Pokémon Brand-Spoofing Campaign: 1,352 Lookalike Domains Ahead of 30th Anniversary

Pokémon Brand-Spoofing Campaign (TL-2026-1520), also tracked as Pokémon 30th Anniversary Domain Spoofing Campaign, is a medium-severity phishing campaign, first published 2026-07-19. It has no confirmed attribution, affects The Pokémon Company Pokémon brand / trademark (consumer-facing games, maps to 17 MITRE ATT&CK techniques (T1005, T1036, T1056), and is covered by 9 detection rules and 29 indicators of compromise.

Key facts for TL-2026-1520

Threat ID
TL-2026-1520
Also known as
Pokémon 30th Anniversary Domain Spoofing Campaign, Pokémon Pre-Crime Domain Report
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
2026-07-19
Last reviewed
2026-07-19
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
consumer, gaming, entertainment, retail, cryptocurrency, financial-services
Target regions
indonesia, turkey, Southeast Asia, Global
Detection rules
9
Indicators of compromise
29

BforeAI PreCrime Labs identified 1,352 lookalike domains impersonating the Pokémon brand, 85% registered March-May 2026 ahead of Pokémon's 30th Anniversary cycle, spanning credential harvesting, character-specific phishing, counterfeit merchandise, trading-card fraud, mobile app trojanization, illegal gambling, and cryptocurrency pump-and-dump schemes.

How Pokémon Brand-Spoofing Campaign works

BforeAI's PreCrime Labs published "Pokémon Brand Spoofing in 2026: Pre-Crime Analysis of 1,352 Lookalike Domains" on 2026-06-17, documenting a large, financially motivated brand-abuse campaign timed to Pokémon's 30th Anniversary. Registration volume spiked across Q2 2026 (401 domains in March, 378 in April, 376 in May — 85% of the total 1,352-domain set), consistent with opportunistic infrastructure staging ahead of anniversary-driven consumer attention, product launches, and trading-card releases.

The domains cluster into six primary abuse categories: credential harvesting (671 domains, 49.6%) using generic typosquats keyed to game launches; character-specific phishing (233 domains, 17.2%) weaponizing named Pokémon (Pikachu, Mewtwo, Charizard, Squirtle) as lure hooks for fake card sales and passes; e-commerce/counterfeit merchandise fraud (161 domains, 11.9%); trading-card-game (TCG) and card-grading fraud (154 domains, 11.4%) impersonating legitimate authentication/grading services; mobile app clones (86 domains, 6.4%) distributing trojanized APKs including Pokémon GO "hack"/spoofing tools; and fan-tool phishing (47 domains, 3.5%) impersonating Pokédex lookups and IV calculators.

Distinct regional/thematic clusters were identified: an Indonesia-based illegal gambling network (170+ domains) using systematically numbered Pikachu branding (pikachu168v1.com through v3) and Indonesian slang ("Gacor" — slot-machine hot streak) across .bet/.live/.sbs/.ink/.world TLDs; a Turkey-targeted geo-affiliate/PPC-fraud cluster (48 domains) following a [city]pikachu[number].click pattern across cities including Alanya, Fethiye, and Kayseri; a TCG/card-grading fraud ecosystem (62 domains) spanning counterfeit shops, wholesale fraud, and scalper tooling; a Pokémon GO spoofing-infrastructure cluster (34 domains) offering GPS-spoofing and coordinate-sharing tools with child-safety implications given the game's ~80M monthly active users; a cryptocurrency meme-coin cluster (7 domains) blending Pokémon characters with Solana-ecosystem tokens for pump-and-dump/rug-pull schemes; and a piracy/bot-infrastructure cluster (19 domains) offering ROM hacks and purchase bots that risk bundling malware with pirated content. A redirect chain was observed routing pokemonromhacks.com traffic through FIFA World Cup 2026 sports content into a fake antivirus-renewal scam, demonstrating traffic-monetization layering typical of malvertising redirector chains.

Registrar concentration favors GoDaddy LLC (191 domains), Namecheap Inc (158), Spaceship Inc (78), and Cloudflare Inc (60), with TLD distribution led by .com (673), followed by .net (78), .online (52), .xyz (52), .click (47), and specialty gTLDs (.vip, .bet, .app, .exposed, .lat). A distinct 6-domain sub-cluster using an "a1-" naming prefix is hosted on Aliyun infrastructure and targets Asian slot-gambling providers.

Separately, Bitdefender's Hot for Security (2026-02-26, author Alina Bîzgă) corroborates the trading-card-fraud vector: at least 477 reported Pokémon TCG scam cases since October 2025 totaling over $958,000 in losses, driven by pre-order fraud, fake marketplace seller accounts, counterfeit graded-card slabs mimicking legitimate grading companies, non-card merchandise scams (anniversary plushes/figurines), and credential-harvesting phishing emails — consistent with, and independently reported ahead of, the domain infrastructure BforeAI later mapped.

No CVE or software vulnerability underlies this threat; it is a brand-impersonation/social-engineering infrastructure campaign. At-risk populations include children (gambling sites using child-facing mascots, trojanized mobile apps), collectors (card fraud, investment scams), gamers (credential harvesting, app clones), and cryptocurrency investors (meme-coin rug pulls).

MITRE ATT&CK techniques used in TL-2026-1520

Collection

T1005 Data from Local System

Defense Evasion

T1036 Masquerading

Credential Access

T1056 Input Capture; T1539 Steal Web Session Cookie

Command and Control

T1102 Web Service; T1104 Multi-Stage Channels

Initial Access

T1189 Drive-by Compromise; T1566 Phishing

Execution

T1204 User Execution

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1588 Obtain Capabilities

Reconnaissance

T1589 Gather Victim Identity Information

Impact

T1657 Financial Theft

stealth

T1684.001 Impersonation

Affected products and versions in Pokémon Brand-Spoofing Campaign

  • The Pokémon Company — Pokémon brand / trademark (consumer-facing games, TCG, mobile apps)
    Vulnerable versions: Brand/trademark impersonation — not a versioned software product
  • Niantic — Pokémon GO (mobile game, ~80M MAU)
    Vulnerable versions: All versions — targeted by GPS-spoofing tool phishing and trojanized APK clones

Remediation for Pokémon Brand-Spoofing Campaign

Immediate actions

  • Block/sinkhole newly-observed Pokémon-lookalike domains at DNS/perimeter as they are identified (registrar and hosting data provided by BforeAI)
  • Flag and quarantine incoming email/notifications referencing Pokémon anniversary promotions, giveaways, or limited-time drops for phishing inspection
  • Report confirmed trademark-infringing/phishing domains to registrars (GoDaddy, Namecheap, Spaceship, Cloudflare) and TLD registries for takedown
  • Alert parents/guardians and school IT filtering systems to the child-safety risk from gambling sites using Pikachu/Pokémon branding

Workarounds

  • Verify all Pokémon-branded promotions, drops, or giveaways exclusively through official pokemon.com and verified social channels before any purchase or credential entry
  • Treat unsolicited crypto-wallet-connection requests or seed-phrase prompts on any Pokémon-themed site as malicious
  • Use platform-protected payment methods for TCG purchases and refuse direct bank transfer/cryptocurrency payment requests from sellers

Longer-term hardening

  • Deploy brand-protection/domain-monitoring services to continuously track new registrations combining 'pokemon', character names, or franchise terms with high-risk TLDs (.xyz, .click, .bet, .vip)
  • Partner with app-store operators (Google Play, Apple App Store, third-party APK repositories) to detect and remove trojanized Pokémon GO and TCG-related mobile app clones
  • Establish official-channel verification guidance for TCG marketplaces and collectors to reduce counterfeit-grading and pre-order fraud exposure
  • Monitor cryptocurrency exchanges/DEXs for Pokémon-themed meme-coin launches exhibiting pump-and-dump patterns

Timeline of Pokémon Brand-Spoofing Campaign

  • BforeAI notes legacy Pokémon-brand domain squatting dates back to 2018, forming a small baseline of pre-existing infrastructure distinct from the 2026 anniversary-driven surge.
  • Bitdefender/Singapore authorities begin logging Pokémon TCG scam cases (477 cases by Feb 2026, $958K+ losses) predating the domain-infrastructure buildout.
  • Singapore Police Force issues a public advisory warning consumers about Pokémon trading-card scams amid rising reported case volume.
  • "Mega Evolution – Ascended Heroes" TCG expansion set releases, prompting a documented increase in pre-order and counterfeit-listing scam activity around the launch window.
  • Bitdefender Hot for Security publishes Alina Bîzgă's article corroborating the trading-card-fraud vector, citing 477 reported cases and $958,000+ in losses since October 2025.
  • Pokémon Day marks the franchise's 30th-anniversary celebration, the flagship event around which the domain-registration surge and scam activity are timed.
  • 401 Pokémon-lookalike domains registered in March 2026, the first month of the Q2 registration surge.
  • "Mega Evolution—Perfect Order" TCG expansion set is scheduled for release, a further product-launch trigger event anticipated to drive additional pre-order and counterfeit-listing scam infrastructure.
  • 378 additional lookalike domains registered in April 2026, continuing the pre-anniversary infrastructure buildout.
  • 376 additional lookalike domains registered in May 2026, completing the 85%-of-total Q2 registration wave.
  • bfore.ai report first captured by TL-Intel Harness source feed as initial reference for hunt skeleton.
  • BforeAI PreCrime Labs publishes "Pokémon Brand Spoofing in 2026" report, disclosing the full 1,352-domain dataset, registrar/TLD breakdown, and regional threat clusters.
  • TL-Intel Harness RESEARCH phase compiles corroborating sourcing (BforeAI + Bitdefender) into full threat-intelligence record.

Sources cited for Pokémon Brand-Spoofing Campaign

Threats related to Pokémon Brand-Spoofing Campaign

Detection coverage for TL-2026-1520

As of 2026-07-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1520 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats