Anatomy of a Ten-Cluster Dating-Spam Credit-Drain Ecosystem
Anatomy of a Ten-Cluster Dating-Spam Credit-Drain Ecosystem
Across a seven-month window, analysts mapped a dating-spam ecosystem where ten operator clusters funnel users into credit-draining fake-romance platforms. The mail arrives as a fake engagement notification, a "someone visited your profile" nudge or a "you have a new message" tease, and every link auto-logs the recipient into a platform that charges by the message to chat with profiles that do not exist. The clusters differ in how they deliver, from self-hosted mail stacks to hijacked government school accounts, but they share a monetization playbook and, more tellingly, a set of shared backend plumbing that ties dozens of "independent" brands to a handful of operators. This report walks through how the clusters are structured, the infrastructure they abuse, the registration cohorts that unmask them, and the behavioral signals that separate the traffic from legitimate dating mail.
Key Takeaways
- Ten operator clusters run the same credit-draining playbook through different delivery rails, and the tell is not any single message but the shared plumbing beneath the brands: one image CDN, one affiliate redirect platform, a pair of shared cloud-relay endpoints, and a single mail-relay return-path.
- The largest cluster proves single-operator control of dozens of near-identical white-label dating brands by serving every brand's profile imagery from one shared CDN and wrapping every call to action in an identical base64 auto-login token.
- Domain provisioning splits cleanly into a pre-aged pool registered years in advance and switched on only recently, and same-day bulk-registered throwaway cohorts that share one registrar signature per batch.
- One cluster delivers by taking over real accounts on a national ministry-of-education school-mail system, a step beyond the free-tier email-provider signup that the other clusters rely on.
- Inbound authentication is not a usable signal anywhere in this ecosystem, because the operators send through authenticated marketing platforms, self-hosted stacks with aligned DKIM and SPF, or stolen high-reputation government and education domains.
- The adversary footprint spans several hundred domains and, across the window, hundreds of thousands of messages, including a disposable rail that burned through 640 single-use sender addresses and an affiliate rail that doubled to 92 domains before going dormant with its inventory intact.
Background
Romance and dating fraud has become one of the highest-loss consumer-fraud categories because it monetizes sustained emotional engagement rather than a single trick. The U.S. Federal Trade Commission has reported romance-scam losses in the billions, roughly $1.3 billion in 2022 against a median individual loss near $4,400, and about $1.14 billion in the following reporting year, consistently among the costliest imposter-scam types. The FTC also reports that most romance-scam victims say the first contact came through social media or a dating and messaging platform, and that losses to social-media-originated scams have climbed roughly eight-fold since 2020.
The recipient lists that feed dating-spam blasts come from the data-broker economy. Brokers aggregate email addresses enriched with demographic and interest attributes and sell them as solicitation lists, and the FTC has documented cases where a broker sold lists of elderly consumers directly to fraud operations. That pipeline hands dating-spam operators cheap, pre-targeted audiences.
The monetization model at the bottom of every cluster is the credit or "pay-per-letter" dating platform. Instead of a flat subscription, users buy credits and are charged per message read or sent, so revenue scales directly with how long a conversation runs. In the fully fraudulent variant, the "matches" are fictional personas run by paid chat operators, or increasingly by generative-AI chat tooling, whose job is to prolong the conversation and never meet. One platform in this ecosystem states the model outright in its own site footer: "Fictional entertainers' profiles marked with a heart icon are for entertainment purposes only; physical contact with these profiles is impossible." A multi-country regulatory action in the Netherlands ordered compensation for users of seventeen fake dating sites whose matches were fictional profiles staffed by chat operators, and security researchers have documented tooling that plugs generative AI into romance-scam chat automation. The clusters below are the delivery layer that fills those platforms.
Several clusters lean on legitimate sending infrastructure so their mail authenticates cleanly and inherits an established sender reputation. Amazon Simple Email Service is AWS's high-throughput mail service; its links are rewritten through the AWS-owned tracking domain awstrack[.]me, so a click redirects through a trusted-looking hop before reaching the real destination. Freemium marketing platforms such as ConvertKit, GetResponse, MailerLite, AWeber, Brevo, and Beehiiv are built for legitimate creators, but their self-service signup, generous free sending, and well-warmed shared IP pools let a throwaway campaign send DKIM-aligned mail from a reputable relay and rotate accounts as individual ones are suspended. SparkPost and MessageBird are large commercial relays whose infrastructure shows up in the envelope return-path, anchoring authentication to a high-reputation platform rather than to disposable attacker domains. ClickBank is a digital-product affiliate marketplace and ClickFunnels and Keap are funnel and automation builders, all abused to monetize scam traffic on reputable vendor hosting. Twitter/X applies its t[.]co wrapper to posted links, and because t[.]co is universally trusted it makes a convenient extra redirect hop. Profile imagery is hotlinked from Google Cloud Storage so it renders without tripping filters. The most aggressive delivery move in the ecosystem, though, is not any of these: it is account-takeover of a legitimate government and education mail system, which inherits years of institutional domain trust that a fresh free-tier account can never buy.
Discovery and Infrastructure
The ecosystem separates into ten clusters by how each one delivers and monetizes. They are not ten campaigns but ten operators running one business model, and the infrastructure fingerprints below are what tie the brands within each cluster, and in several cases across clusters, back to single hands.
The largest cluster runs a self-hosted, authentication-verified rail of near-identical white-label dating brands. Each brand sends from noreply@<brand>[.]com, replies route to donotreply@reply.<brand>[.]com, support sits at support@<brand>[.]help, and every call to action is a one-click auto-login link on the host n.<brand>[.]com. The decisive fingerprint is that every brand in the cluster serves its profile photos from one shared CDN, i.gstatvb[.]com, which collapses dozens of ostensibly separate dating sites into a single operator.
A pay-per-letter cluster delivers through Amazon SES with a distinctive /mailer/click link pattern and its own image CDN. A senior-targeted cluster centralizes on notification apexes like datingvipnotifications[.]com and chatcitynotifications[.]com that redirect to brands built for the sixty-plus and seventy-plus demographics. A flirt-and-match affiliate cluster runs lead generation through delivery. and mails. subdomains carrying affiliate-ID parameters.
A bulk-affiliate cluster generates disposable dating domains in themed families and funnels every click through one redirect platform, abe-2[.]com, on the path /index.php/campaigns/*/track-url/*. Its signature tell is that the Reply-To domain never matches the From domain, classic affiliate cross-routing that hides the terminus. A disposable .biz cluster uses single-use sender addresses on misspelled-dating-term domains, each address used exactly once, laundering clicks through t[.]co. A spiritual and tarot cluster routes manifestation and prosperity upsells through mainstream marketing platforms into a ClickFunnels-to-ClickBank checkout.
Two clusters post-date the original mapping and show where the operators are innovating. One takes over real accounts on Indonesian ministry-of-education school subdomains under belajar[.]id and delivers dating invitations to a single lander, datespark[.]club. Another rotates opaque-named domains sending from support@, all converging on two shared Amazon SES tracking endpoints that fingerprint one operator behind the rotation. A tenth cluster runs a seven-brand adult coin-drain fleet whose mail relays through a single commercial platform return-path and whose links are signed deep-links that auto-authenticate the recipient and drain prepaid coins.
| Infrastructure signal | Role | Notes |
|---|---|---|
i.gstatvb[.]com |
Shared CDN | Serves profile imagery across the entire white-label credit-drain cluster; single-operator fingerprint |
abe-2[.]com |
Redirect platform | One click-tracker behind 92 bulk-affiliate domains; cross-routed Reply-To confirms shared control |
n.bestdates[.]com |
Auto-login CTA host | Per-email base64 token one-click login; grammar repeats across the cluster as n.<brand>[.]com |
datespark[.]club |
Landing page | Sole CTA target for the hijacked-school delivery cluster |
datingvipnotifications[.]com |
Notification apex | Senior-targeted white-label redirector |
flyingenvelope[.]com |
Relay return-path | Legitimate mail-relay infrastructure abused by the coin-drain fleet; a pivot fingerprint, not an indicator |
How It Works
The lures separate by cluster, but all of them share one mechanic: the link does not ask for a password. It carries a per-message token that logs the recipient straight into the platform, so a single click starts the billable conversation. The samples below show how each cluster wraps that mechanic in a different pretext.
Sample Lures
All samples are email and show attacker-side content only. Recipient identifiers and per-message login tokens are redacted.
White-Label Credit-Drain: Fake Engagement Notification
From: "BestDates" <noreply@bestdates[.]com>
Reply-To: donotreply@reply.bestdates[.]com
Subject: Knock-knock! You have a new guest!
Body: Someone was visiting you. Ready to test your intuition?
[profile photo served from i.gstatvb[.]com, name "Gabriel"]
CTA: http[:]//n.bestdates[.]com/link/?p=[id]&u=[id]&m=[id]&t=[id]&o=[base64-token]
Pay-Per-Letter: Bonus-Credit Re-Engagement
From: "MySpecialDates" <no-reply@myspecialdates[.]com>
Subject: Enjoy your bonus credits
Body: Come back and explore the most beautiful profiles. 50 credits plus
a limited discount are waiting. Offer expires in 24 hours.
CTA: http[:]//myspecialdates[.]com/mailer/click?r=[id]&t=[id]&mid=[id]
Adult Coin-Drain Fleet: Persona Flirt With Coin-Expiry Urgency
From: "SexualSensual" <noreply@sexualsensual[.]com>
Subject: [recipient], you received a message from Kara1966
Body: Kara1966 wants to talk to you. Your coins expire soon, see her
message in full before they are gone.
CTA: http[:]//sexualsensual[.]com/#/token-login/[jwt]
Spiritual Cluster: Manifestation Hook
From: "The Universe" <contact@universeloveyou[.]com>
Subject: Your deepest prayers have not been ignored
Body: The portal for unlocking financial worries, strained relationships,
and ailing health has opened. Claim your reading.
CTA: http[:]//gift.universeloveyou[.]com/ulygifts
Hijacked-School Delivery
This cluster sends from real, compromised education accounts. The attacker-side sender grammar encodes a persona name and a phone number into the local part before the stolen domain.
From: saylor---[phone]@smk.belajar[.]id
Subject: You have a new match nearby
CTA: http[:]//datespark[.]club/[path]
Technical Analysis
Ten Rails, One Playbook
Each cluster is defined by a rigid delivery grammar that survives brand rotation, which is what lets a never-before-seen domain be attributed to a cluster on structure alone. The table below maps the ten rails to their delivery mechanism, sender grammar, and click-through family.
| Cluster (by behavior) | Delivery rail | Sender / subdomain grammar | CTA / redirect family |
|---|---|---|---|
| White-label credit-drain (largest) | Self-hosted, DKIM/SPF-verified | noreply@<brand>[.]com; n. / reply. / .help subdomains |
n.<brand>[.]com/link/?p=&u=&m=&t=&o=<base64> auto-login; CDN i.gstatvb[.]com |
| Pay-per-letter | Amazon SES | no-reply@<brand>[.]com, newsletter@emails.<brand>[.]com |
<brand>[.]com/mailer/click?r=&t=&mid= |
| Senior white-label | Centralized notification apex | notify@<x>notifications[.]com |
redirect to senior-targeted brand landers |
| Flirt/match affiliate | Marketing platform, delivery subdomains | mail@/info@<flirt-word>[.]com, mails.<brand>[.]com |
affiliate-ID URL parameters |
| Bulk affiliate | Bulk-generated domains | persona local-part, cross-routed Reply-To | abe-2[.]com/index.php/campaigns/*/track-url/* |
Disposable .biz |
Single-use senders | misspelled-dating-term <word>[.]biz |
t[.]co shortlinks |
| Spiritual/tarot | ConvertKit / GetResponse / MailerLite / Beehiiv | persona local-part on coined-compound domains | ClickFunnels to ClickBank checkout |
| Hijacked-school | Account-takeover *.belajar[.]id |
<firstname>---<phone>@<school>.belajar[.]id |
single lander datespark[.]club |
| Cloud-relay rotators | Amazon SES | support@<opaque-name>[.]com / [.]net |
two shared awstrack[.]me tracking endpoints |
| Adult coin-drain fleet | SparkPost / MessageBird | noreply@<brand>[.]com |
signed /#/token-login/ deep links; return-path flyingenvelope[.]com |
The CDN and the Token Give the Operator Away
The white-label cluster is the clearest study in single-operator control hiding behind brand variety. Dozens of dating brands present as separate businesses, but every one of them serves profile photos from the same CDN host, i.gstatvb[.]com, and every one wraps its call to action in the same auto-login grammar: n.<brand>[.]com/link/ carrying a per-email base64 token, sometimes labelled authKey or dm_key, that logs the recipient in with no password. A shared image host and an identical token scheme across brands that claim no relationship is not a coincidence; it is the operator's own infrastructure betraying the seam. The fabricated female personas that populate these brands, names like Gabriel, Ana, Tatiana, and Olga, rotate freely across the brand set, which is consistent with one profile database feeding many storefronts.
Aged Pools Versus Same-Day Batches
Registration metadata cleanly separates two provisioning models, and the recurring lesson is that creation date does not equal first-seen date. Several clusters run on domains registered years before they ever sent mail, a pre-aged inventory bought specifically to slip past new-domain heuristics. The coin-drain fleet is the sharpest example: its apexes were registered between 2019 and 2022 through one registrar and only entered mail traffic in late 2025, a dormant pool switched on years later. The white-label cluster anchors on genuinely old apexes, including one registered in 1999.
The opposite pattern is same-day bulk registration under a single registrar signature. The affiliate cluster's domains were registered in a tight seven-week window in early 2024 through one registrar, the .biz disposables cluster on another registrar across 2025 into 2026, and a sub-batch of white-label brands on one shared day in mid-2025 behind a single privacy proxy. The registrar-and-privacy fingerprint, not the brand name, is what unmasks each batch as one operator's work.
| Cohort (by behavior) | Registrar signature | Creation window | Example domains | Type |
|---|---|---|---|---|
| Credit-drain anchors | Aged-apex registrar family | 1999 to 2023 | bestdates[.]com (1999), placetochat[.]com, elenadate[.]com |
Aged, staged |
| Coin-drain fleet pool | One registrar, single proxy org | 2019 to 2022 | americumdream[.]com, sexualsensual[.]com, adultbusters[.]com |
Aged, activated 2025 |
| Spiritual apexes | Two registrars | 2020 to 2021 | universeloveyou[.]com, angelloveyou[.]com, godspirituallove[.]com |
Aged, staged |
| White-label sub-batch | One registrar plus privacy proxy | 2025-06-06 (same day) | fiestadates[.]com, sameagedates[.]com, lovesmoments[.]com |
Purpose-built recent |
| Affiliate families | Single registrar | 2024-02 to 2024-04 | abe-2[.]com, roachingdate[.]com, datingxher[.]com |
Purpose-built recent |
.biz disposables |
Single registrar | 2025-06 to 2026-02 | smartflirtmatcch[.]biz, keasymatchcity[.]biz, partnerfignd[.]biz |
Purpose-built recent |
| Cloud-relay rotators | One registrar family | 2024-06 to 2025-09 | dateordering[.]com, romanceof[.]com, matchequaly[.]net |
Purpose-built recent |
Domain Generation and Typo Siblings
Two clusters generate their domains from templates, and the vocabulary is visible in the output. The .biz cluster deliberately misspells dating terms, producing names like smartflirtmatcch[.]biz, keasymatchcity[.]biz, lovzematch[.]biz, and partnerfignd[.]biz, and it scaled from roughly 33 domains in the original window to 640 unique single-use senders. The affiliate cluster batches themed word-stems into families: a breadcrumb family (breadcrumbn[.]com, breadcrumbingx[.]com), a heythere family (heytherenow[.]com, heythere-yougo[.]com), a teasing family, a chick-finder family, a roach family, and a farm-dating family, among others. Near-duplicate typo siblings cluster the batches together, affordating alongside affrodating and affro-dating, roachingdate alongside roachxdate and roachesingdate. The white-label cluster templates its brands on the slot grammar noreply@<word>date[s][.]com, and the cloud-relay rotators go the other way, choosing semantically empty coined words like matchequaly[.]net and aheartness[.]com precisely to defeat keyword-based sender matching.
Shared Plumbing Across Clusters
The strongest cross-cluster pivots are the pieces of infrastructure that more than one brand, or more than one cluster, quietly shares. Within the white-label cluster, the i.gstatvb[.]com CDN and the n.<brand>[.]com/link/ token grammar bind the brands. The affiliate cluster is bound by the single abe-2[.]com redirect platform. The cloud-relay rotators converge on two specific Amazon SES tracking endpoints that also cross-link to a separate parcel-scam ring running on the same controlled cloud accounts, which suggests one operator servicing multiple fraud verticals. The coin-drain fleet is bound by a single commercial relay return-path, flyingenvelope[.]com, which is itself legitimate infrastructure and useful only as a pivot rather than as an indicator to block. The spiritual cluster shares one monetization chain from marketing platform to ClickFunnels lander to ClickBank checkout. And the two pay-per-letter and white-label URL fingerprints, /mailer/click?r=&t=&mid= and /link/?p=&u=&m=&t=&o=, each repeat verbatim across their respective brand sets.
From Rented Reputation Toward Owned and Stolen Infrastructure
The ecosystem is escalating along a predictable axis. The white-label cluster spun up fourteen new brand domains inside a single window, with the large majority of volume concentrated in the trailing weeks, active churn to outrun sender-reputation classification. The spiritual cluster began on rented marketing platforms and then expanded onto forty more routed domains and an additional platform spanning both email and SMS. The disposable rail exploded twenty-fold. The affiliate rail doubled to 92 domains before going quiet, retaining its expanded inventory rather than abandoning it, which reads as staging for revival rather than shutdown. And the two newest rails move past rented infrastructure entirely: one activates a years-old aged domain pool, and the other steals delivery capacity outright from a government education mail system.
Detection Observations
The clusters differ sharply in how recognizable their traffic is, and the difference tracks how far each one sits from the money.
The white-label and pay-per-letter clusters are the hardest to separate from legitimate dating mail on any single message, because a "someone visited your profile" notification is exactly what a real dating platform sends. The signal is structural rather than per-message: the shared CDN host behind unrelated brands, the identical auto-login token grammar, and the reused profile personas are what expose the cluster, not the wording of one email. The affiliate cluster carries a strong structural tell in its cross-routed Reply-To, where the reply domain never matches the sending domain, and in the single redirect platform behind every click.
The bottom-of-funnel clusters carry stronger per-message signal. The .biz disposables announce themselves through misspelled-dating-term domains and single-use sender addresses. The spiritual cluster pairs manifestation and prosperity subject lines with a marketing-platform-to-affiliate-checkout funnel that no legitimate dating service uses. The coin-drain fleet's signed auto-login deep links and coin-expiry urgency are internally consistent with an adult pay-to-message model and inconsistent with ordinary correspondence.
Inbound authentication is not a usable signal anywhere in this ecosystem. Mail rides authenticated marketing platforms, self-hosted stacks with aligned DKIM and SPF, or stolen high-reputation government and education domains, so SPF, DKIM, and DMARC checks pass across the board. Defenders should weight the shared backend pivots, the CDN host, the redirect platform, the cross-routed Reply-To, and the registrar-and-date cohorts, over any header-authentication result.
Mitigation and Guidance
- Pivot on shared backend infrastructure rather than on brand domains. One image-CDN host or one redirect platform behind many "independent" dating brands is a single-operator fingerprint that survives brand rotation.
- Treat a mismatch between the From domain and the Reply-To domain as a strong structural signal in dating and affiliate mail; legitimate platforms rarely cross-route replies to an unrelated domain.
- Cluster domains by registrar and creation-date cohort, not by name. Same-day bulk registrations under one registrar signature and aged pools activated long after registration are both strong batch-attribution signals.
- Do not rely on inbound authentication. Weight sender-to-content consistency, auto-login link grammar, and known scam-infrastructure hosts over SPF, DKIM, and DMARC results.
- Watch for account-takeover of education and government mail domains as a delivery method, and treat unexpected consumer-dating content from an institutional domain as a compromise indicator for that domain's owner.
- Flag one-click auto-login links that carry an opaque per-message token, especially where the destination host is a bare
n.<brand>style subdomain, as a credit-platform funnel pattern.
MITRE Fight Fraud Framework Mapping
The mapping below aligns to the MITRE Center for Threat-Informed Defense Fight Fraud Framework, at https://ctid.mitre.org/fraud. The public matrix renders client-side and does not expose stable technique identifiers in a citable form, so behaviors are mapped by tactic and technique name; consult the live matrix for current identifiers.
| Tactic | Technique observed in this ecosystem |
|---|---|
| Resource Development | Acquire freemium and cloud-relay sending accounts; take over government and education mailboxes; purchase data-broker recipient lists; register aged and bulk domain cohorts; build fictional personas |
| Initial Access | Mass unsolicited dating-notification email; engagement-bait and re-engagement lures; link-driven contact through wrapped and shortened URLs |
| Initial Access | Fabricated persona profiles; fake engagement metrics and visit notifications; scripted or AI-assisted chat operators posing as matches |
| Execution | Emotional-vulnerability and loneliness pretexts; coin-expiry and bonus-credit urgency; one-click auto-login that removes friction to the billable conversation |
| Monetization | Credit and pay-per-letter billing that drains funds per message; affiliate lead-generation payouts; funnel and checkout pages on reputable vendor hosting |
| Stealth | Redirect and shortlink laundering through trusted wrappers; imagery on reputable CDNs; delivery through high-reputation relays and authenticated domains; domain and account rotation |
Indicators of Compromise
All indicators are defanged. Victim data has been removed. Each table is a representative subset of the verified-malicious set; where a type was capped, the note gives a floor, not the exact observed total. Legitimate infrastructure the operators abuse (mainstream marketing platforms, cloud relays, and the compromised education domains that are themselves victims) is deliberately excluded.
Senders
| Value | Cluster | Notes |
|---|---|---|
noreply@bestdates[.]com |
White-label credit-drain | Auto-login token CTA, shared CDN |
noreply@fiestadates[.]com |
White-label credit-drain | Same-day-registered sub-batch |
noreply@sameagedates[.]com |
White-label credit-drain | Brand-rotation expansion |
notify@datingvipnotifications[.]com |
Senior white-label | Redirects to senior-targeted landers |
notify@chatcitynotifications[.]com |
Senior white-label | Notification-apex redirector |
mail@hometownflirt[.]com |
Flirt/match affiliate | Lead-generation sender |
addison@datingxher[.]com |
Bulk affiliate | Persona local-part, cross-routed Reply-To |
angel@roachingdate[.]com |
Bulk affiliate | roach naming family |
contact@godspirituallove[.]com |
Spiritual/tarot | Marketing-platform relay |
contact@universeloveyou[.]com |
Spiritual/tarot | Manifestation upsell funnel |
support@manifestwithaaron[.]com |
Spiritual/tarot | Dominant persona in the cluster |
noreply@americumdream[.]com |
Adult coin-drain fleet | Relay return-path pivot |
noreply@sexualsensual[.]com |
Adult coin-drain fleet | Signed auto-login deep link |
support@matchequaly[.]net |
Cloud-relay rotators | Opaque-name rotating domain |
… (representative subset; hundreds of verified-malicious sender addresses)
Domains
| Value | Cluster | Notes |
|---|---|---|
bestdates[.]com |
White-label credit-drain | Aged apex, 1999 registration |
fiestadates[.]com |
White-label credit-drain | Same-day sub-batch |
placetochat[.]com |
White-label credit-drain | Shared CDN and token grammar |
datingsmatch[.]com |
White-label credit-drain | Brand-rotation expansion |
abe-2[.]com |
Bulk affiliate | Redirect platform behind 92 domains |
datingxher[.]com |
Bulk affiliate | Persona sender, cross-routed Reply-To |
roachingdate[.]com |
Bulk affiliate | roach naming family |
smartflirtmatcch[.]biz |
Disposable .biz |
Misspelled-term single-use domain |
datespark[.]club |
Hijacked-school | Sole lander for the school-account rail |
americumdream[.]com |
Adult coin-drain fleet | Aged pool activated 2025 |
sexualsensual[.]com |
Adult coin-drain fleet | Aged pool activated 2025 |
godspirituallove[.]com |
Spiritual/tarot | ClickFunnels-to-ClickBank funnel |
universeloveyou[.]com |
Spiritual/tarot | Manifestation upsell |
matchequaly[.]net |
Cloud-relay rotators | Opaque-name rotator |
… (representative subset; 500+ verified-malicious domains). The .biz cluster follows the misspelled-dating-term template and rotates continuously, and the affiliate cluster batches themed word-stem families (breadcrumb, heythere, teasing, chick-finder, roach, farm-dating).
Hosts
| Value | Role | Notes |
|---|---|---|
i.gstatvb[.]com |
Shared CDN | Profile imagery across the white-label cluster |
n.bestdates[.]com |
Auto-login CTA | Per-email base64 token login host |
n.elenadate[.]com |
Auto-login CTA | Same n.<brand> grammar |
reply.bestdates[.]com |
Reply-To host | donotreply@reply.<brand> convention |
gift.universeloveyou[.]com |
Landing | Spiritual gift-claim lander |
go.yourspiritualsoul[.]club |
Redirect | Spiritual cluster redirect host |
… (representative subset; hundreds of verified-malicious hosts, most of which are apex hosts already listed above)
Conclusion
The operators here have industrialized loneliness. Ten clusters run one credit-draining business model across rented, owned, and stolen infrastructure, and their resilience comes from brand churn fast enough to outrun sender reputation and from a domain pipeline that stages inventory years in advance. The durable tell is never the brand on the envelope; it is the plumbing underneath, the shared image CDN, the single redirect platform, the reused cloud endpoints, the identical auto-login token. Defenders tracking dating spam should map that shared backend first and treat any one-click auto-login notification as the front door to a metered conversation with a profile that was never real.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.