<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
<channel>
<title>PhishDestroy — News &amp; Investigations</title>
<link>https://phishdestroy.io/news</link>
<description>Investigations, threat research, registrar accountability reports and platform updates from PhishDestroy.</description>
<language>en</language>
<lastBuildDate>Sun, 23 Aug 2026 03:25:01 +0000</lastBuildDate>
<atom:link href="https://phishdestroy.io/feed-news.xml" rel="self" type="application/rss+xml"/>
<item>
<title>The Steam API Scam Symbiosis: Deception, Negligence &amp; Accountability</title>
<link>https://phishdestroy.io/steam-api-scam-exposed</link>
<guid isPermaLink="true">https://phishdestroy.io/steam-api-scam-exposed</guid>
<description>An in-depth profile of private scam panel mechanics, the five offer swap algorithms, maFile phishing bundles, and why Steam&apos;s &apos;anti-scam&apos; measures are a calculated business strategy.</description>
<pubDate>Fri, 21 Aug 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/category_content/images/news-og.png"/>
</item>
<item>
<title>Valve Profits from 578,000 Stolen Steam Accounts</title>
<link>https://phishdestroy.io/valve-profits-from-stolen-accounts</link>
<guid isPermaLink="true">https://phishdestroy.io/valve-profits-from-stolen-accounts</guid>
<description>897,000+ stolen accounts live on LZT Market across 16 platforms. $40M+ in criminal listings. $450M estimated victim liability. Five legal vectors. Interactive forensics. Live intelligence dashboard. Valve&apos;s decade of profitable blindness — documented.</description>
<pubDate>Fri, 14 Aug 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/investigations/lzt/preview1.png"/>
</item>
<item>
<title>The Steam Illusion: How Valve Operates a Shadow Economy</title>
<link>https://phishdestroy.io/steam-shadow-economy</link>
<guid isPermaLink="true">https://phishdestroy.io/steam-shadow-economy</guid>
<description>Valve’s regional pricing, outsourced support, item economy, the CEVA Logistics breach, and the European legal response.</description>
<pubDate>Wed, 12 Aug 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/og-cards/articles/steam-shadow-economy-og.webp"/>
</item>
<item>
<title>The Seed Was Valid. The RNG Was Broken.</title>
<link>https://phishdestroy.io/seed-security-score</link>
<guid isPermaLink="true">https://phishdestroy.io/seed-security-score</guid>
<description>Coldcard, Trust Wallet and Libbitcoin produced valid wallet seeds from dangerously small keyspaces. Read the evidence and check how yours was generated.</description>
<pubDate>Thu, 06 Aug 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/articles/seed-security-score/seed-security-score-card-560.webp"/>
</item>
<item>
<title>From Detection to Enforcement: A Measurable Framework for DNS Abuse Response</title>
<link>https://phishdestroy.io/dns-abuse-enforcement-framework</link>
<guid isPermaLink="true">https://phishdestroy.io/dns-abuse-enforcement-framework</guid>
<description>Measurable DNS abuse response: proportionate action, transparent decisions, safeguards and rapid appeals.</description>
<pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/articles/dns-abuse-framework/dns-abuse-framework-card-560.webp"/>
</item>
<item>
<title>The ICANN Cartel: $155M a Year for Contracts Nobody Honors</title>
<link>https://phishdestroy.io/icann-155-million-illusion</link>
<guid isPermaLink="true">https://phishdestroy.io/icann-155-million-illusion</guid>
<description>A cartel wants the money, refuses outside regulation, and ignores its own contracts. Three toothless Trustname breach notices, one “inadvertently” unblocked card-stealing domain, a 60-day grace period — and $155M a year for it. RegisterFly, EstDomains, Epik, NameSilo: same pattern.</description>
<pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/icann-155m-sham-hero.jpg"/>
</item>
<item>
<title>NameSilo Defended a $100M Crypto Drainer — Then Had to Defend Itself</title>
<link>https://phishdestroy.io/namesilo-investigation/</link>
<guid isPermaLink="true">https://phishdestroy.io/namesilo-investigation/</guid>
<description>NameSilo first defended xmrwallet. After the wallet had already closed, PhishDestroy argues that the remaining campaign protected the registrar itself: overlapping SEO topics, review manipulation patterns, paid PR distribution, and attempts to remove individual search results — documented with 27 source articles and archived evidence.</description>
<pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/namesilo-investigation/og-namesilo-abuse.jpg"/>
</item>
<item>
<title>Registrar Accountability — Who Acts on Abuse Reports</title>
<link>https://phishdestroy.io/registrar-accountability/</link>
<guid isPermaLink="true">https://phishdestroy.io/registrar-accountability/</guid>
<description>A live, evidence-based scoreboard built from every abuse report we send: confirmed-suspension rate, response times, repeat-report escalations, and how many reported domains each registrar never suspended. Deterministic, reproducible, MIT-licensed, updated daily.</description>
<pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/registrar-accountability-og.jpg"/>
</item>
<item>
<title>We Are No Longer Volunteers</title>
<link>https://phishdestroy.io/we-are-no-longer-volunteers</link>
<guid isPermaLink="true">https://phishdestroy.io/we-are-no-longer-volunteers</guid>
<description>Why we are retiring a word weaponized against the public interest — when ICANN (a $50M non-profit) and a decade-long wallet thief both call themselves “volunteers,” the word protects only the entities hiding behind it.</description>
<media:thumbnail url="https://phishdestroy.io/assets/images/news/no-longer-volunteers-og.jpg"/>
</item>
<item>
<title>The Real Enemy Isn&apos;t the Scammer. It&apos;s the Registrar.</title>
<link>https://phishdestroy.io/the-real-enemy-is-the-registrar</link>
<guid isPermaLink="true">https://phishdestroy.io/the-real-enemy-is-the-registrar</guid>
<description>An op-ed: scammers are cheap, replaceable foot soldiers. The scam economy runs on registrars that sell silence — and an ICANN that won&apos;t enforce. $16B lost in 2024; phishing up 180% since 2021. Make impunity expensive.</description>
<pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/news/the-real-enemy-registrar-og.jpg"/>
</item>
<item>
<title>ShortDot Evidence: 6.2M Domains, 9.5% of Global Phishing</title>
<link>https://phishdestroy.io/icann-cybercrime-economy-exposed</link>
<guid isPermaLink="true">https://phishdestroy.io/icann-cybercrime-economy-exposed</guid>
<description>Full enumeration of ShortDot SA (Luxembourg) — 7 zones (.icu, .bond, .cyou, .sbs, .cfd, .buzz, .qpon), 6.2M domains and 51,670 brand-impersonation sites targeting Chase, Binance, MetaMask &amp; Ledger. .bond ranks #3 worldwide for phishing. IOC feeds + daily updates.</description>
<media:thumbnail url="https://phishdestroy.io/category_content/images/shortdot-evidence-card.gif"/>
</item>
<item>
<title>Behind the Investigation — How We Baited a Monero-Theft Cartel at the Cost of Our Twitter</title>
<link>https://phishdestroy.io/behind-the-investigation</link>
<guid isPermaLink="true">https://phishdestroy.io/behind-the-investigation</guid>
<description>Monero leaves no blockchain trail. So we hunted differently. We injected 21 million decoy seed phrases into xmrwallet, burned 200K+ tweets as bait on X, and filed 11–12 abuse complaints NameSilo ignored on schedule. Every Medium article they deindexed, every DMCA they filed against us, every Twitter ban they triggered — logged by the receiving platform, timestamped, subpoenable. Same requester, same speed, same platforms — for both NameSilo and xmrwallet. That behavioral fingerprint is the case. &quot;They thought they were silencing us. They were building our case.&quot;</description>
<pubDate>Sat, 16 May 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/screenshots/motivation/Screenshot_46.png"/>
</item>
<item>
<title>NameSilo Killed Our Twitter Because We Told the Truth About Them</title>
<link>https://phishdestroy.io/namesilo-killed-our-twitter</link>
<guid isPermaLink="true">https://phishdestroy.io/namesilo-killed-our-twitter</guid>
<description>@Phish_Destroy is banned on X. X&apos;s automated review: &quot;no violation, account restored to full functionality.&quot; Account still gone. Two weeks earlier we exposed NameSilo sheltering a $20M+ crypto-theft operation with victims across multiple regions — now under active EU criminal investigation. Same playbook NameSilo ran for the scammer — weaponize a bureaucratic process — now running against us. Where&apos;s the paid gold-checkmark human support? Where&apos;s the unban the automation already granted? Where&apos;s our refund?</description>
<pubDate>Wed, 15 Apr 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/category_content/images/namesilo-retal-01-hero.jpg?v=2"/>
</item>
<item>
<title>Seed Flooding: Why PhishDestroy Openly Disables Active Phishing Sites</title>
<link>https://phishdestroy.io/seed-flooding/</link>
<guid isPermaLink="true">https://phishdestroy.io/seed-flooding/</guid>
<description>We flood active phishing forms with fake seed phrases. It buries the real victim submissions under thousands of decoys, poisons the drainer&apos;s credential pool, and forces the operator to sink hours triaging worthless data — often enough to abandon the campaign. This article explains why it works, how we do it responsibly, and why it is not illegal: no unauthorized access (the form is public and explicitly asks for input), no damage to legitimate systems (the site has no legitimate users), no violation of CFAA/Computer Misuse Act (feeding a public form deceptive data submitted voluntarily is not hacking). Full methodology, legal analysis, and real takedown results inside.</description>
<pubDate>Tue, 31 Mar 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/seed-flooding/01_Dark_cyberpunk_digital_battlefield_scene.png"/>
</item>
<item>
<title>Trustname.com Exposed: Inside a “Bulletproof” ICANN-Accredited Registrar Serving Scam Casinos</title>
<link>https://phishdestroy.io/trustname-bulletproof-exposed/</link>
<guid isPermaLink="true">https://phishdestroy.io/trustname-bulletproof-exposed/</guid>
<description>IANA #4318. €120 declared annual revenue. 1 employee. Negative equity. Deletion notice published. Two Belarusian owners. Six fake crypto casinos registered in a single week — one calling itself “Elon Musk’s Official Casino” — all hidden behind Trustname’s own offshore privacy proxies. The registrar literally calls itself bulletproof in its own DNS TXT record.</description>
<pubDate>Tue, 14 Apr 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/category_content/images/trustname-01-dashboard.jpg?v=1"/>
</item>
<item>
<title>Telegram Bot Analyzer v2: Full Message Dump, User Intel &amp; Content Analysis</title>
<link>https://phishdestroy.io/telegram-bot-analyzer/</link>
<guid isPermaLink="true">https://phishdestroy.io/telegram-bot-analyzer/</guid>
<description>Extract complete message history, identify users with account age estimation, detect stolen credentials, credit cards, crypto wallets, seed phrases and API keys. Branded intelligence reports with interactive charts.</description>
<pubDate>Fri, 03 Apr 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/og-tg-analyzer.png"/>
</item>
<item>
<title>How Crypto Scammers Hijack Bing &amp; DuckDuckGo Search Results</title>
<link>https://phishdestroy.io/seo-hijack/</link>
<guid isPermaLink="true">https://phishdestroy.io/seo-hijack/</guid>
<description>How crypto scammers exploit Yahoo SERP injection and PBN networks to rank phishing sites #1 on Bing and DuckDuckGo, stealing millions from search users.</description>
<pubDate>Mon, 30 Mar 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/og-cards/articles/seo-hijack/seo-hijack-hero.png"/>
</item>
<item>
<title>The End of xmrwallet[.]com: A Decade-Long $2M Scam Destroyed — But Why Did NameSilo Lie to Protect the Thief?</title>
<link>https://phishdestroy.io/xmrwallet-namesilo-exposed</link>
<guid isPermaLink="true">https://phishdestroy.io/xmrwallet-namesilo-exposed</guid>
<description>A 10-year, $2M+ Monero theft operation — finally destroyed. Three registrars suspended the domains. NameSilo fabricated a cover story, called the scammer “the victim,” and helped suppress VirusTotal alerts. We proved 7 lies, filed with ICANN and law enforcement. The domain is dead. The registrar’s reputation should be too.</description>
<pubDate>Fri, 27 Mar 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/category_content/images/xmrwallet-namesilo-og.png?v=2"/>
</item>
<item>
<title>When Abuse Reports Go Nowhere: How Registrars Become Silent Partners in Cybercrime</title>
<link>https://phishdestroy.io/registrar-abuse-response-failure</link>
<guid isPermaLink="true">https://phishdestroy.io/registrar-abuse-response-failure</guid>
<description>16 antivirus detections. 13 reports. 1,788 hours online. Real data from our abuse escalation log shows registrars ignoring evidence-packed reports while phishing domains stay active for months. Who in their abuse department overrules Kaspersky, ESET, and Fortinet?</description>
<pubDate>Sun, 22 Mar 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/category_content/images/registrar-abuse-wall.png?v=2"/>
</item>
<item>
<title>Military Aid Phishing Network Exposed: 5 Ukrainian Banks Targeted, 3 Operators Identified</title>
<link>https://phishdestroy.io/dopomogvoina-exposed</link>
<guid isPermaLink="true">https://phishdestroy.io/dopomogvoina-exposed</guid>
<description>A fake military aid foundation targeting Ukrainian veterans. 5 banks cloned with real-time operator control. One misconfigured file on a shared server exposed the entire operation — operators identified via 6 Telegram API calls. Full behavioral analysis of 261 messages reveals a cross-border criminal enterprise.</description>
<pubDate>Wed, 25 Mar 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/category_content/images/dopomogvoina-homepage.png"/>
</item>
<item>
<title>Anatomy of Crypto Phishing: 8 Real Seed Phrase Stealers Reverse-Engineered</title>
<link>https://phishdestroy.io/phishing-anatomy</link>
<guid isPermaLink="true">https://phishdestroy.io/phishing-anatomy</guid>
<description>We intercepted live phishing traffic, reverse-engineered 8 seed phrase stealers, and traced data to Telegram bots, EmailJS, FormSubmit, custom C2 APIs, and PhaaS backends. 1,824+ stolen credentials. Total attacker cost: $0.</description>
<pubDate>Fri, 27 Mar 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/category_content/images/phishing-anatomy-og.png"/>
</item>
<item>
<title>Trust Wallet Phishing Panel Exposed: $239K Stolen, 1,900 Victims, 6 Operators Identified</title>
<link>https://phishdestroy.io/trustwallet-panel-exposed</link>
<guid isPermaLink="true">https://phishdestroy.io/trustwallet-panel-exposed</guid>
<description>Full takedown of a Russian-speaking scam operation running a fake Trust Wallet support panel with live chat, staking simulation, and multi-operator support. 1,900 victim sessions dumped via IDOR, 21 scammer wallets tracked, primary actor deanonymized.</description>
<pubDate>Sun, 01 Mar 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/og-trustwallet-new.webp"/>
</item>
<item>
<title>Scammers Are Not Hackers: 4 Backends Dissected, All Trivially Compromised</title>
<link>https://phishdestroy.io/scam-infrastructure-exposed</link>
<guid isPermaLink="true">https://phishdestroy.io/scam-infrastructure-exposed</guid>
<description>4 live scam backends analyzed — Firebase with open Firestore rules, Supabase with full CRUD access, Express.js with zero auth, and a 19K-seed drainer campaign. All trivially deanonymizable.</description>
<pubDate>Wed, 18 Feb 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/og-scam-infrastructure.webp"/>
</item>
<item>
<title>BUYTRX Exposed: 55 Domains, Zero Auth APIs, and a TRON Approval Drainer Dissected</title>
<link>https://phishdestroy.io/buytrx-drainer-exposed</link>
<guid isPermaLink="true">https://phishdestroy.io/buytrx-drainer-exposed</guid>
<description>Full infrastructure teardown: 55+ phishing domains, unauthenticated APIs leaking victim data, on-chain drainer contracts, Google Ads funding, and Chinese-language operators exposed.</description>
<pubDate>Sun, 08 Feb 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/og-buytrx-drainer.webp"/>
</item>
<item>
<title>xmrwallet.com Exposed: 10 Years of Stolen Keys &amp; Hijacked Transactions</title>
<link>https://phishdestroy.io/xmrwallet-exposed</link>
<guid isPermaLink="true">https://phishdestroy.io/xmrwallet-exposed</guid>
<description>Forensic investigation: Monero web wallet leaks your private view key 40+ times per session via Base64 session tokens, then nullifies your transaction with raw_tx = 0. Operator identified.</description>
<pubDate>Mon, 16 Mar 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/og-xmrwallet.webp"/>
</item>
<item>
<title>Why We Ban &quot;White Pages&quot; and Redirects to Official Sites — The Cloaking Problem Explained</title>
<link>https://phishdestroy.io/cloaking-whitepages-explained</link>
<guid isPermaLink="true">https://phishdestroy.io/cloaking-whitepages-explained</guid>
<description>How scammers use cloaking, white pages, and TDS systems to hide phishing from security scanners while targeting real victims. 50,000+ sites analyzed.</description>
<pubDate>Sun, 29 Mar 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/category_content/images/cloaking-og.png"/>
</item>
<item>
<title>Keitaro TDS: 1,500 Panels Exposed and Zero Legitimate Uses Found</title>
<link>https://phishdestroy.io/keitaro-tds-exposed</link>
<guid isPermaLink="true">https://phishdestroy.io/keitaro-tds-exposed</guid>
<description>50,000+ sites scanned, 1,565 admin panels discovered, 0% legitimate use rate. Criminal clients include EvilCorp, LockBit, and VexTrio. Open-source detection tools released.</description>
<pubDate>Wed, 10 Dec 2025 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/og-keitaro.webp"/>
</item>
<item>
<title>Scam Teams Compared: MercuryTeam, WasabiSquad, and 717Team</title>
<link>https://phishdestroy.io/scam-team-operations</link>
<guid isPermaLink="true">https://phishdestroy.io/scam-team-operations</guid>
<description>The &quot;middle class&quot; of fraud exposed. Three teams, shared Google Spreadsheets, and proof that OSINT disruption works — 717Team archived after intelligence operations.</description>
<pubDate>Wed, 08 Oct 2025 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/og-scam-teams.webp"/>
</item>
<item>
<title>TheProject: Inside a $10M Scam Mentorship Empire</title>
<link>https://phishdestroy.io/theproject-scam-empire</link>
<guid isPermaLink="true">https://phishdestroy.io/theproject-scam-empire</guid>
<description>Not a scam tool — a scam university. $10M+ claimed, 5,000+ members trained since 2021. 730+ scammer usernames leaked. The upstream producer behind casino and drainer operations.</description>
<pubDate>Mon, 15 Sep 2025 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/og-theproject.webp"/>
</item>
<item>
<title>Anatomy of a Crypto Drainer: How $1.93B Vanished in 6 Months</title>
<link>https://phishdestroy.io/crypto-drainer-anatomy</link>
<guid isPermaLink="true">https://phishdestroy.io/crypto-drainer-anatomy</guid>
<description>Technical breakdown of wallet-draining phishing kits behind $1.93B stolen in H1 2025. Kill-chain, real exploits, DaaS economy, and recovery steps.</description>
<pubDate>Mon, 04 May 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/grok/06-crypto-drainer-anatomy.jpg"/>
</item>
<item>
<title>Crypto Drainer Toolkit: Inside the Angel Drainer Resellers</title>
<link>https://phishdestroy.io/crypto-drainer-networks</link>
<guid isPermaLink="true">https://phishdestroy.io/crypto-drainer-networks</guid>
<description>Code-level deep-dive into TRXDrop (50 forced signing retries, AI-generated code) and NiceCrypto (80% affiliate commission, 4-chain expansion). Full 9-step attack chain deconstructed.</description>
<pubDate>Thu, 19 Feb 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/og-crypto-drainer.webp"/>
</item>
<item>
<title>Fake Casino Epidemic: 5 Scam Panels Exposed From the Inside</title>
<link>https://phishdestroy.io/fake-casino-panels-exposed</link>
<guid isPermaLink="true">https://phishdestroy.io/fake-casino-panels-exposed</guid>
<description>383 verified victims across 30+ countries. Celebrity deepfakes, AI chatbots, and a meta-scam that steals from its own scammers. Four casino PaaS operations dissected.</description>
<pubDate>Mon, 22 Dec 2025 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/og-fake-casino-panels.webp"/>
</item>
<item>
<title>NiceNIC Verdict: Every Domain Reviewed, Zero Legitimate Uses Found</title>
<link>https://phishdestroy.io/nicenic-verdict</link>
<guid isPermaLink="true">https://phishdestroy.io/nicenic-verdict</guid>
<description>Follow-up investigation: 24.7 MB dataset reviewed, 5,000+ abuse tickets ignored, all NiceNIC domains now flagged as unsafe. Challenge: find a legitimate domain.</description>
<pubDate>Tue, 24 Feb 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/og-nicenic-verdict.webp"/>
</item>
<item>
<title>NiceNIC Exposed: The ICANN Registrar Powering Global Cybercrime</title>
<link>https://phishdestroy.io/nicenic-real</link>
<guid isPermaLink="true">https://phishdestroy.io/nicenic-real</guid>
<description>Investigation into IANA 3765 with phishing score 1,141.74, $8.5M Trust Wallet heist, and open confession: &quot;we are not against scamming.&quot;</description>
<pubDate>Tue, 13 Jan 2026 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/niceshit.webp"/>
</item>
<item>
<title>DestroyScammers: Scammers Are Not Hackers</title>
<link>https://phishdestroy.io/destroy-scammers</link>
<guid isPermaLink="true">https://phishdestroy.io/destroy-scammers</guid>
<description>The dashboard proving that scammers are frightened mice. We expose crypto scammer infrastructure, collect evidence, and help victims fight back by refusing to stay silent.</description>
<media:thumbnail url="https://phishdestroy.io/assets/images/destroyscammers.webp"/>
</item>
<item>
<title>$100K Returned: Malvertising Crypto Scam Dismantled</title>
<link>https://phishdestroy.io/100k-returned-malvertising</link>
<guid isPermaLink="true">https://phishdestroy.io/100k-returned-malvertising</guid>
<description>We detected a Russian malvertising operation using stealer malware, restored wallet access, and returned $100K to the victim.</description>
<pubDate>Tue, 12 Aug 2025 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/category_content/images/100k-returned-og.png"/>
</item>
<item>
<title>NameSilo, Webnic, NiceNic: Registrars Enabling Global Scams</title>
<link>https://phishdestroy.io/registrars-enabling-global-scams</link>
<guid isPermaLink="true">https://phishdestroy.io/registrars-enabling-global-scams</guid>
<description>How major domain registrars enable global phishing scams through weak abuse policies and slow response times.</description>
<pubDate>Sun, 10 Aug 2025 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/category_content/images/registrars-scams-og.png"/>
</item>
<item>
<title>150+ Fake Mozilla Extensions: One Backend, One Network</title>
<link>https://phishdestroy.io/moz-fake-extensions-paid-media</link>
<guid isPermaLink="true">https://phishdestroy.io/moz-fake-extensions-paid-media</guid>
<description>150+ malicious Mozilla extensions sharing a single C2 backend on Nigerian infrastructure, all controlled by one operator.</description>
<pubDate>Tue, 26 Aug 2025 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/category_content/images/moz-extensions-og.png"/>
</item>
<item>
<title>Steam BlockBlasters: Platform Negligence Exposed</title>
<link>https://phishdestroy.io/steam-not-good-guy</link>
<guid isPermaLink="true">https://phishdestroy.io/steam-not-good-guy</guid>
<description>How Valve enabled BlockBlasters to deploy crypto-drainer malware on Steam, stealing hundreds of thousands from gamers.</description>
<pubDate>Sat, 18 Oct 2025 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/category_content/images/steam-og.png"/>
</item>
<item>
<title>Impact Metrics: 500K+ Phishing Threats Neutralized</title>
<link>https://phishdestroy.io/impact-metrics</link>
<guid isPermaLink="true">https://phishdestroy.io/impact-metrics</guid>
<description>Comprehensive breakdown of PhishDestroy operations: domains tracked, abuse reports filed, takedowns coordinated, and response times measured.</description>
<pubDate>Mon, 01 Jul 2024 00:00:00 +0000</pubDate>
<media:thumbnail url="https://phishdestroy.io/assets/images/og-impact.webp"/>
</item>
</channel>
</rss>
