Be wary, miHoYo’s official website domain “mihoyo.com” has seemingly been compromised and some bad actors are creating various new malicious subdomains as phishing sites to draw out users’ personal information.
miHoYo has yet made any official statement regarding this matter.
miHoYo, the developers of the popular Honkai Impact 3rd, Genshin Impact, and Honkai Star Rail, seemingly have their website domain “mihoyo.com” compromised and their DNS records stolen.
The news came about when Twitter user @merlin_impact tweeted out a screenshot of a browser showing a subdomain of mihoyo.com getting flagged by Google for containing malicious malware that can collect user data.
The URL of the subdomain is shown to be “vpn.mihoyo.com”, which is not an official subdomain of miHoYo’s website.
With attackers having access to miHoYo’s DNS records, new sites are being created under “mihoyo.com” and may contain login fields to phish personal information out of the user.
For example, the new website can be of “(random word).mihoyo.com”, masking itself to look like an official miHoYo website.
So far, users report that no established official miHoYo websites have been compromised but the best advice is to be cautious when accessing any miHoYo websites for now.
While the attackers are using fake subdomains for now, they can still use the stolen DNS records to redirect established official domains to malicious fake websites.