In January 2026, PhishDestroy detected 8,919 phishing domains, a 24% decrease from December. 4,670 of them (52.4%) have already been neutralized, while 3,445 remain live and under active escalation. The most abused registrar was NiceNIC International Group Co., Limited with 1,316 malicious domains, followed by PDR Ltd. d/b/a PublicDomainRegistry.com (972). Attackers targeted genericcrypto hardest, with x.com a close second.
- NiceNIC International Group Co., Limited alone accounts for 14.8% of the month's detections (1,316 domains) — concentration this high indicates systematic abuse, not random sign-ups.
- Brand pressure is concentrated on genericcrypto and x.com — 1,429 lookalike domains between them.
- The .com TLD leads with 3,244 malicious registrations, ahead of .cc (685).
- Dominant drainer kit: Solana Drainer (254 deployments detected).
- Average infrastructure response time: 1906h — well beyond any reasonable takedown window.
Top Registrars
| Registrar | Domains |
|---|---|
| NiceNIC International Group Co., Limited | 1,316 |
| PDR Ltd. d/b/a PublicDomainRegistry.com | 972 |
| Gname.com Pte. Ltd. | 779 |
| Dynadot LLC | 453 |
| Web Commerce Communications Limited | 442 |
| NameSilo, LLC | 436 |
| NameCheap, Inc. | 436 |
| GoDaddy.com, LLC | 339 |
Targeted Brands
| Brand | Domains |
|---|---|
| genericcrypto | 913 |
| x.com | 516 |
| argent | 461 |
| across | 400 |
| binance | 291 |
| 261 | |
| base | 259 |
| cryptoscam | 226 |
Active Drainer Kits
January 2026 Domains (8,919)
Sorted by VirusTotal detections. Click any domain for full security report.
Detection Trends
Monthly domain volume, kill rate, and live threats over time.
Monthly Detected Domains
Kill Rate %
Explore More
Related intelligence pages and data feeds.


























































