The .vu Surge: How Threat Actors Are Exploiting Vanuatu's Domain Extension

KnowBe4 Threat Lab | Aug 28, 2026

Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal

Phishing infrastructure is built to be thrown away. When a domain gets blocklisted, scrutinized, or too hot to handle, the attackers don't stop. They just move. To them, a domain extension is just a cheap tool. They go wherever it is easiest to strike.

That pattern is visible in our own telemetry. In late 2024 and early 2025, KnowBe4 Threat Lab documented a 98% spike in phishing campaigns abusing .ru domains. 1,500 unique domains, over 13,000 malicious emails, with an average domain age of just 7.4 days.

The .ru advantage was jurisdictional: bulletproof registrars operated out of Russia, effectively immune to takedown requests, with registration policies that allowed fake identities and proxy registrations. This means infrastructure was genuinely hard to disrupt.

That window eventually slammed shut. As .ru domains flooded abuse reports and triggered detection alarms, security platforms flagged the entire extension as high-risk by default. Blocklists finally caught up, forcing the operation to relocate.

Eighteen months later, we are tracking a structurally identical playbook — now running through .vu, Vanuatu's country-code top-level domain. A 159% increase in phishing sites, 1,660 unique domains, and over 28,000K malicious emails were reported across April through July 2026.

The delivery mechanism evolved, yet the logic remains unchanged: hunt for a TLD with no reputation, open registration, and minimal scrutiny, build the infrastructure, and run hard until the window slams shut.

But the shift from .ru to .vu also marks a tactical evolution. The .ru advantage was resilience — infrastructure that was difficult to take down. The .vu advantage is invisibility — infrastructure that was difficult to detect in the first place. Attackers are not just replacing the domain extension. They are optimizing for a different failure mode in the defensive stack.

Key Findings

  • 159.6% increase in phishing sites abusing .vu domains, observed between April and July 2026
  • 1660 unique .vu domains identified and added to the KnowBe4 global blocklist as confirmed malicious indicators of compromise
  • Across the observation timeframe in KnowBe4 Defend and PhishER, 28,167 phishing emails with notable surges occurred between April - July 2026.
  • 99.9% of all malicious .vu entries appear in embedded URLs within email bodies, not in sender domains, meaning traditional sender-based filters alone will not catch this threat
  • The average age of the monitored .vu domains did not exceed 20 days.
  • The campaign primarily targets users in the United States across Education, Manufacturing, Government, Business and Financial sectors.
Figure1
Figure 1. Targeted sector distribution observed across the .vu phishing campaign, April – July 2026.

Why Does .vu Work? The Reputation Gap

The effectiveness of this campaign is less about technical sophistication and more about a structural gap in how email security tools evaluate new domains.

Most enterprise email security platforms assign risk scores based on observed domain history. A domain with no prior send activity, no blocklist entries and a valid TLS certificate will clear many first-pass filters. That is not a flaw in any single product; it reflects the inherent challenge of evaluating something with no track record.

The .vu extension accelerates this gap in several specific ways:

  • Low baseline scrutiny: Security vendors have historically seen almost no .vu traffic, so there is no TLD-level risk signal built into most threat feeds.
  • Open registration: No verification of registrant intent is required. A threat actor can register dozens of .vu domains in minutes across multiple registrars.
  • WHOIS privacy available: Registrant identity is routinely obscured, which slows abuse reporting and attribution.
  • Short operational windows by design: At an average domain age of 20 days, these domains are typically abandoned or rotated before a takedown can complete.
  • Valid TLS certificates: Let's Encrypt certificate issuance on .vu domains is trivially automated, giving phishing landing pages the padlock icon that many users associate with a legitimate site.

The .vu TLD: Open Registration

The .vu extension serves as the country-code top-level domain for Vanuatu. While regional suffixes like .au or .uk generally mandate a verified local presence or physical business nexus, .vu maintains an open registration policy accessible to any global entity. Major international registrars provide direct .vu procurement without residency constraints.

How It Started

Early signals were modest; a handful of user-reported emails with .vu links were mostly impersonating document-sharing and invoice notifications.

To evade detection systems targeting new domains, threat actors allowed their previously registered infrastructure to mature. As a result, email traffic grew consistently throughout May and June before security defences responded. By the time mitigation efforts commenced, the operation had already achieved substantial scale.

How Did the .vu Campaign Start?

The operation ran in four deliberate phases, each calibrated to stay ahead of defensive response times. Infrastructure was seeded weeks before volume escalated. This maturation strategy is designed to exploit the historical absence of .vu traffic in enterprise threat feeds.

April — Infrastructure Seeding

The observation period started with relatively low volumes however, the significant initial presence of domains suggested early infrastructure seeding rather than opportunistic exploitation.

May — Ramp-Up

Activity intensified with expanding traffic and scope. Despite increased scrutiny of the .vu extension, steady deployment of new infrastructure bypassed blocklist updates to sustain growth.

June — Scale-Up

Threat activity transitioned to systematic growth driven by coordinated registration batches rather than tactical changes. Spikes in mid-May and June confirm deliberate wave-based deployment.

July — Persistent Operations

Campaign activity remained stable throughout July, with established infrastructure enabling the operation to maintain a consistent volume of malicious emails. Steady domain registrations continued as proactive mitigation efforts and improved blocklists eventually achieved full efficacy, successfully neutralizing the infrastructure at scale.

Longitudinal data shows threat actors used seasoned infrastructure to bypass initial detection before countermeasures became fully effective.

Figure2
Figure 2. Monthly campaign volume and domain registration activity, April – July 2026. The May -July surge corresponds to peak interception of 28,167 fraudulent emails across the observation period.

Observed Phishing Templates

The emails observed in this campaign impersonate routine business interactions — document sharing requests, account verification alerts and corporate invitations — each crafted to create urgency without raising immediate suspicion. The examples below, captured from live campaign traffic, illustrate how closely these lures mirror legitimate communications employees encounter daily.

Figure3
Figure 3. Representative phishing lure emails observed in the .vu campaign. Lures impersonate document-sharing requests, account alerts, and corporate notifications with embedded .vu payload links in the email body.

Infrastructure Analysis

Figure4
Figure 4. Attack chain illustrates how a clean-sender email carrying a .vu link bypasses automated defenses, intercepts MFA session tokens in real time, and achieves full account takeover.

Analysis of infrastructure patterns and phishing kit artifacts hosted across these .vu domains reveals infrastructure engineered with a singular focus: credentials harvesting and bypassing multi-factor authentication.

The infrastructure acts as a covert, transparent relay to intercept authentication tokens in real time rather than relying on static credential-harvesting pages.

Registration patterns across the 1,660 malicious domains show strategic operational planning:

  • Coordinated wave deployment. Spikes in May and June indicate domains are registered in coordinated waves, deployed rapidly and rotated before defences can block them.

  • Naming to evade filters. Long, plausible business names and complex subdomain structures are deliberately generated to evade brand-protection filters.

  • Sender–payload separation. Only 1 of the 1,660 malicious .vu entries (0.1%) was ever used as a sending domain. The remaining 99.9% relied on clean or aged domains for delivery, with the malicious .vu link hidden in the email body — specifically to avoid triggering sender-reputation and domain-age filters.
Figure5
Figure 5. Examples of phishing pages hosted on .vu domains, captured during the campaign. Landing pages impersonate legitimate services to harvest credentials and session tokens via adversary-in-the-middle relay.
Associated .vu Domain (IOC) Phishing Lure Type
opsdn[.]vu Event Invitation / e-Card
golkppdmansachs[.]vu Invoice & Remittance Fraud
sofhoeixpefoundation[.]vu Purchase Agreement Lure
finnbusinetttsssalesptyltd[.]vu Document Share / SharePoint Lure
mozskwillafoundation[.]vu Payroll / Salary Adjustment
resiedcltechsrl[.]vu Voicemail Notification
serflrvicestationltd[.]vu QuickBooks / Payment Processing
globalwinnebagoindustriestheindependentp[.]mstsllc.vu Account Alert / Quarantine
umberio[.]vu Payment Dispute / Chargeback
sofxchneidercompany[.]vu Password / Credential Expiry

Top Registrars Used to register these domains

  • Dynadot - 884 domains
  • Sav.com - 770 domains

What End Users Should Watch For

Be highly suspicious of emails containing links ending in .vu, especially those involving urgent document signatures, package updates, account deactivations, voicemail alerts or unexpected HR/payroll notices.

Do not click the link. Instead, independently navigate to the organization's official website to verify the claim. Legitimate services will not lock you out for ignoring a single email, and real urgencies can be confirmed safely without using unsolicited links.

What Immediate Actions Defenders Should Take

  • Block .vu IoCs at the email gateway and DNS layer. Consider a blanket block on all .vu traffic if there is no legitimate business need.
  • Hunt retroactively in SIEM and email logs for .vu traffic from April 2026 onward, focusing on connections before late May that predated gateway coverage.
  • Tighten inbound URL scanning to detonate links at delivery — this campaign relies entirely on embedded URLs rather than attachments or spoofed senders.
  • Audit SPF, DKIM and DMARC configurations to reduce the attack surface and prevent downstream domain abuse.

Where KnowBe4 Can Help

No matter how complex the attack chain becomes, it all starts with an email. The redirects, the credential theft, it all depends on that first email landing in the inbox. This is where KnowBe4 helps stop the attack before it begins.

KnowBe4 Defend: Real-Time Behavioral AI

Email lures in these campaigns depend on social engineering to make the message appear legitimate before any payload is involved. Defend addresses this before the recipient acts.

Behavioral AI + NLP: Analyzes inbound mailflow patterns for anomalies, not file signatures. Defend catches deceptive characteristics that carry no payload and produce no hash.

Context-aware Warning Banners: Defend injects warning banners directly into the email before the recipient opens it. This interrupts the attacker's constructed illusion of legitimacy at the point the social engineering relies on it most: before the click, before the redirect chain begins.

PhishER Plus: Automated Global Eradication

When a recipient reports a suspicious message via the Phish Alert Button, PhishER Plus queues it for immediate analysis by KnowBe4 Threat Lab.

Global Threat Feed: Sourced from millions of users across the KnowBe4 network. When a phishing kit or campaign pattern surfaces anywhere in that network, associated indicators are added to the feed.

Cross-environment Blocking: Messages carrying those indicators are blocked across all connected environments before reaching other inboxes. A kit that hits one organization cannot run unrecognized against another.

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.