A recent analysis of over 1.5 million malicious domains registered in early 2026 reveals an industrial-scale threat model where attackers rapidly create and deploy domains through a concentrated set of registrars, TLDs, and hosting providers. The domains were flagged by multiple VirusTotal scanning engines, indicating coordinated, high-volume campaigns for phishing, malware distribution, or other malicious infrastructure. This pattern underscores the need for security teams to monitor domain registration trends and threat intelligence feeds for emerging infrastructure.
Attackers registered roughly 1.5 million malicious domains during the first five months of 2026. The registration patterns resemble industrial output. Most of the domains were created by attackers, put to use within weeks, and concentrated among a small set of registrars, top-level domains, and hosting providers. New research examined more than 1.5 million unique domains flagged on VirusTotal between January and May 2026. Each domain was flagged by at least five independent VirusTotal scanning engines … More → The post The assembly line behind 1.5 million malicious domains appeared first on Help Net Security .