Where is malicious infrastructure being built?

Instagram and WhatsApp are the most impersonated platforms we track

They carry 51% of the domains with a critical detection across this platform set.

What we identified on 2026-09-14

10 detection surfaces, each stating the period it covers. Impersonation figures count registrable domains with a critical detection. Free to quote with attribution.

Identity capture

Taking the login. Two separate detections, not halves of a total — a few domains trip both.

37.9%were registered in the last 90 days

8.6× the 4.4% baseline across the 433,496 domains we hold registration data for. Measured over 1,484 critical detections to date, 5.02% of all of them, as of 2026-09-24.

0

domains impersonating a platform

0 observations of those domains, on the most recent complete day shared by every feed

Source: Datazag · as of 2026-09-14

login pages built to look like a service someone already trusts

on 2026-09-14 · 0 observations

typical day 181 domains · median over 42 complete days

244

domains impersonating a watchlist brand

279 observations of those domains, on the most recent complete day shared by every feed

Source: Datazag · as of 2026-09-14

aimed at a name on the watchlist — a test list, so read it as a sample rather than a total

on 2026-09-14 · 279 observations

typical day 242 domains · median over 50 complete days

Command and control

Using it. Where a bought credential turns into access.

24,909

malware domains

24,909 of 41,992 domains on the malware list

Source: Datazag · as of 2026-09-24

listed by an indicator feed and present in our corpus · standing list as of 2026-09-24

8

c2 domains

8 of 42 domains on the c2 list

Source: Datazag · as of 2026-09-24

listed by an indicator feed and present in our corpus · standing list as of 2026-09-24

663

bulletproof hosting

577 distinct domains, on the most recent complete day shared by every feed

Source: Datazag · as of 2026-09-14

hosting that ignores abuse reports · all severities

typical day 2,753 · median over 43 complete days

Drill down

Cover and reach

Where campaigns hide. Counts over the whole corpus, not a single day.

58,910

prefixes carrying a listed threat IP

the whole corpus, on the snapshot the threat artifact was built from

Source: Datazag · as of 2026-09-14

2,418

prefixes on a do-not-route list

the whole corpus, on the snapshot the threat artifact was built from

Source: Datazag · as of 2026-09-14

342,509

IP addresses with a threat score

the whole corpus, on the snapshot the threat artifact was built from

Source: Datazag · as of 2026-09-14

771,225

domains using a disposable email provider

771,225 of 363.6M resolving domains

Source: Datazag · as of 2026-09-14

32,201,582

domains parked on a recognized platform

32,201,582 of 363.6M resolving domains

Source: Datazag · as of 2026-09-14

Who is being impersonated

A page built to pass for a service, or a domain built to pass for a name.

Platforms impersonated

Domains with a critical detection, over 42 complete days.

  1. 1Instagram4,76992,336 observations
  2. 2WhatsApp2,70557,047 observations
  3. 3Amazon2,19626,185 observations
  4. 4Google1,01415,936 observations
  5. 5Netflix94318,989 observations
  6. 6Microsoft60311,679 observations
  7. 7Pinterest48910,685 observations
  8. 8YouTube4558,704 observations
Source: Datazagas of 2026-09-14registrable domains with a critical platform impersonation detection over 42 complete days

Brands impersonated

Domains with a critical detection, over 50 complete days. Watchlist brands only. Customer brands are never published.

  1. 1Binance99612,844 observations
  2. 2WhatsApp2962,655 observations
  3. 3Chase2361,974 observations
  4. 4NatWest1824,079 observations
  5. 5Kaufland67869 observations
  6. 6Baidu58412 observations
  7. 7Apple44477 observations
  8. 8Toyota38668 observations

This ranks a defined watchlist, not the internet: it shows what is most impersonated among the brands we watch. Watch terms that are ordinary words (brand, square, jordan, enterprise, prime, mobil) are excluded, because a domain containing the word is not impersonating a brand by that name.

Source: Datazagas of 2026-09-14registrable domains with a critical brand impersonation detection over 50 complete days, watchlist brands only

United States, Singapore and Hong Kong host the most detected impersonation infrastructure

They account for 94% of domains with a critical detection in this sample. Hosting location follows where capacity is cheap and plentiful, so it describes the market an operator bought from rather than the operator.

Countries hosting domains with a critical platform impersonation detection

the United States10,856domains · 245,730 observations
Singapore5,176domains · 8,255 observations
Hong Kong723domains · 4,542 observations
Germany413domains · 6,278 observations
Seychelles381domains · 1,704 observations
Russia92domains · 575 observations
China58domains · 1,264 observations
the Netherlands50domains · 273 observations
France49domains · 825 observations
the United Kingdom49domains · 160 observations
United Arab Emirates32domains · 704 observations
Cyprus30domains · 64 observations
Source: Datazagas of 2026-09-14registrable domains with a critical platform detection over 42 complete days

Impersonation infrastructure appears in bursts, not at a steady rate

Across 21 days the busiest carried 8,840 detections against a typical 240 — a campaign stands up many domains at once, so a quiet week says little about the next one.

Source: Datazag impersonation detectionsas of 2026-09-14registrable domains with a critical platform detection, last 21 complete days

Red alerts arrive in bursts, not at a steady rate

529 domains on a typical day, 9,456 on the busiest of the last 28 complete days. Registrable domains, counted once however often they were observed. Critical severity only — the band that means act now rather than review later.

Source: Datazag impersonation detectionsas of 2026-09-23registrable domains with a critical platform or brand detection, last 28 days

WhatsApp was the most impersonated platform last week

Ranked by registrable domains with a critical detection in the week beginning 2026-09-14. The arrow is the move against the week before. Only the top eight are published, so “unranked” means outside last week’s eight rather than newly appearing.

#PlatformDomainsObservationsvs last week
1WhatsApp168174
2Google551
3Azure483
4Gmail44unranked
5Amazon33
6iCloud342
7LinkedIn23unranked
8Outlook22unranked

All of it lands on 316 networks

Every critical impersonation detection resolves to a set of autonomous systems small enough to list, and 180 of them carry ten or more. Impersonation is not spread thinly across the internet; it concentrates.

316

Networks hosting a critical impersonation detection

complete collection days, across the platform and brand lanes

Source: Datazag · as of 2026-09-23

Counted over complete collection days, across both impersonation lanes.

180

Networks carrying ten or more critical impersonation detections

180 of 316 networks hosting a critical detection

Source: Datazag · as of 2026-09-23

A network with one detection may be a victim of its own customer. Ten is a pattern.

The figures

Free to quote with attribution. Open the notes on a card before you do.

37.94%
-0.05pp since 2026-09-23

Impersonation domains registered in the last 90 days

563 of 1,484 critical impersonation domains with registration data

Source: Datazag · as of 2026-09-24

13.32%
no prior period

Impersonation domains whose first certificate is under 30 days old

1,442 of 10,826 critical impersonation domains with a certificate observed

Source: Datazag · as of 2026-09-24

5.02%
+0.01pp since 2026-09-23

Critical impersonation domains with registration data

1,484 of 29,590 critical impersonation domains

Source: Datazag · as of 2026-09-24

2.36%
+0.01pp since 2026-09-23

Impersonation domains that can receive mail

192 of 8,135 critical impersonation domains we can observe

Source: Datazag · as of 2026-09-24

Query these statistics directly

Every figure on this page is served as Parquet. Same format as the corpus itself.

SELECT * FROM read_parquet('https://observatory.datazag.com/observatory_statistics.parquet');