Cybersecurity experts from Cofense reveal a significant increase in malicious campaigns using .es domains, with a 19x rise from Q4 2024 to Q5 2025.
Credential phishing attacks made up 99% of the malicious campaigns, while 1% were related to remote access trojans, and Microsoft was the most impersonated brand.
.es domains, primarily intended for Spanish-speaking audiences, saw approximately 1,400 malicious subdomains across 450 base domains in the first five months of the year.
Despite the significant rise in .es domain usage for cyberattacks, common attack vectors remained unchanged, with most attacks impersonating Microsoft and using tactics like spoofed emails to deliver malware.