Pokémon Brand-Spoofing Campaign: 1,352 Lookalike Domains Ahead of 30th Anniversary — Threadlinqs Intelligence
As of 2026-07-19, Pokémon Brand-Spoofing Campaign: 1,352 Lookalike Domains Ahead of 30th Anniversary is a medium-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-1520 · Severity: MEDIUM · Status: ACTIVE · Category: PHISHING
BforeAI PreCrime Labs identified 1,352 lookalike domains impersonating the Pokémon brand, 85% registered March-May 2026 ahead of Pokémon's 30th Anniversary cycle, spanning credential harvesting,
BforeAI's PreCrime Labs published "Pokémon Brand Spoofing in 2026: Pre-Crime Analysis of 1,352 Lookalike Domains" on 2026-06-17, documenting a large, financially motivated brand-abuse campaign timed to Pokémon's 30th Anniversary. Registration volume spiked across Q2 2026 (401 domains in March, 378 in April, 376 in May — 85% of the total 1,352-domain set), consistent with opportunistic infrastructure staging ahead of anniversary-driven consumer attention, product launches, and trading-card releases.
The domains cluster into six primary abuse categories: credential harvesting (671 domains, 49.6%) using generic typosquats keyed to game launches; character-specific phishing (233 domains, 17.2%) weaponizing named Pokémon (Pikachu, Mewtwo, Charizard, Squirtle) as lure hooks for fake card sales and passes; e-commerce/counterfeit merchandise fraud (161 domains, 11.9%); trading-card-game (TCG) and card-grading fraud (154 domains, 11.4%) impersonating legitimate authentication/grading services; mobile app clones (86 domains, 6.4%) distributing trojanized APKs including Pokémon GO "hack"/spoofing tools; and fan-tool phishing (47 domains, 3.5%) impersonating Pokédex lookups and IV calculators.
Distinct regional/thematic clusters were identified: an Indonesia-based illegal gambling network (170+ domains) using systematically numbered Pikachu branding (pikachu168v1.com through v3) and Indonesian slang ("Gacor" — slot-machine hot streak) across .bet/.live/.sbs/.ink/.world TLDs; a Turkey-targeted geo-affiliate/PPC-fraud cluster (48 domains) following a [city]pikachu[number].click pattern across cities including Alanya, Fethiye, and Kayseri; a TCG/card-grading fraud ecosystem (62 domains) spanning counterfeit shops, wholesale fraud, and scalper tooling; a Pokémon GO spoofing-infrastructure cluster (34 domains) offering GPS-spoofing and coordinate-sharing tools with child-safety implications given the game's ~80M monthly active users; a cryptocurrency meme-coin cluster (7 domains) blending Pokémon characters with Solana-ecosystem tokens for pump-and-dump/rug-pull schemes; and a piracy/bot-infrastructure cluster (19 domains) offering ROM hacks and purchase bots that risk bundling malware with pirated content. A redirect chain was observed routing pokemonromhacks.com traffic through FIFA World Cup 2026 sports content into a fake antivirus-renewal scam, demonstrating traffic-monetization layering typical of malvertising redirector chains.
Registrar concentration favors GoDaddy LLC (191 domains), Namecheap Inc (158), Spaceship Inc (78), and Cloudflare Inc (60), with TLD distribution led by .com (673), followed by .net (78), .online (52), .xyz (52), .click (47), and specialty gTLDs (.vip, .bet, .app, .exposed, .lat). A distinct 6-domain sub-cluster using an "a1-" naming prefix is hosted on Aliyun infrastructure and targets Asian slot-gambling providers.
Separately, Bitdefender's Hot for Security (2026-02-26, author Alina Bîzgă) corroborates the trading-card-fraud vector: at least 477 reported Pokémon TCG scam cases since October 2025 totaling over $958,000 in losses, driven by pre-order fraud, fake marketplace seller accounts, counterfeit graded-card slabs mimicking legitimate grading companies, non-card merchandise scams (anniversary plushes/figurines), and credential-harvesting phishing emails — consistent with, and independently reported ahead of, the domain infrastructure BforeAI later mapped.
No CVE or software vulnerability underlies this threat; it is a brand-impersonation/social-engineering infrastructure campaign. At-risk populations include children (gambling sites using child-facing mascots, trojanized mobile apps), collectors (card fraud, investment scams), gamers (credential harvesting, app clones), and cryptocurrency investors (meme-coin rug pulls).
Target sectors: consumer, gaming, entertainment, retail, cryptocurrency, financial-services
Target regions: indonesia, turkey, Southeast Asia, Global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, MEDIUM, threat intelligence, cybersecurity, T1583, T1584, T1587, T1585, T1588, T1566, T1189, T1204, T1204, T1036