Phishing Frenzy: Top 20 Most Abused TLDs of 2025 Revealed!
Phishing attackers are getting craftier, using TLDs like .li, .es, and .dev to orchestrate cunning credential heists. ANY.RUN’s 2025 data reveals .li as the top culprit, often acting as a stealthy redirector. So, the next time you’re navigating the web, keep one eye on the URL and the other on your bank account!

Hot Take:
Looks like hackers are turning the internet into a digital version of the Wild West, where the .li, .es, and .dev domains are their trusty horses for phishing scams. Who knew that the quest for your credentials could come from something as unassuming as a .li domain? It’s like finding out that the quiet librarian is actually a mastermind thief!
Key Points:
- Hackers are exploiting TLDs like .li, .es, and .dev for phishing attacks.
- The .li domain is primarily used as a redirector in phishing chains.
- ANY.RUN identified the top 20 TLDs used in phishing for 2025.
- Interactive sandboxes like ANY.RUN help in real-time phishing analysis.
- Domains like .sbs and .cfd are popular due to their low registration costs.
Already a member? Log in here