# b81a899.nxcli.io — SUSPICIOUS > The domain b81a899.nxcli.io is active in a generic phishing campaign. Users should remain vigilant and avoid interaction with this site while investigations. ## Summary PhishDestroy has identified the domain b81a899.nxcli.io as part of an ongoing generic phishing campaign. While the specific brand or service impersonated remains unclear, this domain is used to deceive users into divulging sensitive information or credentials. The campaign is currently under investigation to clarify its exact threat vector and targeted entities. Technically, b81a899.nxcli.io was registered recently on March 23, 2026. Despite its recent creation and active use in phishing attempts, scans conducted via VirusTotal have revealed no detections by any of the 95 security vendors at this time. The domain is hosted on infrastructure related to nxcli.io, which is commonly utilized in phishing setups for its ease of deployment and low cost. As the situation develops, the status remains active and under close observation. PhishDestroy recommends users exercise caution by avoiding clicking links or submitting any information on b81a899.nxcli.io. Security teams should monitor network traffic and email filters for this domain to mitigate potential exposure while threat intelligence updates are awaited. ## Threat Details - Verdict: SUSPICIOUS - Site status: alive (HTTP ?) ## Domain Intelligence - Registered: 2026-03-23 21:07:02 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - PhishDestroy: https://phishdestroy.io/domain/b81a899.nxcli.io/ - LLM endpoint: https://phishdestroy.io/domain/b81a899.nxcli.io/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/b81a899.nxcli.io/ Last updated: 2026-03-23