Skip to content
DnsLister Forum

Where domain hunters compare notes

DoppelCart fraud network uses 119,000 fake shops to steal credit cards

This is a massive, well-orchestrated fraud operation targeting online shoppers. The scale alone—over 119,000 domains—makes this a significant threat for anyone handling e-commerce traffic or user transactions.

Technical Breakdown

  • TTPs (MITRE): This is primarily Resource Development (T1583) via domain registration and User Execution (T1204) by luring victims to the fake shops. The core objective is Credential Access / Unsecured Credentials (T1552) for payment card data (PCI DSS violation).
  • Infrastructure: The network uses a "Doppelganger" technique—copying legitimate brand storefronts (e.g., clothing, electronics) to create convincing phishing pages. The 119,000 domains are likely parked on a shared hosting infrastructure or a bulletproof provider.
  • IOCs: No specific IPs or hashes provided in the summary, but the primary IOC is the domain list itself. Defenders should monitor for domains containing misspellings of major brands (e.g., "nike-outlet-xyz[.]com") or using TLDs like .shop, .store, or .xyz with suspicious registration dates.
  • Victim Profile: Targets consumers searching for deals on popular brands. The fake shops likely use SEO poisoning and social media ads to drive traffic.

Defense

  • For Users: Enable browser-based phishing protection (e.g., Google Safe Browsing, Microsoft Defender Smartscreen). Never enter payment details on a site you found via a social media ad or a suspicious search result.
  • For Organizations: If you operate an e-commerce platform, monitor for domain squatting on your brand. Use threat intelligence feeds to block known DoppelCart domains at the DNS or web proxy level.

Source: https://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-119-000-fake-shops-to-steal-credit-cards/

Source: r/SecOpsDaily · by /u/falconupkid

Leave a Reply

Your email address will not be published. Required fields are marked *