On July 30, 2026 analysts observed that the domain a1-kraken.net, created on July 29, 2026 and registered through Dominet (HK) Limited, is actively being used in a generic phishing operation. The domain resolves to the IPv4 address 163.181.254.142 and is served by the authoritative name servers ns7.alidns.com and ns8.alidns.com. Infrastructure analysis shows that the host has been added to three public security blocklists and is actively blocked by the PhishDestroy, MetaMask, and SEAL filtering services.
A VirusTotal assessment recorded scans from 91 independent vendors, none of which issued a detection at the time of review; this absence of detections does not constitute a validation of safety. No public information on SSL certificate parameters, HTTP response codes, page title, or trust‑score metrics has been released, leaving those vectors unverified. The limited visibility suggests that the adversary is leveraging a freshly registered domain and a single IP address to host malicious content, a pattern consistent with rapid‑deployment phishing campaigns that aim to evade early detection.
Defenders should prioritize adding the domain and its resolving IP to deny‑list rules, monitor DNS queries for the associated name servers, and enforce outbound filtering that references the blocklists already flagging the host. Continuous re‑scanning of the domain with multi‑vendor engines is advised, as the lack of detections may change rapidly. Organizations that employ Web‑gateway or browser‑level protection should ensure that the domain is included in existing phishing‑mitigation policies, and incident response teams should be prepared to investigate any credential submissions that may be directed to this address.