Analysis of fortnite-vb.com indicates a high-risk credential-harvesting operation targeting users of the Epic Games platform. The domain was registered on July 21, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with phishing infrastructure. It currently resolves to 186.2.171.13 and uses nameservers ns01.serverspace.ru and ns02.serverspace.ru, a hosting pattern observed in prior gaming-related phishing campaigns. The site presents a Let's Encrypt SSL certificate issued under the YR2 intermediate, providing HTTPS without identity validation.
As of July 31, 2026, the domain appears on one security blocklist and is flagged by PhishDestroy. AlienVault OTX includes it in a recent threat intelligence pulse, and seven of 91 security vendors on VirusTotal detect the domain as malicious. No Safe Browsing or additional brand-specific indicators are currently available, and the exact page content remains unanalyzed. Infrastructure analysis reveals no direct ties to known phishing kits, but the combination of domain naming, hosting provider, and SSL certificate suggests a deliberate attempt to mimic legitimate Epic Games services.
Defenders should treat this domain as active and malicious. Recommended actions include blocking the domain and its resolving IP at perimeter security controls, alerting users to avoid interaction with any Epic Games-related login prompts hosted on fortnite-vb.com, and monitoring for credential reuse if exposure is suspected. The domain remains active, and further analysis may reveal additional infrastructure or campaign linkages.