Independent research on internet spam, phishing, abuse, and malware. Our monthly brief covers the email, identity, and DNS threat landscape, combining attributable public threat-intelligence sources with original analysis of the vspam.org collector corpus. The archive also holds earlier studies drawn from the scored threat dataset and operator reporting pipeline.
All publications are released under CC BY 4.0. Citation format: vspam.org Research Team. (2026). [Title]. vspam.org, [Report No.].
vSpam.org Independent Research — Publisher · vSpam Researcher Team — Corpus Analysis
July 2026 monthly research brief. The Q2 retrospectives landed and resolved the year's central question: Microsoft measured Tycoon2FA-linked phishing down 92% after the March takedown, while Cisco Talos recorded phishing in over half of all incident-response engagements and authentication abuse in 65%. Aggregate volume fell as successful intrusion rose. Includes a scorecard against every forecast this series has published, including the one we got wrong.
Key Findings▸▾
01.Tycoon2FA-linked phishing fell to 1.2M messages in June — a 92% reduction, roughly 8% of its 15.1M monthly H2 2025 baseline
02.Cisco Talos recorded phishing in over half of Q2 incident-response engagements, up from a third, with authentication abuse in 65% against 35% in Q1
03.Ransomware reached a 2026 high of 811 victims across 66 groups, with TheGentlemen and Qilin tied at 119 each
04.ChatGPT entered the ten most-impersonated brands for the first time; Microsoft led at 22.6%, LinkedIn second at 11.6%
05.vSpam.org corpus recorded IP-layer malware distribution appearing from zero to 1,538 indicators, below the reach of DNS and registrar controls
vSpam.org Independent Research — Publisher · vSpam Researcher Team — Corpus Analysis
June 2026 monthly research brief, focused on disruption. Operation Endgame removed 326 servers and 142 domains supporting SocGholish, Amadey and StealC, recovering 27 million stolen credentials, while Europol dismantled a laundering service that had washed €336M since 2021. Ransomware nevertheless rose 9.4%, leadership changed hands after five months, and an unseen group debuted at number two. The issue examines what disruption actually buys.
Key Findings▸▾
01.Operation Endgame seized 326 servers and 142 domains, recovered ~27 million credentials and restrained €41M in criminal assets
02.Ransomware rose 9.4% to 707 victims across 63 groups; TheGentlemen displaced Qilin after its five-month run, and DeadLock debuted directly at second place with 81
03.Spamhaus recorded botnet C&C servers down 30% to 14,952, with Sliver overtaking Cobalt Strike as detections for the latter fell 68%
04.One registrar cut abused registrations 90% in six months while another rose 901% — registrar abuse volume is a policy variable, not a constant
05.vSpam.org corpus recorded a 5,059-indicator single-month loader burst and the complete reversion of May's novelty-gTLD concentration
vSpam.org Independent Research — Publisher · vSpam Researcher Team — Corpus Analysis
May 2026 monthly research brief. Three flagship datasets published in sixteen days and disagreed: Barracuda found one in three messages malicious across 3.1 billion emails, the Verizon DBIR placed vulnerability exploitation ahead of social engineering, and APWG recorded 971,181 phishing attacks with telecom rocketing from 5.9% to 33% of all attacks. The issue reconciles the divergence as a window-alignment artefact and reports the vSpam.org collector corpus.
Key Findings▸▾
01.APWG recorded 971,181 phishing attacks in Q1 2026, up 13.8%, with telecom rising from 5.9% of attacks in Q3 2025 to 33%
02.The Verizon DBIR and Cisco Talos reach opposite conclusions on the leading initial-access vector because their observation windows do not overlap
03.Ransomware fell 16% to 646 victims — the first month of 2026 below the 2025 pace — while three groups entered the top ten simultaneously
04.Only about 9% of domains combine DMARC enforcement with reporting, against a 52.1% headline adoption figure
05.vSpam.org corpus recorded 38.1% of May's domain indicators concentrated in four novelty gTLDs, a bulk-registration signature with no precedent in our data
April 2026 monthly research brief covering the email, identity, and DNS threat landscape, with a focus on the operationalization of generative AI across the attack chain. The report synthesizes cross-cutting AI-driven trends across phishing, malware, ransomware, email authentication and spoofing, DNS abuse, and major incidents.
Key Findings▸▾
01.Generative AI is now operationalized across the email-borne attack chain, affecting phishing, spoofing, malware, ransomware, and DNS abuse workflows
02.KnowBe4's seventh Phishing Threat Trends report found roughly 82.6% of phishing emails use signatures consistent with AI generation
03.Cisco Talos placed phishing back as the leading initial-access vector for the first time in three quarters
04.EasyDMARC reported global DMARC adoption at 52.1%, with only 11.1% at full enforcement
05.The FBI IC3 2025 Annual Report recorded $20.88B in reported losses, up 26% year over year
Comprehensive research analysis covering phishing website trends, spam domain registration patterns, and IP address abuse across 2025–2026. This report examines the evolving threat landscape, infrastructure abuse patterns, and provides actionable threat intelligence for mail operators and security teams.
A controlled study measuring the effectiveness of the vspam.org DNSBL feed across 2,400 participating mail servers over 60 days. We analyze false positive rates, detection latency, and the impact of trust-tier weighted voting on blocklist accuracy.
Key Findings▸▾
01.DNSBL feed blocked 94.7% of phishing emails within 2 hours of community confirmation
02.False positive rate measured at 0.003% across 2,400 participating mail servers
03.Trust-tier weighted voting reduced false confirmations by 67% compared to simple majority voting
Comprehensive analysis of abuse notification response times across 180+ hosting providers. We measure time-to-acknowledgment, time-to-takedown, and identify which provider characteristics correlate with faster response to phishing abuse reports.
Cross-referencing vspam.org confirmed IOCs against PhishTank, OpenPhish, URLhaus, and APWG feeds to measure unique coverage and identify blind spots in the collective phishing intelligence ecosystem.
Key Findings▸▾
01.vspam.org contributed 18.3% unique IOCs not found in any other analyzed public feed
02.Combined coverage of all 5 feeds reached 89% of known active phishing URLs (sampled via honeypots)
03.Email-based phishing IOCs had the lowest cross-feed overlap (34%), indicating significant blind spots
04.Average lag between first appearance in any feed and propagation to all feeds: 6.8 hours
05.Domain-based IOCs showed highest correlation (72% overlap) across all analyzed feeds
Weekly summary of notable phishing campaigns, newly observed tactics, and community reporting trends. This week features a spike in QR-code phishing targeting corporate Microsoft 365 accounts and a new phishing kit distributed via Telegram channels.
The monthly brief covers the preceding calendar month and is published mid-month. Every numeric claim is attributed to a primary or secondary public source, or to the vspam.org collector corpus. For questions about methodology or data access, contact research@vspam.org.