WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Community Partnerships The Top Domains that Threat Actors Prefer
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Directory
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

The Top Domains that Threat Actors Prefer

Author: Alec Davison

Created: Tuesday, November 16, 2021 - 19:00

Categories: Cybersecurity

Amidst thousands of top-level domains (TLD) available, researchers at Palo Alto Networks have identified the most widely exploited TLDs by threat actors. The researchers discovered threat actors prefer a small group of 25 TLDs, accounting for 90 percent of all malicious websites. Threat actors prefer exploiting .com and .net TLDs because they appear more legitimate to victims and thus improve success rates. The TLDs that spread the most malware include .ga, .xyz, .cf, ,tk, .org, and .ml. The researchers also discovered that malicious domains are more frequently registered in developing countries, with six out of the top ten TLDs originating from the developing world. To protect your utility from malicious TLDs, members are encouraged to utilize URL filtering to block traffic from TLDs not commonly used for business purposes. Read more at BleepingComputer.

Related Resources

Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated April 30, 2026)

Apr 30, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

Tip of the Week – April 30, 2026

Apr 30, 2026 in Cybersecurity, Security Preparedness

(TLP:CLEAR) Cyber Readiness Institute Joins WaterISAC as a Community Partner to Strengthen Cyber Readiness Across the Water Sector

Apr 30, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar