A Thousand Throwaway Domains: Brushing Package-Tracking Phishing
A Thousand Throwaway Domains: Brushing Package-Tracking Phishing
Since December 2025, a single operator has run a brushing-themed package-tracking phishing campaign using more than a thousand throwaway email domains. The lure combines the plausibility of a physical brushing delivery, a cheap product the recipient never ordered, with the urgency of a fake parcel-tracking notice. Each message comes from a separate disposable support@<random-word>.com address, uses Amazon SES or SendGrid to pass authentication, and includes the recipient's real name, taken directly from their email address. We have tracked the operation for more than seven months. It is still sending.
Key Takeaways
- One operator has sustained the campaign for more than seven months, cycling through over a thousand disposable sender domains at one mailbox per domain.
- Domains are bulk-registered in same-day cohorts through Alibaba Cloud / HiChina, using both fresh batches and a multi-year aged stash activated only in 2026.
- Delivery uses two parallel rails: AWS SES with
awstrack[.]meclick-tracking across four regions, and a single shared SendGrid sub-account. - The lure combines a brushing motif with fake USPS-style tracking and name personalization drawn from the recipient's email address.
- Three template families evolved over time, moving from overt package-tracking phish toward generic promotional-code mail with no brand-impersonation signature.
- A stable set of correlators ties the operation to one actor: two primary click-tracking IDs, one SendGrid sub-account, a uniform custom MAIL FROM grammar, and a shared UTM tag.
Background
A brushing scam, in its original form, has nothing to do with email. A third-party seller ships cheap, unordered goods to real names and addresses harvested from breach data, then posts fake "verified purchase" reviews under those identities to inflate a marketplace rating. Regulators have warned about the physical version for years, including the FTC and the U.S. Postal Inspection Service. This operator retained the motif but dropped the package. The email mentions a plausible but never-ordered parcel, complete with an order number, a tracking number, a USPS-style status line, and a real US city. It is designed to prompt the "wait, what did I order?" reaction that drives a click. Even if nothing arrived, the recipient is primed to click because the message implies that someone bought something in their name.
Fake package-tracking phishing is one of the most-reported scam categories in circulation, and delivery-themed messages dominate consumer fraud complaints. This campaign warrants closer examination because of the machinery behind it: the sending infrastructure, the domain supply chain, and the way both change. Its reach is large. Across its life, the operation has sent hundreds of thousands of messages.
The operator abuses several legitimate services, each for a specific property. Amazon SES is AWS's bulk-send API. When click-tracking is enabled, SES rewrites every link to route through awstrack[.]me, an Amazon-owned redirect domain that conceals the actual destination behind a trusted hostname and gives the operator free, per-recipient click telemetry. SendGrid provides a second rail. A single sub-account allows fraudulent volume to blend into the reputation of an established email-service provider, a pattern Netcraft and others have documented repeatedly. The domains are registered through Alibaba Cloud / HiChina (registrar strings www.net.cn, aliyun, and wanwang), a high-volume, low-cost registrar with a bulk API and privacy-by-default WHOIS that make disposable domains cheap and unattributable.
Two older tradecraft techniques tie the operation together. The first is snowshoe sending: distributing low volume across many domains so that no single sender crosses a rate threshold. Cisco Talos described the pattern a decade ago, and it still works. The second is aged-domain staging: registering domains and leaving them dormant for months or years before first use, so they have no recent reputation signal when activated. Unit 42 has explained why strategically aged domains can slip past reputation scoring. This operator uses both techniques at once.
Discovery and Infrastructure
The campaign does not rely on a single relay, so mapping it required clustering on correlators that persist through domain rotation. Every send resolves to one of two delivery rails, both of which leave durable fingerprints.
The primary rail is Amazon SES with click-tracking across four regions (us-east-1, us-east-2, us-west-1, us-west-2). Two primary click-tracking correlator IDs on awstrack[.]me recur across hundreds of otherwise unrelated sender domains, while several short-lived tail IDs appear at the edges. The secondary rail is SendGrid, where one shared sub-account generates bounces+<subaccount>@sendgrid[.]net return-paths throughout the promotional traffic. On the SES rail, a custom MAIL FROM subdomain (send-28.us-<region>.<sender-domain>) aligns the return-path with the From domain, allowing SPF, DKIM, and DMARC to pass. Authentication proves control of a throwaway domain, not the sender's honesty.
The promotional template loads image assets from cdn.webfastcdn[.]com and handles list management and unsubscribe requests through app.email-rec[.]com. These hosts behave differently, and that distinction matters when clustering on them. The CDN is shared infrastructure. It belongs to a pool of generic-named CDN domains registered through GoDaddy in a single September 2022 batch, and storefronts run by several unrelated operators load assets from the same pool. Its presence identifies the storefront kit, not this operator, making it a poor correlator and an even worse blocking target. app.email-rec[.]com is generic-named and GoDaddy-registered in 2024, outside that pool; the extent to which it is shared has not been established.
| Indicator | Role | Notes |
|---|---|---|
awstrack[.]me (4 SES regions) |
Click-tracking redirect | Primary rail through early 2026; two primary correlator IDs across many senders |
sendgrid[.]net (one sub-account) |
Secondary delivery | bounces+<subaccount>@sendgrid[.]net return-path |
send-28.us-<region>.<domain> |
Custom MAIL FROM | Aligns return-path to From domain; full auth pass |
cdn.webfastcdn[.]com |
Image CDN - shared kit infrastructure | Also serves storefronts of unrelated operators; marks the kit, not this operator |
app.email-rec[.]com |
List management / unsubscribe | Promotional template only |
How It Works
A representative send starts with a domain that the operator registered earlier, sometimes years earlier, and activated for the first time that week. The message is sent from support@<random-word>.com through SES, with links rewritten through awstrack[.]me. The subject is [Important] Your parcel's status has updated. The greeting uses a name derived from the local part of the recipient's email address, so sylvesterwhite@ becomes "Dear SylvesterWhite." The body includes an order number, an 18-to-19-digit tracking number, and a delivery status written in USPS phrasing for a real US city. The product is a cheap brushing good: disposable toilet-seat covers, all-year strawberry seeds, an adjustable resistance band. A "Track your Parcel" button redirects through the SES tracker to the lure.
The same infrastructure supports two other pretexts. One is an abandoned-cart variant that links directly to a fake storefront on the sender domain. The other, newer variant drops the parcel story entirely and imitates ordinary promotional mail with a discount code that "expires soon." All three use the same sender grammar, delivery rails, and correlators.
Sample Lures
Below are redacted, defanged samples of the three template families. All recipient-identifying data has been replaced with placeholders.
Template A, the package-tracking phish:
From: "Parcel Service" <support@indicatek[.]com>
Subject: [Important] Your parcel's status has updated
Dear [recipient name]:
Your order number is [order #] and the product name is Disposable Toilet Seat Covers.
The tracking number is: [tracking #].
We checked that your package logistics status has been updated.
Now the package logistics status is: Delivered, In/At Mailbox.
Detail status of the logistics: [USPS-style status, real US city/state].
[ Track your Parcel ] -> http[:]//awstrack[.]me/... -> lure
If you have any questions, please contact us at support@[domain][.]com
Template B, the abandoned-cart / storefront lure:
From: "Order Team" <support@peshoriadm[.]com>
Subject: Order Confirm
Still deciding? Your item is waiting.
Special Offer - 10% Discount for Your Order!
[ Complete Your Order ] -> http[:]//www.peshoriadm[.]com/products/...
Template C, the promotional / discount-code lure:
From: "Rewards" <support@premiumetsy[.]com>
Subject: VIP Exclusive: Your Personal 15% Appreciation Discount
[recipient name], your reserved discount is ready.
Use CODE: OFF20 - Limited Time. Expires in 20 Minutes!
[ Shop Now ] -> image assets on http[:]//cdn.webfastcdn[.]com/...
unsubscribe via http[:]//app.email-rec[.]com/...
Technical Analysis
Registration Cohorts and Aged-Domain Staging
Public WHOIS data for a sample of the operator's domains shows two concurrent behaviors. Fresh domains appear in same-day batches, with several registered on one date through the same registrar, consistent with a scripted bulk-registration run. Alongside those batches is an aged stash: domains created in 2021, 2022, and 2023 that remained dormant until they were first activated for sending in 2026. The oldest example in the sample was registered in September 2021 and did not send until this campaign.
| Registration date | Domains in cohort (sample) | Registrar family |
|---|---|---|
| 2021-09-24 | 1 (aged stash) | Alibaba / HiChina |
| 2023-04-26 | 4 | Alibaba / HiChina |
| 2023-05-25 | 4 | Alibaba / HiChina |
| 2025-04-28 | 6 | Alibaba / HiChina |
| 2025-08 (two dates) | 2 | Xin Net |
| 2025-09-19 | 4 (.com and .net) | Alibaba / HiChina |
| 2026-02-24 | 1 | Alibaba / HiChina |
These counts come from a WHOIS sample rather than the full inventory, so the actual cohorts are larger. The pattern combines batch registration with a long aging tail, both supplying the same campaign.
Domain-Generation Grammar
Two naming templates operate in parallel. The first uses single English words that are misspelled or truncated: indicatek[.]com, journalw[.]com, routinem[.]com. The second concatenates common words into word-salad names: outunusual[.]com, accustomedtoit[.]com, anotheralways[.]com. Both appear to be machine-generated attempts to create innocuous-looking names that remain unregistered. Most use .com, with a .net tail (auralotic[.]net, correctmain[.]net) and a rare .live. Storefront links use a consistent utm_source=AN& parameter across domains that otherwise share nothing, making it one of the clearer same-operator signals in the set.
Two-Rail Delivery and Authentication
The division between SES and SendGrid is deliberate. SES with awstrack[.]me carries the package-tracking and abandoned-cart traffic while providing click telemetry. SendGrid carries much of the promotional template through its shared sub-account. On both rails, the operator publishes its own SPF, DKIM, and DMARC records on the sending domain and aligns the MAIL FROM subdomain with the From domain, so every message authenticates cleanly. This poses a problem for defenders who treat authentication as a trust signal: when the scammer controls the entire domain, standing up a fully DMARC-aligned domain is trivial.
Template Evolution
The lure changed over the campaign's life, and its direction is notable.
| Family | Example subject | Lure | Delivery rail / distinctive host |
|---|---|---|---|
| A | [Important] Your parcel's status has updated |
Fake tracking for an unordered parcel | SES + awstrack[.]me |
| B | Order Confirm / 10% Discount for Your Order |
Abandoned-cart storefront | SES; storefront on sender domain |
| C | VIP Exclusive: Your Personal 15% Appreciation Discount |
Promo-code marketing | SES/SendGrid + app.email-rec[.]com; storefront assets from a shared kit CDN |
Family C is the most discreet because it removes the impersonation and manufactured urgency that make A easy to recognize. It has no delivery brand to spoof and no "your package" hook, only content that resembles ordinary opt-in marketing. The operator is exchanging a strong lure for a lower profile.
Operator Fingerprint
No individual indicator survives rotation, but the full set does. Two primary awstrack[.]me correlator IDs, one SendGrid sub-account and return-path, the uniform send-28.us-<region>.<domain> MAIL FROM grammar, the app.email-rec[.]com promotional endpoint, the support@ one-mailbox-per-domain convention, and the utm_source=AN& tag all indicate one actor. Each is weak on its own. Together, they tightly cluster the traffic. The CDN that serves the promotional storefront assets is intentionally excluded from that set. It is shared across unrelated operators, so it identifies the kit rather than the sender. Treating it as a correlator would include traffic unrelated to this operation.
Escalation Over Time
Around mid-2026, the operator stopped using awstrack[.]me click-tracking, removing both the redirect and the shared correlator that had connected much of the traffic. The registrar mix also changed, with a partial move from Alibaba / HiChina to Xin Net. Considered alongside the template shift from A to C, the change suggests an operator monitoring which signatures are exposed and moving away from them.
Detection Observations
The behavioral signal distinguishing this traffic from legitimate mail is in the sender construction rather than the content. A support@ mailbox that is the only address ever observed on its domain, where that domain is newly activated or drawn from an aged stash and sends through SES or SendGrid with a send-28.us-<region>.<domain> MAIL FROM, forms a strong composite signal before the body is read. The brushing family adds a lexical fingerprint: an unordered product, a fabricated tracking number, USPS status phrasing, and a greeting name derived from the recipient's email local part rather than any name the recipient uses.
The promotional family is the most difficult to distinguish from real traffic because it is designed to resemble marketing. It contains no impersonated brand and no urgency beyond what is common in commercial mail, so the recognizable signal moves almost entirely to the infrastructure correlators rather than the message. Defenders tracking this operator should rely on the shared tracking IDs, the SendGrid sub-account, the MAIL FROM grammar, and the UTM tag rather than any single content rule.
Indicators of Compromise
All indicators are defanged. Victim data has been removed. The following lists are representative subsets of the verified-malicious set, not the full inventory.
Senders (Email)
| Value | Role | Notes |
|---|---|---|
support@indicatek[.]com |
Sender | One mailbox per domain |
support@outunusual[.]com |
Sender | Word-salad domain |
support@heapbulb[.]com |
Sender | |
support@journalw[.]com |
Sender | Misspelled-word domain |
support@sculptiure[.]com |
Sender | |
support@spiritukal[.]com |
Sender | |
support@cherishty[.]com |
Sender | |
support@petitionm[.]com |
Sender | |
support@peshoriadm[.]com |
Sender | Storefront variant |
support@premiumetsy[.]com |
Sender | Promotional variant |
support@tempergauge[.]com |
Sender | |
support@rearedition[.]com |
Sender | |
| ... (representative subset; 50+ verified-malicious sender addresses) |
Domains
| Value | Role | Notes |
|---|---|---|
indicatek[.]com |
Sender domain | Misspelled word |
journalw[.]com |
Sender domain | Misspelled word |
outunusual[.]com |
Sender domain | Word-salad |
accustomedtoit[.]com |
Sender domain | Word-salad |
abeautyful[.]com |
Sender domain | |
gogodusk[.]com |
Sender domain | Aged stash (reg 2021) |
coefficienta[.]com |
Sender domain | |
premiumetsy[.]com |
Sender domain | Promotional variant |
peshoriadm[.]com |
Sender domain | Storefront |
legacyof1776[.]com |
Sender domain | |
uptopco[.]com |
Sender domain | |
breliance[.]com |
Sender domain | |
effiective[.]com |
Sender domain | |
auralotic[.]net |
Sender domain | .net tail |
correctmain[.]net |
Sender domain | .net tail |
| ... (representative subset; 750+ verified-malicious sender domains) |
Hosts
| Value | Role | Notes |
|---|---|---|
cdn.webfastcdn[.]com |
Shared kit CDN - not operator-owned | Listed for recognition only; serves unrelated operators, so do not block |
app.email-rec[.]com |
List management / unsubscribe | Promotional template |
email-rec[.]com |
List management | Promotional template |
www.peshoriadm[.]com |
Storefront | Abandoned-cart lure |
breliance[.]com |
Sender / storefront apex | |
coefficienta[.]com |
Sender / storefront apex | |
effectvalid[.]com |
Sender / storefront apex | |
juvenileon[.]com |
Sender / storefront apex | |
perfectdid[.]com |
Sender / storefront apex | |
poemood[.]com |
Sender / storefront apex | |
quotationy[.]com |
Sender / storefront apex | |
sufficientw[.]com |
Sender / storefront apex | |
uptopco[.]com |
Sender / storefront apex |
MITRE Fight Fraud Framework Mapping
This activity maps to the MITRE Fight Fraud Framework (F3), which reuses ATT&CK technique IDs for pre-monetization behavior. The technique IDs below are the confirmed ATT&CK identifiers adopted by F3. The monetization stage is consistent with credential and payment-data theft but was not independently observed in this dataset.
| Tactic | Observed behavior | ID |
|---|---|---|
| Reconnaissance | Gather Victim Identity Information | T1589 |
| Resource Development | Acquire Infrastructure: Domains | T1583.001 |
| Resource Development | Establish Accounts: Email Accounts | T1585.002 |
| Initial Access | Phishing: Spearphishing Link | T1566.002 |
| Stealth | Impersonation | T1656 |
| Monetization | Credential / payment-data capture (consistent with, not observed) | not mapped |
Conclusion
The pretext is old and the infrastructure is cheap, which helps explain why the operation has lasted more than seven months. Its resilience comes from supply rather than sophistication: a deep inventory of aged and freshly batched domains, two reputable delivery rails, and clean authentication on every burner. The direction of the template shift matters. By moving from a brand-impersonation package lure toward generic promotional mail, the operator trades reach for stealth. An operator that retains its correlators while discarding its most recognizable content is harder to keep out.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.