Twelve Brands, Two Backends: A Single-Operator Loan-Smishing Network
Twelve Brands, Two Backends: A Single-Operator Loan-Smishing Network
Since December 2025, one operator has run at least twelve fake lending brands over dozens of domains that all funnel to two shared backend redirectors. The brands present as separate companies with separate names, separate domains, and separate "account reps," but they share plumbing that gives the game away: every front-end resolves through the same pair of redirect servers, the domains carry an identical subdomain grammar, the emails ship an identical footer template with the same Delaware shell address, and a small cast of first-name-only personas rotates across the whole set. This is an attribution study. It walks through how a dozen ostensibly independent loan brands collapse into one operator once you look at the infrastructure, the registration cohorts, and the naming conventions underneath the names on the envelope.
Key Takeaways
- At least twelve loan, insurance, and retirement "brands" across roughly forty domains all resolve through two shared redirect backends, and that shared convergence is the proof of a single operator.
- The operator splits its registrar posture deliberately: the two backends sit on one registrar while the front-end brand fleet sits almost entirely on another, isolating the infrastructure tier from the disposable brand tier.
- Roughly a hundred SMS senders, spanning 27 numeric shortcodes, more than 70 VoIP phone numbers, and a handful of email addresses, all push the same fabricated-prior-engagement lure ("your request has been accepted") toward per-victim tracking links.
- The front-end domains share a single mail fingerprint and a rigid trust-building subdomain grammar (auth, signin, login, my, go, start), so a never-before-seen domain can be attributed to the network on structure alone.
- The operation is cross-channel: SMS-collected phone numbers surface as the subject lines of the follow-up emails, and the redirect backend carries a Facebook domain-verification token that ties the network to paid-social ad delivery.
- For months the two backends stayed absent from mainstream public threat feeds, so any defense that leans only on public blocklists would have had little to work with against a network sending tens of thousands of messages.
Background
Fake loan-approval texts are a mature, high-volume fraud category. In January 2026 the U.S. Federal Trade Commission published a consumer alert on exactly this pattern: unsolicited messages telling recipients they have been approved or pre-approved for a loan they never applied for, designed to pull them into responding or clicking. The Consumer Financial Protection Bureau has long warned about unsolicited pre-approved loan offers as a vector for advance-fee fraud and data harvesting. The network described here is a large, sustained instance of that pattern, built for lead-generation fraud rather than for any real lending.
The monetization is the lead itself. A fake loan application collects full name, date of birth, Social Security number, employment, income, bank-account details, and home address, and that record has resale value whether or not the victim ever sees a dollar. Harvested profiles feed predatory lenders paying per delivered lead, data brokers, and outright identity theft, and the same profile can be sold more than once. The tell that this is a lead-gen operation rather than a single scammer is the industrial breadth of the brand set and the shared backend that every brand funnels into.
Several pieces of legitimate infrastructure carry the operation. Amazon Simple Email Service is AWS's high-throughput mail platform; the operator sends its email follow-ups through it so the mail authenticates cleanly and inherits a trusted relay's reputation. Most of the front-end domains are registered through Namecheap behind the "Withheld for Privacy ehf" proxy, a routine privacy service that here masks bulk registrations under one hand. The two backend redirectors sit on a different registrar entirely. None of these services is the adversary; each is ordinary infrastructure the operator leans on to stay cheap, fast, and hard to attribute.
Discovery and Infrastructure
The network surfaced as a wave of loan-approval SMS traffic across many senders and many brand names, and it resolved into a single operator once the redirect layer came into view. Clicking any brand's link runs the victim through one of two backend servers, loadingaccount[.]com or nwtrk[.]com, before landing on the fake application. Both backends are registered through Squarespace Domains II LLC, a registrar that none of the front-end brand domains use. That split is the first structural fingerprint: the operator keeps its durable infrastructure tier on one registrar and burns disposable brand domains on another.
The brands cross-redirect to each other in ways no set of genuine competitors would. Observed chains include brrwly[.]com routing to gochecks[.]org, lendlli[.]com routing to checkgo[.]org, and gochecks[.]org routing to clearcheck[.]org. Front-end brands that claim no relationship redirect into one another and then converge on the same two backends. Alongside the shared backends, the email channel shows an identical footer template across three separate "companies" and the same Delaware address, 1042 N Dupont Hwy Dover, DE 19901, a mass-mail registered-agent address that appears byte-for-byte in Borrowly, PartnerPros, and ClearCheck mail.
| Indicator | Role | Notes |
|---|---|---|
loadingaccount[.]com |
Redirect backend | Primary landing/redirect server; Squarespace-registered; every brand resolves here |
nwtrk[.]com |
Redirect backend | Secondary redirect/tracking server; name reads as "network track"; carries a Facebook domain-verification token |
checkgo[.]io |
Brand front-end | CheckGo family; Namecheap; resolves to both backends |
borrowly[.]io |
Brand front-end | Borrowly family; auto-login subdomain grammar |
lendli[.]org |
Brand front-end | Lendli family; note the spelling, distinct from the unrelated legitimate lender "Lendly" |
fintara[.]org |
Brand front-end | Fintara brand; registered the same day as checkgonow[.]com |
txtro[.]cc |
Auxiliary | Short "txt-router" style tracking domain on a cheap TLD |
How It Works
The contact chain is the same across every brand. It starts with an unsolicited message that invents a prior relationship, moves the victim through a per-victim tracking link, bounces them through a shared backend, and drops them on a fake application form.
The lure claims the victim already applied. Messages say the "request has been accepted," the "review team gave your request the green light," or the application "expires tonight," and they attach a first-name-only rep, Amy, Mark, Ben, Jackie, or Jaclyn, to manufacture a personal thread. Financial hooks name a specific amount ("an extra 3200," "around 600") to make the fiction concrete. Each message carries a unique URL with a per-victim token on a trust-building subdomain such as signin.borrowly[.]io or go.partnerpros[.]org.
The click runs through loadingaccount[.]com or nwtrk[.]com on an obfuscated path, then lands on a form that harvests full name, date of birth, Social Security number, employment, income, bank details, and address. Victims who submit then receive branded email follow-ups sent through Amazon SES from the same brand domains, and those emails reuse the SMS-collected data. The clearest proof of cross-channel reuse is a Borrowly email whose subject line is the recipient's own phone number in E.164 format, and an ExpressFunds email whose call-to-action URL pre-fills the victim's email and name as plaintext query parameters.
Sample Lures
All samples show attacker-side content only. Every recipient identifier (name, email, phone, IP, account digits, per-victim token, date) has been redacted to a placeholder, and every URL and domain is defanged. The operator's own shell-entity footer addresses are retained because they are attribution evidence, not victim data.
SMS: Loan-Approval Pretext With PIN Follow-Up (CheckGo)
Sender: [SMS shortcode]
Hi [recipient], our review team just gave your request the green light.
View your options: http[:]//go.checkgo[.]io/[token]
PIN REQUIRED: [code]
Access your request: http[:]//my.checkgo[.]io/[token]
SMS: Named-Rep Fabricated Engagement (Borrowly)
Sender: [VoIP number]
Hi this is Amy with Borrowly, your request has been accepted!
Sign in to review your options: http[:]//signin.borrowly[.]io/[token]
SMS: Wellness/Benefits Vertical (CareMile)
Sender: [VoIP number]
Hello [recipient], your request got accepted and your benefits are ready.
Review here: http[:]//go.caremile[.]org/[token]
Email: Broken Templating and the Shared Shell Footer (Borrowly)
From: Ben Masters <ben.masters@borrowly[.]io>
Subject: Received for: [recipient phone]
Return-Path: <[token]@amazonses.com>
Hi ,
This is Ben from Borrowly, received your submission. View below.
View Submission
Ben Masters
Borrowly
[recipient email] registered to receive email on [date]
with [recipient IP] at borrowly.
To not hear from me again, unsub here.
1042 N Dupont Hwy Dover, DE 19901
Email: Funding-Amount Pretext With PII-Laden CTA (ExpressFunds)
From: ExpressFunds <info@expressfundin[.]com>
Subject: Final reminder: Confirm your e-deposit by [date], [recipient].
Hi [recipient], have you checked your unused $19,800 funding request?
Take a moment to review your details and complete your application.
Complete Your Application:
http[:]//expressfundin[.]com/?email=[recipient email]&source=_&firstName=[recipient]&lastName=[recipient]
Best Regards, ExpressFundin
539 W. Commerce St #8014, Dallas, TX 75208
The "Hi ," with no name is the templating engine failing when the upstream data row lacks a first name, and it confirms the mail is generated from a harvested list. The call-to-action URL in the second sample carries the recipient's email and name as query parameters, so the operator pre-fills its own downstream form with data it already holds, and anyone who sees a forwarded copy of that link sees the victim's data too.
Technical Analysis
The brand names are noise. Everything durable about this network lives in the registrar posture, the registration cohorts, the subdomain grammar, the mail fingerprint, and the domain-generation scheme, and each of those ties the "twelve brands" back to one operator.
The Registrar Split That Isolates the Backends
The operator runs a two-tier registrar strategy. The two redirect backends, loadingaccount[.]com and nwtrk[.]com, are registered through Squarespace Domains II LLC. The front-end brand fleet, the bulk of the domains, sits almost entirely on Namecheap behind the "Withheld for Privacy ehf" proxy, with a couple of newer additions branching to Amazon Registrar as older domains lapse. Keeping the infrastructure tier on a separate registrar from the disposable brand tier means the brand domains can burn and rotate without touching the backends that actually route the money, and it means a takedown at the front-end registrar leaves the redirect layer intact.
Registration Cohorts: Aged Acquisitions and Monthly Bulk Waves
WHOIS creation dates separate the fleet into staged pools and a rolling expansion, and they show the operator both buying legacy footprint and spinning up brands on a monthly cadence.
| Domain | Registrar | Created | Cohort |
|---|---|---|---|
lendli[.]com |
GoDaddy | 2012-01-30 | Aged acquisition, reused for legacy footprint |
simpleverify[.]co |
Namecheap | 2021-09-13 | Aged acquisition |
checkgobenefits[.]com |
Namecheap | 2023-11-10 | Late-2023 bulk wave |
lendli[.]io |
Namecheap | 2023-11-17 | Late-2023 bulk wave |
makesaveretire[.]com |
Namecheap | 2023-11-17 | Late-2023 bulk wave |
partnerpros[.]org |
Namecheap | 2024-05-16 | Mid-2024 wave |
clearcheck[.]org |
Namecheap | 2024-06-18 | Mid-2024 wave |
lendli[.]org |
Namecheap | 2024-06-26 | Mid-2024 wave |
checkgonow[.]com |
Namecheap | 2025-03-21 | Same-day pair |
fintara[.]org |
Namecheap | 2025-03-21 | Same-day pair |
brrwly[.]com |
Namecheap | 2025-10-14 | Rolling 2025 to 2026 expansion |
justborrow[.]co |
Namecheap | 2026-01-07 | Rolling 2025 to 2026 expansion |
loadingaccount[.]com |
Squarespace Domains II LLC | 2024-04-11 | Backend |
nwtrk[.]com |
Squarespace Domains II LLC | 2023-03-01 | Backend |
Two lessons come out of the dates. First, creation date is not first-seen date: lendli[.]com was registered in 2012 and simpleverify[.]co in 2021, years before this campaign, aged assets acquired to lend the family a legacy look and slip past new-domain heuristics. Second, checkgonow[.]com and fintara[.]org were created on the same day, 2025-03-21, two "different brands" provisioned in one sitting. The rest arrive in waves, a late-2023 cluster, a mid-2024 cluster, and then roughly one new brand or variant per month through 2025 into 2026.
Subdomain Grammar as a Cross-Brand Fingerprint
Every brand builds hosts from the same menu of trust-building and urgency prefixes, and the reuse is near-identical across domains that claim no relationship. The prefixes group into an auth family, an account family, and a funnel family, plus a set of impersonation and benefit-bait prefixes.
| Prefix family | Prefixes observed | Example |
|---|---|---|
| Authentication | auth., signin., login., logins., mylogin. |
signin.borrowly[.]io |
| Account | my., myaccount., accounts., consumeraccounts., portal. |
myaccount.fintara[.]org |
| Funnel / CTA | go., start., open., complete., finalize., finish., continue., submit., request., form., offer., report., log. |
go.partnerpros[.]org |
| Impersonation / bait | affirm., stimulus., foodstamp., rewards., expired., verify., confirm. |
affirm.clearcheck[.]org |
The my. and go. prefixes appear on essentially every active brand, and affirm. is worth calling out on its own: the operator stands up an affirm. subdomain on several brands to borrow the name of Affirm, a legitimate buy-now-pay-later provider it has nothing to do with. The two backends break the pattern in a telling way. loadingaccount[.]com and nwtrk[.]com carry only their apex and a www. host, with none of the funnel grammar, exactly what you would expect from pure redirect infrastructure that victims never see a branded page on.
Shared Mail Plumbing
The front-end fleet shares one mail fingerprint. Around twenty-seven of the brand domains publish the identical SPF record v=spf1 include:spf.efwd.registrar-servers.com ~all, which is Namecheap's default email-forwarding record and, repeated across the whole fleet, a single shared plumbing signature. A distinct subset layers in an Amazon SES include (clearcheck[.]org, fintara[.]org, makesaveretire[.]com, and expressfundin[.]com), which marks the domains provisioned for outbound blast mail as opposed to the ones that only serve landers. DMARC posture is not uniform, most publish p=reject while a couple run p=none, which reads as configuration drift across the monthly registration waves rather than a single template. A shared google-site-verification cohort on three of the domains points at one provisioning toolchain behind the fleet.
Domain Generation: TLD Rotation, Misspell Siblings, Semantic Suffixing
The domains are generated from a three-lever scheme, and the vocabulary is visible in the output. The levers are TLD rotation of a base label across .org, .io, .com, and .co; intentional misspell siblings; and semantic suffixing. The CheckGo family shows all three: checkgo[.]org rotates to checkgo[.]io, pluralizes to checkgos[.]org, suffixes to checkgonow[.]com and checkgobenefits[.]com, swaps word order to gochecks[.]org, and respells phonetically to gochex[.]org. The Borrowly family runs borrowly[.]io and borrowly[.]org alongside the doubled-consonant borrowlly[.]com and the vowel-dropped brrwly[.]com. The Lendli family does the same with lendli[.]org, lendli[.]io, and the doubled-consonant lendlli[.]com.
| Family | Members | Generation levers |
|---|---|---|
| CheckGo | checkgo[.]org, checkgo[.]io, checkgos[.]org, checkgonow[.]com, checkgobenefits[.]com, gochecks[.]org, gochex[.]org |
TLD rotation, pluralization, suffixing, word-order swap, phonetic respell |
| Borrowly | borrowly[.]io, borrowly[.]org, borrowlly[.]com, brrwly[.]com |
TLD rotation, doubled consonant, vowel drop |
| Lendli | lendli[.]org, lendli[.]io, lendli[.]com, lendlli[.]com |
TLD rotation, doubled consonant, aged acquisition |
| Funding / lending brands | justborrow[.]co, partnerpros[.]org, fintara[.]org, expressfundin[.]com |
Invented fintech-sounding labels |
| Insurance / retirement | automaticpolicy[.]org, makesaveretire[.]com, makesaveretire[.]org, caremile[.]org |
Vertical diversification into insurance and retirement lures |
The last two families show the operator diversifying its pretext beyond loans into insurance, retirement, and wellness while keeping the identical backend and subdomain machinery underneath.
Cross-Channel Convergence and the Facebook Pivot
Three signals put SMS and email on the same operator. The email follow-ups send from the same brand domains the SMS links point to. The email subject lines are the recipients' own phone numbers, which only makes sense if the SMS-collected number pool is feeding the mail merge. And the same personas, Amy, Mark, and Ben, appear as both SMS "reps" and email display names. A fourth signal reaches into a third channel: the nwtrk[.]com backend carries a Facebook domain-verification token, which ties the redirect tier to Facebook ad delivery and suggests paid-social acquisition feeding the same funnel that SMS and email feed.
Detection Observations
The signal in this network is structural. Any single message reads like a slightly pushy loan notification, and the first-name-rep framing is deliberately mundane. What separates the traffic from legitimate lending mail is the shared machinery underneath.
The strongest pivot is the pair of redirect backends. Dozens of unrelated-looking brands converging on loadingaccount[.]com and nwtrk[.]com is a single-operator fingerprint that survives any amount of brand rotation, and the cross-brand redirect chains between front-ends reinforce it. The subdomain grammar is the next signal: a fresh domain that stands up two or more of the network's trust-building prefixes, especially the my. and go. pair, behaves like a network member before it has sent a single message. The shared Namecheap SPF fingerprint clusters the front-end fleet, and the email footer template with its fixed Delaware shell address ties the mail brands together on its own.
Behavioral tempo is a softer but consistent signal. Send activity concentrates in United States business hours, Monday through Friday, peaks in the mid-morning Eastern window when people check their phones, and falls to near zero overnight, a profile that fits a boiler-room operating on a work schedule rather than a fully automated cannon. Several senders have stayed active for more than a hundred days, unusual longevity for SMS infrastructure that is normally rotated far faster, which points to stable carrier or aggregator relationships. For much of the run neither backend appeared in mainstream public threat feeds, so defenders relying only on public blocklists would have seen little of a network this size.
Mitigation and Guidance
- Pivot on the shared redirect backends, not the brand domains. Many "independent" loan brands resolving through the same one or two redirect hosts is a single-operator signal that outlives brand churn.
- Treat the subdomain grammar as an attribution feature. A new domain that publishes two or more of the network's trust-building prefixes, particularly
my.andgo.together with anauth/signin/loginhost, should be treated as network-member until proven otherwise. - Cluster domains by registrar and creation-date cohort. A same-day registration pair under one privacy proxy and an aged domain activated years after registration are both strong batch-attribution signals, and neither shows up if you sort by brand name.
- Watch for cross-channel reuse. A follow-up email whose subject line or CTA parameters contain the recipient's own phone number or name indicates a shared harvested-data pool feeding multiple rails.
- Do not lean on inbound authentication. Mail sent through Amazon SES from the operator's own domains authenticates cleanly, so SPF and DKIM results are not a useful discriminator here.
- Flag unsolicited loan-approval messages that assert a prior application the recipient never made, especially when paired with a first-name-only rep and a per-recipient tracking link.
MITRE Fight Fraud Framework Mapping
The mapping below aligns to the MITRE Center for Threat-Informed Defense Fight Fraud Framework, at https://ctid.mitre.org/fraud. The public matrix renders client-side and does not expose stable technique identifiers in a citable form, so behaviors are mapped by tactic and technique name; consult the live matrix for current identifiers.
| Tactic | Technique observed in this network |
|---|---|
| Resource Development | Register aged and bulk domain cohorts across two registrars; acquire numeric shortcodes and VoIP numbers; provision Amazon SES sending; build fabricated brands and personas |
| Initial Access | Mass unsolicited loan-approval SMS; branded email follow-ups; per-recipient tracking links |
| Initial Access | Fabricated prior engagement ("your request was accepted"); first-name-only account reps; impersonation of a legitimate BNPL brand via subdomain |
| Execution | Urgency and expiration deadlines; named funding amounts; PIN-required and account-status framing |
| Monetization | Loan-application harvest of SSN, banking, income, and address; resale of leads to predatory lenders and data brokers |
| Stealth | Shared redirect backends behind disposable brands; WHOIS privacy; registrar split; obfuscated redirect paths; brand and sender rotation |
Indicators of Compromise
All indicators are defanged. Victim data has been removed. Each table is a representative subset of the verified-malicious set; where a type was capped, the note gives a floor, not the exact observed total. Legitimate infrastructure the operator abuses (Amazon SES, the registrars, the WHOIS privacy proxy) is deliberately excluded.
Senders (Email)
| Value | Brand | Notes |
|---|---|---|
ben.masters@borrowly[.]io |
Borrowly | "Received for: [phone]" subject; Amazon SES |
lane.charles@clearcheck[.]org |
ClearCheck | Form-results pretext; shared footer template |
amy.goss@partnerpros[.]org |
PartnerPros | Same body template as Borrowly mail |
info@expressfundin[.]com |
ExpressFunds | Funding-amount pretext; PII-laden CTA URL |
Domains
| Value | Role | Notes |
|---|---|---|
loadingaccount[.]com |
Redirect backend | Primary; Squarespace-registered |
nwtrk[.]com |
Redirect backend | Secondary; Facebook domain-verification token |
checkgo[.]io |
Brand front-end | CheckGo family |
checkgos[.]org |
Brand front-end | CheckGo family, pluralized |
checkgobenefits[.]com |
Brand front-end | CheckGo benefits variant |
borrowly[.]io |
Brand front-end | Borrowly family |
borrowlly[.]com |
Brand front-end | Doubled-consonant typosquat |
lendli[.]org |
Brand front-end | Lendli family (distinct from legitimate "Lendly") |
lendlli[.]com |
Brand front-end | Doubled-consonant typosquat |
gochecks[.]org |
Brand front-end | Word-order variant |
clearcheck[.]org |
Brand front-end | Amazon SES sending subset |
partnerpros[.]org |
Brand front-end | Persona-heavy SMS brand |
fintara[.]org |
Brand front-end | Same-day registration as checkgonow[.]com |
justborrow[.]co |
Brand front-end | 2026 expansion brand |
txtro[.]cc |
Auxiliary | Tracking/router domain |
… (representative subset; the network spans at least 100 domains across at least 20 brands)
Hosts
| Value | Role | Notes |
|---|---|---|
www.loadingaccount[.]com |
Redirect backend host | Bare apex/www only, no funnel grammar |
www.nwtrk[.]com |
Redirect backend host | Bare apex/www only |
signin.borrowly[.]io |
Auth CTA host | signin. trust prefix |
login.lendli[.]org |
Auth CTA host | login. trust prefix |
go.partnerpros[.]org |
Funnel host | go. click-through prefix |
go.fintara[.]org |
Funnel host | go. click-through prefix |
myaccount.fintara[.]org |
Account host | myaccount. trust prefix |
go.clearcheck[.]org |
Funnel host | go. click-through prefix |
log.clearcheck[.]org |
Application host | log. prefix |
go.caremile[.]org |
Funnel host | Wellness-vertical brand |
… (representative subset; hundreds of verified-malicious hosts, many of which are apex hosts already listed under Domains; the subset above shows the shared subdomain grammar)
Phone Numbers and Shortcodes
Sender-attributed numbers only; recipient numbers are excluded.
| Value | Type | Notes |
|---|---|---|
+1-202-603-1542 |
VoIP number | Loan brand sender |
+1-210-401-6074 |
VoIP number | CheckGo / Lendli block |
+1-281-326-9945 |
VoIP number | CareMile (wellness vertical) |
+1-302-412-3001 |
VoIP number | CareMile |
+1-310-758-4481 |
VoIP number | Lendli sequential block |
+1-360-207-2411 |
VoIP number | PartnerPros |
+1-385-341-2355 |
VoIP number | AutomaticPolicy (insurance vertical) |
+1-470-256-4516 |
VoIP number | Borrowly |
+1-470-750-9962 |
VoIP number | CheckGo block |
+1-480-944-4173 |
VoIP number | CheckGo block |
+1-844-496-4823 |
VoIP number | Lendli / CheckGo |
+1-855-914-8663 |
VoIP number | JustBorrow |
264301 |
SMS shortcode | JustBorrow brand |
211004 |
SMS shortcode | Loan brand sender |
16782 |
SMS shortcode | Loan brand sender |
… (representative subset; 200+ verified-malicious phone numbers, and 27 numeric shortcodes rotated across the network)
Conclusion
This operator has turned brand identity into a disposable resource. A dozen loan, insurance, and retirement names, dozens of domains, and roughly a hundred senders are all one business, and the proof is never the name on the message. It is the two redirect backends every brand funnels into, the trust-building subdomain grammar repeated verbatim across the fleet, the shared mail fingerprint, and the Delaware shell address stamped into every email footer. The brand set will keep churning on its monthly cadence, and the pretext will keep drifting from loans into insurance and retirement, but the plumbing changes slowly. Defenders tracking loan smishing should map the shared backend first and treat the subdomain grammar as identity, because the names are built to be thrown away.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.