This Week In Phishing
Reporting window: 2026-07-08 to 2026-07-15
Impersonation activity remained active in this reporting window; Dralvia observed 1,583 suspicious pages across 29,240 unique suspicious URLs and 2,431 enriched observations.
Processing Snapshot
- Feed records processed: 25,369,285
- Unique suspicious URLs: 29,240
- Enriched page observations: 2,431
- Suspicious pages: 1,583
- Notable observations: 497
- Delivery URLs: 25,151
- Source count: 2
What This Window Means
In plain English, this was a day where attacker-controlled web content remained visible enough to analyze directly. That usually means the risk was not only raw feed noise, but also live lure pages, credential-harvesting flows, or impersonation infrastructure that a real user could encounter.
What We Processed
- Dralvia ingested 25,369,285 raw feed records from urlhaus (25017985), openphish (351300). These are sightings and submissions from external feeds, so repeated sightings of the same target can appear more than once at this stage.
- After normalization and deduplication, those raw records collapsed into 29,240 unique suspicious URLs for the reporting window. This is the cleaner count of distinct suspicious destinations, not the noisier feed-ingest total.
- Dralvia completed 2,537 scans across 2,523 targets and extracted 2,431 enriched observations. 497 of those observations were strong enough to promote into analyst-facing notable findings.
Executive Takeaway
Attackers most often leaned on unknown such as aacc.edu, apus.edu. Common lures included password reset or account verification prompt. Defenders should review suspicious sign-ins, password resets, and MFA or account-verification events tied to the impersonated workflows.
Top Impersonation / Targeting Themes
- Unknown such as aacc.edu, apus.edu (2277 observed pages)
- Email, SSO, and account-login impersonation such as aacc.edu, apus.edu (118 observed pages)
- Credential-harvesting login flows such as aacc.edu, apus.edu (31 observed pages)
- E-commerce and delivery-brand impersonation such as aacc.edu, apus.edu (2 observed pages)
- Banking and payment-brand impersonation such as aacc.edu, apus.edu (1 observed pages)
What Stood Out
- Impersonation pressure centered on email identity login, credential harvesting. That means these themes appeared more often than others in the enriched portion of the window, not that every suspicious URL was part of the same campaign.
- Targeting pressure concentrated on identity, credential harvesting. In practice, this suggests attackers were reusing lure ideas and infrastructure around those sectors more often than around others.
- Frequently impersonated brands included aacc.edu, apus.edu, bitso.com. This reflects attacker brand abuse and imitation pressure, not a claim that those organizations were breached.
- 25,151 of the unique suspicious URLs looked like delivery infrastructure. In practice, that means the URL or its feed context pointed more strongly to payload delivery or staged malware distribution than to a normal browsing flow.
- The most common payload types were .zip, .sh, .exe. These extensions matter because they often map to shell scripts, archives, or Windows executables that are used as first-stage delivery mechanisms.
- Feed labeling was dominated by malware download. That does not prove every sample is identical, but it does indicate that the external feeds themselves mostly saw this window as a delivery-oriented or malware-oriented day.
- 15,323 delivery URLs were served directly from raw IP hosts rather than named domains. That pattern is common in throwaway hosting and short-lived delivery chains because it avoids the work of standing up a believable branded site.
Who Should Care
- IAM, helpdesk, and Microsoft 365 / Google Workspace administrators
- SOC, IAM, and incident-response teams
- E-commerce operations, trust-and-safety, and support teams
- Finance, treasury, fraud, and payment-operations teams
- IAM, helpdesk, and cloud identity administrators
Common Lure Patterns
- Password reset or account verification prompt (130 observed pages)
- Wallet recovery or seed-phrase lure (1 observed pages)
Initial Access / Technique Notes
- Credential-harvesting flows were present through login or password-entry pages.
- Wallet-connect prompts appeared in suspicious pages, suggesting Web3 account-takeover or approval lures.
- Suspicious delivery URLs pointed to staged payload, loader, or malware-delivery infrastructure.
- Redirect chains were used to move users toward the final lure or delivery destination.
- Template reuse suggests kit-based deployment across multiple suspicious pages.
How To Read The Numbers
- `Feed records processed` means the raw feed sightings Dralvia pulled in from urlhaus (25017985), openphish (351300). Multiple feeds, repeated submissions, or repeated sightings can all raise this number without creating a new destination.
- `Unique suspicious URLs` means the deduplicated set after normalization. In this window, 25,369,285 feed records reduced to 29,240 distinct suspicious URLs that were worth tracking as separate destinations.
- `Scans completed` means Dralvia actually inspected 2,537 targets or pages in this window instead of only storing feed hits.
- `Enriched observations` means Dralvia extracted usable page or infrastructure evidence from 2,431 scans, such as redirect behavior, page traits, hosting data, hashes, or classification signals.
- `Notable findings` means 497 observations were strong enough to promote into evidence worth showing to analysts, reports, or screenshots, instead of being left as background telemetry.
What To Watch For
- Direct download links ending in .zip, .sh, .exe, especially when a user is pushed toward the file before any believable account, payment, update, or support workflow is established.
- Raw IP or IP:port download hosts serving scripts, binaries, or archives without a normal branded website around them. These are often disposable delivery points rather than legitimate customer-facing services.
- Lure pages or messages that lean on email identity login, credential harvesting themes while also pushing an urgent verification step, software update, wallet action, or downloaded archive. That blend of impersonation and delivery is often what gets people to click.
- Watch for fake workflows abusing aacc.edu, apus.edu, bitso.com branding, especially when the user is pushed from a familiar-looking page into a download, wallet action, or secondary login step.
What Defenders Should Do This Week
- review suspicious sign-ins, password resets, and MFA or account-verification events tied to the impersonated workflows
- review browser, email, and proxy telemetry for unexpected .exe, archive, script, or direct-download activity
- hunt for new messages, domains, and pages reusing the dominant theme around unknown such as aacc.edu, apus.edu
- check redirect chains and short-lived destinations that move users from a lure page into a final login or download step
Next Steps For Teams
- Review browser, email, chat, and proxy telemetry for unexpected .zip, .sh, .exe downloads delivered outside normal software-distribution channels.
- Alert on direct-to-IP downloads and direct-to-IP redirects, especially when the destination serves an archive, script, or executable instead of a normal application page.
- Treat 'urgent update', 'verification required', and 'document package' download lures as possible first-stage delivery chains, not just harmless file-sharing events.
Analyst Notes
- abuse pressure on .com
- shared favicon reuse across suspicious pages
- ASN overlap across suspicious infrastructure
- Reused TLD pressure centered on .com, .dev, .xyz.
- Delivery-tag overlap included elf, mozi, smartloader.
- Identity provider overlap included sso, google, apple.