# royanta.gd — SUSPICIOUS > royanta.gd, a crypto-drainer phishing site, hit VirusTotal with 3/95 detections. This active domain mimics legitimate login pages to steal credentials. ## Summary PhishDestroy identifies royanta.gd as a live credential theft domain posing as a login portal to harvest user passwords and crypto wallet keys. This domain was flagged by 3 of 95 VirusTotal security vendors, registered on March 1, 2026 through NICENIC INTERNATIONAL GROUP CO., LIMITED, and resolves to IP address 188.114.97.3. A Let’s Encrypt SSL certificate lends false legitimacy to the site. This domain is engineered to trick visitors into submitting login credentials or wallet recovery phrases by mimicking a trusted service interface. Its recent registration date—just days ago—suggests it’s part of an active campaign. The low detection rate on VirusTotal (only 3 vendors) means many security tools haven’t yet blacklisted it, increasing the risk of exposure. If you visited royanta.gd, assume credentials entered were compromised. Disconnect from the internet if you used a work device. Revoke any session tokens, change passwords on other accounts using the same credentials, and scan devices for malware. Report the domain to your security team and block it at the network level. Monitor financial accounts and crypto wallets for unauthorized activity. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-01 19:59:03 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 188.114.97.3 ## Detection Status - VirusTotal: 3 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/domains/royanta.gd - PhishDestroy: https://phishdestroy.io/domain/royanta.gd/ - LLM endpoint: https://phishdestroy.io/domain/royanta.gd/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/royanta.gd/ Last updated: 2026-04-07