The domain nexus-info.cfd is currently active and has been identified as a high-risk generic phishing threat. According to available intelligence as of July 28, 2026, this domain was registered on July 25, 2026, via NICENIC INTERNATIONAL GROUP CO., LIMITED, which is notable for frequently servicing recently observed phishing campaigns. The domain resolves to IP address 188.114.97.3 and utilizes Cloudflare nameservers (adel.ns.cloudflare.com and javon.ns.cloudflare.com), a configuration typical for phishing domains that aim to conceal origin infrastructure and resist takedown efforts.
Security analysis shows that nexus-info.cfd already appears on one security blocklist and is actively blocked by PhishDestroy, indicating its detection by threat intelligence sources. VirusTotal results reveal one security vendor has flagged this domain as malicious out of 91 scanning engines, further supporting its association with phishing activity. However, the specific brand or service being targeted is not identified in the current intelligence, and the actual website content has not yet been analyzed.
Given the rapid registration-to-detection timeline and the domain's presence on both blocklists and at least one reputable security vendor's detection list, defenders should treat nexus-info.cfd as a credible and ongoing phishing threat. It is recommended to implement immediate network-level blocking and review logs for any attempted access to mitigate potential compromise. Further investigation is advised to determine the specific attack vector or impersonated entity once additional content evidence becomes available. Until then, the domain should be considered highly suspicious and subject to strict access restrictions.