Rising Threat: Phishing Campaigns Exploiting .es And .com.br Domains

Phishing actors are increasingly abusing regional domains such as Spain’s .es and Brazil’s .com.br to carry out large-scale credential harvesting operations. These domains, typically associated with localized trust, have become strategic tools for bypassing traditional security controls and deceiving users through high-fidelity spoofing of Microsoft 365, banking services, and government platforms.

This article explores the tactics, domain abuse patterns, and defensive measures surrounding this ongoing threat, supported by active campaign observations and real-world indicators of compromise (IOCs).

The Evolution of Domain-Based Phishing

Traditionally, phishing campaigns leveraged generic top-level domains (TLDs) like .com, .net, or known-abuse TLDs such as .ru. Recently, attackers have shifted focus to more “trusted” regional country-code TLDs (ccTLDs), where abuse monitoring and automated blocking may be less stringent.

Two ccTLDs now trending in active abuse are:

  • .es — The ccTLD for Spain, openly available for global registration.
  • .com.br — The commercial domain extension for Brazil, widely recognized and trusted by local users.

Key Findings from Recent Campaigns

  • +1,800% increase in .es phishing domains observed between January and May 2025.
  • Over 1,373 unique phishing subdomains tied to credential-harvesting infrastructure.
  • Majority of spoofed content targets Microsoft 365 logins.
  • Threat actors are using CAPTCHA protections (e.g., Cloudflare Turnstile) to block automated scanners.
  • Infrastructure frequently hosted on Cloudflare or similar CDNs to evade blacklists and reputation filters.
  • Domain structure is randomized, e.g., hkdzd.tynorra.es, to hinder domain-based defenses.

Abuse of .com.br Domains

  • Continued abuse in financial fraud and malware delivery targeting Brazilian users.
  • Common lures include fake tax notices, invoice alerts, and government impersonation.
  • Several campaigns linked to spoofed banking portals, including fake Santander and Caixa Econômica logins.
  • Emphasis on local language, familiar branding, and regional trust to trick users

Tactics and Techniques

CAPTCHA Shielding

Stops automated scanners from indexing phishing pages.

Domain Randomization

Uses random subdomains to bypass blocklists.

Cloud-based Hosting

Hides infrastructure behind CDNs like Cloudflare.

Phishing Kits

Professional kits mimic real login pages and branding.

Localized Social Engineering

Targets users with language and formatting tailored for Spanish or Brazilian audiences.

Example Email Themes Used

  • “You have received a New Secure Voicemail.”
  • Scanned Invoice attached – Action Required.”
  • Microsoft Security Alert: Unusual sign-in attempt.”
  • Payment Failed – Please Update Billing Info.”
  • These lures are carefully crafted to prompt urgency and interaction, leading to credential phishing attacks.

Indicators of Compromise (IOCs):

Malicious .es Domains:

hxxps://1h4aslkj0r[.]unxzo[.]es

hxxps://hkdzd[.]tynorra[.]es

hxxps://uh[.]ggcpvxtlkd[.]es

hxxps://ysloww[.]yyfimbnxk[.]es

Malicious .com.br Domains:

hxxps://itshotel[.]com[.]br

hxxp://esclerosemultiplario[.]com[.]br

hxxp://raphaelclimaco[.]com[.]br

hxxps://41mrimper[.]com[.]br

Why It Matters

The use of regional domains in phishing is not new—but the scale, sophistication, and evasion tactics now being employed mark a significant shift. Security filters that rely on static domain reputation are increasingly ineffective. CAPTCHA shielding and randomized DNS configurations make detection by legacy tools even more difficult.

Phishing campaigns using .es domains in particular are now globally distributed, while .com.br campaigns remain regionally concentrated but highly targeted and damaging.

Conclusion

Phishing campaigns exploiting .es and .com.br domains reflect a broader trend in abuse of regional trust. As attackers adopt more advanced delivery techniques—such as CAPTCHA evasion, randomized domain naming, and CDN masking—defenders must evolve beyond static controls and enhance both user education and infrastructure-level detection.

Organizations should remain vigilant, continuously adapt detection logic, and operationalize intelligence to respond to this rapidly growing threat.

Find out how Wizard Cyber can help you stay protected against phising!

CYBERSECURITY READINESS

Strengthen Your Cyber Defences Today

As cyber threats grow more complex, proactive detection is no longer optional.

With Wizard Cyber’s Microsoft expertise, organizations can transform their security posture and gain real-time visibility across all endpoints.

Start your journey to smarter, faster cybersecurity today.

EXPLORE MORE

Related Blogs & Insights

Discover blogs that deepen your knowledge and accelerate your security strategy.

ABOUT THE AUTHOR
Mahdi Alabdallah
Offensive Security Engineer

Mahdi specialises in penetration testing, web application security, network security assessments, and vulnerability exploitation. He holds the globally recognised OSCP (Offensive Security Certified Professional) certification, eCPPT, eWPT, and eCIR certifications, alongside Microsoft SC-200, SC-300, and AZ-500 certifications

 

Certifications: OSCP+/OSCP, eCPPT, eWPT, eCIR, SC200, SC300, AZ500

Cyber Shield Intelligence (CSI) Team

Cyber Shield Intelligence (CSI) Team

Wizard Cyber’s first line of defense in proactive threat intelligence. CSI is dedicated to the identification, monitoring, and analysis of emerging cyber threats, including activity across the dark web, underground forums, and threat actor infrastructure. Leveraging advanced threat intelligence platforms, OSINT tools, and adversary tracking methodologies, the team provides actionable intelligence to anticipate attacks before they occur. With expertise in threat actor profiling, TTP mapping (aligned with the MITRE ATT&CK framework), and IOC enrichment, CSI equips clients with the critical insights needed to fortify defenses, mitigate risk, and stay ahead of evolving threat landscapes.

WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-27001-scaled.png
https://wizardcyber.com/wp-content/uploads/2026/04/ISO-QSL-Cert-ISO-9001-scaled.png
WIZARD CYBER
Headquarters
Providing enterprises with bespoke & powerful managed solutions to protect against all forms of cybercrime
OUR LOCATIONS
Where to find us?
world map
GET IN TOUCH
Latest Updates
Stay up to date with the latest news from Wizard Cyber and the cybersecurity industry

Copyright by Wizard Cyber. All rights reserved.

Copyright by Wizard Cyber. All rights reserved.

Contact Us
×
Contact Us
Need Cybersecurity Guidance? Get in touch with us!

Our experts are ready to help with your cybersecurity questions—book a conversation with us by clicking the button.

Book a Meeting
Funded Workshops
×
Funded Workshops
Explore Our Funded Microsoft Security Workshops

Click to learn more about each Microsoft-supported engagement

Book a Consultation