Lead Analysts: Prabhakaran Ravichandhiran and Jeewan Singh Jalal
Phishing infrastructure is built to be thrown away. When a domain gets blocklisted, scrutinized, or too hot to handle, the attackers don't stop. They just move. To them, a domain extension is just a cheap tool. They go wherever it is easiest to strike.
That pattern is visible in our own telemetry. In late 2024 and early 2025, KnowBe4 Threat Lab documented a 98% spike in phishing campaigns abusing .ru domains. 1,500 unique domains, over 13,000 malicious emails, with an average domain age of just 7.4 days.
The .ru advantage was jurisdictional: bulletproof registrars operated out of Russia, effectively immune to takedown requests, with registration policies that allowed fake identities and proxy registrations. This means infrastructure was genuinely hard to disrupt.
That window eventually slammed shut. As .ru domains flooded abuse reports and triggered detection alarms, security platforms flagged the entire extension as high-risk by default. Blocklists finally caught up, forcing the operation to relocate.
Eighteen months later, we are tracking a structurally identical playbook — now running through .vu, Vanuatu's country-code top-level domain. A 159% increase in phishing sites, 1,660 unique domains, and over 28,000K malicious emails were reported across April through July 2026.
The delivery mechanism evolved, yet the logic remains unchanged: hunt for a TLD with no reputation, open registration, and minimal scrutiny, build the infrastructure, and run hard until the window slams shut.
But the shift from .ru to .vu also marks a tactical evolution. The .ru advantage was resilience — infrastructure that was difficult to take down. The .vu advantage is invisibility — infrastructure that was difficult to detect in the first place. Attackers are not just replacing the domain extension. They are optimizing for a different failure mode in the defensive stack.
Key Findings
- 159.6% increase in phishing sites abusing .vu domains, observed between April and July 2026
- 1660 unique .vu domains identified and added to the KnowBe4 global blocklist as confirmed malicious indicators of compromise
- Across the observation timeframe in KnowBe4 Defend and PhishER, 28,167 phishing emails with notable surges occurred between April - July 2026.
- 99.9% of all malicious .vu entries appear in embedded URLs within email bodies, not in sender domains, meaning traditional sender-based filters alone will not catch this threat
- The average age of the monitored .vu domains did not exceed 20 days.
- The campaign primarily targets users in the United States across Education, Manufacturing, Government, Business and Financial sectors.
Why Does .vu Work? The Reputation Gap
The effectiveness of this campaign is less about technical sophistication and more about a structural gap in how email security tools evaluate new domains.
Most enterprise email security platforms assign risk scores based on observed domain history. A domain with no prior send activity, no blocklist entries and a valid TLS certificate will clear many first-pass filters. That is not a flaw in any single product; it reflects the inherent challenge of evaluating something with no track record.
The .vu extension accelerates this gap in several specific ways:
- Low baseline scrutiny: Security vendors have historically seen almost no .vu traffic, so there is no TLD-level risk signal built into most threat feeds.
- Open registration: No verification of registrant intent is required. A threat actor can register dozens of .vu domains in minutes across multiple registrars.
- WHOIS privacy available: Registrant identity is routinely obscured, which slows abuse reporting and attribution.
- Short operational windows by design: At an average domain age of 20 days, these domains are typically abandoned or rotated before a takedown can complete.
- Valid TLS certificates: Let's Encrypt certificate issuance on .vu domains is trivially automated, giving phishing landing pages the padlock icon that many users associate with a legitimate site.
The .vu TLD: Open Registration
The .vu extension serves as the country-code top-level domain for Vanuatu. While regional suffixes like .au or .uk generally mandate a verified local presence or physical business nexus, .vu maintains an open registration policy accessible to any global entity. Major international registrars provide direct .vu procurement without residency constraints.
How It Started
Early signals were modest; a handful of user-reported emails with .vu links were mostly impersonating document-sharing and invoice notifications.
To evade detection systems targeting new domains, threat actors allowed their previously registered infrastructure to mature. As a result, email traffic grew consistently throughout May and June before security defences responded. By the time mitigation efforts commenced, the operation had already achieved substantial scale.
How Did the .vu Campaign Start?
The operation ran in four deliberate phases, each calibrated to stay ahead of defensive response times. Infrastructure was seeded weeks before volume escalated. This maturation strategy is designed to exploit the historical absence of .vu traffic in enterprise threat feeds.
April — Infrastructure Seeding
The observation period started with relatively low volumes however, the significant initial presence of domains suggested early infrastructure seeding rather than opportunistic exploitation.
May — Ramp-Up
Activity intensified with expanding traffic and scope. Despite increased scrutiny of the .vu extension, steady deployment of new infrastructure bypassed blocklist updates to sustain growth.
June — Scale-Up
Threat activity transitioned to systematic growth driven by coordinated registration batches rather than tactical changes. Spikes in mid-May and June confirm deliberate wave-based deployment.
July — Persistent Operations
Campaign activity remained stable throughout July, with established infrastructure enabling the operation to maintain a consistent volume of malicious emails. Steady domain registrations continued as proactive mitigation efforts and improved blocklists eventually achieved full efficacy, successfully neutralizing the infrastructure at scale.
Longitudinal data shows threat actors used seasoned infrastructure to bypass initial detection before countermeasures became fully effective.
Observed Phishing Templates
The emails observed in this campaign impersonate routine business interactions — document sharing requests, account verification alerts and corporate invitations — each crafted to create urgency without raising immediate suspicion. The examples below, captured from live campaign traffic, illustrate how closely these lures mirror legitimate communications employees encounter daily.
Infrastructure Analysis
Analysis of infrastructure patterns and phishing kit artifacts hosted across these .vu domains reveals infrastructure engineered with a singular focus: credentials harvesting and bypassing multi-factor authentication.
The infrastructure acts as a covert, transparent relay to intercept authentication tokens in real time rather than relying on static credential-harvesting pages.
Registration patterns across the 1,660 malicious domains show strategic operational planning:
- Coordinated wave deployment. Spikes in May and June indicate domains are registered in coordinated waves, deployed rapidly and rotated before defences can block them.
- Naming to evade filters. Long, plausible business names and complex subdomain structures are deliberately generated to evade brand-protection filters.
- Sender–payload separation. Only 1 of the 1,660 malicious .vu entries (0.1%) was ever used as a sending domain. The remaining 99.9% relied on clean or aged domains for delivery, with the malicious .vu link hidden in the email body — specifically to avoid triggering sender-reputation and domain-age filters.
| Associated .vu Domain (IOC) | Phishing Lure Type |
|---|---|
opsdn[.]vu |
Event Invitation / e-Card |
golkppdmansachs[.]vu |
Invoice & Remittance Fraud |
sofhoeixpefoundation[.]vu |
Purchase Agreement Lure |
finnbusinetttsssalesptyltd[.]vu |
Document Share / SharePoint Lure |
mozskwillafoundation[.]vu |
Payroll / Salary Adjustment |
resiedcltechsrl[.]vu |
Voicemail Notification |
serflrvicestationltd[.]vu |
QuickBooks / Payment Processing |
globalwinnebagoindustriestheindependentp[.]mstsllc.vu |
Account Alert / Quarantine |
umberio[.]vu |
Payment Dispute / Chargeback |
sofxchneidercompany[.]vu |
Password / Credential Expiry |
Top Registrars Used to register these domains
- Dynadot - 884 domains
- Sav.com - 770 domains
What End Users Should Watch For
Be highly suspicious of emails containing links ending in .vu, especially those involving urgent document signatures, package updates, account deactivations, voicemail alerts or unexpected HR/payroll notices.
Do not click the link. Instead, independently navigate to the organization's official website to verify the claim. Legitimate services will not lock you out for ignoring a single email, and real urgencies can be confirmed safely without using unsolicited links.
What Immediate Actions Defenders Should Take
- Block .vu IoCs at the email gateway and DNS layer. Consider a blanket block on all .vu traffic if there is no legitimate business need.
- Hunt retroactively in SIEM and email logs for .vu traffic from April 2026 onward, focusing on connections before late May that predated gateway coverage.
- Tighten inbound URL scanning to detonate links at delivery — this campaign relies entirely on embedded URLs rather than attachments or spoofed senders.
- Audit SPF, DKIM and DMARC configurations to reduce the attack surface and prevent downstream domain abuse.
Where KnowBe4 Can Help
No matter how complex the attack chain becomes, it all starts with an email. The redirects, the credential theft, it all depends on that first email landing in the inbox. This is where KnowBe4 helps stop the attack before it begins.
KnowBe4 Defend: Real-Time Behavioral AI
Email lures in these campaigns depend on social engineering to make the message appear legitimate before any payload is involved. Defend addresses this before the recipient acts.
Behavioral AI + NLP: Analyzes inbound mailflow patterns for anomalies, not file signatures. Defend catches deceptive characteristics that carry no payload and produce no hash.
Context-aware Warning Banners: Defend injects warning banners directly into the email before the recipient opens it. This interrupts the attacker's constructed illusion of legitimacy at the point the social engineering relies on it most: before the click, before the redirect chain begins.
PhishER Plus: Automated Global Eradication
When a recipient reports a suspicious message via the Phish Alert Button, PhishER Plus queues it for immediate analysis by KnowBe4 Threat Lab.
Global Threat Feed: Sourced from millions of users across the KnowBe4 network. When a phishing kit or campaign pattern surfaces anywhere in that network, associated indicators are added to the feed.
Cross-environment Blocking: Messages carrying those indicators are blocked across all connected environments before reaching other inboxes. A kit that hits one organization cannot run unrecognized against another.
