Skip to content

Research & Reports

vspam.org Threat Intelligence Research

Independent research on internet spam, phishing, abuse, and malware. Our monthly brief covers the email, identity, and DNS threat landscape, combining attributable public threat-intelligence sources with original analysis of the vspam.org collector corpus. The archive also holds earlier studies drawn from the scored threat dataset and operator reporting pipeline.

All publications are released under CC BY 4.0. Citation format: vspam.org Research Team. (2026). [Title]. vspam.org, [Report No.].

9 PublicationsNewest first
2026-VSPAM-007August 12, 2026

Trends in Spam, Phishing, Spoofing, Malware & DNS Abuse

vSpam.org Independent ResearchPublisher · vSpam Researcher TeamCorpus Analysis

July 2026 monthly research brief. The Q2 retrospectives landed and resolved the year's central question: Microsoft measured Tycoon2FA-linked phishing down 92% after the March takedown, while Cisco Talos recorded phishing in over half of all incident-response engagements and authentication abuse in 65%. Aggregate volume fell as successful intrusion rose. Includes a scorecard against every forecast this series has published, including the one we got wrong.

Key Findings
  • 01.Tycoon2FA-linked phishing fell to 1.2M messages in June — a 92% reduction, roughly 8% of its 15.1M monthly H2 2025 baseline
  • 02.Cisco Talos recorded phishing in over half of Q2 incident-response engagements, up from a third, with authentication abuse in 65% against 35% in Q1
  • 03.Ransomware reached a 2026 high of 811 victims across 66 groups, with TheGentlemen and Qilin tied at 119 each
  • 04.ChatGPT entered the ten most-impersonated brands for the first time; Microsoft led at 22.6%, LinkedIn second at 11.6%
  • 05.vSpam.org corpus recorded IP-layer malware distribution appearing from zero to 1,538 indicators, below the reach of DNS and registrar controls
monthly-briefphishingransomwareauthentication-abusebrand-impersonationforecast-scorecard
2026-VSPAM-006July 12, 2026

Trends in Spam, Phishing, Spoofing, Malware & DNS Abuse

vSpam.org Independent ResearchPublisher · vSpam Researcher TeamCorpus Analysis

June 2026 monthly research brief, focused on disruption. Operation Endgame removed 326 servers and 142 domains supporting SocGholish, Amadey and StealC, recovering 27 million stolen credentials, while Europol dismantled a laundering service that had washed €336M since 2021. Ransomware nevertheless rose 9.4%, leadership changed hands after five months, and an unseen group debuted at number two. The issue examines what disruption actually buys.

Key Findings
  • 01.Operation Endgame seized 326 servers and 142 domains, recovered ~27 million credentials and restrained €41M in criminal assets
  • 02.Ransomware rose 9.4% to 707 victims across 63 groups; TheGentlemen displaced Qilin after its five-month run, and DeadLock debuted directly at second place with 81
  • 03.Spamhaus recorded botnet C&C servers down 30% to 14,952, with Sliver overtaking Cobalt Strike as detections for the latter fell 68%
  • 04.One registrar cut abused registrations 90% in six months while another rose 901% — registrar abuse volume is a policy variable, not a constant
  • 05.vSpam.org corpus recorded a 5,059-indicator single-month loader burst and the complete reversion of May's novelty-gTLD concentration
monthly-briefoperation-endgameransomwarebotnet-c2dns-abuselaw-enforcement
2026-VSPAM-005June 12, 2026

Trends in Spam, Phishing, Spoofing, Malware & DNS Abuse

vSpam.org Independent ResearchPublisher · vSpam Researcher TeamCorpus Analysis

May 2026 monthly research brief. Three flagship datasets published in sixteen days and disagreed: Barracuda found one in three messages malicious across 3.1 billion emails, the Verizon DBIR placed vulnerability exploitation ahead of social engineering, and APWG recorded 971,181 phishing attacks with telecom rocketing from 5.9% to 33% of all attacks. The issue reconciles the divergence as a window-alignment artefact and reports the vSpam.org collector corpus.

Key Findings
  • 01.APWG recorded 971,181 phishing attacks in Q1 2026, up 13.8%, with telecom rising from 5.9% of attacks in Q3 2025 to 33%
  • 02.The Verizon DBIR and Cisco Talos reach opposite conclusions on the leading initial-access vector because their observation windows do not overlap
  • 03.Ransomware fell 16% to 646 victims — the first month of 2026 below the 2025 pace — while three groups entered the top ten simultaneously
  • 04.Only about 9% of domains combine DMARC enforcement with reporting, against a 52.1% headline adoption figure
  • 05.vSpam.org corpus recorded 38.1% of May's domain indicators concentrated in four novelty gTLDs, a bulk-registration signature with no precedent in our data
monthly-briefphishingtelecomdmarcransomwaremethodology
2026-VSPAM-004May 12, 2026

Trends in Spam, Phishing, Spoofing, Malware & DNS Abuse

vSpam.org Independent ResearchPublisher

April 2026 monthly research brief covering the email, identity, and DNS threat landscape, with a focus on the operationalization of generative AI across the attack chain. The report synthesizes cross-cutting AI-driven trends across phishing, malware, ransomware, email authentication and spoofing, DNS abuse, and major incidents.

Key Findings
  • 01.Generative AI is now operationalized across the email-borne attack chain, affecting phishing, spoofing, malware, ransomware, and DNS abuse workflows
  • 02.KnowBe4's seventh Phishing Threat Trends report found roughly 82.6% of phishing emails use signatures consistent with AI generation
  • 03.Cisco Talos placed phishing back as the leading initial-access vector for the first time in three quarters
  • 04.EasyDMARC reported global DMARC adoption at 52.1%, with only 11.1% at full enforcement
  • 05.The FBI IC3 2025 Annual Report recorded $20.88B in reported losses, up 26% year over year
monthly-briefphishingspoofingmalwaredns-abusegenerative-ai
VSPAM-2026-012March 17, 2026

Phishing Websites, Spam Domains & IP Abuse: Research Analysis & Threat Intelligence Report 2025–2026

vspam.org Research TeamPrimary Investigator

Comprehensive research analysis covering phishing website trends, spam domain registration patterns, and IP address abuse across 2025–2026. This report examines the evolving threat landscape, infrastructure abuse patterns, and provides actionable threat intelligence for mail operators and security teams.

Key Findings
  • 01.Phishing websites increasingly leverage cloud hosting platforms and legitimate SaaS infrastructure
  • 02.Spam domain registration patterns show coordinated bulk registration across low-cost registrars
  • 03.IP abuse analysis reveals concentration of malicious activity in specific autonomous systems
  • 04.Community-driven reporting provides unique coverage not found in automated-only detection systems
  • 05.Cross-referencing multiple threat intelligence sources significantly improves detection accuracy
phishingspam-domainsip-abusethreat-intelligenceannual
VSPAM-2026-011March 10, 2026

The DNSBL Effectiveness Study: Measuring Real-World Impact of Community-Driven Blocklists

vspam.org Research TeamPrimary Investigator

A controlled study measuring the effectiveness of the vspam.org DNSBL feed across 2,400 participating mail servers over 60 days. We analyze false positive rates, detection latency, and the impact of trust-tier weighted voting on blocklist accuracy.

Key Findings
  • 01.DNSBL feed blocked 94.7% of phishing emails within 2 hours of community confirmation
  • 02.False positive rate measured at 0.003% across 2,400 participating mail servers
  • 03.Trust-tier weighted voting reduced false confirmations by 67% compared to simple majority voting
  • 04.Median detection-to-blocklist latency: 47 minutes for Tier 2 (Trusted) reporter submissions
  • 05.Combined with existing RBLs, vspam.org DNSBL provided 12% additional unique threat coverage
dnsbleffectivenessmail-securitymethodology
VSPAM-2026-010March 3, 2026

Abuse Notification Response Times: A Cross-Provider Analysis of Takedown Effectiveness

vspam.org Research TeamPrimary Investigator

Comprehensive analysis of abuse notification response times across 180+ hosting providers. We measure time-to-acknowledgment, time-to-takedown, and identify which provider characteristics correlate with faster response to phishing abuse reports.

Key Findings
  • 01.Top 10 hosting providers by volume averaged 4.2 hours time-to-takedown; bottom 50 averaged 127 hours
  • 02.Providers with dedicated abuse API endpoints responded 8.3x faster than email-only providers
  • 03.XARF-formatted abuse reports received 23% faster acknowledgment than free-text reports
  • 04.Weekend takedown times were 2.1x longer than weekday averages across all provider tiers
  • 05.Automated re-notification at 24-hour intervals reduced overall time-to-takedown by 31%
abuse-reportingtakedownhosting-providersanalysis
VSPAM-2026-009February 24, 2026

Threat Intelligence Feed Correlation: Mapping Overlap Between Public Phishing Data Sources

vspam.org Research TeamPrimary Investigator

Cross-referencing vspam.org confirmed IOCs against PhishTank, OpenPhish, URLhaus, and APWG feeds to measure unique coverage and identify blind spots in the collective phishing intelligence ecosystem.

Key Findings
  • 01.vspam.org contributed 18.3% unique IOCs not found in any other analyzed public feed
  • 02.Combined coverage of all 5 feeds reached 89% of known active phishing URLs (sampled via honeypots)
  • 03.Email-based phishing IOCs had the lowest cross-feed overlap (34%), indicating significant blind spots
  • 04.Average lag between first appearance in any feed and propagation to all feeds: 6.8 hours
  • 05.Domain-based IOCs showed highest correlation (72% overlap) across all analyzed feeds
threat-intelfeed-correlationecosystemcoverage
VSPAM-2026-008February 17, 2026

Weekly Threat Briefing: February 17–23, 2026

vspam.org Research TeamPrimary Investigator

Weekly summary of notable phishing campaigns, newly observed tactics, and community reporting trends. This week features a spike in QR-code phishing targeting corporate Microsoft 365 accounts and a new phishing kit distributed via Telegram channels.

Key Findings
  • 01.QR-code phishing (quishing) reports increased 340% week-over-week, primarily targeting M365 credentials
  • 02.New phishing kit 'PayGate-v3' identified across 120+ domains, distributed via Telegram marketplace
  • 03.Community submitted 8,247 reports this week; 6,102 confirmed, 891 rejected, 1,254 pending review
  • 04.Top targeted brands: Microsoft (28%), PayPal (14%), DHL (11%), Amazon (9%), Apple (7%)
  • 05.3 hosting providers issued proactive takedowns within 1 hour of vspam.org abuse notification
weekly-briefingqr-phishingmicrosoft-365phishing-kits

The monthly brief covers the preceding calendar month and is published mid-month. Every numeric claim is attributed to a primary or secondary public source, or to the vspam.org collector corpus. For questions about methodology or data access, contact research@vspam.org.