Dralvia Research
Archive/weekly

This week in phishing: who attackers impersonated, who they targeted, and what to check now

May 13, 2026

Reporting window: 2026-05-06 to 2026-05-13

Digest focus

Impersonated brands

Mixed attacker brand pressure

Common lure

Password reset or account verification prompt, Wallet recovery or seed-phrase lure

Teams to brief

SOC, incident-response, endpoint, and email-security teams, IAM, helpdesk, and cloud identity administrators

Scan window

33,569 URLs analyzed

Impersonated brands

Mixed attacker brand pressure

Common lure

Password reset or account verification prompt, Wallet recovery or seed-phrase lure

Teams to brief

SOC, incident-response, endpoint, and email-security teams, IAM, helpdesk, and cloud identity administrators

Attack path

Staged payload or malware-delivery links, Redirect chains into the final lure

Processing snapshot

In plain English, this was a day where attacker-controlled web content remained visible enough to analyze directly. That usually means the risk was not only raw feed noise, but also live lure pages, credential-harvesting flows, or impersonation infrastructure that a real user could encounter.

Feed records

79,517

Unique suspicious URLs

33,569

Enriched observations

11,829

Notable findings

183

Delivery URLs

29,115

What stood out

  • - Impersonation pressure centered on email identity login, credential harvesting. That means these themes appeared more often than others in the enriched portion of the window, not that every suspicious URL was part of the same campaign.
  • - Targeting pressure concentrated on identity, credential harvesting. In practice, this suggests attackers were reusing lure ideas and infrastructure around those sectors more often than around others.
  • - 29,115 of the unique suspicious URLs looked like delivery infrastructure. In practice, that means the URL or its feed context pointed more strongly to payload delivery or staged malware distribution than to a normal browsing flow.

What to watch for

  • - Direct download links ending in .sh, .ps1, .zip, especially when a user is pushed toward the file before any believable account, payment, update, or support workflow is established.
  • - Raw IP or IP:port download hosts serving scripts, binaries, or archives without a normal branded website around them. These are often disposable delivery points rather than legitimate customer-facing services.
  • - Lure pages or messages that lean on email identity login, credential harvesting themes while also pushing an urgent verification step, software update, wallet action, or downloaded archive. That blend of impersonation and delivery is often what gets people to click.

This Week In Phishing

Reporting window: 2026-05-06 to 2026-05-13

Impersonation activity remained active in this reporting window; Dralvia observed 4,051 suspicious pages across 33,569 unique suspicious URLs and 11,829 enriched observations.

Executive Takeaway

Attackers most often leaned on unknown. Common lures included password reset or account verification prompt. Defenders should review suspicious sign-ins, password resets, and MFA or account-verification events tied to the impersonated workflows.

Top Impersonation / Targeting Themes

  • Unknown (11328 observed pages)
  • Email, SSO, and account-login impersonation (370 observed pages)
  • Credential-harvesting login flows (120 observed pages)
  • Web3 wallet and token lures (11 observed pages)

Who Should Care

  • IAM, helpdesk, and Microsoft 365 / Google Workspace administrators
  • SOC, IAM, and incident-response teams
  • Web3 security, wallet-support, and community operations teams
  • IAM, helpdesk, and cloud identity administrators
  • SOC, endpoint, and email-security teams watching staged payload delivery

Common Lure Patterns

  • Password reset or account verification prompt (602 observed pages)
  • Wallet recovery or seed-phrase lure (11 observed pages)

Initial Access / Technique Notes

  • Credential-harvesting flows were present through login or password-entry pages.
  • Wallet-connect prompts appeared in suspicious pages, suggesting Web3 account-takeover or approval lures.
  • Seed-phrase or wallet-recovery harvesting signals were observed.
  • Suspicious delivery URLs pointed to staged payload, loader, or malware-delivery infrastructure.
  • Redirect chains were used to move users toward the final lure or delivery destination.

What Defenders Should Do This Week

  • review suspicious sign-ins, password resets, and MFA or account-verification events tied to the impersonated workflows
  • review browser, email, and proxy telemetry for unexpected .exe, archive, script, or direct-download activity
  • hunt for new messages, domains, and pages reusing the dominant theme around unknown
  • check redirect chains and short-lived destinations that move users from a lure page into a final login or download step

Analyst Notes

  • abuse pressure on .net
  • shared favicon reuse across suspicious pages
  • ASN overlap across suspicious infrastructure
  • Reused TLD pressure centered on .net, .lat, .com.
  • Delivery-tag overlap included elf, mozi, mirai.
  • Identity provider overlap included sso, google.
Address this risk

Products that stop it

This week in phishing: who attackers impersonated, who they targeted, and what to check now | Dralvia Research