*Published: 10/2/2026* > Note: Still a running WIP! > **High-level Overview:** Phishing operators buy domains the way they buy anything else they plan to throw away, and they buy the cheapest one that will last long enough to do the job. That one decision explains most of the TLD abuse data. A handful of new generic TLDs sell their first year for under two dollars and charge seven to seventeen times that to renew, so the attacker registers, burns and replaces without ever seeing the second bill. Malware operators price things differently and lean on stolen reputation, and anyone who needs to stay up longer moves onto developer platforms, where blocking the parent domain would also block legitimate projects. Each piece below builds on the last, and the block list at the end falls out of the economics. ## Where the phishing actually sits Ranked by raw count, .com is the worst TLD on the internet. Interisle counted 869,180 domains reported for phishing in .com over a single year, more than double .top in second place [^1]. That number mostly reflects how big .com is, since 869,180 domains is only about 1 in 190 of the zone. Ranked by share of the zone, the picture flips. In .xin, 35,077 domains were reported for phishing in the same year, against a zone of 59,352, or about 59 for every 100 registered [^1]. The next tier down, .win, .icu and .garden, each sit around 16%. A defender who blocks by volume ends up staring at .com, which can never be blocked, while the zones where most of the domains exist only to phish go unnoticed. ![[tld_v3_volume_vs_rate.png]] ## Ephemeral domains From the attacker's side a phishing domain is a consumable with a short shelf life. It gets reported, it lands on a blocklist and it stops working, so the only question worth asking at purchase is what each one costs. **What a domain costs [^1][^2][^3]:** - Every TLD where more than 1 domain in 10 was reported for phishing sells its first year for under $5, and that group includes .pro alongside .xin, .win, .icu, .garden, .cfd and .help - .help, .rest, .mom, .lat, .garden, .homes, .click, .lol, .cfd, .sbs, .bond and .cyou all sell their first year for $1.54 to $1.80, against $11.08 for .com - In its 2025 study, Interisle found that 18 of the 25 new TLDs with the highest phishing rates offered non-promotional registrations under $2 at some registrar At $1.54 a domain, a phishing crew can buy seven of them for the price of one .com. When each domain only has to survive a few days, the cheap zone wins on cost per working day, and there is no reason to pay for reputation that the page will burn through anyway. ![[tld_v3_price_vs_phishing.png]] ## Nobody pays for year two The pricing on these zones is lopsided. The twelve zones listed above at $1.54 to $1.80 charge 7 to 17 times that to renew, so .cfd costs $1.80 to register and $15.96 to keep [^2]. For a legitimate owner that renewal price is the real price of the domain. For an attacker it rarely matters, because, as Spamhaus notes in its reputation updates, attackers use bulk-registered, disposable domains and burn through them as each one is detected and taken down [^4]. ![[tld_v3_first_year_vs_renewal.png]] **Burn and replace [^4][^1]:** - In six months, new .bond registrations came to 98.6% of the zone's total size, while Spamhaus considers 10 to 20% new domains in a zone unusually high - In .bond, .cyou, .xin, .cfd, .icu and .sbs, 94% to 99% of phishing domains were registered by the attacker for the purpose - In .com that figure is 66%, and in .cn it is 39%, because those zones still carry a large number of hacked legitimate sites In the cheap zones the attacker is the customer, paying the registry directly for every domain. In .com the attacker is far more often a squatter on someone else's site, paying nothing for the domain and getting its age and reputation for free. **Where the cheap zones land on blocklists [^5][^4]:** - About a third of the 5.2M .top domains registered in 2025 (1.79M) were blocklisted as malicious by April 2026, against 1 in 20 for .com - Most new .xin and .mobi registrations from 2025 met the same test, at 59% and 63% - Spamhaus calls 5% of a zone listed a red flag, and .cfd sits at 17.5%, .qpon at 12.2% and .icu at 9.7% ## A handful of sellers A short list of companies operates most of these zones. Shortdot SA runs .cfd, .sbs, .bond, .icu and .cyou, while XYZ.COM runs .xyz, .lol, .mom, .homes, .lat, .autos, .boats and .hair [^6]. On the retail side, the registrar NICENIC saw more phishing domains in a year (272,696) than the 237,724 gTLD domains it had under management [^7]. For a defender the concentration is useful, because a new TLD launched by the same registry is worth watching from its first day. ## Phishing and malware shop differently Malware delivery follows a different set of economics, and the abuse.ch data for July through October 2026 shows it plainly [^8][^9]. .com still leads by count with 9,187 malware domains, mostly ClearFake, ClickFix fake-CAPTCHA pages and unattributed loaders. Sekoia documents both ClearFake and ClickFix lures as JavaScript injected into compromised websites, mostly WordPress, so much of that count sits on hacked sites rather than bought ones [^10][^11]. An old domain carries a benign reputation built over time, which lets it go undetected longer once it turns malicious, and a new two-dollar .click domain has none of that, so loader operators would rather steal an old site than buy a new domain [^12]. Where malware operators do buy, they cluster by family. ACR Stealer accounts for 74 of the 177 .cfd domains and 103 of the 204 .cc domains, ClickFix fake-CAPTCHA pages account for 99 of the 162 on .icu and 109 of the 122 on .life, and .click carries 200 split mostly between the Remus and RevStealer infostealers and ClickFix [^8][^9]. Of the TLDs with an Interisle zone size, .garden and .mom carry the most malware for their size, with 135 and 49 malware domains for every 100,000 registered, while .com stays under 6 [^13]. Almost all of the .garden figure is a single ClearFake cluster, 87 of its 89 malware domains. **Cases that look worse or better than they are [^8][^9][^5][^14]:** - .xyz has the second most malware domains of any TLD at 1,544, but 995 of them are tagged MetaStealer - .xin had no malware domains in the 90-day window and .mobi had two, even though most of their new registrations were blocklisted, because their abuse is phishing, which abuse.ch does not track - .top carries less malware per domain than .com, and its domains show up in Smishing Triad's toll and postal SMS lures ## Why the platforms still win An attacker who needs a page to stay up for weeks has a better option than any TLD. Phishing on cloud and developer platforms sits on shared hostnames, so the attacker skips the registrar entirely and takes a subdomain on a platform that legitimate projects use every day. Kaspersky notes that this legitimate use complicates bulk blocking, because security teams risk cutting off non-malicious projects [^15]. **Where platform phishing sits [^15]:** - 24.9% of the phishing Kaspersky found on cloud platforms was on pages.dev, 13.8% on vercel.app, 13.7% on github.io, 10.0% on netlify.app, 7.8% on dweb.link, 5.3% on ipfs.io and 2.5% on workers.dev - Counting only the top ten platforms, at least 71% of it sits under .dev, .app and .io, the same TLDs that legitimate engineering teams work on every day None of these are TLDs, and blocking .dev or .app to stop them would break real work while missing the point. The control belongs on the hostname. ![[tld_v3_dev_platforms.png]] **What to block on platform hostnames [^15][^8][^9]:** - Subdomains first seen in the last 30 days on pages.dev, vercel.app, github.io, netlify.app, dweb.link, ipfs.io, workers.dev, wixstudio.com, webflow.io, azurewebsites.net and r2.dev, the last of which ranked third among platforms in the abuse.ch data - Project names that carry brand or security words, following illustrative patterns like captcha-verify-*.vercel.app - Subdomains that no one inside the organization has visited before ## What a defender does with this The economics give three different answers depending on the zone. Where most of the zone is attacker-bought and nothing legitimate depends on it, block the TLD. Where the zone has heavy abuse but also millions of real sites, block only the new registrations, since the attacker's domains are almost always young. Where the abuse rides on platform hostnames, leave the TLD open and block at the hostname. To make the first call repeatable, each TLD is compared against .com on four measures: the share of its 2025 registrations that Interisle found blocklisted as malicious by April 2026 [^5], the share of the zone reported for phishing [^1], the share Spamhaus lists [^4], and malware domains over the last 90 days for every 100,000 in the zone [^8][^9]. A TLD that is at least four times worse than .com on two or more of those lands in Tier 1A. Only .cfd and .icu are four times worse on all four, while .mom, .click, .life, .lat, .garden, .bid, .loan and .win are four times worse on every measure that has data for them. ![[tld_v3_tier1a_scorecard.png]] | Tier | Action | TLDs | |---|---|---| | 1A | Block | .top .cc .xin .cfd .cyou .icu .sbs .bond .vip .click .lat .mom .bid .mobi .pro .life .garden .qpon .loan .help .rest .win .ink | | 1B | Block | .zip .mov .su .tk .ml .ga .cf .gq .homes .boats .autos .hair .cam .best .wang | | 2 | Block domains under 30 days old | .shop .xyz .info .online .live .digital .cn .lol .site .store .space .fun .wiki .asia .biz .finance | | 3 | Leave open, block by hostname | .dev .app .io .me .co .ai .page .sh .gg .tv .link | | 4 | Leave open | .com .net .org .edu .gov .mil .int .us .uk .ca .au .de .fr .eu, plus the national TLDs you do business in | | Watch | Monitor only | .ru | ![[tld_v3_tier_map.png]] **The Tier 1B reasoning [^6][^16][^17][^18][^1][^19][^20]:** - .zip and .mov are real TLDs run by Charleston Road Registry, Google's registry operator, and they get blocked because mail, messaging and forum apps can turn a typed file name like invoices.zip into a clickable link - Quad9 blocked 195M unique .su names, more than in .com, and each drew only about three lookups, which is the pattern malware leaves when it generates throwaway domain names - The old Freenom zones (.tk, .ml, .ga, .cf, .gq) were free to register until Freenom stopped registrations in January 2023, and they have little legitimate use left - .homes, .best and .wang are small zones where 5% to 7% of domains were reported for phishing over the year, and .cam, .boats, .autos and .hair ran at 2% to 5% in May through July 2026, against about 0.5% for .com - .ru stays on watch because botnet command servers there swing with single campaigns, falling 83% from 3,726 to 630 in the first half of 2026 after a spike driven by ClearFake **Why .shop, .xyz and .info stay in Tier 2:** - Each is four times worse than .com on one measure at most, and each carries millions of real sites alongside the abuse Before any of this goes in, pull 30 days of DNS logs for the Tier 1 zones and allowlist whatever your environment actually depends on. Recheck the tiers every quarter, because the cheap zones shift fast, and from February through April to May through July 2026, domains reported for phishing on .cn rose 270% and on .icu 228% [^19]. ## Gaps - **No abuse rates for .dev, .app and .me:** if their own registrations turn out as abused as .xyz, Tier 3 also needs a block on newly registered domains - **.lol is only scored on malware:** at 33 malware domains for every 100,000 in its zone it runs about six times .com, but no phishing share or blocklist rate is published for it, so it stays in Tier 2 until one is [^4][^8][^9] - **No local view:** every environment depends on a few odd zones, and only its own DNS logs will show which ## References [^1]: Interisle CIC. *Phishing Activity in TLDs, 2025-05-01 to 2026-04-30*. [cybercrimeinfocenter.org](https://www.cybercrimeinfocenter.org/phishing-activity-in-tlds-may-april-2026) [^2]: Porkbun. *Public TLD pricing API*. Retrieved 2026-10-02. [api.porkbun.com](https://api.porkbun.com/api/json/v3/pricing/get) [^3]: Interisle Consulting Group. *Phishing Landscape 2025* (data 2024-05 to 2025-04). [PDF](https://static1.squarespace.com/static/63dbf2b9075aa2535887e365/t/68dfd315512a675a8fd94ee8/1759499029838/phishinglandscape2025.pdf) [^4]: Spamhaus. *Domain Reputation Update: October 2025 to March 2026*. Published 2026-04-15. [spamhaus.org](https://www.spamhaus.org/resource-hub/domain-reputation/domain-reputation-update-oct-2025-mar-2026/) [^5]: Interisle Consulting Group. *Malicious Registrations in the Domain Name Market: An Analysis of 2025 gTLD Registrations*. Published 2026-06. [interisle.net](https://interisle.net/cybercriminaldomaindemand) [^6]: IANA. *Root Zone Database*. Retrieved 2026-10-02. [iana.org](https://www.iana.org/domains/root/db) [^7]: Interisle CIC. *Phishing Activity in Domain Registrars, 2025-05 to 2026-04*. [cybercrimeinfocenter.org](https://www.cybercrimeinfocenter.org/phishing-activity-in-registrars-may-april-2026) [^8]: abuse.ch. *ThreatFox IOC database*, domain and URL IOCs 2026-07-04 to 2026-10-02. Retrieved 2026-10-02. [threatfox.abuse.ch](https://threatfox.abuse.ch/) [^9]: abuse.ch. *URLhaus database dump*, URLs 2026-07-04 to 2026-10-02. Retrieved 2026-10-02. [urlhaus.abuse.ch](https://urlhaus.abuse.ch/) [^10]: Sekoia TDR. *ClearFake's New Widespread Variant: Increased Web3 Exploitation for Malware Delivery*. Published 2025-03-18. [sekoia.com](https://www.sekoia.com/blog/clearfakes-new-widespread-variant-increased-web3-exploitation-for-malware-delivery) [^11]: Sekoia TDR. *Meet IClickFix: a widespread WordPress-targeting framework using the ClickFix tactic*. Published 2026-01-29. [sekoia.com](https://www.sekoia.com/blog/meet-iclickfix-a-widespread-wordpress-targeting-framework-using-the-clickfix-tactic) [^12]: Palo Alto Networks Unit 42. *Strategically Aged Domain Detection: Using DNS Traffic Trends*. Published 2021-12-29. [unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/strategically-aged-domain-detection/) [^13]: Malware rates divide abuse.ch distinct malware domains for 2026-07-04 to 2026-10-02 by Interisle CIC zone sizes for 2025-05 to 2026-04, so the two periods do not overlap and the rates are indicative. [^14]: Palo Alto Networks Unit 42. *Smishing Triad global smishing campaign*. Published 2025-10-23. [unit42.paloaltonetworks.com](https://unit42.paloaltonetworks.com/global-smishing-campaign/) [^15]: Kaspersky Securelist. *Phishers Are Hijacking Legitimate Cloud Infrastructure*. Published 2026-08-04. [securelist.com](https://securelist.com/cloud-platforms-in-phishing/120832/) [^16]: Intego, Joshua Long. *Expect .zip and .mov domains to be used in phishing and malware attacks*. Published 2023-05-18. [intego.com](https://www.intego.com/mac-security-blog/expect-zip-and-mov-domains-to-be-used-in-phishing-and-malware-attacks/) [^17]: Quad9. *H1 2026 Cyber Insights*. Published 2026-08-03. [quad9.net](https://quad9.net/news/blog/trends-h1-2026-cyber-insights/) [^18]: Interisle Consulting Group. *Phishing Landscape 2023*, Executive Summary. [interisle.net](https://www.interisle.net/PhishingLandscape2023-ExecutiveSummary.pdf) [^19]: Interisle CIC. *Phishing Activity: TLDs Quarter over Quarter, 2026-05 to 2026-07*. [cybercrimeinfocenter.org](https://www.cybercrimeinfocenter.org/phishing-activity-quarter-over-quarter-tlds-may-july-2026) [^20]: Spamhaus. *Botnet Threat Update: January to June 2026*. Published 2026-07-10. [spamhaus.org](https://www.spamhaus.org/resource-hub/botnet-c-c/botnet-threat-update-january-to-june-2026/)