🚨 Fraud-as-a-Service Campaign Targets Domain Suspension via Registrar Abuse and Legal Takedown Channels 🚨
A threat actor known as “convince” is advertising a Fraud-as-a-Service offering on underground forums, claiming the ability to forcibly suspend domains across major TLDs such as .com, .net, .org, .io, and .ai by abusing registrar abuse-reporting and legal takedown workflows. The service is marketed as a “Private Domain Suspension Method | Registrar Exploit 2026” and is positioned as a non-technical attack relying heavily on social engineering and process manipulation.
The offering is structured in two tiers, one providing a direct takedown service where the actor claims domains can be taken offline within 24 hours, and another offering a full methodology kit that teaches buyers how to replicate the process independently using prepared templates and submission channels.
According to the listing, the method focuses on bypassing frontline support and reaching registrar compliance or legal teams with forged or manipulated documentation, aiming to trigger actions such as domain suspension (clientHold status). The actor promotes the service for use against a wide range of targets, including competitors, journalists, researchers, and businesses.
Key risks highlighted by this activity include the ability to target high-value domains across multiple TLDs, the abuse of trust-based legal and compliance workflows, and the scalability of the method through resale of the toolkit.
#CyberCrime #FraudAsAService #DomainSecurity #ThreatIntelligence