BforeAI has revealed that they identified a total of 39 malicious domains, all newly registered on June 5 and 6, being used across a variety of scams as threat actors exploit the recent, notable, and escalating public trade policy feud between Elon Musk and Donald Trump.
Multiple domains related to hypothetical Trump vs. Elon conflicts have surfaced, often mimicking betting platforms, fake giveaways, or crypto multipliers. Threat actors are using a wide range of low-cost and under-regulated top-level domains (TLDs), indicating abuse-friendly zones. Such TLDs are also known for their ongoing malicious use for hosting and conducting phishing campaigns.
BeforeAI’s research provides a domain breakdown and threat types, including crypto scams, gaming and engagement lures (fake game, fraudulent mobile app, engagement farming), betting and merchandise, disinformation and reputation abuse, and telegram bot automation.
Malicious infrastructure trends identified include the rise of threat actors taking advantage of a geopolitical event to launch new meme coins, fake betting sites, and phishing lures tied to online games and merchandise, and cybercriminals leveraging games to attract supporters to a phishing site.
You can read the report here.
New Threat Research Identifies Malicious Telegram APK Campaign
Posted in Commentary with tags BforeAI on July 15, 2025 by itnerdBforeAI has revealed that its threat research division has identified a large malicious campaign of 607 domains linked to a large-scale phishing and malware campaign actively distributing application files claiming to be Telegram Messenger, registered through the Gname registrar, and are primarily hosted in the Chinese language.
There were two instances in which applications were prompted for download, each being 60MB and 70MB in size, respectively. The new report provides the hash values gathered from this APK, depicts the blog-like appearance of a phishing site distributing the malicious Telegram APK, and shows the permissions requested by the malicious Telegram APK, flagged according to severity as well as proposed mitigations.
You can read the research here: https://bfore.ai/report/malicious-telegram-apk-campaign-advisory
Leave a comment »