Characterizing and Mitigating Phishing Attacks at ccTLD Scale
Giovane C. M. Moura, Thomas Daniels, Maarten Bosteels, Sebastian Castro, Moritz Müller, Thymen Wabeke, Thijs van Den Hout, Maciej Korczynski, Georgios Smaragdakis
Abstract
Phishing on the web is a model of social engineering and an attack vector for getting access to sensitive and financial data of individuals and corporations. Phishing has been identified as one of the prime cyber threats in recent years. With the goal to effectively identify and mitigate phishing as early as possible, we present in this paper a longitudinal analysis of phishing attacks from the vantage point of three country-code top-level domain (ccTLD) registries that manage more than 8 million active domains -namely the Netherlands' .nl, Ireland's .ie, and Belgium's .be. We perform a longitudinal analysis on phishing attacks spanning up to 10 years, based on more than 28 thousand phishing domains. Our results show two major attack strategies: national companies and organizations are far more often impersonated using malicious registered domains under their country's own ccTLD, which enables better mimicry of the impersonated company. In stark contrast, international companies are impersonated using any domains that can be compromised, reducing overall mimicry but bearing no registration and financial costs. Although most research works focus on detecting new domain names, we show that 80% of phishing attacks in the studied ccTLDs employ compromised domain names. We find banks, financial institutions, and high-tech giant companies at the top of the most impersonated targets. We also show the impact of ccTLDs' registration and abuse handling policies on preventing and mitigating phishing attacks, and that mitigation is complex and performed at both web and DNS level at different intermediaries. Last, our results provide a unique opportunity for ccTLDs to compare and revisit their policies and impacts, with the goal of improving mitigation procedures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 0ec417fe-1aae-4ab0-9ae9-cdd99302392bCited by top-tier papers1
Ask how each one uses itBuilds on9
- PREDATOR: Proactive Recognition and Elimination of Domain Abuse at Time-Of-RegistrationShuang Hao, Alex Kantchelian, Brad Miller, Vern Paxson et al.CCS 2016 · 133 citations
- PhishEye: Live Monitoring of Sandboxed Phishing KitsXiao Han, Nizar Kheir, Davide BalzarottiCCS 2016 · 118 citations
- Catching Phishers By Their Bait: Investigating the Dutch Phishing Landscape through Phishing Kit DetectionHugo L. J. Bijmans, Tim M. Booij, Anneke Schwedersky, Aria Nedgabat et al.USENIX Security 2021 · 61 citations
- Don't Let One Rotten Apple Spoil the Whole Barrel: Towards Automated Detection of Shadowed DomainsDaiping Liu, Zhou Li, Kun Du, Haining Wang et al.CCS 2017 · 60 citations
- Cracking the Wall of Confinement: Understanding and Analyzing Malicious Domain Take-downsEihal Alowaisheq, Peng Wang, Sumayah A. Alrwais, Xiaojing Liao et al.NDSS 2019 · 48 citations
Related papers
- Hiding in Plain Sight: A Longitudinal Study of Combosquatting AbusePanagiotis Kintis, Najmeh Miramirkhani, Charles Lever, Yizheng Chen et al.CCS 2017 · 166 citations
- Exposing the Roots of DNS Abuse: A Data-Driven Analysis of Key Factors Behind Phishing Domain RegistrationsYevheniya Nosyk, Maciej Korczynski, Carlos Gañán, Sourena Maroofi et al.CCS 2025 · 1 citation
- Assessing Browser-level Defense against IDN-based PhishingHang Hu, Steve T. K. Jan, Yang Wang, Gang WangUSENIX Security 2021 · 22 citations
- Misty Registry: An Empirical Study of Flawed Domain Registry OperationMingming Zhang, Yunyi Zhang, Baojun Liu, Haixin Duan et al.USENIX Security 2025
- Unveiling the Underground Phishing Ecosystem: A 12-Year Longitudinal Study of Deep and Dark Web ForumsDohee Kim, Hui Zhao, Doowon Kim, Sungjae HwangWWW 2026
