Close Menu
The CISO Brief
  • Home
  • Cyberattacks
    • Ransomware
    • Cybercrime
    • Data Breach
  • Emerging Tech
  • Threat Intelligence
    • Vulnerabilities
    • Cyber Risk
  • Expert Insights
  • Careers and Learning
  • Compliance

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Over 400 SharePoint Servers Targeted in ToolShell Attacks: US Government Among Victims

July 24, 2025

CISA Alerts: Hackers Targeting SysAid Vulnerabilities

July 23, 2025

Ukraine Strikes: Suspected Admin of Major Russian Hacking Forum Arrested

July 23, 2025
Facebook X (Twitter) Instagram
The CISO Brief
  • Home
  • Cyberattacks
    • Ransomware
    • Cybercrime
    • Data Breach
  • Emerging Tech
  • Threat Intelligence
    • Vulnerabilities
    • Cyber Risk
  • Expert Insights
  • Careers and Learning
  • Compliance
The CISO Brief
Home » Elon-Trump Feud Sparks Surge in Malicious Domain Activit
Solutions & Tech

Elon-Trump Feud Sparks Surge in Malicious Domain Activit

Staff WriterBy Staff WriterJune 18, 2025No Comments5 Mins Read0 Views
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email


In response to the escalating public trade policy feud between Elon Musk and Donald Trump — amplified by political tensions, social media clashes, and media coverage — threat actors are attempting to capitalize on this new, high-profile rivalry to register and weaponize a broad array of malicious domains.

PreCrime™ Labs, the threat research team at BforeAI, has identified multiple domains being used to proliferate crypto scams, phishing, fake betting sites, impersonation schemes, and engagement farming, leveraging the notoriety of both figures to lure victims.

Key Insights

Publicized online disputes, especially between celebrities or political figures, are repeatedly used as social engineering bait. In this case, multiple domains related to hypothetical Trump vs. Elon conflicts have surfaced, often mimicking betting platforms, fake giveaways, or crypto multipliers. Threat actors are using a wide range of low-cost and under-regulated top level domains (TLDs), including “.xyz”, “.space”, “.wtf”, “.live”, “.info”, “.fun”, “.store”, “.icu”, and “.online”, indicating abuse-friendly zones. Such TLDs are also known for their ongoing malicious use for hosting and conducting phishing campaigns.

Cyber Technology Insights : Cyber A.I. Group Appoints Irving Bruckstein as Director of Global Technology Integration

In the case of the Donald Trump and Elon Musk feud, once Musk publicly voiced his distaste for Trump’s “big beautiful bill” on June 4, 2025, cybercriminals leapt into action, creating at least 39 new domains aimed at scamming and defrauding internet users. All of these new domains were registered in the following two days, on June 5 and 6, 2025.

A wide range of typical TLDs were employed; however, “.com” had the most with 21. This is notable as “.com” is considered a more familiar and reputable TLD, indicating that the criminals were seeking to gain credibility with potential users.

The next largest cluster belongs the “.xyz” with 5 domains, followed by “.info” (3), “.online” and “.fun” (2 each) and “.space”, “.wtf”, “.live”, “.site”, “.store”, and “.icu” (with one each).

The team also observed a surge in the use of thematic keywords, delivering the relevance of the event on which it is based. For example, URLs containing keywords like “trumpvselon”, “elonvstrump”, “elonprivateaccess”, “trumploveselon”, “trumpmuskfeud”. Then, keywords such as “crypto”, “billiondollar”, “betting”, “private access”, and “game” were tied to the above set of keywords to establish the category of their operations, for example, to host fake apps, contests, etc., as discussed with examples below.

Cyber Technology Insights : NuHarbor Security Recognized as Top Workplace by VermontBiz, Best Practice Institute

Malicious Infrastructure Trends:

Telegram bot integrations seen through a purported malicious website (e.g., trumpversuselon.com) leveraged X (formerly Twitter) automation to redirect users to compose posts. Additionally, this particular domain was configured to leverage Telegram’s messaging API, either by auto-redirecting visitors or by presenting a Telegram bot interface. This functionality is achieved through client-side scripting (e.g., JavaScript) or meta-refresh tags, directing individuals to a specific Telegram handle or channel. This method is frequently observed in campaigns designed to funnel victims into fraudulent investment schemes, as the domain promotes crypto or facilitates impersonation-based scams.

Additionally, there were also themes based on users’ popular internet surfing preferences. For example, fake betting sites and phishing lures tied to online games and merchandise (e.g., elonvstrumpfight.com, elonvstrump.store, elongame.icu).

Abusive or reputational attack domains (e.g., elonsucksmydick.com, elonrip.com) were also observed to psychologically manipulate visitors, making them support one side of the conflict, depending on the website’s agenda. Such platforms often include calls-to-action, like signing up for a movement or providing sensitive personal details, which can compromise their identity.

Cyber Technology Insights : Mattermost Launches Enterprise Advanced for Multi-Domain Defense and Critical Infrastructure

Domain Breakdown & Threat Types

Crypto Scam Infrastructure

Threat TypeDomainNotesCrypto scamtrumpvselon.spaceFake Trump-vs-Elon event giveawaytrumpbilliondollar.comClaims Trump backing $1B giveawaytrump2mars.comExploits Musk’s Mars ambitionstrumpvselon.wtfURL suggests “shocking” feud contenttrumpvselon.liveHosted fake livestream countdowntrumpvsmusk.xyzHosted Musk impersonator walletelonxparty.siteMeme coin airdrop impersonating Muskelonvstrump.xyzLive wallet embeddedelonprivateaccess.com / .info / .onlineMimic Tesla private share saleelonrip.onlineUsed fake obituary as bait

Gaming & Engagement Lures

Threat TypeDomainNotesFake gameelonvstrumpfight.comHTML5 game redirect to betting pageFake mobile appelongame.icuPseudo Google Play page, scam downloadEngagement farmingelonvstrumpwars.fun

elonvstrump.fun

Meme tournament bracket voting

Reddit-style image votes

Betting & Merchandise

Threat TypeDomainNotesBettingtrumpelonbingo.comHosted a Trump-Elon ‘Bingo’ card wagerMerchandiseelonvstrump.storeShirt sales, unclear legitimacy

Disinformation / Reputation Abuse

Threat TypeDomainNotesAbuseelonsucksmydick.com

elonrip.com

Reputation defamation

Fake news site publishing false death

Bot Automation

Threat TypeDomainNotesTelegram bottrumpversuselon.comAuto-post crypto promo links

Tactical Observations

Based on PreCrime Labs’ observations, certain scams are event-driven, in which threat actors pivot rapidly from one theme to another as public attention surges and wanes. The most recent example we have analyzed is the current Trump/Musk feud, in which domain registrations immediately peaked as this event was gaining attention. The active content themes (images of Trump/Musk in crypto, gaming, and shopping contexts), along with domain names combined with “.xyz”, “.space”, “.wtf”, “.live”, and “.site” TLDs, are consistent indicators of suspicious activity in this campaign.

The presence of Telegram integrations and fake app stores used in this campaign represents a shift to multi-channel attack vectors. There is a strong potential that we will continue to see scams spreading to other popular social media platforms, where media consumption and redirection are high.

Conclusions

The Elon vs. Trump feud has become a fertile ground for opportunistic threat actors, with a range of scams exploiting the names and media coverage of both figures. As public interest in these figures continues, more weaponized domains will likely be registered.

This trend is a reminder of the importance of real-time monitoring of current events in domain threat intelligence and the need to act fast when trending news becomes a vector for cybercrime.

Cyber Technology Insights : AvePoint Launches New Advanced Security and Optimization Features to Elements Platform

To participate in our interviews, please write to our CyberTech Media Room at sudipto@intentamplify.com

Source: prnewswire



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleSecuring the Future: Bridging AI and Legacy Systems
Next Article Water Curse Unleashes Multi-Stage Malware via 76 GitHub Accounts
Avatar photo
Staff Writer
  • Website

John Marcelli is a staff writer for the CISO Brief, with a passion for exploring and writing about the ever-evolving world of technology. From emerging trends to in-depth reviews of the latest gadgets, John stays at the forefront of innovation, delivering engaging content that informs and inspires readers. When he's not writing, he enjoys experimenting with new tech tools and diving into the digital landscape.

Related Posts

Weekly Cybertech Roundup: Highlights of the Week

July 19, 2025

Silobreaker Backs NATO CCDCOE with New Cyber Threat Repor

July 19, 2025

Aeris, Bridge Alliance Launch Integrated Cellular IoT Securit

July 19, 2025
Leave A Reply Cancel Reply

Latest Posts

Over 400 SharePoint Servers Targeted in ToolShell Attacks: US Government Among Victims

July 24, 20250 Views

CISA Alerts: Hackers Targeting SysAid Vulnerabilities

July 23, 20250 Views

Ukraine Strikes: Suspected Admin of Major Russian Hacking Forum Arrested

July 23, 20250 Views

Fortify Your Active Directory Against Kerberoasting

July 23, 20250 Views
Don't Miss

Big Risks for Malicious Code, Vulns

By Staff WriterFebruary 14, 2025

Attackers are finding more and more ways to post malicious projects to Hugging Face and…

North Korea’s Kimsuky Attacks Rivals’ Trusted Platforms

February 19, 2025

Deepwatch Acquires Dassana to Boost Cyber Resilience With AI

February 18, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to The CISO Brief, your trusted source for the latest news, expert insights, and developments in the cybersecurity world.

In today’s rapidly evolving digital landscape, staying informed about cyber threats, innovations, and industry trends is critical for professionals and organizations alike. At The CISO Brief, we are committed to providing timely, accurate, and insightful content that helps security leaders navigate the complexities of cybersecurity.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Over 400 SharePoint Servers Targeted in ToolShell Attacks: US Government Among Victims

July 24, 2025

CISA Alerts: Hackers Targeting SysAid Vulnerabilities

July 23, 2025

Ukraine Strikes: Suspected Admin of Major Russian Hacking Forum Arrested

July 23, 2025
Most Popular

Designing and Building Defenses for the Future

February 13, 202515 Views

United Natural Foods Faces Cyberattack Disruption

June 10, 20257 Views

Attackers lodge backdoors into Ivanti Connect Secure devices

February 15, 20255 Views
© 2025 thecisobrief. Designed by thecisobrief.
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions

Type above and press Enter to search. Press Esc to cancel.