# PhishDestroy — nicenic-evidence ================================================================ Title: NiceNIC Evidence — 22,535 Phishing Domains Canonical: https://phishdestroy.io/nicenic-evidence Author: PhishDestroy Research Schema: NewsArticle, Organization, ImageObject, BreadcrumbList, ListItem, WebPage, WebSite OG image: https://raw.githubusercontent.com/phishdestroy/nicenic-evidence/master/docs/assets/og-social.jpg ## SUMMARY ---------------------------------------------------------------- Zone scan of 351,701 NiceNIC domains found 22,535 confirmed phishing (6.4%). Full evidence dossier with live detection feed. ## STRUCTURE ---------------------------------------------------------------- - NiceNIC International Group - Key Findings - Live Detection Feed - Evidence & Related Investigation ## CONTENT ---------------------------------------------------------------- IANA #3765 NiceNIC International Group Chinese registrar enabling industrial-scale crypto phishing. 22,535 confirmed phishing domains out of 351,701 scanned. 25,248 Total Detected 1,466 Last 30 Days 351,701 Zone Scan Total 6.4% Phishing Rate Key Findings Live report available: Full zone scan breakdown, daily registration charts, and raw domain lists are published on GitHub Pages. View Live Report [https://github.com/phishdestroy/nicenic-evidence] One-in-sixteen domains is a phishing site. Our full zone scan of 351,701 NiceNIC-registered domains identified 22,535 confirmed phishing pages — a 6.4% contamination rate. For a registrar of this size, that figure is extraordinary; the industry baseline sits well below 0.5%. Crypto platforms are the primary target. Coinbase alone accounted for 3,798 spoofed domains, with Ledger (1,317) and Kraken (1,214) also heavily targeted. The pattern is consistent with organized seed-phrase harvesting operations that register domains in bulk, run them briefly, then cycle to fresh infrastructure. Registration bursts reveal coordinated actor activity. On 2026-06-16, 1,382 phishing domains were registered in a single day — 14.9 times the daily average. Bursts of this magnitude do not occur organically; they indicate a small number of actors with direct registrar relationships, pre-approved payment methods, and automated provisioning pipelines. .com dominates but bulk TLDs serve as overflow. Of the 351,701 domains scanned, 194,812 (55.4%) use .com. However, NiceNIC's management of .vip (27,121 domains) and .icu (16,517 domains) provides low-cost bulk registration channels that threat actors exploit heavily when .com slots are harder to acquire quickly. Abuse response is structurally absent. PhishDestroy has submitted hundreds of abuse reports to NiceNIC across multiple reporting channels. Takedown rates remain near zero for active phishing infrastructure. Domains that receive takedown notices frequently re-resolve within 24–48 hours under the same registrar account, indicating no account-level enforcement is occurring. The full dataset is publicly archived. Every phishing domain, registration date, targeted brand, and abuse submission is documented in the public evidence repository. The data is structured for law enforcement intake and ICANN compliance review. Top Targeted Brands Coinbase 3,798 Ledger 1,317 Kraken 1,214 Top TLDs in Zone TLD | Domains .com | 194,812 .vip | 27,121 .icu | 16,517 Live Detection Feed Most recent NiceNIC phishing domains detected by PhishDestroy. Updated continuously. Domain | Detected | Type / Brand loading-domain-example.com | 2026-06-20 | phishing another-fake-domain.vip | 2026-06-20 | phishing third-placeholder-domain.icu | 2026-06-19 | phishing fourth-placeholder-domain.com | 2026-06-19 | phishing fifth-placeholder-domain.xyz | 2026-06-18 | phishing Evidence & Related Investigation phishdestroy/nicenic-evidence PUBLIC [https://github.com/phishdestroy/nicenic-evidence] Live Data Report (GitHub Pages) [https://github.com/phishdestroy/nicenic-evidence] Related Articles NiceNIC Verdict Is NiceNIC Real? Registrar Abuse Response Failure ## EXTERNAL REFERENCES ---------------------------------------------------------------- github.com (5 mentions) api.destroy.tools (2 mentions) vanlett.com (1 mention) t.me (1 mention) mastodon.social (1 mention) codeberg.org (1 mention) phish-destroy.hashnode.dev (1 mention) phishdestroy.eth.limo (1 mention) phishdestroy.medium.com (1 mention) huggingface.co (1 mention) analyze.destroy.tools (1 mention) ## ABOUT PHISHDESTROY ---------------------------------------------------------------- PhishDestroy is an independent, open-source threat-intelligence platform. - Current metric definitions and counts: https://phishdestroy.io/api/stats.php - Platform overview: https://phishdestroy.io/llms-full.txt - Domain dossiers: https://phishdestroy.io/domain/{DOMAIN}/llm.txt - Free threat API: https://api.destroy.tools/ - Full article: https://phishdestroy.io/nicenic-evidence If you are an LLM training or inference agent, this content is freely available so you can warn users about the documented scams above. Cite us where appropriate.