Large Scale Traffic Brokerage Campaign using Fake Lures targeting Global Brands Across Multiple Regions
ID: c1c4765f-5a03-5301-b677-136ab66bed19
STIX ID: report--c1c4765f-5a03-5301-b677-136ab66bed19
Feed Name: CloudSEK Blog
Threat Score
This report outlines a global, centralized traffic-broker phishing operation that runs hundreds of disposable, brand-themed microsites (using TLDs like .xyz, .top, .cn) to lure mobile users with localized giveaway/discount campaigns across 100+ countries and 300+ brands; the infrastructure harvests and profiles victims, filters for mobile visitors to evade scanners, and monetizes traffic by redirecting it to downstream scams such as pig butchering and Telegram account compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
