New 'Gray Zone' Web Threat: Kaspersky Exposes Sites That Steal Without Being Phishing

By ✦ min read

Breaking: Kaspersky Reveals Widespread 'Undefined Trust Level' Sites—Fake Extensions Top Global Threat

January 2026 – A new category of deceptive websites is evading traditional security filters, according to cybersecurity firm Kaspersky. These sites, labeled as "Sites with an undefined trust level," cannot be classified as phishing but still trick users into losing money or data.

New 'Gray Zone' Web Threat: Kaspersky Exposes Sites That Steal Without Being Phishing
Source: securelist.com

Kaspersky’s latest data shows that fake browser extensions mimicking security products are now the most common such threat, detected in 9 out of 10 regions analyzed worldwide. These extensions intercept browser data, track activity, hijack searches, and inject ads.

"These sites operate in a legal gray area, using carefully crafted terms of service to make victims voluntarily pay for fake services or unknowingly sign up for subscriptions," said Maria Garnaeva, a security researcher at Kaspersky. "Unlike phishing, they don’t steal credentials—they manipulate consent."

Background: What Makes a Site ‘Undefined’?

Kaspersky introduced a new web filtering category for these resources in its Premium, Android, and iOS apps. The system automatically analyzes domain name and age, IP reputation, DNS configuration, HTTP security headers, and SSL certificates to flag suspicious sites—without definitively labeling them as phishing.

Examples include fake online stores, dubious crypto exchanges, investment platforms, and services with hidden paid subscriptions. These sites often use cheap domains (.xyz, .top, .shop), are registered less than six months ago, and make unrealistic promises like “100% guaranteed income” or “up to 300% profit.” Payment is only via cryptocurrency or irreversible bank transfers.

Regional Variations of the Threat

What This Means for Users

The rise of undefined trust level sites blurs the line between legitimate and malicious. Even security-savvy users can fall victim because the sites appear legal on the surface.

New 'Gray Zone' Web Threat: Kaspersky Exposes Sites That Steal Without Being Phishing
Source: securelist.com

Kaspersky advises checking for red flags: strange domain names (numbers/random characters), very recent registration (under 6 months via WHOIS), lack of company contact info, and payment methods that offer no buyer protection.

If you encounter a site that feels off but isn’t obviously malicious, treat it with extreme caution. “The best defense is skepticism,” Garnaeva added. “If an offer sounds too good to be true, it likely is—even if the site isn’t technically phishing.”

For more details, see our guide on key indicators of suspicious websites.

Key Indicators to Watch

  1. Domain oddities: Numbers or random strings, cheap TLDs (.xyz, .top, .shop).
  2. Young domain: Registered less than 6 months ago.
  3. Unrealistic promises: “Guaranteed income,” “300% profit.”
  4. No contact info: Missing company details, no physical address.
  5. Irreversible payments: Cryptocurrency or wire transfers only.
Tags:

Recommended

Discover More

How to Revamp Group Search for Community Knowledge10 Mind-Blowing Facts About AlteredBlood+ – The Movement Shooter Where Blood Is PowerHow to Install and Use Orion for Linux Beta with New Content Blocker and Download ManagerMapbox Styles Unlocked: A Step-by-Step GuideStrengthening Deployment Safety with eBPF: A GitHub-Inspired Guide