700+ Typosquatted/Lookalike Domains Targeting Oil and Gas Brands (Chevron, ExxonMobil, Shell) for Phishing, BEC, and Recruitment Fraud
700+ Typosquatted/Lookalike Domains Targeting Oil and Gas (TL-2026-1519) is a medium-severity phishing campaign, first published 2026-07-19. It is attributed to BEC with low confidence, affects Chevron Corporate brand / HR-recruitment / vendor-procurement channels, maps to 16 MITRE ATT&CK techniques (T1036.005, T1114, T1199), and is covered by 9 detection rules and 37 indicators of compromise.
Key facts for TL-2026-1519
- Threat ID
- TL-2026-1519
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-07-19
- Last reviewed
- 2026-07-19
- Attribution
- BEC
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- energy, oil-and-gas, manufacturing, engineering-and-construction
- Target regions
- North America, Latin America, Africa, Middle East, Asia-Pacific, Europe
- Detection rules
- 9
- Indicators of compromise
- 37
BforeAI's PreCrime platform tracked 701 typosquatted and lookalike domains (Nov 2025-May 2026) impersonating Chevron, ExxonMobil, Shell, Bechtel, and 20+ other energy-sector brands to run phishing, business email compromise, HR/recruitment fraud, procurement scams, and social-engineering schemes. Over 85% of the domains use privacy-proxy registration and cheap/disposable TLDs, and 94.4% remained actively registered at publication, indicating most of the infrastructure is still live and operational.
How 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas works
In a report published June 23, 2026, domain-threat-intelligence vendor BforeAI (PreCrime platform) disclosed a sustained, multi-brand domain-abuse campaign targeting the oil and gas sector. Over a seven-month tracking window (November 2025-May 2026), BforeAI's predictive infrastructure-monitoring system identified 701 suspicious domains registered to typosquat or otherwise impersonate major energy companies, led by Chevron (171 domains, 24.4% of total), ExxonMobil (145 domains, 20.7%), Shell (53 domains, 7.6%), Bechtel (44), Comstock (32), Sempra (32), Motiva (26), Fluor (23), Technip (22), and Coterra (22), with additional targeting of Phillips 66, Diamondback Energy, ConocoPhillips, Kinder Morgan, and 20+ other companies across the sector.
The domains cluster into distinct abuse categories rather than a single attack pattern: HR/recruitment-fraud domains (e.g. hr-chevron.com, careerbechteljob.com, conocophillips-career.com, ngchevronrecruitment.com) harvest resumes/PII or solicit upfront 'onboarding' fees from job seekers; procurement/BEC domains (chevron-procurement.com, vendor-chevron.com, exxonmobilcontracts.com, vendor-exxonmobil.com) impersonate vendor or accounts-payable portals to redirect invoice payments or harvest supplier credentials; region-specific domains (indonesia-exxonmobil.com, chevronvenezuela.com, chevronafrica.co.za, exxonuae.com) target local subsidiaries and joint-venture staff, and project-specific domains (gorgonchevronproject.com, impersonating Chevron's Gorgon LNG facility) exploit named capital projects to lend phishing lures credibility. A smaller cluster is repurposed for e-commerce fraud (phillips66vzla.com selling counterfeit goods), gambling redirection (shellgasstations.com), and lottery/social-engineering scams (clubeshell.com 'spin-the-wheel', exxonmobilfuels.com fake loyalty program).
Infrastructure analysis shows attackers prioritize communication capability over web presence: over 85% of the 701 domains use privacy-proxy registration services (predominantly NameBright Privacy and Fundacion Privacy Services LTD) to obscure registrant identity, register almost exclusively on 1-year expiration cycles, and disproportionately favor cheap/disposable TLDs (.xyz, .top, .online, .sbs, .cfd, .store) alongside standard .com/.net and country-code variants (.de, .pl, .ar, .br, .cz, .co.za, .co.ke, .uk, .biz.id). Critically, many domains that serve no live website nonetheless maintain active MX, SPF, and DKIM records, confirming the domains exist principally to send convincing, authenticated-looking phishing/BEC email rather than to host content. At publication, only 5.6% of the tracked domains were reported as deregistered/unregistered, meaning 94.4% of the identified infrastructure remained live and actionable for defenders and takedown teams.
BforeAI assesses the campaign(s) are opportunistic and financially motivated brand-abuse operations rather than a single coordinated APT effort, most likely run by multiple independent phishing/BEC crews and domain-squatting operators exploiting the oil-and-gas sector's high public profile, complex global-subsidiary structure, and large indirect/contractor workforce. The report flags a set of predictable future activation triggers energy-sector defenders should watch for renewed domain-registration and phishing spikes around: quarterly earnings announcements, M&A activity, AI-partnership announcements, new LNG export facility news, regional expansion initiatives, OPEC+ production-policy changes, and contractor/vendor onboarding cycles.
MITRE ATT&CK techniques used in TL-2026-1519
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location
Collection
T1114 Email Collection; T1213 Data from Information Repositories
Initial Access
T1199 Trusted Relationship; T1566.002 Spearphishing Link; T1566.003 Spearphishing via Service
Execution
Credential Access
T1539 Steal Web Session Cookie
Resource Development
T1583.001 Domains; T1585.002 Email Accounts; T1586.002 Email Accounts; T1587.003 Digital Certificates
Reconnaissance
T1591.003 Identify Business Tempo; T1598.003 Spearphishing Link
Impact
stealth
Affected products and versions in 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas
- Chevron — Corporate brand / HR-recruitment / vendor-procurement channels
Vulnerable versions: 171 impersonating domains identified - ExxonMobil — Corporate brand / HR-recruitment / vendor-procurement channels
Vulnerable versions: 145 impersonating domains identified - Shell — Corporate brand / fuel-loyalty / customer-facing channels
Vulnerable versions: 53 impersonating domains identified - Bechtel — Corporate brand / HR-recruitment / cloud-portal channels
Vulnerable versions: 44 impersonating domains identified - Oil and Gas Sector (Comstock, Motiva, Fluor, Sempra, Technip, Coterra, Phillips 66, Diamondback Energy, ConocoPhillips, Kinder Morgan, and 20+ others) — Corporate brand / vendor-procurement / recruitment channels
Vulnerable versions: remaining ~230 domains across 20+ additional targeted brands
Remediation for 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas
Immediate actions
- Block/sinkhole known malicious domains at DNS and email gateway (see IOC list)
- Alert HR, procurement/accounts-payable, and vendor-management teams to the active recruitment-fraud and vendor-impersonation lures
- Register or defensively monitor high-risk typosquat variants (hyphenated brand+keyword combos, cheap TLDs) of your organization's brand names
- Report confirmed malicious domains to registrars and, where privacy-proxy-registered, escalate via WHOIS/abuse channels (NameBright Privacy, Fundacion Privacy Services LTD) and hosting providers for takedown
Workarounds
- Manually verify recruiter/vendor/procurement email domains against an approved allow-list before acting on job offers, invoices, or payment-detail changes
- Treat urgent payment-detail-change or job-offer emails from newly-seen domains as high-risk pending out-of-band verification
Longer-term hardening
- Deploy continuous domain-abuse / brand-protection monitoring (DNS certificate-transparency and newly-registered-domain feeds) tuned to organization and subsidiary/project brand names
- Implement DMARC enforcement (p=reject) and monitor for spoofed-domain SPF/DKIM abuse targeting your brand
- Extend anti-phishing awareness training to cover HR/recruitment fraud and vendor/procurement BEC specifically, not just generic phishing
- Coordinate with third-party recruiters, procurement vendors, and regional subsidiaries to establish verified-contact channels resistant to lookalike-domain impersonation
Timeline of 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas
- BforeAI's PreCrime predictive-infrastructure platform begins tracking a sustained wave of newly registered domains impersonating major oil-and-gas brands, opening a seven-month observation window.
- Observation window closes with 701 suspicious typosquatted/lookalike domains cataloged, impersonating Chevron, ExxonMobil, Shell, Bechtel, and 20+ other energy-sector brands.
- WHOIS/registrant geographic analysis shows 55.2% of tracked domains have missing or unreported registrant country data and 29.3% use privately redacted registrations, leaving only a small minority with attributable registrant geography.
- Report identifies a cluster of anti-corporate activist/hacktivism-adjacent domains targeting Chevron and ExxonMobil (antichevronday.org, chevronthinkswerestupid.org, fuckchevron.org, stopexxonmobil.org), distinct from the financially-motivated phishing/BEC clusters.
- BforeAI discloses a targeted analysis of 14 .tel domains registered against tracked brands; 12 are assessed as legitimate defensive registrations by the brand owners, while 2 (motiva.tel, technipcorporateservices.tel) are flagged as unresolved/suspicious and held for continued monitoring.
- Report expands the targeted-brand list beyond the top 10 to include Diamondback Energy (19 domains), Targa Resources (19), ConocoPhillips (13), Antero Resources (12), Occidental (9), Phillips 66 (8), Devon Energy (8), Kinetik Holdings (7), Marathon Petroleum (7), Kinder Morgan (7), Expand Energy (6), Murphy Oil (5), Ovintiv (4), Cheniere Energy (3), Colonial Pipeline (2), and Western Midstream (1), confirming the campaign spans 25+ distinct energy-sector brands.
- Report identifies anticipated activation/registration-spike triggers for the tracked infrastructure: quarterly earnings announcements, M&A activity, AI-partnership announcements, LNG export facility news, regional expansion initiatives, OPEC+ production-policy changes, and contractor/vendor onboarding cycles.
- Analysis reveals over 85% of tracked domains use privacy-proxy registration (chiefly NameBright Privacy and Fundacion Privacy Services LTD) and disproportionately use cheap/disposable TLDs (.xyz, .top, .online, .sbs, .cfd, .store), while many maintain active MX/SPF/DKIM records despite hosting no live website.
- Report discloses that only 5.6% of the 701 tracked domains are reported as unregistered/taken down at publication; 94.4% remain actively registered, indicating most of the infrastructure is still live.
- BforeAI publishes 'Over 700 Suspicious Domains Targeting Oil and Gas Brands,' detailing brand-impersonation infrastructure, registration patterns, abuse categories, and predicted future activation triggers.
Sources cited for 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas
- Over 700 Suspicious Domains Targeting Oil and Gas Brands
- Beyond Typosquatting: Why Financial Institutions Need PreCrime, Not Just Domain Monitoring
- How to Find Malicious Domains
- Cybersquatting: Attackers Mimicking Domains of Major Brands Including Facebook, Apple, Amazon and Netflix to Scam Consumers
- What is Typosquatting? Domain-Based Deception Explained
- Typosquatting & Brand Impersonation Trends and Tactics
Threats related to 700+ Typosquatted/Lookalike Domains Targeting Oil and Gas
- TRUSTMARKET Phishing Campaign Expands to Chileautos and New International Platforms
- Phishing Campaign Impersonates LastPass and Bitwarden Security Alerts to Deliver Fake DocuSign Pages
- Malwarebytes Subscription Renewal Scam — Fake-Invoice / Refund-Bait Callback Phishing Campaign ("Account Maintenance Update")
- Forg365 Phishing-as-a-Service Platform Uses AI-Generated Lures and AiTM/Device-Code Phishing to Compromise Microsoft 365 Accounts
- Bad Grammar is Dead — AI-Driven Tone-Matching Phishing via LLM Executive Mimicry
- CalPhishing: Phishing Campaign Abusing Microsoft 365 Groups and Outlook Calendar Invites for Persistent Lures and EvilTokens Device-Code Session Theft
Detection coverage for TL-2026-1519
As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1519 across Splunk SPL, Microsoft KQL and Sigma, covering 37 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.