Analysis of valorantor.club indicates a high-risk phishing domain targeting users of the Riot Games platform, likely through credential harvesting. The domain was registered on February 21, 2026, via Dynadot Inc, with nameservers hosted on a.dnspod.com, b.dnspod.com, and c.dnspod.com, a configuration commonly associated with malicious infrastructure. It currently resolves to IP address 193.187.110.3 and remains active as of July 31, 2026. Security vendor detections on VirusTotal show 11 of 91 engines flagging the domain, and it appears on at least one public blocklist, with PhishDestroy currently blocking access.
No Safe Browsing or Open Threat Exchange records were provided in the available data, so real-time browser or endpoint protection status is uncertain. The domain's registration age—less than six months at the time of reporting—aligns with patterns observed in short-lived phishing campaigns. While the specific content of the site has not been analysed, the domain name and detection context suggest an attempt to impersonate Riot Games or its title Valorant, likely aiming to deceive users into entering account credentials.
Defenders should treat this domain as malicious and prioritise blocking it at DNS, network, and endpoint layers. Monitoring for related subdomains or newly registered lookalike domains using similar infrastructure is recommended. No SSL certificate or HTTP response details were provided, so further technical indicators such as certificate transparency logs or page headers are not available for additional context.