The Operator Was Already Public. These 39 Domains Were Not.
This is a div block with a Webflow interaction that will be triggered when the heading is in the view.

Seven domains arrived as separate brand tickets. 2netflix[.]com. 5facebook[.]com. awmazon[.]ca. instagramf[.]com. twhatsapp[.]com. whatsapp0[.]com. whatsappv[.]com. Netflix, Facebook, Amazon, Instagram, WhatsApp. On a busy queue they look like noise, the kind of typosquat a brand desk closes one at a time.
They are one case. Each hostname answers a web request with an HTTP 301. On the registrar-forwarding path the banner is openresty, and the header order matches. The Location is always the same door: choto[.]click, path /vx/, plus an identifier that belongs to that domain and to no other.
GET / HTTP/1.1
Host: 2netflix[.]com
HTTP/1.1 301 Moved Permanently
Server: openresty
Location: https://choto[.]click/vx/6461db92d920a
That door already has a public file. In August 2024, Unit 42 documented 112 domains on newly released top-level domains redirecting into a traffic distribution system, first choto[.]xyz, later choto[.]click/vx/. The destinations they described were gambling sites. In September 2024, Infoblox named the same operation a TDS: lookalike domains funnel people through profiling servers, then conditionally redirect toward illegal gambling and other malicious content, with a geo-conditional second stage at victory-leads[.]xyz. Infoblox said it had tracked the TDS since spring 2023, and that by early September 2024 only choto[.]click was still active.
We compared the 39 domains in this set with both published indicator lists. The intersection is empty. The operator was known. This inventory was not. On 28 September 2026 the door was still answering, two years after the last public write-up, with new lures still rotating in by the month.

If you only have two minutes: block choto[.]click. Treat lure-by-lure blocking as temporary. Do not rely on newly registered domain controls. Several of these names sat dark for 15 to 41 months before anyone would have called them new. And do not block the shared registrar addresses below. They belong to hundreds of thousands of other customers.
Seven tickets, one hallway
The seven names were the start of the trail. Pivoting from them surfaced 32 more domains. Thirty-nine in total. Malanta domain-reputation data had already marked every one of them malicious. The brands run through banks, consumer technology, gaming, and media. ICICI, Scotiabank, Commonwealth Bank, Bank of Montreal, Kasikorn, IPKO, BancoEstado. Google, Microsoft, Meta properties, Discord, X, TikTok, DuckDuckGo, Netflix, Steam, Intuit. British Gas, Sky Sports, El País, Chosun Ilbo. One name, oine[.]me, does not resolve to a brand we can defend. We left it undetermined.

Three brands also appear in the 2024 publications, always as different domains. Infoblox had icicibank[.]observer, netflixg[.]com, and dizscord[.]com. This set has icicibank[.]red, icicibano[.]com, 2netflix[.]com, netflpx[.]com, djscord[.]com, and discordapp[.]top. Same brands. Fresh names. That is inventory replacement.
The spelling is consistent, which is the useful part. Insert a character: twhatsapp, instagramf, googleh. Prefix or suffix a digit: 2netflix, 5facebook, whatsapp0. Miss an adjacent key: awmazon, duckdudkgo, twitfter, djscord, netflpx. Swap letters inside the word: steamdommunity, steacmommunity. One grammar, many brands.
MITRE ATT&CK calls the impersonation T1656. The names themselves are Acquire Infrastructure: Domains, T1583.001, inside Resource Development, TA0042. The redirect is what a proxy logs later. The registration is the setup.
The public file, and what changed
We assess with high confidence that these 39 domains belong to the operator Unit 42 and Infoblox track behind the choto TDS. The judgement is convergent. Every domain terminates at that TDS with a unique /vx/ identifier, the convention both publications describe. The TDS sits on the same host as 36 of the lure domains, which is an operator relationship. Registration, dormancy, and rotation repeat across the set.
We do not go further than that operator. WHOIS on this set is privacy-protected. Neither prior publication assigned a group, a nationality, or a person. Neither do we.
The tradecraft moved. Unit 42's 112 domains sat on newly released TLDs such as .bot, .zip, and .ing, with actor-managed DNS. None of these 39 uses any of those TLDs. Twenty-seven are .com. The rest are ordinary suffixes: .ca, .top, .best, .name, .network, .capital, .school, .space, .red, .me.
Delivery moved with the names. Of the domains we resolved, 27 share Porkbun nameservers (curitiba, fortaleza, maceio, and salvador.ns.porkbun.com) and the same three A records: 207.207.210.23, 207.207.210.36, and 207.207.210.50. That is Porkbun URL forwarding. The operator no longer needs a web server for the lure. A registrar feature sends the visitor on.
Those three addresses are shared by very large numbers of legitimate customers, on the order of hundreds of thousands for two of them. They are consistent with this operator. They have no standalone attribution value. Do not block them.
A minority take other paths, including other registrar nameservers and Cloudflare, and still redirect to choto[.]click. Behavior beats hosting. A block on any one provider's address will miss the rest of the set. A block on the TDS will not.

The door has an address
167.99.154.23, AS14061, DigitalOcean, serves choto[.]click and 36 of the impersonation domains. We observed that residency from 17 May 2025 through 1 September 2026. To our knowledge the address was not in the 2024 publications. It is the cleanest new pivot in the case. The TDS and the lures are linked by more than a redirect. They sit on the same machine.
It is also a busy machine. Thousands of other domains have been observed on it. Blocking the IP would sweep up neighbors who have nothing to do with this operator. Watch the host for new names. Block the TDS domain.
A second pair, 52.33.207.7 and 44.230.85.241, carries 16 of the family as a mirrored parking setup, with tens of thousands of other tenants on each address. Co-tenancy there is weak on its own. It matters because the same portfolio shows up again as a block, on infrastructure that is otherwise unrelated to the DigitalOcean host.
Lures are burned. The door stays.
The operator keeps an inventory and cycles it through live hosting in monthly waves. The TDS stays put. Malicious domains newly appearing on 167.99.154.23 in 2026:

Individual tenure is short. twhatsapp[.]com showed up only in April 2026. whatsapp0[.]com ran May through August. whatsappv[.]com and awmazon[.]ca appeared in August. choto[.]click has been continuously resident since May 2025.
The accounting is ordinary. Lure domains are consumable. Defenders block them, browsers warn on them, brands complain about them. The TDS profiles the visitor and carries the campaign token. Protect the door. Replace the signs.
Remediation aimed only at the typos has a short half-life. Both prior publications reached the same recommendation this collection reaches: block the TDS.
Nothing is new when it is used
Registration dates in the set run from May 2022 to March 2026. First observed live hosting clusters in 2026.

steamdommunity[.]com was registered on 9 May 2025 and first seen hosted on 1 August 2026, about 15 months later. discordapp[.]top and duckdudkgo[.]com waited about 16 months. ttktok[.]com waited about 21. 2netflix[.]com was registered on 22 April 2023 and, as of 28 September 2026, still had no observed hosting, about 41 months of dormancy. Its place in the set rests on the live redirect to choto[.]click and on a short-link identifier minted in the same batch window as other names.
This is the control that should change. Newly registered domain feeds will not catch an operator who ages inventory for a year or more before pointing it at the door. Unit 42's 2024 observation was the opposite pattern: register and use within months. The setup window here is long, quiet, and already paid for.
That is the pre-attack picture. An indicator of compromise on a live typosquat arrives when someone follows the redirect, or when a feed finally labels the name. An Indicator of Pre-Attack (IoPA) is earlier: the aged sibling names, the batch they were minted with, and the TDS that stays up while the lures rotate. Mean Time to Preempt (MTTP) moves when that inventory is in scope during Resource Development, before the 301 is the only thing left to see.
The identifiers were stamped in batches
Every domain maps to its own choto[.]click/vx/<id>. No identifier is shared. Two formats coexist. Twenty-three of the 39 are 16-character mixed-case strings. Sixteen are 13-character lowercase hex.
The hex values follow the MongoDB ObjectId convention. The first eight hex digits are a Unix timestamp. Decoded, same-brand names land in the same second.

Three variants of one brand inside one second is a script walking a prepared list.
Read the timestamps as relative batch markers. choto[.]click itself was registered on 19 April 2024, after several of these decoded times, and Unit 42 records choto[.]xyz as the earlier endpoint. The identifiers were most likely migrated from the predecessor TDS, which fits the published history. They are strong evidence of scripted provisioning. They are not, by themselves, proof that the operation began in July 2022. That date is earlier than Infoblox's stated spring 2023 tracking start. It is suggestive. It is not settled.
Per Infoblox, /vx/ is a TDS entry, not a dumb short link. It profiles the visitor, plausibly on geography, user agent, and referrer, before it decides what to show. The per-domain token is a campaign label: which lure sent this person. A proxy log hit on choto[.]click/vx/<id> can be tied back to the exact impersonation domain. Handle that hit as probable user exposure to a fraud funnel.
We confirmed the 301 on 28 September 2026. We did not walk the TDS through to a 2026 landing page. Gambling and fraud destinations, including pages Infoblox named in 2024 such as lotto60[.]com, joya[.]casino, and tickets[.]love, belong to that earlier reporting. Whether the final content has changed since then is outside this collection.
What to do on Monday

Block choto[.]click at DNS and at the web proxy. Add the historic and second-stage names from the public reporting if they are not already on the list: choto[.]xyz, choto[.]store, victory-leads[.]xyz. That single block covers the current lure set, and it matches what Unit 42 and Infoblox already recommended.
Block the 39 domains as defense in depth, and expect to do it again. The inventory rotates monthly. An alert on any 301 or 302 whose Location resolves to a choto.* domain survives that rotation when the lure is new.
Search proxy and DNS logs back across at least 24 months for choto[.]click/vx/. The public trail starts in 2023, and the door we measured has been up since May 2025. Because the identifier is unique per lure, a hit names the impersonation domain that referred the user.
Monitor 167.99.154.23 for names that appear. Through 2026 the cadence on that host was a handful of new malicious domains in most months, with August the busiest at eight.
Notify the impersonated brands. Start with the banks.
Leave the Porkbun forwarding ranges and the parking pair off the blocklist. High signal when the redirect target is already known. Unacceptable collateral on their own.

The full set, for hunting and for the brands on the list:

The Bottom Line
The choto TDS operator did not go quiet when the 2024 articles shipped. The door is still up. The signs in front of it are new, aged, and pointed at banks, consumer brands, and media properties people already trust. Blocking the typos one by one measures response time. Blocking the door, and reading the inventory while the names are still dark, is how Mean Time to Preempt gets inside the setup window.
Pre-Attack Intelligence is that read: Resource Development, before the redirect is the only evidence left.
If brand controls in your stack still start at the lure, look at what choto[.]click was already doing in May 2025, while most of these names were dark: malanta.ai.
References
1. Ramesh, R., Li, W., Liu, D., Chen, Z. TLD Tracker: Exploring Newly Released Top-Level Domains. Unit 42, Palo Alto Networks. 30 August 2024. https://unit42.paloaltonetworks.com/tracking-newly-released-top-level-domains/
2. Infoblox Threat Intel. Post on the choto TDS operator. 4 September 2024. https://infosec.exchange/@InfobloxThreatIntel/113080959417640696
The 39 IoPAs
The lookalike names in this inventory are published as Indicators of Pre-Attack. The file is 39 domains, one per line, for blocking and hunting: choto-click-brand-impersonation on Malanta's public GitHub.








