This Week In Phishing
Reporting window: 2026-05-06 to 2026-05-13
Impersonation activity remained active in this reporting window; Dralvia observed 4,051 suspicious pages across 33,569 unique suspicious URLs and 11,829 enriched observations.
Executive Takeaway
Attackers most often leaned on unknown. Common lures included password reset or account verification prompt. Defenders should review suspicious sign-ins, password resets, and MFA or account-verification events tied to the impersonated workflows.
Top Impersonation / Targeting Themes
- Unknown (11328 observed pages)
- Email, SSO, and account-login impersonation (370 observed pages)
- Credential-harvesting login flows (120 observed pages)
- Web3 wallet and token lures (11 observed pages)
Who Should Care
- IAM, helpdesk, and Microsoft 365 / Google Workspace administrators
- SOC, IAM, and incident-response teams
- Web3 security, wallet-support, and community operations teams
- IAM, helpdesk, and cloud identity administrators
- SOC, endpoint, and email-security teams watching staged payload delivery
Common Lure Patterns
- Password reset or account verification prompt (602 observed pages)
- Wallet recovery or seed-phrase lure (11 observed pages)
Initial Access / Technique Notes
- Credential-harvesting flows were present through login or password-entry pages.
- Wallet-connect prompts appeared in suspicious pages, suggesting Web3 account-takeover or approval lures.
- Seed-phrase or wallet-recovery harvesting signals were observed.
- Suspicious delivery URLs pointed to staged payload, loader, or malware-delivery infrastructure.
- Redirect chains were used to move users toward the final lure or delivery destination.
What Defenders Should Do This Week
- review suspicious sign-ins, password resets, and MFA or account-verification events tied to the impersonated workflows
- review browser, email, and proxy telemetry for unexpected .exe, archive, script, or direct-download activity
- hunt for new messages, domains, and pages reusing the dominant theme around unknown
- check redirect chains and short-lived destinations that move users from a lure page into a final login or download step
Analyst Notes
- abuse pressure on .net
- shared favicon reuse across suspicious pages
- ASN overlap across suspicious infrastructure
- Reused TLD pressure centered on .net, .lat, .com.
- Delivery-tag overlap included elf, mozi, mirai.
- Identity provider overlap included sso, google.