AliExpress Fake Site Pushes “Add to Browser” Scam

Infosecurity Magazine · Medium sophistication
Last updated September 25, 2026

Researchers tracked a live phishing flow that used 10 newly-registered “disposable” domains as entry points that redirected visitors to a fake AliExpress-themed site. The end site impersonated a shopping-assistant brand and pushed a browser extension, putting users at risk of credential and payment theft.

Key findings

  • Researchers identified 10 suspicious .cyou domains before they were registered, then observed them go live and redirect to a fake AliExpress-themed phishing site.
  • The 10 domains appeared “disposable” and were used as entry points, not hosting the final lure content; they redirected through a tracking layer to allow quick swapping of exposed domains.
  • The phishing chain ended at a lookalike site (using a zero in “shop”) that promoted a browser extension and urged visitors to click “Add to Browser.”
  • Researchers warned of potential credential/payment theft and browsing-activity exposure via the extension; the article does not report confirmed victims or losses.

Who’s being targeted

  • Commonly targeted roles: All staff, Procurement, Finance, IT / Security (SOC and Helpdesk).
  • Affected industries: Retail / e-commerce, Consumers / general public.
  • Attack channels: website.
  • Impersonated: AliExpress-themed shopping assistant styled after Alitools.

Awareness takeaways

  • Treat unexpected browser-extension install prompts as high risk, only install extensions from approved sources and the official store listings.
  • Be cautious of brand lookalikes and subtle typos in URLs (e.g., swapping characters like 0 for o).
  • Don’t rely only on “site reputation” warnings, newly registered redirect domains may not be classified yet when users first click.
  • If someone interacted with a suspicious shopping/login page or installed an extension, respond quickly: reset passwords, contact card issuers, and remove the extension.

Red flags to watch for

  • Lookalike branding: a site “using a zero in place of the "o" in "shop"”
  • Pressure to install a browser extension from a non-official source
  • Entry via newly registered “disposable” domains and redirects/tracking parameters
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You click a random AliExpress deal link… and land on a slick “shopping assistant” page yelling: “Add to Browser.” Behind that page are throwaway .cyou links, all redirecting through tracking hops to a fake AliExpress site styled like Alitools, ending on a URL with a zero instead of an “o” in “shop.” The fake site claims over 500,000 users and pushes that “Add to Browser” button. Install it, and you could hand over AliExpress logins, card details, and your entire browsing history. Here’s the move: if any site pops up an AliExpress-style helper and says “Add to Browser,” ignore the button and only install extensions from our approved list or the official browser store.

Categories

Similar attacks

Kratos PhaaS Takedown: Fake Microsoft Logins

Kratos PhaaS Takedown: Fake Microsoft Logins

German and international law enforcement disrupted the infrastructure behind “Kratos,” a phishing-as-a-service kit used at scale to steal Microsoft account logins. The kit provided convincing Microsoft-themed fake login pages designed to steal passwords and session cookies, which could help…

July 21, 2026
Placeholder Domain Now Pushes ClickFix Malware

Placeholder Domain Now Pushes ClickFix Malware

A commonly used documentation placeholder domain, third-party.com, was registered by an unknown party and is now serving a ClickFix social-engineering lure to Windows users. The page pretends to run a Cloudflare security check, silently poisons the clipboard, and tells victims to paste and run a…

September 24, 2026
Device-Code Phish + Fake Recruiter Interview Lures

Device-Code Phish + Fake Recruiter Interview Lures

This news roundup describes multiple real-world social engineering operations, including a device-code phishing service that stole access to over 12,000 inboxes and a North Korean campaign posing as recruiters to trick developers during fake coding interviews. The attackers used legitimate login…

September 24, 2026
Microsoft Disrupts ‘EvilTokens’ Phishing Service

Microsoft Disrupts ‘EvilTokens’ Phishing Service

Microsoft says it disrupted the “EvilTokens” phishing-as-a-service platform, which it links to compromises of over 12,000 inboxes across more than 10,000 organizations. The service used AI to tailor phishing emails to a victim’s role and to analyze compromised inboxes to identify trusted…

September 23, 2026
Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft Disrupts EvilTokens Device-Code Phishing

Microsoft says it disrupted “EvilTokens,” an AI-assisted phishing service used to trick employees into authorizing attacker access via the device-code login flow (often used for TVs/printers). Victims who entered an attacker-provided code in their browser unknowingly granted access tokens that…

September 23, 2026
EvilTokens Device-Code Phish Hit 12,000 Inboxes

EvilTokens Device-Code Phish Hit 12,000 Inboxes

EvilTokens was a phishing-as-a-service operation that used “device code phishing” to trick employees into authorizing an attacker session on Microsoft’s real login infrastructure, often bypassing MFA without stealing passwords. After access, attackers used AI to find payment-related conversations…

September 23, 2026