700+ Typosquatted/Lookalike Domains Targeting Oil and Gas Brands (Chevron, ExxonMobil, Shell) for Phishing, BEC, and Recruitment Fraud

700+ Typosquatted/Lookalike Domains Targeting Oil and Gas (TL-2026-1519) is a medium-severity phishing campaign, first published 2026-07-19. It is attributed to BEC with low confidence, affects Chevron Corporate brand / HR-recruitment / vendor-procurement channels, maps to 16 MITRE ATT&CK techniques (T1036.005, T1114, T1199), and is covered by 9 detection rules and 37 indicators of compromise.

Key facts for TL-2026-1519

Threat ID
TL-2026-1519
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
2026-07-19
Last reviewed
2026-07-19
Attribution
BEC
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
energy, oil-and-gas, manufacturing, engineering-and-construction
Target regions
North America, Latin America, Africa, Middle East, Asia-Pacific, Europe
Detection rules
9
Indicators of compromise
37

BforeAI's PreCrime platform tracked 701 typosquatted and lookalike domains (Nov 2025-May 2026) impersonating Chevron, ExxonMobil, Shell, Bechtel, and 20+ other energy-sector brands to run phishing, business email compromise, HR/recruitment fraud, procurement scams, and social-engineering schemes. Over 85% of the domains use privacy-proxy registration and cheap/disposable TLDs, and 94.4% remained actively registered at publication, indicating most of the infrastructure is still live and operational.

How 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas works

In a report published June 23, 2026, domain-threat-intelligence vendor BforeAI (PreCrime platform) disclosed a sustained, multi-brand domain-abuse campaign targeting the oil and gas sector. Over a seven-month tracking window (November 2025-May 2026), BforeAI's predictive infrastructure-monitoring system identified 701 suspicious domains registered to typosquat or otherwise impersonate major energy companies, led by Chevron (171 domains, 24.4% of total), ExxonMobil (145 domains, 20.7%), Shell (53 domains, 7.6%), Bechtel (44), Comstock (32), Sempra (32), Motiva (26), Fluor (23), Technip (22), and Coterra (22), with additional targeting of Phillips 66, Diamondback Energy, ConocoPhillips, Kinder Morgan, and 20+ other companies across the sector.

The domains cluster into distinct abuse categories rather than a single attack pattern: HR/recruitment-fraud domains (e.g. hr-chevron.com, careerbechteljob.com, conocophillips-career.com, ngchevronrecruitment.com) harvest resumes/PII or solicit upfront 'onboarding' fees from job seekers; procurement/BEC domains (chevron-procurement.com, vendor-chevron.com, exxonmobilcontracts.com, vendor-exxonmobil.com) impersonate vendor or accounts-payable portals to redirect invoice payments or harvest supplier credentials; region-specific domains (indonesia-exxonmobil.com, chevronvenezuela.com, chevronafrica.co.za, exxonuae.com) target local subsidiaries and joint-venture staff, and project-specific domains (gorgonchevronproject.com, impersonating Chevron's Gorgon LNG facility) exploit named capital projects to lend phishing lures credibility. A smaller cluster is repurposed for e-commerce fraud (phillips66vzla.com selling counterfeit goods), gambling redirection (shellgasstations.com), and lottery/social-engineering scams (clubeshell.com 'spin-the-wheel', exxonmobilfuels.com fake loyalty program).

Infrastructure analysis shows attackers prioritize communication capability over web presence: over 85% of the 701 domains use privacy-proxy registration services (predominantly NameBright Privacy and Fundacion Privacy Services LTD) to obscure registrant identity, register almost exclusively on 1-year expiration cycles, and disproportionately favor cheap/disposable TLDs (.xyz, .top, .online, .sbs, .cfd, .store) alongside standard .com/.net and country-code variants (.de, .pl, .ar, .br, .cz, .co.za, .co.ke, .uk, .biz.id). Critically, many domains that serve no live website nonetheless maintain active MX, SPF, and DKIM records, confirming the domains exist principally to send convincing, authenticated-looking phishing/BEC email rather than to host content. At publication, only 5.6% of the tracked domains were reported as deregistered/unregistered, meaning 94.4% of the identified infrastructure remained live and actionable for defenders and takedown teams.

BforeAI assesses the campaign(s) are opportunistic and financially motivated brand-abuse operations rather than a single coordinated APT effort, most likely run by multiple independent phishing/BEC crews and domain-squatting operators exploiting the oil-and-gas sector's high public profile, complex global-subsidiary structure, and large indirect/contractor workforce. The report flags a set of predictable future activation triggers energy-sector defenders should watch for renewed domain-registration and phishing spikes around: quarterly earnings announcements, M&A activity, AI-partnership announcements, new LNG export facility news, regional expansion initiatives, OPEC+ production-policy changes, and contractor/vendor onboarding cycles.

MITRE ATT&CK techniques used in TL-2026-1519

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location

Collection

T1114 Email Collection; T1213 Data from Information Repositories

Initial Access

T1199 Trusted Relationship; T1566.002 Spearphishing Link; T1566.003 Spearphishing via Service

Execution

T1204.001 Malicious Link

Credential Access

T1539 Steal Web Session Cookie

Resource Development

T1583.001 Domains; T1585.002 Email Accounts; T1586.002 Email Accounts; T1587.003 Digital Certificates

Reconnaissance

T1591.003 Identify Business Tempo; T1598.003 Spearphishing Link

Impact

T1657 Financial Theft

stealth

T1684.001 Impersonation

Affected products and versions in 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas

  • Chevron — Corporate brand / HR-recruitment / vendor-procurement channels
    Vulnerable versions: 171 impersonating domains identified
  • ExxonMobil — Corporate brand / HR-recruitment / vendor-procurement channels
    Vulnerable versions: 145 impersonating domains identified
  • Shell — Corporate brand / fuel-loyalty / customer-facing channels
    Vulnerable versions: 53 impersonating domains identified
  • Bechtel — Corporate brand / HR-recruitment / cloud-portal channels
    Vulnerable versions: 44 impersonating domains identified
  • Oil and Gas Sector (Comstock, Motiva, Fluor, Sempra, Technip, Coterra, Phillips 66, Diamondback Energy, ConocoPhillips, Kinder Morgan, and 20+ others) — Corporate brand / vendor-procurement / recruitment channels
    Vulnerable versions: remaining ~230 domains across 20+ additional targeted brands

Remediation for 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas

Immediate actions

  • Block/sinkhole known malicious domains at DNS and email gateway (see IOC list)
  • Alert HR, procurement/accounts-payable, and vendor-management teams to the active recruitment-fraud and vendor-impersonation lures
  • Register or defensively monitor high-risk typosquat variants (hyphenated brand+keyword combos, cheap TLDs) of your organization's brand names
  • Report confirmed malicious domains to registrars and, where privacy-proxy-registered, escalate via WHOIS/abuse channels (NameBright Privacy, Fundacion Privacy Services LTD) and hosting providers for takedown

Workarounds

  • Manually verify recruiter/vendor/procurement email domains against an approved allow-list before acting on job offers, invoices, or payment-detail changes
  • Treat urgent payment-detail-change or job-offer emails from newly-seen domains as high-risk pending out-of-band verification

Longer-term hardening

  • Deploy continuous domain-abuse / brand-protection monitoring (DNS certificate-transparency and newly-registered-domain feeds) tuned to organization and subsidiary/project brand names
  • Implement DMARC enforcement (p=reject) and monitor for spoofed-domain SPF/DKIM abuse targeting your brand
  • Extend anti-phishing awareness training to cover HR/recruitment fraud and vendor/procurement BEC specifically, not just generic phishing
  • Coordinate with third-party recruiters, procurement vendors, and regional subsidiaries to establish verified-contact channels resistant to lookalike-domain impersonation

Timeline of 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas

  • BforeAI's PreCrime predictive-infrastructure platform begins tracking a sustained wave of newly registered domains impersonating major oil-and-gas brands, opening a seven-month observation window.
  • Observation window closes with 701 suspicious typosquatted/lookalike domains cataloged, impersonating Chevron, ExxonMobil, Shell, Bechtel, and 20+ other energy-sector brands.
  • WHOIS/registrant geographic analysis shows 55.2% of tracked domains have missing or unreported registrant country data and 29.3% use privately redacted registrations, leaving only a small minority with attributable registrant geography.
  • Report identifies a cluster of anti-corporate activist/hacktivism-adjacent domains targeting Chevron and ExxonMobil (antichevronday.org, chevronthinkswerestupid.org, fuckchevron.org, stopexxonmobil.org), distinct from the financially-motivated phishing/BEC clusters.
  • BforeAI discloses a targeted analysis of 14 .tel domains registered against tracked brands; 12 are assessed as legitimate defensive registrations by the brand owners, while 2 (motiva.tel, technipcorporateservices.tel) are flagged as unresolved/suspicious and held for continued monitoring.
  • Report expands the targeted-brand list beyond the top 10 to include Diamondback Energy (19 domains), Targa Resources (19), ConocoPhillips (13), Antero Resources (12), Occidental (9), Phillips 66 (8), Devon Energy (8), Kinetik Holdings (7), Marathon Petroleum (7), Kinder Morgan (7), Expand Energy (6), Murphy Oil (5), Ovintiv (4), Cheniere Energy (3), Colonial Pipeline (2), and Western Midstream (1), confirming the campaign spans 25+ distinct energy-sector brands.
  • Report identifies anticipated activation/registration-spike triggers for the tracked infrastructure: quarterly earnings announcements, M&A activity, AI-partnership announcements, LNG export facility news, regional expansion initiatives, OPEC+ production-policy changes, and contractor/vendor onboarding cycles.
  • Analysis reveals over 85% of tracked domains use privacy-proxy registration (chiefly NameBright Privacy and Fundacion Privacy Services LTD) and disproportionately use cheap/disposable TLDs (.xyz, .top, .online, .sbs, .cfd, .store), while many maintain active MX/SPF/DKIM records despite hosting no live website.
  • Report discloses that only 5.6% of the 701 tracked domains are reported as unregistered/taken down at publication; 94.4% remain actively registered, indicating most of the infrastructure is still live.
  • BforeAI publishes 'Over 700 Suspicious Domains Targeting Oil and Gas Brands,' detailing brand-impersonation infrastructure, registration patterns, abuse categories, and predicted future activation triggers.

Sources cited for 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas

Threats related to 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas

Detection coverage for TL-2026-1519

As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1519 across Splunk SPL, Microsoft KQL and Sigma, covering 37 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats