Ten Verticals, One Shortlink Grammar: An SMS Lead-Gen Ecosystem
Ten Verticals, One Shortlink Grammar: An SMS Lead-Gen Ecosystem
Since late 2025 one operator has run at least ten unrelated scam verticals over a single shared SMS shortlink infrastructure to harvest consumer PII. The verticals look unrelated at street level: home equity one week, roofing the next, then an auto-insurance "refund," a Medicare plan review, a weight-loss offer. Underneath, they share one path grammar, one personalization engine keyed to real names and home addresses, and one economic model. The messages rarely try to steal money in the moment. They exist to feed harvested consumer data into the lead-generation market, where it is sold on to insurers, mortgage brokers, and home-services contractors. This is a survey of that ecosystem across a 180-day window: the infrastructure that ties the verticals together, how the operator provisions and rotates it, and the behavioral signals that separate its traffic from the legitimate quote-and-lead economy it hides inside.
Key Takeaways
- A single SMS operator runs at least ten consumer verticals (home equity, FHA mortgage, safe-driver rebate, auto-insurance refund, Medicare and health plans, roofing, real-estate buyer leads, solar, GLP-1 weight-loss, home remodeling) over shared plumbing.
- The unifying fingerprint is a short-TLD redirect grammar: a two-to-six-character label on
.us/.me/.app/.co, followed by a/{4 chars}/{6-7 chars}path that encodes a campaign selector and a per-recipient victim ID. - Lures are personalized with the recipient's real first name and street address, sourced from public property and voter records combined with bought lead lists. The same name-to-address pairing recurs in messages months apart, which points to a stable victim database, not random generation.
- Infrastructure is provisioned in same-day registration batches and rotated continuously: two single-purpose shortlinks registered on one day at one registrar, a new vertical landing domain minted roughly every four to eight weeks.
- The operator mixes freshly-minted burner domains (registered days before deployment) with aged domains created years earlier and held dormant until activation, a staging pattern that blunts age-based reputation signals.
- The redirect chains terminate at the legitimate bottom of the lead-generation funnel. That gray-zone monetization, deceptive at the gate but ending in a real quote engine, is the operator's cover story.
Background
The operation is delivered entirely over SMS: US five-digit shortcodes, toll-free 8XX long-codes, and a set of malformed sender IDs that surface as impossible "+777..." phone numbers. Across the 180-day window it produced tens of thousands of scam text messages from more than 30 distinct senders, pushing dozens of domains through a shared redirect layer. Activity held continuous for 22 consecutive weeks with no gap longer than seven days, which reads as sustained operator presence rather than a burst campaign.
Short-TLD shortlinks are the connective tissue. A label of a few characters on .us, .me, .app, or .co is cheap, forgettable, and easy to batch-register, and it gives the operator a redirect hop that decouples the SMS-visible domain from the eventual landing page. Because the visible link is short and brand-free, it survives a glance and it survives keyword filters that key on scam vocabulary. The landing page it resolves to can be swapped without changing anything the recipient sees.
The senders sit on top of application-to-person (A2P) SMS infrastructure: high-throughput messaging provisioned through gateway resellers that obscure the originator. Shortcodes and toll-free numbers are the legitimate rails for bulk business texting, which is exactly why a lead-gen operator wants them. The malformed "+777..." identifiers are more unusual. Country code 777 does not exist, so these are almost certainly alphanumeric sender IDs being reshaped into 12-digit strings and then parsed downstream as if they were E.164 phone numbers. One of those identifiers alone carried messages across ten different domains.
The economic layer is the lead-generation affiliate market. This is a real, large, and mostly legal industry: consumers who search for insurance or mortgage products generate "leads" (a name, contact details, and intent) that are sold to brokers, carriers, and lenders through data sales, inbound calls, warm transfers, and click traffic. The scam sits at the front of that pipeline. It manufactures intent that the consumer never expressed, by fabricating a refund, a buyer for their home, or an expiring benefit, then routes the harvested data into the same downstream buyers a legitimate publisher would use. That is what lets the operator frame the activity as marketing rather than fraud. The deception is in the message, not the destination.
Discovery and Infrastructure
What first looked like one SMS cluster resolved, over the longer window, into five sub-clusters that share plumbing but serve different buyers. A single home-equity shortcode also pushes the real-estate and roofing shortlinks, which is the clearest sender-level evidence that the sub-clusters are one operation rather than coincidental neighbors.
The sub-clusters break down as follows:
| Sub-cluster | Pretext family | Representative infrastructure |
|---|---|---|
| Multi-pretext core | Home equity, FHA, safe-driver, vague curiosity | 80k[.]us, a2e[.]us, clcks[.]me, k1ick[.]me, trcks[.]me |
| Real-estate buyer lead | "Buyers are interested in your home" | lcbr[.]us |
| Roofing | "A roof upgrade is available for [address]" | rfup[.]us |
| Auto-insurance refund / fake credit | "You are due a credit back" | collisioncn[.]com, atocrednw[.]com, inscrdttdy[.]com |
| Insurance / Medicare hub | Medicare plans, health coverage | lnsure[.]co, medicarezero[.]com, glpialrt[.]com |
Two facts pin the sub-clusters to one operator. The first is shared path grammar. Every vertical, regardless of registrar or TLD, emits the same /{4 chars}/{6-7 chars} redirect path, where the first segment selects a campaign or landing page and the second encodes a per-recipient identifier. The second is the personalization engine. Every address-bearing vertical (home equity, real estate, roofing) draws the recipient's real name and street address from the same style of record, and the same pairing recurs across verticals and across months.
The senders are treated as consumable. Sender count holds steady at roughly seven to thirteen active per week while individual shortcodes and numbers rotate in and out. The operator burns and replaces senders rather than scaling volume on any one of them, a low-and-slow cadence that suits sustained A2P sending and spreads exposure across the pool.
How It Works
A single message does a lot of work in one line. It opens with a two-to-four-character brand prefix (LCBR:, RU:, ILB:, CCN:, MedicareInfo:, UCheckUs:), which gives the vertical a throwaway identity without a real brand to verify. It personalizes with the recipient's first name and, in the property verticals, their street address. It manufactures urgency or curiosity: an as-is offer, an expiring benefit, a specific dollar amount already "owed" to the recipient. Then it hands off to a short link.
The link is the pivot. It resolves through one or more redirect hops to a landing page carrying a quote or intake form. The form asks for the fields that give a lead its market value: name, address, ZIP, phone, age, and vertical-specific data such as home value, mortgage balance, vehicle details, or Medicare status. Once submitted, that record enters the lead market. The consumer may then receive a real callback (an insurance pitch, a refinance offer, a Medicare brokerage call), which is precisely what lets the operator claim the interaction was marketing.
The fabricated dollar amounts are worth isolating. Refund and credit lures cite specific, mid-range sums ($983, $1,493, $1,583, $1,748) rather than round numbers. Precision reads as legitimate. A "$1,583 overpayment" feels like it came from a records system; "$1,500 back" feels like an ad.
Sample Lures
Every sample below is a real message with all recipient PII removed (name, street address, and per-recipient tracking tokens replaced by placeholders) and all operator domains defanged. Attacker-side content, the sender identity, brand prefix, pretext, and link grammar, is preserved.
Real-estate buyer-lead pretext (invents prospective buyers for the recipient's home):
LCBR: Hi [name], Buyers are interested in your home at [street address].
See your July as-is offer. http[:]//lcbr[.]us/IlA/[victim-id] Reply Stop to Quit
Roofing pretext (same address personalization, different downstream buyer):
RU: [name], A roof upgrade is available for [street address]. The new
estimate is ready (good). http[:]//rfup[.]us/uDfv/[victim-id] Reply Stop to Quit
Auto-insurance refund / fake-credit pretext (note the fabricated precise amount and the templated grammar):
CCN: We show indicate an over charge of $1,583 on your auto insure for
25' You are due a credit back. collisioncn[.]com/xWF/[id] Stop2END
Medicare plan-review pretext (delivered through an "insure" typosquat with a per-recipient token):
MedicareInfo: [name], find a Medicare plan that works for you. Review
options. Explore: lnsure[.]co/care5290?elid=[recipient-token] STOP to optout
Health-plan / GLP-1 pretext (rides the demand for weight-loss drugs):
Important Notice. Your Health Plan now covers three months free of Ozempic.
offer expires on 4/4 glpIalrt[.]com/f53/[id] Stop2END
Safe-driver rebate pretext (reward framing, no real brand to verify):
ILB: If you've had no driving penalties or records for six months, we're
excited to make this yours. http[:]//ilb904[.]com/[id] Reply Stop to Opt Out
Technical Analysis
Redirect Grammar and Subdomain Structure
The operator's most durable fingerprint is a link grammar, not any single domain. The dominant form is a short label on a short TLD followed by two path segments:
http[:]//<2-6 chars>.<us|me|app|co>/<4 chars>/<6-7 chars>
The first path segment selects a campaign or landing page; the second is a high-entropy per-recipient identifier. Observed live paths include lcbr[.]us/IlA/tLnO99, rfup[.]us/uDfv/a7am8M, collisioncn[.]com/xWF/bbDkdHQ, and glpialrt[.]com/f53/bjhzzcZ. Two alternate forms coexist with it: a parameterized redirect (?u=<id>&l=<id>) and a Medicare variant that carries the per-recipient token in an elid= query string (lnsure[.]co/care5290?elid=...). On the landing side, function-prefixed subdomains recur across otherwise-unrelated verticals: quote. and re. on the auto-comparison domain, insur. on the safe-driver brand layer. The grammar is stable enough to pivot on directly: a short-TLD domain emitting the /{4}/{6-7} path in SMS traffic is a strong cluster signal on its own, even before the domain appears on any list.
Domain Generation Vocabulary
Naming falls into four consistent buckets:
- Typosquats of function words:
lnsure[.]co(insure, with a lowercase L for the I),k1ick[.]me(click),clcks[.]me(clicks),trcks[.]me(tracks),atocrednw[.]com(auto-credit-now),inscrdttdy[.]com(insure-credit-today),fulcrdtdy[.]com(full-credit-today). - Descriptive vertical names:
safedriverbenefit[.]com,autopolicy2026[.]com,medicarezero[.]com,summitautoins[.]com,horizonautoins[.]com. - Year-tokened freshness names:
2026safedriver[.]com,autopolicy2026[.]com, which signal currency and get replaced as the year turns. - Coined, meaningless burners:
numoxa[.]com,carvioo[.]com,kohzo[.]app,kcvbg[.]app,ilb904[.]com.
The vowel-dropped credit-repair triplet (atocrednw, inscrdttdy, fulcrdtdy) is the tightest sibling cluster: three domains, one registrar, all registered within two weeks of each other and all first seen in traffic the same month they were created.
Registration Cohorts and Aged-Domain Staging
Public WHOIS separates the inventory into two clear cohorts, and the mix is the interesting part. Some domains are freshly minted and deployed within days. Others were created years earlier and held dormant, then activated in 2025.
| Domain | Registrar | Created | Cohort |
|---|---|---|---|
80k[.]us |
Cloudflare | 2018-06 | Aged shortlink core, first seen in traffic 2025 |
k1ick[.]me |
Enom | 2019-09 | Aged shortlink core |
clcks[.]me |
Enom | 2020-04 | Aged shortlink core |
jkclk[.]com |
Namecheap | 2018-06 | Aged redirect backend, first seen in traffic 2025 |
lcbr[.]us |
GoDaddy | 2025-06-29 | 2025 batch (twin registration) |
rfup[.]us |
GoDaddy | 2025-06-29 | 2025 batch (twin registration) |
2026safedriver[.]com |
GoDaddy | 2025-12-28 | 2025 batch (twin registration) |
safedriveract[.]com |
GoDaddy | 2025-12-28 | 2025 batch (twin registration) |
collisioncn[.]com |
Namecheap | 2026-01 | 2026 burn cohort |
inscrdttdy[.]com |
Namecheap | 2026-03 | 2026 burn cohort |
atocrednw[.]com |
Namecheap | 2026-03 | 2026 burn cohort |
autopolicy2026[.]com |
GoDaddy | 2026-04 | 2026 burn cohort |
insplanmkt[.]com |
GoDaddy (Domains-by-Proxy) | 2026-04 | 2026 burn cohort |
Two registrations landing on the same day at the same registrar, then deploying into different verticals, is the strongest single-operator signal in the set. It happened at least twice: lcbr[.]us with rfup[.]us (real estate and roofing), and 2026safedriver[.]com with safedriveract[.]com. Registrar choice tracks function: GoDaddy carries the short-TLD shortlinks and the safe-driver and auto landings; Namecheap carries the credit-and-refund typosquat burners, frequently behind privacy protection; the aged shortlink core sits at Cloudflare and Enom. The aged-domain staging is the defense-relevant detail. Age-of-registration is a common reputation input, and holding a domain created years before its first appearance in traffic is a deliberate way to blunt it.
Cross-Cluster Pivots
Three pivots collapse the sub-clusters into one operation. A single home-equity shortcode also carries the real-estate and roofing shortlinks, bridging three verticals at the sender level. A single malformed "+777..." identifier spans ten domains across the auto-refund, credit, and health verticals. And the "insure" typosquat funnel resolves to multiple downstream destinations depending on its landing-page selector, which shows the redirect layer is a routing switch rather than a fixed one-to-one hop.
Where the Funnel Terminates
The redirect chains do not end at operator-owned credential-harvest pages. They terminate at the legitimate bottom of the lead-generation market: third-party insurance and mortgage quote engines and affiliate click-routers run by real, established lead-generation companies. That is the operator's cover. Because a submitted form often does produce a real quote or a real callback, the operator can argue the traffic was marketing. The fraud is upstream, in the fabricated refund, the invented home-buyer, and the impersonated benefit program that manufactured the click in the first place. For defenders, the practical consequence is that the landing page is not always a reliable tell. The deception lives in the message and the redirect grammar.
Detection Observations
The following behaviors separate this ecosystem's traffic from the legitimate quote-and-lead economy it imitates. They are framed as signals a defender can key on, not as any claim about outcomes.
- The
/{4 chars}/{6-7 chars}path on a short-TLD label is the single strongest cross-vertical pivot. It is consistent across registrars, TLDs, and pretexts, and it appears regardless of which brand prefix the message wears. - Same-day registration pairs at one registrar that deploy into unrelated verticals are a high-confidence clustering signal. Bulk registration is the operator's supply chain, and it is visible in public WHOIS.
- Malformed sender identifiers with impossible country codes (the "+777..." pattern) are anomalous on their face and worth treating as suspect independent of message content.
- Real-name-plus-street-address personalization in an unsolicited commercial text is itself a signal. Legitimate businesses the recipient has no relationship with do not open with the recipient's home address.
- Fabricated, oddly-precise dollar amounts ("$1,583 overpayment," "$983 safe driver credit") in a refund or rebate pretext are a recurring content marker.
- Aged domains appearing in SMS traffic for the first time long after registration deserve scrutiny; registration age alone is not a safety signal here.
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE Center for Threat-Informed Defense Fight Fraud Framework (F3), available at https://ctid.mitre.org/fraud. Technique names below are drawn from the F3 vocabulary; the framework is the authoritative reference for identifiers.
| Tactic | Observed technique |
|---|---|
| Resource Development | Bulk acquisition of short-TLD domains and aged-domain staging; provisioning of shortcodes, toll-free numbers, and malformed sender IDs through A2P resellers |
| Initial Access | Smishing (SMS phishing) with per-vertical brand prefixes and short-link redirects |
| Initial Access | Name-and-address personalization from public records; impersonation of benefit programs, refunds, and property-buyer interest |
| Execution | Urgency and reward framing (expiring offers, fabricated refunds, "as-is" home offers) driving click-through to intake forms |
| Monetization | Harvesting of identity and financial or health PII via quote and intake forms |
| Monetization | Sale of harvested leads into the downstream insurance, mortgage, and home-services lead markets |
Indicators of Compromise
All indicators below are defanged. Recipient data has been removed. Aggregate totals are stated as verified-malicious floors, not exact counts.
Sender Shortcodes (US 5-digit)
| Value | Role | Notes |
|---|---|---|
35187 |
Sender | Multi-pretext core, highest-volume single sender |
32361 |
Sender | Home equity, FHA |
40494 |
Sender | Multi-pretext + insurance |
47839 |
Sender | Safe-driver |
62863 |
Sender | Cross-vertical bridge (home equity, real estate, roofing) |
67457 |
Sender | Insurance, Medicare |
69349 |
Sender | Insurance, Medicare |
86109 |
Sender | Safe-driver, auto-policy landing |
86757 |
Sender | Safe-driver brand layer |
90293 |
Sender | Safe-driver |
36126 |
Sender | Auto / Medicare brand layer |
87912 |
Sender | FHA |
| … | (representative subset; the cluster spans over 50 verified-malicious shortcodes) |
Sender Numbers and Sender IDs
| Value | Role | Notes |
|---|---|---|
+18337012255 |
Sender | Real-estate buyer-lead, dedicated number |
+18664592112 |
Sender | Real-estate buyer-lead, secondary |
+18559575034 |
Sender | Roofing, dedicated number |
+18666360188 |
Sender | Roofing |
+18337006170 |
Sender | Auto-insurance refund |
+18889905261 |
Sender | Medicare / insurance hub |
+18886986422 |
Sender | Insurance funnel |
+18775831819 |
Sender | Insurance funnel |
+18337890842 |
Sender | Auto vertical |
+777203825016 |
Sender | Malformed sender ID (impossible country code), spans ~10 domains |
+777203825010 |
Sender | Malformed sender ID, cross-vertical |
| … | (representative subset; over a 100 verified-malicious sender numbers and IDs) |
Domains
| Value | Role | Notes |
|---|---|---|
lcbr[.]us |
Shortlink | Real-estate buyer-lead; GoDaddy twin registration 2025-06-29 |
rfup[.]us |
Shortlink | Roofing; GoDaddy twin registration 2025-06-29 |
80k[.]us |
Shortlink | Aged core (Cloudflare, 2018) |
clcks[.]me |
Shortlink | Aged core typosquat (clicks) |
k1ick[.]me |
Shortlink | Aged core typosquat (click) |
lnsure[.]co |
Redirect funnel | "insure" typosquat, multi-destination Medicare routing |
collisioncn[.]com |
Landing | Auto-insurance refund; Namecheap 2026-01 |
atocrednw[.]com |
Landing | Auto-credit typosquat |
inscrdttdy[.]com |
Landing | Insure-credit typosquat |
autopolicy2026[.]com |
Landing | Auto-policy vertical; GoDaddy 2026-04 |
summitautoins[.]com |
CTA | Auto-insurance refund CTA (Domains-by-Proxy) |
medicarezero[.]com |
Landing | Medicare vertical |
fharg2[.]com |
Landing | FHA mortgage vertical; GoDaddy 2025-04 |
glpialrt[.]com |
Landing | GLP-1 / health-plan vertical |
safedriverbenefit[.]com |
Landing | Safe-driver rebate vertical |
| … | (representative subset; 150+ verified-malicious domains) |
Hosts
| Value | Role | Notes |
|---|---|---|
quote.ucheckus[.]com |
Landing host | Auto-comparison quote host |
re.ucheckus[.]com |
Landing host | Auto-comparison redirect host |
URL Path Pattern
^https?://[a-z0-9]{2,6}\.(us|me|app|co)/[A-Za-z0-9_-]{4}/[A-Za-z0-9_-]{6,8}$
Lure-Body Markers
"Buyers are interested in your home at <address>"
"A roof upgrade is available for <address>"
"home equity options for <address>"
"You are due a credit back" / "overpayment on your auto"
"safe driver credit of $<amount>"
"Your Health Plan now covers"
brand prefixes: LCBR: / RU: / ILB: / CCN: / MedicareInfo: / UCheckUs:
Conclusion
The durable asset here is not any domain, sender, or landing page. It is the grammar: a redirect path structure, a personalization engine, and a supply chain for cheap short-TLD domains and disposable senders. Each of those outlives any single vertical, which is why the operator can retire roofing and stand up weight-loss offers in the same week without changing anything structural. Defenders get more leverage from the grammar than from the inventory. Watch the /{4}/{6-7} path on short TLDs, watch same-day registration batches in public WHOIS, and treat an unsolicited text that already knows your name and street address as the signal it is.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.