SphereTI

Threat analysis

Albania e-Visa scam: fake domains exposed

Alphatechs' June 2026 investigation documented a continuing campaign of lookalike domains impersonating Albania's official e-Visa portal. Some cloned government branding and application workflows; another targeted visa verification. Separately, infostealer data contained saved credentials or sessions for the legitimate portal, showing that the risk extended beyond phishing sites.

How the fake portals were uncovered

In April 2026 the Albanian Ministry for Europe and Foreign Affairs warned the public about a fraudulent site imitating the official e-Visa service. The advisory named one domain. Tracking certificate transparency logs and new registrations against the “evisa” and “albania” keyword patterns, Alphatechs documented multiple lookalikes registered between October 2025 and June 2026.

The most complete clone reproduces the official branding, the visa exemption information and the full application workflow, down to working login and registration forms; the address bar is the only tell. Another runs a French-language “visa verification” page — a design that appears aimed at Francophone travelers — asking for tracking number, visa number and passport number together. A related site poses as an instant document verification registry with QR scanning, which could target not only the traveler but the employer or border officer checking their papers. The newest hostname in the report was registered on 8 June 2026 and was harvesting credentials within days.

The exposed-system count is a separate measurement, and worth stating precisely: more than 1,950 devices compromised by infostealer malware — Lumma and Nexus among the families observed — carried saved logins or session data for the legitimate portal in the stolen files. It is not a breach of the government system. It means a substantial number of people are applying for visas from machines that are already compromised, and their travel document data is circulating in criminal datasets either way.

Read the full analysis on alphatechs.al →
8 Fake Domains, 1,950 Compromised Systems: How We Uncovered an Ongoing Albania e-Visa Scam Campaign · Imelda, Alphatechs · published 12 June 2026 · full IOC set and registration detail in the accompanying TLP:WHITE report

How SphereTI detected the campaign

Both halves of that investigation are the platform's own work. Finding multiple domains where an advisory named one is DNS and brand monitoring — certificate transparency logs and new registrations, read continuously. The exposed-system measurement comes from the same collection that feeds dark web and stealer log monitoring. One campaign, two modules, and the honest answer to where a threat intelligence platform's intelligence comes from.

It also sets the standard for what gets published here: measured numbers, a stated observation window, and a method that can be challenged.

How to avoid the fake portals

Albania's official electronic visa service is at e-visa.al. Type that address directly, and check the address bar before entering passport, visa, account, or payment information. A familiar-looking logo and a working application form do not establish that a site belongs to the government.

Earlier: the Lumma Stealer takedown

Over a 60-day window spanning the May 2025 international operation against Lumma Stealer, the team measured 881,387 compromised systems, of which 242,091 were attributed to Lumma. The source recorded 786,041 antivirus installations across compromised systems — evidence that having endpoint protection installed did not prevent every infection in the observed dataset.

Read the Lumma Stealer analysis →
Lumma Stealer Disruption: A Comprehensive Analysis of the World's Most Prolific Infostealer Takedown · Brenton, CTO, Alphatechs · published 9 September 2025

About Alphatechs

Alphatechs is the cybersecurity company that builds and operates SphereTI, based in Tirana, Albania. Its team handles the collection, analysis, and engineering behind the platform's five intelligence modules.

The platform is published as SphereTI, previously Sphere Threat Intelligence. The name changed; the team, the collection, and the domain did not.

Check your own exposure

Enter a work email and SphereTI checks it against known breaches and stealer logs, then shows you which credentials have been exposed. Free, and it never asks for your password.

Get your free report