logo

Large Scale Traffic Brokerage Campaign using Fake Lures targeting Global Brands Across Multiple Regions

ID: c1c4765f-5a03-5301-b677-136ab66bed19

STIX ID: report--c1c4765f-5a03-5301-b677-136ab66bed19

Feed Name: CloudSEK Blog

Threat Score
70/100

Date Published: 2026-04-07

Date Updated: 2026-05-12

...
...

This report outlines a global, centralized traffic-broker phishing operation that runs hundreds of disposable, brand-themed microsites (using TLDs like .xyz, .top, .cn) to lure mobile users with localized giveaway/discount campaigns across 100+ countries and 300+ brands; the infrastructure harvests and profiles victims, filters for mobile visitors to evade scanners, and monetizes traffic by redirecting it to downstream scams such as pig butchering and Telegram account compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.