For many cryptocurrency confidence scams reported, individual victims <a href="https://bankesb.com/pig-butchering-scams/#:~:text=Investment%20scams%2C%20known%20as%20%E2%80%9CPig,to%20a%20conversation%20about%20investing.">on average lost nearly $10,000</a>. Some have lost their life savings, retirement accounts, and home equity after taking out loans to invest more.</p><p>Potential victims are identified and targeted daily by scammers trying to get our attention, often operating out of <a href="https://www.trmlabs.com/resources/blog/unmasking-pig-butchering-scams-the-4-billion-crypto-scheme-preying-on-vulnerable-investors#:~:text=In%20Southeast%20Asia%2C%20organized%20crime,in%20countries%20like%20Cambodia%E2%80%8B.">Southeast Asia</a>. Historically, scams target susceptible users like the elderly who have low digital aptitude and an accumulation of wealth. They also prey on the lonely and isolated. At present, anyone who with money is an attractive target.</p><p>Criminal infrastructures operate these scams out of Southeast Asia, particularly Myanmar, Cambodia, and Laos. Victims are promised high-paying jobs relative to what they would earn in their home country, so they agree to travel to a foreign destination. Upon arrival, they are confined, essentially imprisoned, to a secure compound and forced to run the romance scams against their will.</p><h2>The series continues&#8230;</h2><p>In this series we&#8217;ll cover the following topics:</p><ul><li><p>How Does Pig Butchering Work?</p></li><li><p>Why Are Scammers So Effective? Who Gets Targeted and Why?</p></li><li><p>Role of Cryptocurrency: Why is Cryptocurrency So Attractive for Scammers?</p></li><li><p>Call to Action</p></li></ul><p>Some of the articles in this series may contain or cite &#8220;difficult&#8221; material, for example, scripts or how-to posts shared among romance scammers. These articles will be accessible only to paid members.</p>]]></content:encoded></item><item><title><![CDATA[How to Protect Against Phishy Top-level Domains, Part 2]]></title><description><![CDATA[Matt Piscitello and Dave Piscitello]]></description><link>https://interisle.substack.com/p/how-to-protect-against-phishy-top-b41</link><guid isPermaLink="false">https://interisle.substack.com/p/how-to-protect-against-phishy-top-b41</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Wed, 22 Apr 2026 12:59:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!jcF8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47177bd3-d6dd-4a11-acf9-313ca09f1ea0_808x455.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In a previous <a href="https://interisle.substack.com/p/how-to-protect-against-phishy-top">article</a>, we explained that risk-averse organizations routinely adopt TLD blocking as a defense against cyber-attacks. We emphasized why this is a last resort measure and offered examples of TLDs that were persistently associated with major phishing and scam attacks in CY2025. We explained how organizations or individuals could use Cisco&#8217;s OpenDNS service to adopt TLD blocking. Today, we&#8217;ll be taking a look at how NextDNS could be used to block TLDs.</p><h2>TLDs and Best Practices</h2><p>We explained in our first article that blocklisting a domain name or hyperlink (URL) is a commonly used to deter cyber attacks. We cited data from our Cybercrime Information Center to illustrate that criminals often single out specific Top-Level Domains when they register domains for their attacks.</p><p>&#183; <strong>Why Would You Block a TLD? </strong>Your individual or organization&#8217;s risk tolerance should identify a threshold for criminal domain registration activity, and any activity above that threshold makes that TLD untrustworthy. In such cases, you may conclude that blocking a TLD is necessary to manage risk.</p><p>&#183; <strong>When Would You Block a TLD?:</strong> When evidence indicates that your threshold has been crossed, and you conclude that further exposure to attack (risk) cannot be tolerated, you should consider TLD blocking.</p><p><strong>How to Block a TLD Using NextDNS</strong></p><p>Most users default to using a DNS server provided by their ISP, but these typically don&#8217;t provide customers with the means to block TLDs. You can instead configure your devices or access router to use <a href="https://nextdns.io">NextDNS</a>, a public, open resolver with TLD blocking capabilities.</p><p>For this article, we created a <strong>NEW </strong>free consumer account at https://nextdns.io. You can sign up for free and create a temporary 7-day account to test these settings yourself.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jcF8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47177bd3-d6dd-4a11-acf9-313ca09f1ea0_808x455.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jcF8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47177bd3-d6dd-4a11-acf9-313ca09f1ea0_808x455.png 424w, https://substackcdn.com/image/fetch/$s_!jcF8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47177bd3-d6dd-4a11-acf9-313ca09f1ea0_808x455.png 848w, https://substackcdn.com/image/fetch/$s_!jcF8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47177bd3-d6dd-4a11-acf9-313ca09f1ea0_808x455.png 1272w, https://substackcdn.com/image/fetch/$s_!jcF8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47177bd3-d6dd-4a11-acf9-313ca09f1ea0_808x455.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jcF8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47177bd3-d6dd-4a11-acf9-313ca09f1ea0_808x455.png" width="690" height="388.5519801980198" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47177bd3-d6dd-4a11-acf9-313ca09f1ea0_808x455.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:455,&quot;width&quot;:808,&quot;resizeWidth&quot;:690,&quot;bytes&quot;:89305,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/195028194?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47177bd3-d6dd-4a11-acf9-313ca09f1ea0_808x455.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jcF8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47177bd3-d6dd-4a11-acf9-313ca09f1ea0_808x455.png 424w, https://substackcdn.com/image/fetch/$s_!jcF8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47177bd3-d6dd-4a11-acf9-313ca09f1ea0_808x455.png 848w, https://substackcdn.com/image/fetch/$s_!jcF8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47177bd3-d6dd-4a11-acf9-313ca09f1ea0_808x455.png 1272w, https://substackcdn.com/image/fetch/$s_!jcF8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47177bd3-d6dd-4a11-acf9-313ca09f1ea0_808x455.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>To use NextDNS features, you must change the IP address of your DNS server to NextDNS servers, for example, 40.90.28.147 and 40.90.30.147 (Note: NextDNS server IP addresses may be different in your region). The NextDNS <a href="https://my.nextdns.io/cfb99f/setup">Setup Guide</a> provides detailed instructions for how to configure individual device (Android, iOS, Windows, ChromeOS, MacOS, Linux), browsers, or your router.</p><p>Once you&#8217;ve configured DNS servers, scroll to the Block Top-Level Domains (TLDs) feature under the <strong>Security</strong> Tab:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4wlO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82250c6d-89ea-4204-8db1-016a2babda88_773x96.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4wlO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82250c6d-89ea-4204-8db1-016a2babda88_773x96.png 424w, https://substackcdn.com/image/fetch/$s_!4wlO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82250c6d-89ea-4204-8db1-016a2babda88_773x96.png 848w, https://substackcdn.com/image/fetch/$s_!4wlO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82250c6d-89ea-4204-8db1-016a2babda88_773x96.png 1272w, https://substackcdn.com/image/fetch/$s_!4wlO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82250c6d-89ea-4204-8db1-016a2babda88_773x96.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4wlO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82250c6d-89ea-4204-8db1-016a2babda88_773x96.png" width="690" height="85.69210866752911" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/82250c6d-89ea-4204-8db1-016a2babda88_773x96.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:96,&quot;width&quot;:773,&quot;resizeWidth&quot;:690,&quot;bytes&quot;:19913,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/195028194?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82250c6d-89ea-4204-8db1-016a2babda88_773x96.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4wlO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82250c6d-89ea-4204-8db1-016a2babda88_773x96.png 424w, https://substackcdn.com/image/fetch/$s_!4wlO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82250c6d-89ea-4204-8db1-016a2babda88_773x96.png 848w, https://substackcdn.com/image/fetch/$s_!4wlO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82250c6d-89ea-4204-8db1-016a2babda88_773x96.png 1272w, https://substackcdn.com/image/fetch/$s_!4wlO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82250c6d-89ea-4204-8db1-016a2babda88_773x96.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kjRR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F755e0c45-01ce-4996-a360-370d8199b9de_770x224.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kjRR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F755e0c45-01ce-4996-a360-370d8199b9de_770x224.png 424w, https://substackcdn.com/image/fetch/$s_!kjRR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F755e0c45-01ce-4996-a360-370d8199b9de_770x224.png 848w, https://substackcdn.com/image/fetch/$s_!kjRR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F755e0c45-01ce-4996-a360-370d8199b9de_770x224.png 1272w, https://substackcdn.com/image/fetch/$s_!kjRR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F755e0c45-01ce-4996-a360-370d8199b9de_770x224.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kjRR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F755e0c45-01ce-4996-a360-370d8199b9de_770x224.png" width="690" height="200.72727272727272" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/755e0c45-01ce-4996-a360-370d8199b9de_770x224.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:224,&quot;width&quot;:770,&quot;resizeWidth&quot;:690,&quot;bytes&quot;:18178,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/195028194?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F755e0c45-01ce-4996-a360-370d8199b9de_770x224.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kjRR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F755e0c45-01ce-4996-a360-370d8199b9de_770x224.png 424w, https://substackcdn.com/image/fetch/$s_!kjRR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F755e0c45-01ce-4996-a360-370d8199b9de_770x224.png 848w, https://substackcdn.com/image/fetch/$s_!kjRR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F755e0c45-01ce-4996-a360-370d8199b9de_770x224.png 1272w, https://substackcdn.com/image/fetch/$s_!kjRR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F755e0c45-01ce-4996-a360-370d8199b9de_770x224.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Here, we&#8217;ve added the .TOP and .XIN TLDs. We reported our earlier <a href="https://interisle.substack.com/p/how-to-protect-against-phishy-top">post</a> that .TOP and .XIN had been persistently exploited by phishers throughout 2025 to support <a href="https://interisle.substack.com/p/unpaid-toll-scams-continue-in-2025">Unpaid Toll Scams</a>. Our Cybercrime Information Center quarterly reports show that both continue to be exploited by phishers and spammers in 1Q2026. A case can again be made to block .TOP or .XIN in their entirety because there&#8217;s a much higher chance of a domain registered in these smaller TLDs being reported as a phishing domain.</p><p>We&#8217;re again using a Windows PC, so we&#8217;ll open a command prompt to confirm our configuration. Again, <strong>do not visit a malicious website with the blocked TLD while testing</strong>. Instead, try it out safely, from command prompt:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!CMyz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77af3131-8e1d-4fd3-b36a-f88aaae31e16_381x174.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!CMyz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77af3131-8e1d-4fd3-b36a-f88aaae31e16_381x174.png 424w, https://substackcdn.com/image/fetch/$s_!CMyz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77af3131-8e1d-4fd3-b36a-f88aaae31e16_381x174.png 848w, https://substackcdn.com/image/fetch/$s_!CMyz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77af3131-8e1d-4fd3-b36a-f88aaae31e16_381x174.png 1272w, https://substackcdn.com/image/fetch/$s_!CMyz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77af3131-8e1d-4fd3-b36a-f88aaae31e16_381x174.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!CMyz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77af3131-8e1d-4fd3-b36a-f88aaae31e16_381x174.png" width="381" height="174" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/77af3131-8e1d-4fd3-b36a-f88aaae31e16_381x174.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:174,&quot;width&quot;:381,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:46072,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/195028194?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77af3131-8e1d-4fd3-b36a-f88aaae31e16_381x174.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!CMyz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77af3131-8e1d-4fd3-b36a-f88aaae31e16_381x174.png 424w, https://substackcdn.com/image/fetch/$s_!CMyz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77af3131-8e1d-4fd3-b36a-f88aaae31e16_381x174.png 848w, https://substackcdn.com/image/fetch/$s_!CMyz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77af3131-8e1d-4fd3-b36a-f88aaae31e16_381x174.png 1272w, https://substackcdn.com/image/fetch/$s_!CMyz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F77af3131-8e1d-4fd3-b36a-f88aaae31e16_381x174.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>We see that we&#8217;re using an NextDNS server IP address.</p><p>The 0.0.0.0 IP address returned looks unusual. The NextDNS <a href="https://help.nextdns.io/t/x2yfygh/test-dns-query">Test DNS Query?</a> page explains that NextDNS queries will return an IP address of 0.0.0.0 when it blocks a domain or TLD. Your device&#8217;s DNS client interprets this IP address as &#8220;unable to connect&#8221;. Here, 0.0.0.0 confirms that our TLD block is working.</p><h2>Benefits and Risks</h2><p>As we highlighted last time, TLDs like .TOP and .XIN have been persistently misused, and this has continued in 1Q2026, so you&#8217;re blocking domains that continue to resolve, remain on blocklists from CY2025, and thus remain potential threats. You&#8217;re preemptively blocking domains that may be registered by phishers for phishing attacks.</p><p>We&#8217;ll emphasize <strong>again </strong>that blocking a TLD is an all-or-nothing measure. Before you block <em>any</em> TLD, consider whether it is likely that you&#8217;d want to visit web sites in a TLD that you&#8217;d block. We again emphasize that you should do this as a security measure.</p><p>We don&#8217;t advocate blanket condemnation of any TLD. Our six years of accumulated phishing activity show that phishers are TLD agnostic &#8211; they&#8217;ll exploit a TLD so long as they are successful and profitable doing so. We&#8217;ve seen occasions where a TLD was exploited by phishers. Some operators have responded quickly, they revised their detection and mitigation techniques, and the phishers moved on to a different TLD.</p><p>Unfortunately, metrics for phishing or spam domain reports for some TLDs are so chronically bad that the risk of exposure to attack is too great to ignore. We recommend that if you do choose to block TLDs, periodically check our quarterly phishing <em>and </em>spam activity reports. Decide for yourself which TLDs are too phishy or spammy for your safety.</p><p></p>]]></content:encoded></item><item><title><![CDATA[Malware Trends: January 1 – March 31, 2026]]></title><description><![CDATA[Dave Piscitello]]></description><link>https://interisle.substack.com/p/malware-trends-january-1-march-31</link><guid isPermaLink="false">https://interisle.substack.com/p/malware-trends-january-1-march-31</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Thu, 16 Apr 2026 13:02:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XB9-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779af0b2-da63-42ff-b130-01373e91710f_532x382.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Results for <a href="https://www.cybercrimeinfocenter.org/malware-activity-numbers-october-december-2025">malware activity</a> for the period January 1 &#8211; March 31, 2026, are now available at the <a href="https://cyberrimeinfocenter.org/">Cybercrime Information Center</a>. They include top 20 rankings of Top-level Domain, Domain Registrar, and Hosting operator (by ASN) and aggregate <a href="https://www.cybercrimeinfocenter.org/records-repository">records</a> of operators with malware activity.</p><h2>Malicious IP Activity and Redirector Malware on the Rise</h2><p>Malicious IP activity reports (e.g., attackware and traffic injectors) dramatically increased during the current period. Fourteen previously unranked hosting networks appeared in our <a href="https://www.cybercrimeinfocenter.org/malware-activity-in-hosting-networks-january-march-2026">Ranking of Hosting Networks (ASNs) by Number of Malware Records</a>. ApateWeb, a resilient redirector campaign, reappeared with vengeance. Reports of malicious scanners probing email server vulnerability or injection opportunities increased significantly as well.</p><h2>Endpoint Malware</h2><p>We saw a modest quarter over quarter decrease (7%) in the number of endpoint devices reported for malware (<a href="https://www.cybercrimeinfocenter.org/malware-activity-quarter-over-quarter-numbers-january-march-2026">Key Statistics</a>). Here, we show the most reported malware types and within that type, the named malware most reported:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XB9-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779af0b2-da63-42ff-b130-01373e91710f_532x382.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XB9-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779af0b2-da63-42ff-b130-01373e91710f_532x382.png 424w, https://substackcdn.com/image/fetch/$s_!XB9-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779af0b2-da63-42ff-b130-01373e91710f_532x382.png 848w, https://substackcdn.com/image/fetch/$s_!XB9-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779af0b2-da63-42ff-b130-01373e91710f_532x382.png 1272w, https://substackcdn.com/image/fetch/$s_!XB9-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779af0b2-da63-42ff-b130-01373e91710f_532x382.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XB9-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779af0b2-da63-42ff-b130-01373e91710f_532x382.png" width="498" height="357.5864661654135" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/779af0b2-da63-42ff-b130-01373e91710f_532x382.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:382,&quot;width&quot;:532,&quot;resizeWidth&quot;:498,&quot;bytes&quot;:34163,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/194400897?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779af0b2-da63-42ff-b130-01373e91710f_532x382.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XB9-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779af0b2-da63-42ff-b130-01373e91710f_532x382.png 424w, https://substackcdn.com/image/fetch/$s_!XB9-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779af0b2-da63-42ff-b130-01373e91710f_532x382.png 848w, https://substackcdn.com/image/fetch/$s_!XB9-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779af0b2-da63-42ff-b130-01373e91710f_532x382.png 1272w, https://substackcdn.com/image/fetch/$s_!XB9-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F779af0b2-da63-42ff-b130-01373e91710f_532x382.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Last period, we <a href="https://interisle.substack.com/p/malware-trends-october-1-december">reported</a> a whopping increase in cryptocurrency malware. This period, we received over 40,000 reports of redirector malware, malicious software that exploits your browser behavior in a variety of ways; for example, criminal use click hijacking and search or error page redirection to direct users to criminally controlled advertising (<a href="https://www.malwarebytes.com/malvertising">malvertising</a>) pages or to enable click-fraud (fraudulent pay-per-click campaigns). Other criminals use redirectors, for example, ApateWeb, to lure victims to phishing pages.</p><p><a href="https://unit42.paloaltonetworks.com/apateweb-scareware-pup-delivery-campaign/">ApateWeb</a> was most reported redirector malware (campaign) for this period. Palo Alto Networks Unit42 researchers reported in 2024 that ApateWeb had used more than 130,000 domains to distribute scareware, potentially unwanted programs (PUPs), and other scam pages.</p><p>In 2025, <a href="https://unit42.paloaltonetworks.com/apateweb-scareware-pup-delivery-campaign/">threat research</a> by Unit42 associated ApateWeb with suspicious Blogspot links that redirected users to malicious websites. A later Aaron Meese <a href="https://www.validin.com/blog/malicious_blogspot_apateweb_campaign">post</a> explained the significance of token parameters in ApateWeb campaigns. Approximately half of the path elements of the URLs we associated with ApateWeb in our recent data included the string &#8220;api/users?token&#8221;, which is consistent with URL composition used in the 2025 blogspot campaign.</p><p>The ASNs with the most IP addresses associated with endpoint malware were:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xKS3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2fd5ff5-1aba-423a-b340-3d0376a50bae_577x166.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xKS3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2fd5ff5-1aba-423a-b340-3d0376a50bae_577x166.png 424w, https://substackcdn.com/image/fetch/$s_!xKS3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2fd5ff5-1aba-423a-b340-3d0376a50bae_577x166.png 848w, https://substackcdn.com/image/fetch/$s_!xKS3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2fd5ff5-1aba-423a-b340-3d0376a50bae_577x166.png 1272w, https://substackcdn.com/image/fetch/$s_!xKS3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2fd5ff5-1aba-423a-b340-3d0376a50bae_577x166.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xKS3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2fd5ff5-1aba-423a-b340-3d0376a50bae_577x166.png" width="501" height="144.13518197573657" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2fd5ff5-1aba-423a-b340-3d0376a50bae_577x166.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:166,&quot;width&quot;:577,&quot;resizeWidth&quot;:501,&quot;bytes&quot;:20090,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/194400897?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2fd5ff5-1aba-423a-b340-3d0376a50bae_577x166.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xKS3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2fd5ff5-1aba-423a-b340-3d0376a50bae_577x166.png 424w, https://substackcdn.com/image/fetch/$s_!xKS3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2fd5ff5-1aba-423a-b340-3d0376a50bae_577x166.png 848w, https://substackcdn.com/image/fetch/$s_!xKS3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2fd5ff5-1aba-423a-b340-3d0376a50bae_577x166.png 1272w, https://substackcdn.com/image/fetch/$s_!xKS3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2fd5ff5-1aba-423a-b340-3d0376a50bae_577x166.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>This latest evolution of ApateWeb again uses thousands of domains. The majority appear to be auto generated and bulk registered. Nearly 8,000 of the reported URLs were hosted at pages.dev (hosted by Cloudflare, Inc.).</p><h2>IoT Malware</h2><p>Internet of Things (IoT) malware &#8211; malware that targets sensors, wearables, appliances &#8211; decreased by 18% compared to the prior period. Mirai accounted for most of the fluctuation across the past three reporting periods.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QIQJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc740849b-1bc7-48d3-8a05-eac9e913ede6_531x202.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QIQJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc740849b-1bc7-48d3-8a05-eac9e913ede6_531x202.png 424w, https://substackcdn.com/image/fetch/$s_!QIQJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc740849b-1bc7-48d3-8a05-eac9e913ede6_531x202.png 848w, https://substackcdn.com/image/fetch/$s_!QIQJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc740849b-1bc7-48d3-8a05-eac9e913ede6_531x202.png 1272w, https://substackcdn.com/image/fetch/$s_!QIQJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc740849b-1bc7-48d3-8a05-eac9e913ede6_531x202.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QIQJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc740849b-1bc7-48d3-8a05-eac9e913ede6_531x202.png" width="499" height="189.82674199623352" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c740849b-1bc7-48d3-8a05-eac9e913ede6_531x202.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:202,&quot;width&quot;:531,&quot;resizeWidth&quot;:499,&quot;bytes&quot;:20066,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/194400897?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc740849b-1bc7-48d3-8a05-eac9e913ede6_531x202.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QIQJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc740849b-1bc7-48d3-8a05-eac9e913ede6_531x202.png 424w, https://substackcdn.com/image/fetch/$s_!QIQJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc740849b-1bc7-48d3-8a05-eac9e913ede6_531x202.png 848w, https://substackcdn.com/image/fetch/$s_!QIQJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc740849b-1bc7-48d3-8a05-eac9e913ede6_531x202.png 1272w, https://substackcdn.com/image/fetch/$s_!QIQJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc740849b-1bc7-48d3-8a05-eac9e913ede6_531x202.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>IP addresses in AS 4837, China Unicom, again hosted the most IoT Malware.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!BCQH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51dc9503-03bb-460a-bde2-f83536ec769d_539x169.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!BCQH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51dc9503-03bb-460a-bde2-f83536ec769d_539x169.png 424w, https://substackcdn.com/image/fetch/$s_!BCQH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51dc9503-03bb-460a-bde2-f83536ec769d_539x169.png 848w, https://substackcdn.com/image/fetch/$s_!BCQH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51dc9503-03bb-460a-bde2-f83536ec769d_539x169.png 1272w, https://substackcdn.com/image/fetch/$s_!BCQH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51dc9503-03bb-460a-bde2-f83536ec769d_539x169.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!BCQH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51dc9503-03bb-460a-bde2-f83536ec769d_539x169.png" width="501" height="157.08534322820037" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/51dc9503-03bb-460a-bde2-f83536ec769d_539x169.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:169,&quot;width&quot;:539,&quot;resizeWidth&quot;:501,&quot;bytes&quot;:21984,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/194400897?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51dc9503-03bb-460a-bde2-f83536ec769d_539x169.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!BCQH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51dc9503-03bb-460a-bde2-f83536ec769d_539x169.png 424w, https://substackcdn.com/image/fetch/$s_!BCQH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51dc9503-03bb-460a-bde2-f83536ec769d_539x169.png 848w, https://substackcdn.com/image/fetch/$s_!BCQH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51dc9503-03bb-460a-bde2-f83536ec769d_539x169.png 1272w, https://substackcdn.com/image/fetch/$s_!BCQH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F51dc9503-03bb-460a-bde2-f83536ec769d_539x169.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Malicious IPs (Attackware and Traffic Injectors)</h2><p>We saw an 82% increase in IP addresses reported for malicious traffic generation. The rise of the hosting provider CTG Server Ltd. to the top of our <a href="https://www.cybercrimeinfocenter.org/malware-activity-in-hosting-networks-january-march-2026">Ranking of Hosting Networks (ASNs) by Number of Malware Records</a> is largely the result of reports of malicious activity emanating from IP addresses in its delegations. The same is true for two previously unranked hosting providers: HostHatch, now #9 and Turing Group, now #13.</p><p>The top 5 ASNs with the most IP addresses identified as sources of malicious IP traffic:</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uTT2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28bdbbc7-4455-47b4-b6c4-0bc62a66f998_564x235.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uTT2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28bdbbc7-4455-47b4-b6c4-0bc62a66f998_564x235.png 424w, https://substackcdn.com/image/fetch/$s_!uTT2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28bdbbc7-4455-47b4-b6c4-0bc62a66f998_564x235.png 848w, https://substackcdn.com/image/fetch/$s_!uTT2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28bdbbc7-4455-47b4-b6c4-0bc62a66f998_564x235.png 1272w, https://substackcdn.com/image/fetch/$s_!uTT2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28bdbbc7-4455-47b4-b6c4-0bc62a66f998_564x235.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uTT2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28bdbbc7-4455-47b4-b6c4-0bc62a66f998_564x235.png" width="498" height="207.5" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/28bdbbc7-4455-47b4-b6c4-0bc62a66f998_564x235.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:235,&quot;width&quot;:564,&quot;resizeWidth&quot;:498,&quot;bytes&quot;:27299,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/194400897?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28bdbbc7-4455-47b4-b6c4-0bc62a66f998_564x235.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uTT2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28bdbbc7-4455-47b4-b6c4-0bc62a66f998_564x235.png 424w, https://substackcdn.com/image/fetch/$s_!uTT2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28bdbbc7-4455-47b4-b6c4-0bc62a66f998_564x235.png 848w, https://substackcdn.com/image/fetch/$s_!uTT2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28bdbbc7-4455-47b4-b6c4-0bc62a66f998_564x235.png 1272w, https://substackcdn.com/image/fetch/$s_!uTT2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28bdbbc7-4455-47b4-b6c4-0bc62a66f998_564x235.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h3>Attackware</h3><p>Reports identifying IMAP, Postfix, SSH and (generic) vulnerability scanners increased significantly.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dTqg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92538e74-4aae-4cf1-ab43-8d11a2a0e528_564x293.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dTqg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92538e74-4aae-4cf1-ab43-8d11a2a0e528_564x293.png 424w, https://substackcdn.com/image/fetch/$s_!dTqg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92538e74-4aae-4cf1-ab43-8d11a2a0e528_564x293.png 848w, https://substackcdn.com/image/fetch/$s_!dTqg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92538e74-4aae-4cf1-ab43-8d11a2a0e528_564x293.png 1272w, https://substackcdn.com/image/fetch/$s_!dTqg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92538e74-4aae-4cf1-ab43-8d11a2a0e528_564x293.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dTqg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92538e74-4aae-4cf1-ab43-8d11a2a0e528_564x293.png" width="504" height="261.82978723404256" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/92538e74-4aae-4cf1-ab43-8d11a2a0e528_564x293.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:293,&quot;width&quot;:564,&quot;resizeWidth&quot;:504,&quot;bytes&quot;:34251,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/194400897?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92538e74-4aae-4cf1-ab43-8d11a2a0e528_564x293.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dTqg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92538e74-4aae-4cf1-ab43-8d11a2a0e528_564x293.png 424w, https://substackcdn.com/image/fetch/$s_!dTqg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92538e74-4aae-4cf1-ab43-8d11a2a0e528_564x293.png 848w, https://substackcdn.com/image/fetch/$s_!dTqg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92538e74-4aae-4cf1-ab43-8d11a2a0e528_564x293.png 1272w, https://substackcdn.com/image/fetch/$s_!dTqg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92538e74-4aae-4cf1-ab43-8d11a2a0e528_564x293.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h3>Traffic Injectors</h3><p>We observed very little change in reported traffic injectors.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5Sw8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97213a6f-07ea-4056-b5b2-f1901cff22f2_554x173.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5Sw8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97213a6f-07ea-4056-b5b2-f1901cff22f2_554x173.png 424w, https://substackcdn.com/image/fetch/$s_!5Sw8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97213a6f-07ea-4056-b5b2-f1901cff22f2_554x173.png 848w, https://substackcdn.com/image/fetch/$s_!5Sw8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97213a6f-07ea-4056-b5b2-f1901cff22f2_554x173.png 1272w, https://substackcdn.com/image/fetch/$s_!5Sw8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97213a6f-07ea-4056-b5b2-f1901cff22f2_554x173.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5Sw8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97213a6f-07ea-4056-b5b2-f1901cff22f2_554x173.png" width="500" height="156.13718411552347" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/97213a6f-07ea-4056-b5b2-f1901cff22f2_554x173.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:173,&quot;width&quot;:554,&quot;resizeWidth&quot;:500,&quot;bytes&quot;:19749,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/194400897?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97213a6f-07ea-4056-b5b2-f1901cff22f2_554x173.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5Sw8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97213a6f-07ea-4056-b5b2-f1901cff22f2_554x173.png 424w, https://substackcdn.com/image/fetch/$s_!5Sw8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97213a6f-07ea-4056-b5b2-f1901cff22f2_554x173.png 848w, https://substackcdn.com/image/fetch/$s_!5Sw8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97213a6f-07ea-4056-b5b2-f1901cff22f2_554x173.png 1272w, https://substackcdn.com/image/fetch/$s_!5Sw8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97213a6f-07ea-4056-b5b2-f1901cff22f2_554x173.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><h2>Embrace the Suck?</h2><p>We found an interesting perspective of the benefits of embracing the suck in an <a href="https://www.operationmilitarykids.org/embrace-the-suck-meaning/">article</a> about this common military phrase:</p><blockquote><ul><li><p><strong>Discipline:</strong> This phrase can strengthen discipline among individuals and units so that they have the drive and motivation to overcome challenges and hardships.</p></li><li><p><strong>Mental toughness:</strong> This idea can encourage service people to push past barriers, both psychological and physical, to remain determined and resilient.</p></li><li><p><strong>Perseverance:</strong> This concept can foster an attitude of continuing forward and never giving up.</p></li><li><p><strong>Adaptability:</strong> This phrase can inspire people to understand that others have gone before them so they can improvise and adapt without giving in.</p></li></ul></blockquote><p>Cybersecurity professionals, especially those tasked with dealing with cybercriminal &#8220;suck&#8221; can relate. But take heart: the author notes that</p><blockquote><p style="text-align: center;">&#8220;The suck&#8221; implies a condition or situation that will eventually end.</p></blockquote>]]></content:encoded></item><item><title><![CDATA[How to Protect Against Phishy Top-level Domains ]]></title><description><![CDATA[Matt Piscitello, Dave Piscitello]]></description><link>https://interisle.substack.com/p/how-to-protect-against-phishy-top</link><guid isPermaLink="false">https://interisle.substack.com/p/how-to-protect-against-phishy-top</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Tue, 14 Apr 2026 14:02:25 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/e17a5abb-dd10-4e55-a3aa-b58237fb4f14_1049x514.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Blocklisting a domain name or hyperlink (URL) is a common and effective way to avoid becoming a victim of a phishing attack. Phishers and other cyber adversaries often single out specific Top-Level Domains when they register domains for their cyberattacks. And they do so repeatedly! Sometimes they register domains in one TLD at such an enormous scale that blocklisting domains or URLs individually is not enough to mitigate the attack, and more drastic action may effectively reduce risk. Today, we&#8217;ll explain how use filtering offered by a public, open resolver to reduce your risk to avoid phishy TLDs.</p><h2>What Are Top-Level Domains</h2><p>A Top-level Domain is the last part of a website&#8217;s hyperlink, e.g., the alphanumeric string at the end of that link; for example, in the link </p><p>https://amazon.com</p><p>, the TLD is .COM.</p><p>There are basically two types of TLDs:</p><p>&#183; National top-level domains: country code domains that are assigned to the nation states and their dependency territories; for example, .FR, .JP, .UK, or .US.</p><p>&#183; Generic top-level domains: domains with three or more letters indicating a community or general purpose, such as .EDU for education, .COM for commercial enterprise, and .BANK for verified financial institutions.</p><h2>Why and When Would You Block a TLD?</h2><p>TLD blocking is routinely adopted by risk-averse organizations as a defense against cyber-attacks. Blocking a TLD should always be a carefully made decision based on a practical risk assessment; for example, when evidence indicates that the volume of harmful messages from domains registered in that TLD significantly exceeds the likelihood that legitimate communications will be disrupted.</p><p>In a <a href="https://interisle.substack.com/p/using-malicious-registrations-as">November 2025 post</a>, we explained that &#8220;some TLDs persistently exhibit an alarmingly high percentage of malicious registrations - domains that were purposely registered by criminals for the purpose of conducting cybercrimes&#8221;.</p><p>Data provided at the Cybercrime Information Center (CIC) is useful in determining the risk profile of a TLD. For example, if you visit the page <a href="https://www.cybercrimeinfocenter.org/phishing-activity-in-tlds-august-october-2025">Phishing Activity in Top-level Domains August 1, 2025 - October 31, 2025</a> you&#8217;ll see that the .TOP TLD had over 160,000 phishing domains reported in just 3 months. If you scroll down to the <em>Ranking of TLDs by Phishing Domain Score</em> on the page <a href="https://www.cybercrimeinfocenter.org/phishing-activity-in-tlds-november-january-2026">Ranking of TLDs by Phishing Domain Score (November to January 2026)</a> you&#8217;ll find the .XIN TLD was #1 among TLDs with highest rates of phishing domains. In earlier posts, we reported that .TOP and .XIN had been persistently exploited by phishers throughout 2025 to support <a href="https://interisle.substack.com/p/unpaid-toll-scams-continue-in-2025">Unpaid Toll Scams</a>.</p><p>Given this long history of findings, a case can be made to block .TOP or .XIN in their entirety because there&#8217;s a much higher chance of a domain registered in these smaller TLDs being reported as a phishing domain.</p><p>When deciding, consider using our Cybercrime Information Center data in combination with other risk factors, including the probability that your users will need to interact with legitimate users of TLDs that are otherwise frequently abused by cybercriminals. If you conclude that the risk of your users falling victim to a phishing attack or other cybercriminal activity from a highly abused TLDs is unacceptably high, adopt measures to shield your users from accessing any domain registered in a highly phishy TLD.</p><p>Choosing to block a TLD is an appropriate security measure to mitigate cybercrime: for you, your family, or your organization. However, TLD blocking by an ISP or government has implications and impacts beyond security. We agree with the conclusions of the Internet Society (ISOC) that mandated <a href="https://www.internetsociety.org/blog/2026/04/dns-blocking-mind-the-unintended-consequences/">DNS level blocking at the country level</a> for content purposes is a counterproductive policy tool.</p><h2>&#8220;Cut bait and don&#8217;t get phished&#8221;</h2><p>Most users default to using the DNS server provided by their Internet service. These typically do not provide a means to block a TLD; however, you don&#8217;t have to use these. You can configure your devices or your access router to use a public, open resolver that provides a wildcard or explicit &#8220;block TLD&#8221; feature.</p><p>A public open resolver is a DNS server that anyone can use (hence &#8220;open&#8221;) to provide domain name to IP address resolution. For most of your Internet use, you&#8217;ll get the same name service whether you use your Internet provider&#8217;s DNS server or choose to configure your device to use an open resolver such as <a href="https://opendns.com">OpenDNS</a>. For example, in both configurations, if you type https://interisle.net into your browser, both servers will return the IP addresses for Interisle.net (e.g., 198.185.159.145), and your browser will attempt to connect to our web site.</p><p>However, OpenDNS offers many name and content filtering controls for consumers and enterprises in addition to basic name resolution that your ISP may not.</p><p>To begin using OpenDNS features, you must change the IP addresses of your DNS server to 208.67.222.222 and 208.67.220.220. You can do this at an individual PC or device, at your home network&#8217;s residential proxy (access router), or at your organization&#8217;s firewall, internet gateway, or router.</p><p>For this article, we created a free consumer account at opendns.com.</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!jd6a!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a80f2c-4afe-4a22-b59e-6b8d1c40f502_723x326.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!jd6a!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a80f2c-4afe-4a22-b59e-6b8d1c40f502_723x326.png 424w, https://substackcdn.com/image/fetch/$s_!jd6a!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a80f2c-4afe-4a22-b59e-6b8d1c40f502_723x326.png 848w, https://substackcdn.com/image/fetch/$s_!jd6a!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a80f2c-4afe-4a22-b59e-6b8d1c40f502_723x326.png 1272w, https://substackcdn.com/image/fetch/$s_!jd6a!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a80f2c-4afe-4a22-b59e-6b8d1c40f502_723x326.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!jd6a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a80f2c-4afe-4a22-b59e-6b8d1c40f502_723x326.png" width="501" height="225.90041493775934" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/27a80f2c-4afe-4a22-b59e-6b8d1c40f502_723x326.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:326,&quot;width&quot;:723,&quot;resizeWidth&quot;:501,&quot;bytes&quot;:62257,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/194187883?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a80f2c-4afe-4a22-b59e-6b8d1c40f502_723x326.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!jd6a!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a80f2c-4afe-4a22-b59e-6b8d1c40f502_723x326.png 424w, https://substackcdn.com/image/fetch/$s_!jd6a!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a80f2c-4afe-4a22-b59e-6b8d1c40f502_723x326.png 848w, https://substackcdn.com/image/fetch/$s_!jd6a!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a80f2c-4afe-4a22-b59e-6b8d1c40f502_723x326.png 1272w, https://substackcdn.com/image/fetch/$s_!jd6a!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a80f2c-4afe-4a22-b59e-6b8d1c40f502_723x326.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>Once the account was created, from the <strong>SETTINGS </strong>tab, we created our network profile :</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cFrz!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89be671d-94ad-469f-96b3-0ceee83c63b3_773x537.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cFrz!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89be671d-94ad-469f-96b3-0ceee83c63b3_773x537.png 424w, https://substackcdn.com/image/fetch/$s_!cFrz!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89be671d-94ad-469f-96b3-0ceee83c63b3_773x537.png 848w, https://substackcdn.com/image/fetch/$s_!cFrz!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89be671d-94ad-469f-96b3-0ceee83c63b3_773x537.png 1272w, https://substackcdn.com/image/fetch/$s_!cFrz!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89be671d-94ad-469f-96b3-0ceee83c63b3_773x537.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cFrz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89be671d-94ad-469f-96b3-0ceee83c63b3_773x537.png" width="561" height="389.72445019404915" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/89be671d-94ad-469f-96b3-0ceee83c63b3_773x537.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:537,&quot;width&quot;:773,&quot;resizeWidth&quot;:561,&quot;bytes&quot;:141374,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/194187883?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89be671d-94ad-469f-96b3-0ceee83c63b3_773x537.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cFrz!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89be671d-94ad-469f-96b3-0ceee83c63b3_773x537.png 424w, https://substackcdn.com/image/fetch/$s_!cFrz!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89be671d-94ad-469f-96b3-0ceee83c63b3_773x537.png 848w, https://substackcdn.com/image/fetch/$s_!cFrz!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89be671d-94ad-469f-96b3-0ceee83c63b3_773x537.png 1272w, https://substackcdn.com/image/fetch/$s_!cFrz!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89be671d-94ad-469f-96b3-0ceee83c63b3_773x537.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And then we selected <strong>Web Content Filtering</strong> from the dropdown menu.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sHvt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2352c8a-fe99-4b30-9bb0-01c9af5d01df_776x380.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sHvt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2352c8a-fe99-4b30-9bb0-01c9af5d01df_776x380.png 424w, https://substackcdn.com/image/fetch/$s_!sHvt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2352c8a-fe99-4b30-9bb0-01c9af5d01df_776x380.png 848w, https://substackcdn.com/image/fetch/$s_!sHvt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2352c8a-fe99-4b30-9bb0-01c9af5d01df_776x380.png 1272w, https://substackcdn.com/image/fetch/$s_!sHvt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2352c8a-fe99-4b30-9bb0-01c9af5d01df_776x380.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sHvt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2352c8a-fe99-4b30-9bb0-01c9af5d01df_776x380.png" width="615" height="301.159793814433" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c2352c8a-fe99-4b30-9bb0-01c9af5d01df_776x380.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:380,&quot;width&quot;:776,&quot;resizeWidth&quot;:615,&quot;bytes&quot;:86755,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/194187883?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2352c8a-fe99-4b30-9bb0-01c9af5d01df_776x380.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sHvt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2352c8a-fe99-4b30-9bb0-01c9af5d01df_776x380.png 424w, https://substackcdn.com/image/fetch/$s_!sHvt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2352c8a-fe99-4b30-9bb0-01c9af5d01df_776x380.png 848w, https://substackcdn.com/image/fetch/$s_!sHvt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2352c8a-fe99-4b30-9bb0-01c9af5d01df_776x380.png 1272w, https://substackcdn.com/image/fetch/$s_!sHvt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2352c8a-fe99-4b30-9bb0-01c9af5d01df_776x380.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>At the top of this page, you can customize content filters. At the bottom of this page, <strong>Manage Individual Domains</strong>, we add the TLD string (no &#8220;.&#8221;). Here, we blocked .TOP, and .XIN.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Rudd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397582f7-dfee-42fa-8549-5f52eea6674d_729x361.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Rudd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397582f7-dfee-42fa-8549-5f52eea6674d_729x361.png 424w, https://substackcdn.com/image/fetch/$s_!Rudd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397582f7-dfee-42fa-8549-5f52eea6674d_729x361.png 848w, https://substackcdn.com/image/fetch/$s_!Rudd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397582f7-dfee-42fa-8549-5f52eea6674d_729x361.png 1272w, https://substackcdn.com/image/fetch/$s_!Rudd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397582f7-dfee-42fa-8549-5f52eea6674d_729x361.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Rudd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397582f7-dfee-42fa-8549-5f52eea6674d_729x361.png" width="616" height="305.042524005487" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/397582f7-dfee-42fa-8549-5f52eea6674d_729x361.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:361,&quot;width&quot;:729,&quot;resizeWidth&quot;:616,&quot;bytes&quot;:69854,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/194187883?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397582f7-dfee-42fa-8549-5f52eea6674d_729x361.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Rudd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397582f7-dfee-42fa-8549-5f52eea6674d_729x361.png 424w, https://substackcdn.com/image/fetch/$s_!Rudd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397582f7-dfee-42fa-8549-5f52eea6674d_729x361.png 848w, https://substackcdn.com/image/fetch/$s_!Rudd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397582f7-dfee-42fa-8549-5f52eea6674d_729x361.png 1272w, https://substackcdn.com/image/fetch/$s_!Rudd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F397582f7-dfee-42fa-8549-5f52eea6674d_729x361.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>So, how do we test this filter? The answer is not, &#8220;look up a suspicious domain and check.&#8221; NEVER DO THAT.</p><p>Instead, to <em>safely </em>check if this worked, we open command/DOS window and used the <a href="https://www.nslookup.io">nslookup</a> or <a href="https://www.isc.org/dns-tools/#diagnostics">dig</a> utility to do a DNS query on a reported phishing page from our data sets. (This example was performed using Windows, but these tools are also available for Linux and MacOS).</p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZaCR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad2ab8d-8d3c-4f55-a911-373b8335f241_598x247.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZaCR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad2ab8d-8d3c-4f55-a911-373b8335f241_598x247.png 424w, https://substackcdn.com/image/fetch/$s_!ZaCR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad2ab8d-8d3c-4f55-a911-373b8335f241_598x247.png 848w, https://substackcdn.com/image/fetch/$s_!ZaCR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad2ab8d-8d3c-4f55-a911-373b8335f241_598x247.png 1272w, https://substackcdn.com/image/fetch/$s_!ZaCR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad2ab8d-8d3c-4f55-a911-373b8335f241_598x247.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZaCR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad2ab8d-8d3c-4f55-a911-373b8335f241_598x247.png" width="520" height="214.7826086956522" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8ad2ab8d-8d3c-4f55-a911-373b8335f241_598x247.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:247,&quot;width&quot;:598,&quot;resizeWidth&quot;:520,&quot;bytes&quot;:55276,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/194187883?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad2ab8d-8d3c-4f55-a911-373b8335f241_598x247.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZaCR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad2ab8d-8d3c-4f55-a911-373b8335f241_598x247.png 424w, https://substackcdn.com/image/fetch/$s_!ZaCR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad2ab8d-8d3c-4f55-a911-373b8335f241_598x247.png 848w, https://substackcdn.com/image/fetch/$s_!ZaCR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad2ab8d-8d3c-4f55-a911-373b8335f241_598x247.png 1272w, https://substackcdn.com/image/fetch/$s_!ZaCR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ad2ab8d-8d3c-4f55-a911-373b8335f241_598x247.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p>The output confirmed that we&#8217;re using an OpenDNS server&#8217;s IP address. We also see that an &#8220;answer&#8221; that includes an IP address of 146.112.61.104, which is a <a href="https://www.cisco.com/c/en/us/support/docs/security/umbrella/224799-learn-the-umbrella-block-page-ip.html">Cisco Umbrella Block Page IP Address</a>. A name resolution that is blocked by the Cisco Umbrella service, e.g., OpenDNS, returns this address, and OpenDNS may also return a block page instead of the page with the blocked content. This confirms that we&#8217;ve correctly configured OpenDNS to block the .XIN TLD.</p><p>Confident that our OpenDNS configuration was &#8220;operational&#8221;, we tried a few more reported phishing domains. From the STATS tab of the OpenDNS dashboard, we checked the logs. Here, we applied a filter on the log messages to view only requests (TLDs) that we blocklisted:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!h_9W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68d808b4-8ece-4a24-90e5-fe2953fa24f7_623x376.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!h_9W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68d808b4-8ece-4a24-90e5-fe2953fa24f7_623x376.png 424w, https://substackcdn.com/image/fetch/$s_!h_9W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68d808b4-8ece-4a24-90e5-fe2953fa24f7_623x376.png 848w, https://substackcdn.com/image/fetch/$s_!h_9W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68d808b4-8ece-4a24-90e5-fe2953fa24f7_623x376.png 1272w, https://substackcdn.com/image/fetch/$s_!h_9W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68d808b4-8ece-4a24-90e5-fe2953fa24f7_623x376.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!h_9W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68d808b4-8ece-4a24-90e5-fe2953fa24f7_623x376.png" width="607" height="366.34349919743175" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/68d808b4-8ece-4a24-90e5-fe2953fa24f7_623x376.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:376,&quot;width&quot;:623,&quot;resizeWidth&quot;:607,&quot;bytes&quot;:78980,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/194187883?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68d808b4-8ece-4a24-90e5-fe2953fa24f7_623x376.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!h_9W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68d808b4-8ece-4a24-90e5-fe2953fa24f7_623x376.png 424w, https://substackcdn.com/image/fetch/$s_!h_9W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68d808b4-8ece-4a24-90e5-fe2953fa24f7_623x376.png 848w, https://substackcdn.com/image/fetch/$s_!h_9W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68d808b4-8ece-4a24-90e5-fe2953fa24f7_623x376.png 1272w, https://substackcdn.com/image/fetch/$s_!h_9W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F68d808b4-8ece-4a24-90e5-fe2953fa24f7_623x376.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Note: enable stats and logs to view your network&#8217;s block history.</p><h2>How do I benefit?</h2><p>As tiring as the phrase may be, adversaries &#8211; especially phishers who are increasingly employing AI to enhance their deceptions and impersonations &#8211; are always one step ahead. OpenDNS allows users to be proactive rather than reactive about cybersecurity.</p><p>TLDs like .TOP and .XIN have been persistently misused, and it&#8217;s reasonable to assume that this may continue, so you&#8217;re not only blocking domains that are already reported for phishing (and thus remain active threats) but you&#8217;re preemptively blocking domains that may be registered by phishers for phishing attacks.</p><p style="text-align: justify;">For our experiment and post, we&#8217;ve only blocked 2 TLDs using OpenDNS. At present, the free version of OpenDNS limits accounts to 25 domains (or TLDs), but that&#8217;s enough to include the majority of the persistently phishy TLDs that we report at the Cybercrime Information Center&#8217;s quarterly <a href="https://www.cybercrimeinfocenter.org/phishing-activity">Phishing Activity</a> pages.</p><h2>What&#8217;s the risk?</h2><p>Blocking a TLD is an all or nothing measure. Before you block <em>any</em> TLD, consider whether it is likely that you&#8217;d want to visit web sites in a TLD that you&#8217;d block. We again emphasize that you should do this as a security measure.</p><p>We don&#8217;t advocate blanket condemnation of any TLD. Our six years of accumulated phishing activity show that phishers are TLD agnostic &#8211; they&#8217;ll exploit a TLD so long as they are successful and profitable doing so. We&#8217;ve seen occasions where a TLD was exploited by phishers: they quickly revised their detection and mitigation techniques and the phishers moved on to a different TLD. We recommend that if you do choose to block TLDs, periodically check our quarterly phishing <em>and </em>spam activity reports. Decide for yourself which TLDs are too phishy or spammy for your safety.</p>]]></content:encoded></item><item><title><![CDATA[Cybercrime Reported in March 2026]]></title><description><![CDATA[Colin Strutt]]></description><link>https://interisle.substack.com/p/cybercrime-reported-in-march-2026</link><guid isPermaLink="false">https://interisle.substack.com/p/cybercrime-reported-in-march-2026</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Wed, 08 Apr 2026 13:04:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!OLL6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19d2a92d-f903-4984-8af1-5f309f292618_552x343.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Interisle publishes quarterly data about cybercrime activity (for phishing, malware, and spam) at the <a href="https://cybercrimeinfocenter.org">Cybercrime Information Center</a>.</p><p>Here we look at cybercrime activity for the month of March 2026. We point out anything that strikes us as particularly interesting in overall numbers as well as significant changes in ranking for Top Level Domains (TLDs), Registrars, and Hosting Networks.</p><h2>Overall numbers</h2><p>The March results showed a 28% increase in overall phishing reported compared to February.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!OLL6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19d2a92d-f903-4984-8af1-5f309f292618_552x343.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!OLL6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19d2a92d-f903-4984-8af1-5f309f292618_552x343.png 424w, https://substackcdn.com/image/fetch/$s_!OLL6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19d2a92d-f903-4984-8af1-5f309f292618_552x343.png 848w, https://substackcdn.com/image/fetch/$s_!OLL6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19d2a92d-f903-4984-8af1-5f309f292618_552x343.png 1272w, https://substackcdn.com/image/fetch/$s_!OLL6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19d2a92d-f903-4984-8af1-5f309f292618_552x343.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!OLL6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19d2a92d-f903-4984-8af1-5f309f292618_552x343.png" width="500" height="310.68840579710144" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/19d2a92d-f903-4984-8af1-5f309f292618_552x343.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:343,&quot;width&quot;:552,&quot;resizeWidth&quot;:500,&quot;bytes&quot;:26715,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/193462784?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19d2a92d-f903-4984-8af1-5f309f292618_552x343.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!OLL6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19d2a92d-f903-4984-8af1-5f309f292618_552x343.png 424w, https://substackcdn.com/image/fetch/$s_!OLL6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19d2a92d-f903-4984-8af1-5f309f292618_552x343.png 848w, https://substackcdn.com/image/fetch/$s_!OLL6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19d2a92d-f903-4984-8af1-5f309f292618_552x343.png 1272w, https://substackcdn.com/image/fetch/$s_!OLL6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F19d2a92d-f903-4984-8af1-5f309f292618_552x343.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Spam reported in March increased 14% compared to February.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IRRH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcfa4c0-aad4-4b3a-8648-9f22fd78c3d5_547x340.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IRRH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcfa4c0-aad4-4b3a-8648-9f22fd78c3d5_547x340.png 424w, https://substackcdn.com/image/fetch/$s_!IRRH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcfa4c0-aad4-4b3a-8648-9f22fd78c3d5_547x340.png 848w, https://substackcdn.com/image/fetch/$s_!IRRH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcfa4c0-aad4-4b3a-8648-9f22fd78c3d5_547x340.png 1272w, https://substackcdn.com/image/fetch/$s_!IRRH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcfa4c0-aad4-4b3a-8648-9f22fd78c3d5_547x340.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IRRH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcfa4c0-aad4-4b3a-8648-9f22fd78c3d5_547x340.png" width="501" height="311.4076782449726" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bbcfa4c0-aad4-4b3a-8648-9f22fd78c3d5_547x340.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:340,&quot;width&quot;:547,&quot;resizeWidth&quot;:501,&quot;bytes&quot;:26646,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/193462784?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcfa4c0-aad4-4b3a-8648-9f22fd78c3d5_547x340.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IRRH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcfa4c0-aad4-4b3a-8648-9f22fd78c3d5_547x340.png 424w, https://substackcdn.com/image/fetch/$s_!IRRH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcfa4c0-aad4-4b3a-8648-9f22fd78c3d5_547x340.png 848w, https://substackcdn.com/image/fetch/$s_!IRRH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcfa4c0-aad4-4b3a-8648-9f22fd78c3d5_547x340.png 1272w, https://substackcdn.com/image/fetch/$s_!IRRH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbcfa4c0-aad4-4b3a-8648-9f22fd78c3d5_547x340.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Malware reported in March increased 189% compared to February and was just shy of the amount reported in January. Endpoint malware (targeting user devices) grew 440% and Malicious IP address malware (traffic injectors and attackware) increased over 200% month over month. Internet of Things (IoT) malware decreased by 10%.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qmIf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc33b3566-b909-414b-8144-275f83a0db42_548x342.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qmIf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc33b3566-b909-414b-8144-275f83a0db42_548x342.png 424w, https://substackcdn.com/image/fetch/$s_!qmIf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc33b3566-b909-414b-8144-275f83a0db42_548x342.png 848w, https://substackcdn.com/image/fetch/$s_!qmIf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc33b3566-b909-414b-8144-275f83a0db42_548x342.png 1272w, https://substackcdn.com/image/fetch/$s_!qmIf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc33b3566-b909-414b-8144-275f83a0db42_548x342.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qmIf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc33b3566-b909-414b-8144-275f83a0db42_548x342.png" width="500" height="312.04379562043795" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c33b3566-b909-414b-8144-275f83a0db42_548x342.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:342,&quot;width&quot;:548,&quot;resizeWidth&quot;:500,&quot;bytes&quot;:26929,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/193462784?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc33b3566-b909-414b-8144-275f83a0db42_548x342.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qmIf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc33b3566-b909-414b-8144-275f83a0db42_548x342.png 424w, https://substackcdn.com/image/fetch/$s_!qmIf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc33b3566-b909-414b-8144-275f83a0db42_548x342.png 848w, https://substackcdn.com/image/fetch/$s_!qmIf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc33b3566-b909-414b-8144-275f83a0db42_548x342.png 1272w, https://substackcdn.com/image/fetch/$s_!qmIf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc33b3566-b909-414b-8144-275f83a0db42_548x342.png 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Phishing</h2><p>Phishing domains and phishing domain score increased more than 100% in BOND, CFD, and LIFE; phishing domains also increased more than 100% in XYZ and MOM; phishing domain score also increased more than 100% in INK, HOMES, and BIO.</p><p>BOND, XYZ, CFD, SHOP, LIFE, MOM increased more than 100% in malicious phishing domain registrations.</p><p>The gTLD registrar NICENIC continues at the #1 spot for phishing domains reported, phishing domain score <em>and</em> for malicious phishing domain registrations.</p><p>The gTLD registrars Dominet (HK), West263, Aceville, and NameMart all have the dubious distinction of having at least 100% growth in phishing domains, phishing domain score, <em>and</em> malicious phishing domains. Onamae and URL Solutions had an increase of more than 100% for phishing domains and malicious phishing domains. Epik and URL Solutions increased more than 100% in phishing domain score and malicious phishing domains; Nicnames more than doubled in phishing domain score; Dynadot more than doubled in malicious phishing domains.</p><p>Ten previously unranked hosting providers appeared in the top 20 for phishing attacks reported in March 2026. We continue to observe phishing patterns moving from hosting network to hosting network. The highest increases were in Protocol Labs (AS40680), Network Solutions (AS19871), Dataline (AS49063), DigitalOcean (AS14061), FOP Hornostay Mykhaylo Ivanovych (AS212913), Interserver (AS26666), and Sucuri (AS30148).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!96qd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24850c58-0839-46fd-a05c-a3b133387239_600x662.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!96qd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24850c58-0839-46fd-a05c-a3b133387239_600x662.png 424w, https://substackcdn.com/image/fetch/$s_!96qd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24850c58-0839-46fd-a05c-a3b133387239_600x662.png 848w, https://substackcdn.com/image/fetch/$s_!96qd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24850c58-0839-46fd-a05c-a3b133387239_600x662.png 1272w, https://substackcdn.com/image/fetch/$s_!96qd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24850c58-0839-46fd-a05c-a3b133387239_600x662.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!96qd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24850c58-0839-46fd-a05c-a3b133387239_600x662.png" width="500" height="551.6666666666666" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/24850c58-0839-46fd-a05c-a3b133387239_600x662.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:662,&quot;width&quot;:600,&quot;resizeWidth&quot;:500,&quot;bytes&quot;:71941,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/193462784?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24850c58-0839-46fd-a05c-a3b133387239_600x662.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!96qd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24850c58-0839-46fd-a05c-a3b133387239_600x662.png 424w, https://substackcdn.com/image/fetch/$s_!96qd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24850c58-0839-46fd-a05c-a3b133387239_600x662.png 848w, https://substackcdn.com/image/fetch/$s_!96qd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24850c58-0839-46fd-a05c-a3b133387239_600x662.png 1272w, https://substackcdn.com/image/fetch/$s_!96qd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F24850c58-0839-46fd-a05c-a3b133387239_600x662.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Spam</h2><p>Despite a modest increase in spam detected in March compared to February, some TLDs exhibited a large growth in spam domains, particularly BOND which grew more than 1,000% and CFD, SBS, and HELP which each grew over 100% in both spam domains and malicious spam domains.</p><p>Using additional domain registration data courtesy of <a href="https://www.domaintools.com/">DomainTools</a>, we have been able to identify data for many more domains in TLDs that severely restrict access to domain registration data. We also observed significant increases in gTLD registrars of spam domains (10 of the top 20 registrars increased more than 100%), spam domain score (7 of the top 20 increased more than 100%), and malicious spam domains (11 of the top 20 registrars increased more than 100%).</p><p>Two ASNs had larger increases in hosted spam content: Kaopu Cloud HK Limited (AS138915) grew over 130% and Oracle (AS31898) grew 450% compared to February 2026.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QtUK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ce5c00-c6e2-438c-97ab-ba168edeb6e0_603x581.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QtUK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ce5c00-c6e2-438c-97ab-ba168edeb6e0_603x581.png 424w, https://substackcdn.com/image/fetch/$s_!QtUK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ce5c00-c6e2-438c-97ab-ba168edeb6e0_603x581.png 848w, https://substackcdn.com/image/fetch/$s_!QtUK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ce5c00-c6e2-438c-97ab-ba168edeb6e0_603x581.png 1272w, https://substackcdn.com/image/fetch/$s_!QtUK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ce5c00-c6e2-438c-97ab-ba168edeb6e0_603x581.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QtUK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ce5c00-c6e2-438c-97ab-ba168edeb6e0_603x581.png" width="501" height="482.7213930348259" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/95ce5c00-c6e2-438c-97ab-ba168edeb6e0_603x581.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:581,&quot;width&quot;:603,&quot;resizeWidth&quot;:501,&quot;bytes&quot;:65518,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/193462784?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ce5c00-c6e2-438c-97ab-ba168edeb6e0_603x581.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QtUK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ce5c00-c6e2-438c-97ab-ba168edeb6e0_603x581.png 424w, https://substackcdn.com/image/fetch/$s_!QtUK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ce5c00-c6e2-438c-97ab-ba168edeb6e0_603x581.png 848w, https://substackcdn.com/image/fetch/$s_!QtUK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ce5c00-c6e2-438c-97ab-ba168edeb6e0_603x581.png 1272w, https://substackcdn.com/image/fetch/$s_!QtUK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95ce5c00-c6e2-438c-97ab-ba168edeb6e0_603x581.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Malware</h2><p>The majority of malware reports from our feeds cite IP addresses rather than domain names.</p><p>As we observed with hosting networks for phishing, the ranking of hosting networks for malware showed a huge switch from hosting provider to hosting provider. Thirteen of the top 20 hosting networks were not previously ranked &#8211; each growing to between 5.7k and 26.7k reports of malware hosted in March 2026. As with phishing, it appears that malware actors are moving &#8220;opportunistically&#8221; from hosting provider to hosting provider.</p><h2>Be Prepared</h2><p>Check out the lists above and the tables of the worst TLDs, gTLD registrars, and hosting networks (ASNs) at the most recent <a href="https://www.cybercrimeinfocenter.org/phishing-activity">Phishing Activity</a>, <a href="https://www.cybercrimeinfocenter.org/malware-activity">Malware Activity</a>, and <a href="https://www.cybercrimeinfocenter.org/spam-activity">Spam Activity</a> pages to determine which represent the most risk to your organization. Network staff might consider blocking TLDs and ASNs that appear in our Phishing, Malware, and Spam &#8220;Favorites&#8221; tables to protect against inadvertent access to content that could result in harm, making exceptions only where there is a clear business case.</p><h2>Quarterly Results</h2><p>The quarterly malware activity results for January to March 2026 are published on the <a href="https://www.cybercrimeinfocenter.org/malware-activity">Malware Activity</a> page at the Cybercrime Information Center.</p><p></p>]]></content:encoded></item><item><title><![CDATA[How Criminals Can Exploit the Blockchain Name Space]]></title><description><![CDATA[Andy Malis]]></description><link>https://interisle.substack.com/p/how-criminals-can-exploit-the-blockchain</link><guid isPermaLink="false">https://interisle.substack.com/p/how-criminals-can-exploit-the-blockchain</guid><dc:creator><![CDATA[Interisle Consulting Group]]></dc:creator><pubDate>Mon, 06 Apr 2026 13:00:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FjqL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ade5f15-251b-4f57-bcb2-7bd9a50f00db_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>On March 19, <em>Wired</em> published an <a href="https://www.wired.com/story/us-takes-down-botnets-used-in-record-breaking-cyberattacks/">article</a> on how the US Justice Department and law enforcement agencies of collaborating countries took down the command-and-control of several botnets that were used for a huge number of cyberattacks, such as DDoS (<a href="https://www.cloudflare.com/learning/ddos/what-is-a-ddos-attack/">Distributed Denial of Service</a>) attacks (you can read the original <a href="https://www.justice.gov/usao-ak/pr/authorities-disrupt-worlds-largest-iot-ddos-botnets-responsible-record-breaking-attacks">DoJ press release</a> as well).</p><p>In this article, we&#8217;ll look at botnets generally and how they exploit the DNS. We&#8217;ll then look at a variation of the conventional botnet exploitation of the DNS that leverages the name space for <a href="https://en.wikipedia.org/wiki/Ethereum">Ethereum blockchain</a>.</p><h3>Botnets</h3><p>Botnets are large sets of compromised devices on the Internet that can be used for nefarious purposes by criminals. They are usually comprised of computers in homes and businesses that have been &#8220;taken over&#8221; as a result of not having been patched with the latest security updates or having had malware inadvertently downloaded onto them via a click on a link in a bad email or on a bad web page. The botnets disrupted by this action consisted mainly of &#8220;Internet of Things&#8221; devices such as routers, printers, TVs, networked appliances, and security cameras, which can be compromised and remotely operated by attackers because they are running software that hasn&#8217;t been updated by either the manufacturer or the end user to patch security holes (often, known vulnerabilities).</p><p>Criminals typically use a &#8220;command-and-control&#8221; (C&amp;C, or C2) infrastructure to manage their botnets. This is usually a device or devices controlled by the criminals and identified by the botnet devices via its domain name, usually one using long strings of random characters such as rrfd4ddl8u413.vvb2du7ed4es.top.</p><p>The C&amp;C is the head of the beast.</p><h3>Go for the Head</h3><p>The botnets disrupted by the DOJ pre-programmed the C&amp;C domain name into malware that was loaded into the compromised devices, and the devices used that domain name to look up the C&amp;C device&#8217;s IP address via the Domain Name System (DNS). Once the devices obtained the C&amp;C&#8217;s IP address, they identified themselves to the C&amp;C. Cyberattackers then directed the devices via the C&amp;C to execute attacks of various kinds.</p><p>In the case of a denial of service (DoS) attack, the devices would be directed to send a huge number of packets or connection requests to a particular IP address that the criminals wished to attack. They would amplify a DOS attack by ordering a large number of compromised devices to simultaneously send a large number of connection requests to the same device address. This is called a Distributed DOS (DDoS) attack. By amplifying the DoS attack in this manner, criminals would more effectively and quickly overrun (&#8216;flood&#8221;) the attack target with so much traffic that the target&#8217;s operation would be disrupted or shut down entirely. The aim of such attacks is often to disrupt the target victim&#8217;s operations, create financial losses for them, or demand extortion payments from them.</p><h2>Locating the Head</h2><p>One of the primary ways that law enforcement and online security professionals &#8220;take down&#8221; botnets is by locating the C&amp;C. They can then attempt to physically remove the C&amp;C from the Internet.</p><p>Physical seizure isn&#8217;t always possible; for example, the C&amp;C may be in a foreign country or even be a part of a foreign state apparatus. Law enforcement may request an Internet Service Provider (ISP) to disconnect the C&amp;C from the Internet. In such cases, law enforcement may seek international assistance (for example, through a mutual legal assistance treaty request, MLAT) and will coordinate with international partners to seize the C&amp;C infrastructure.</p><p>Note that jurisdiction matters. In some cases, none of these options are possible: the ISP doesn&#8217;t wish to cooperate, the C&amp;C is run by a foreign state that won&#8217;t recognize a (US) court order, or a foreign state will not agree to an MLAT.</p><p>In such cases, law enforcement will try to determine the domain name for the C&amp;C computer. There are a number of ways this can be done, but it&#8217;s usually done by a security professional examining either the actual malware in a compromised computer or IoT device or a trace of the packets sent to and from a compromised device to find the pre-programmed domain name.</p><p>Once they have determined the domain name, they can then request a domain registrar or registry (usually via a court order) that the domain name be removed from the Domain Name System. Once that happens, the compromised devices cannot communicate with the C&amp;C computer, and the criminals lose control of the botnet. In some cases, depending on the particular malware code, the C&amp;C domain name can then be pointed to a system controlled by law enforcement in order to shut down the malware in the compromised devices. Note that this course of action also relies on jurisdiction but in the case of this takedown, it was a resolvable matter.</p><h3>A Use Case: How Criminals Adapt</h3><p>A quote in the <em>Wired</em> article caught our attention. It stated:</p><p>&#8220;&#8230; cybersecurity researchers and law enforcement had engaged in a monthslong cat-and-mouse game with the botnet operators. At times &#8230; the operators used innovative tricks like moving their domain name system to the Ethereum blockchain to prevent the hijacking of their command-and-control servers.&#8221;</p><p>What is the Ethereum blockchain and how can it be used as an alternative to the DNS to avoid attempts by legal authorities to take down the botnet? This quote is a reference to the <a href="https://docs.ens.domains/learn/protocol/">Ethereum Name Service</a> (ENS), which is an alternative naming service based on the Ethereum blockchain, which is used for applications such as <a href="https://www.google.com/finance/beta/quote/ETH-USD">Ether cryptocurrency</a> itself and the naming service for the Ethereum blockchain network.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FjqL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ade5f15-251b-4f57-bcb2-7bd9a50f00db_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FjqL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ade5f15-251b-4f57-bcb2-7bd9a50f00db_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!FjqL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ade5f15-251b-4f57-bcb2-7bd9a50f00db_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!FjqL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ade5f15-251b-4f57-bcb2-7bd9a50f00db_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!FjqL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ade5f15-251b-4f57-bcb2-7bd9a50f00db_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FjqL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ade5f15-251b-4f57-bcb2-7bd9a50f00db_1024x1024.png" width="480" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6ade5f15-251b-4f57-bcb2-7bd9a50f00db_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:480,&quot;bytes&quot;:2076190,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://interisle.substack.com/i/192984966?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ade5f15-251b-4f57-bcb2-7bd9a50f00db_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FjqL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ade5f15-251b-4f57-bcb2-7bd9a50f00db_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!FjqL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ade5f15-251b-4f57-bcb2-7bd9a50f00db_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!FjqL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ade5f15-251b-4f57-bcb2-7bd9a50f00db_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!FjqL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6ade5f15-251b-4f57-bcb2-7bd9a50f00db_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>The ENS is usually used to identify crypto wallets that contain Ether cryptocurrency. <a href="https://www.coinbase.com/learn/wallet/what-is-a-wallet-address">Ethereum wallet addresses</a> are 42-character hexadecimal strings (such as 0x71c7a56ec7ab88b098defb7c1b7401b5f6d8a76f) that are used to send and receive cryptocurrency &#8211; you can think of them as being similar to a combination of bank account and routing numbers.</p><p>It&#8217;s even harder to memorize wallet addresses than IP addresses, so Ethereum created a naming service so that a user-friendly name, such as andywalletexample.eth, can be used to identify a particular crypto wallet. To send a crypto payment to Andy&#8217;s wallet, you only need to know the ENS name andywalletexample.eth rather than a long wallet address. The association between the ENS name and the wallet address is stored on the Ethereum blockchain, and an ENS name to wallet address lookup is similar in principle to (but differs technically from) a DNS lookup. Note that .ETH is not a DNS top-level domain</p><h3>How Cybercriminals Exploit ENS</h3><p>The ENS can be used to store more than just wallet addresses: it can be used to store any alphanumeric string, such as an IP address. This gets us back to the topic of the article. According to the Wired article, the botnet group(s) used the ENS in addition to (or instead of) the DNS in order to try to thwart law enforcement from dismantling their botnet(s) by taking control of their DNS domain name. They added &#8220;resiliency&#8221; by programming their malware to do an ENS lookup as well as (or instead of) a DNS lookup to find the IP address of the C&amp;C computer on the Internet.</p><p>To make it even more difficult to take down the botnet, the operators often don&#8217;t simply store the IP addresses directly in the ENS, but rather store encrypted addresses or use indirect lookups through other decentralized systems such as the <a href="https://en.wikipedia.org/wiki/InterPlanetary_File_System">InterPlanetary File System (IPFS)</a>.</p><p>There are several reasons why blockchain techniques are exploited by botnet operators. Blockchains are public resources that can be accessed from anywhere on the Internet, they are decentralized without any one single point of management that can be subject to law enforcement, and they are immutable records, meaning that once something has been added to it (such as an ENS name mapping), it can&#8217;t be removed, it can only be changed by the owner of the ENS name (the entity with the proper credentials, such as an Ethereum wallet address and the wallet&#8217;s pass phrase).</p><p>ENS exploitation is yet another example of the arms race between criminals and law enforcement on just one aspect of Internet malfeasance.</p>]]></content:encoded></item></channel></rss>