Rotating Domains, One Nameserver Pair: A Loan Lead-Gen Operator
Rotating Domains, One Nameserver Pair: A Loan Lead-Gen Operator
Since December 2025, one operator has run a loan-funding lead-generation scam behind hundreds of rotating domains, all anchored to one small, shared backend. The lure is a fake loan or funding application: an unsolicited email tells the recipient their "application" is pending, pre-qualified, or one step from approval, then routes them into a multi-step form that harvests identity and financial data. Behind more than two hundred throwaway domains and several thousand burner sender identities sits a compact, stable backend. The operator rotates the front end constantly, but the registration account, the nameserver pair, and the click-tracking architecture stay put, and that is what lets us tie the whole thing to one hand.
Key Takeaways
- The operator runs two email rails in parallel, an Amazon SES rail and a SparkPost rail, after starting on SendGrid, and shifts brands between them while keeping identical content templates.
- Twelve core landing hubs resolve to the same Cloudflare nameserver pair,
armando.ns.cloudflare[.]comandteagan.ns.cloudflare[.]com, with eight of them registered at NameCheap on a single day, 2025-08-19. - The SES rail is hub-and-spoke: many single-purpose "sending" domains carry no landing page and route every click through a
tr.<hub>[.]com/l/<token>tracker back to a shared hub. - Domain names are built from a fixed finance-keyword vocabulary (fund, lend, loan, budget, capital, pay, credit) glued with a small set of affixes, which produces near-duplicate sibling clusters.
- The nameserver pair survives domain rotation, sender churn, and ESP migration, so it is a far more durable pivot than any single domain or sender address.
Background
This is a lead-generation scam, not a credential-phishing or malware operation. It does not try to steal a password or drop a payload. It manufactures a plausible reason for a consumer to hand over identity and financial details willingly, then sells those details downstream. In the online-lending world that resale runs through a "ping-tree": a submitted loan application is offered in real time to the highest-paying buyer tier and cascades down until a lender, debt buyer, or data broker accepts it, so a single applicant's data is auctioned across many buyers within seconds. The economics reward raw application volume regardless of where the applications come from, which is exactly what a high-volume email operation supplies. Regulators have pursued this harm directly: the CFPB has taken action against lead aggregators for trafficking loan-application data, and the FTC has penalized lead generators for indiscriminately reselling sensitive consumer information and, in one case, feeding payday-loan applications to an operation that raided victims' bank accounts.
The operation leans on legitimate infrastructure at every layer, because that is what gets mail delivered. Amazon SES is AWS's high-volume email service; mail sent through it is signed with valid SPF and DKIM and stamps amazonses[.]com into the return path, so it authenticates cleanly and inherits AWS sending reputation. SparkPost is a bulk-email provider whose customers operate segregated subaccounts and whose click tracking rewrites every link through a provider-run tracking host such as post.spmailtechno[.]com. SendGrid, the earliest rail here, has a long public history of hijacked customer accounts pushing spam. NameCheap offers cheap bulk registration and free WHOIS privacy, which makes large batches of disposable finance-keyword domains fast and anonymous to stand up. None of these platforms is the adversary; each is a service the operator abuses.
The load-bearing piece of context is Cloudflare's DNS. When a domain is onboarded to Cloudflare's authoritative DNS, Cloudflare assigns it a pair of branded nameservers of the form <name>.ns.cloudflare[.]com, and it favors the same pair across every zone in a given account. That pair is tied to the account, not the domain, so it persists as an operator burns through disposable domains. Clustering domains by their shared assigned nameserver pair is therefore a durable attribution pivot, and it is the backbone of this analysis.
Discovery and Infrastructure
The campaign first surfaced as a wall of near-identical loan and funding emails: clean HTML, a fabricated application-status pretext, and a call-to-action button that routed through tracking links to a form. Individually the messages looked like mildly spammy financial marketing. The scale and the shared fingerprints told a different story. Across the operation we counted more than five thousand distinct sender addresses on more than two hundred domains, carrying hundreds of thousands of messages since December 2025.
Two sending strategies run side by side. The SparkPost rail uses one sender per domain across 171 disposable domains, with sender addresses in a firstname.initial@domain shape (for example cooper.a@indafunds[.]com). The SES rail inverts that: a handful of landing hubs each carry many burner personas, up to 256 unique firstname.lastname@ addresses on krediblefunds[.]com alone and 226 on fundflippr[.]com, alongside single-address info@<brand>[.]com domains. The content templates are identical across both rails, and the SparkPost customer account (a single customer ID with subaccounts 42, 46, and 48) also delivers mail for domains that route clicks into the SES hubs. That overlap ties the two rails to one operator.
The clustering signal that holds everything together is the nameserver pair. Twelve core landing hubs resolve to armando.ns.cloudflare[.]com and teagan.ns.cloudflare[.]com. Eight of them were registered at NameCheap on the same calendar day, 2025-08-19, a batch-registration event that is itself a fingerprint. The remaining hubs on the pair include one aged domain (gimmelend[.]com, created in 2023) and a re-registered domain (mityfunds[.]com), which points to a mix of a purpose-built cohort and an aged-domain stash under the same account.
How It Works
The contact chain is short and repeatable. The recipient gets an email that addresses them by their real first name (scraped from the address or bought as lead data) and claims a funding or loan application is already in progress. The body carries fabricated legitimacy markers, a "Transaction Number," a "Reference ID," a "Profile Status: Active" line, and time pressure, so the recipient believes they started something they forgot about and need to finish before it expires.
The call-to-action button routes through a tracking layer. On the SparkPost rail that is the provider's own click tracker; on the SES rail it is a tr.<hub>[.]com/l/<token> link that carries an opaque encoded token and lands on one of the shared hubs. The hub presents a multi-step form that collects name, address, contact details, income, employment, and bank information under the guise of completing the application. That harvested data is the product. It is resold into the lending lead market, where it reaches lenders, collectors, and brokers, and where some of it lands with operators that misuse it directly.
Sample Lures
All samples are defanged. Recipient identifiers have been replaced with placeholders. These show attacker-side content only.
Template C is the dominant variant, a fake "resubmit your application" status update on the SparkPost rail:
From: "Indafunds" <cooper.a@indafunds[.]com>
Subject: More funding available, resubmit your application [recipient name]
Return-Path: bounces-340176-42@spmailtechno[.]com
[recipient name],
More providers are ready to process your request.
Transaction Number: [fabricated ID]
Date: [current date]
Amount Requested: up to $3,000
Your application is still open. Additional sources may now be
available which could expand the options shown to you.
Availability can change quickly, so we recommend reviewing and
resubmitting as soon as possible.
[REVIEW YOUR UPDATED OPTIONS] (routes through the provider click tracker)
The process is fast, and your previously entered details may
already be saved.
Template A is a fake bonus claim that pushes account creation, and it carries a fabricated Peru business address in the footer as legitimacy theater:
From: "Diego Hernando" <diego.h@incansoft[.]com>
Subject: Congrats! You qualified...
Congrats, you've been selected for $1,504.97 in bonuses!
All you have to do is create your account, click here to claim it.
[COMPLETE MY ACCOUNT]
[ACCESS HERE]
Las Acacias 246, Surco, Lima, Peru
Template D reframes the same funnel as a paid research-study recruitment offer:
From: "Paid Volunteer Message Center" <ella.f@budgetadirect[.]com>
Subject: Update: Paid Volunteer Roles Are Still Open
Return-Path: bounces-340176-46@spmailtechno[.]com
Update: Paid Volunteer Studies Still Open
Hello [recipient name],
Your active profile is still matched with new paid volunteer
studies now enrolling.
Some opportunities may offer compensation of up to $3500 or
more per study.
[VIEW PAID VOLUNTEER LISTINGS]
Reference ID: [fabricated ID]
Profile Status: Active
Automated notification from budgetadirect[.]com. Do not reply.
The SES rail shows the hub-and-spoke routing directly. The message is sent from a spoke domain, but the unsubscribe and tracking links resolve to a hub tracker on a different domain:
From: "Douglas Lang" <douglas.lang@fundflippr[.]com>
Subject: Next steps to confirm your info
Return-Path: <...>@amazonses[.]com
Hello there [recipient name],
We've received your application. To continue...
Unsubscribe: hxxps://tr.krediblefunds[.]com/cv2/[encoded token]
Technical Analysis
Two Rails, Three Providers, One Content Set
The operator has moved across three email providers over its lifetime, SendGrid first, then SparkPost, then Amazon SES, and currently runs the SparkPost and SES rails together. The migration pattern is consistent with burning and replacing accounts as reputation degrades, while the content templates and the personalization mechanic carry over unchanged. The two live rails differ mainly in distribution strategy and sender-address shape.
| Rail | Tracking / routing | Return-path shape | Sender format | Distribution strategy |
|---|---|---|---|---|
| SparkPost | Provider click tracker (post.spmailtechno[.]com) |
bounces-340176-<subaccount>@spmailtechno[.]com |
firstname.initial@domain |
One sender per domain, heavy domain rotation (171 domains) |
| Amazon SES | Self-hosted tr.<hub>[.]com/l/<token> |
<id>@amazonses[.]com |
firstname.lastname@domain and fixed info@<brand>[.]com |
Many burner personas per hub (up to 256 on one domain) |
| SendGrid (legacy) | Provider click tracker | sendgrid[.]net bounce path |
firstname.initial@domain |
Early, low-volume origin rail |
The sender-format shift from firstname.initial@ to firstname.lastname@ is a reliable marker of the SparkPost-to-SES migration, and the reuse of the single SparkPost customer account to deliver mail for SES-hub-linked domains is the concrete thread tying the two rails to one operator.
Domain-Generation Grammar
The domains are not random. They are assembled from a fixed finance-keyword vocabulary glued together with a small set of affixes, which is why the inventory reads as endless variations on a theme. The core vocabulary is: fund, funding, funds, budget, capital, pay, lend, loan, debt, tax, finance, financial, wealth, vault, asset, credit, alert, smart, direct, connect, trust, pro, nexus, and concept. The TLDs are mostly .com with roughly fifteen .ai domains mixed in.
| Affix pattern | Position | Examples |
|---|---|---|
in- / i- prefix |
leading | indafunds[.]com, incapitalpros[.]com, icashorbit[.]com, icredifynow[.]com |
ez- prefix |
leading | ezbudget[.]ai, ezalerts[.]ai, ezfunda[.]com |
-pro / -pros suffix |
trailing | finproshub[.]com, wealthifypros[.]com, prounderwrite[.]com |
-nexus suffix |
trailing | borrowingnexus[.]com, microloannexus[.]com, personalloannexus[.]com |
romance-language -a / -ica suffix |
trailing | finderica[.]com, ifinantica[.]com, alfinta[.]com, infinansa[.]com |
| SES portmanteau brands | whole name | krediblefunds[.]com, cashluma[.]com, fundflippr[.]com, paydaynova[.]com, loangenieus[.]com |
The grammar produces tight typo-sibling clusters that are a useful hunting signal on their own: qixlend / wixlend / zevenlend, gimmelend / gimmeloans, connectingfunding / connectingfunds, and lendiftyhub / lendiftypro.
The Nameserver Cohort
The registration data is the strongest attribution material. Twelve core landing hubs share the armando.ns / teagan.ns Cloudflare pair, and the same-day NameCheap registration of eight of them turns a set of unrelated-looking domains into a single dated batch.
| Landing hub | Registration | Nameserver pair |
|---|---|---|
krediblefunds[.]com |
cohort account | armando.ns / teagan.ns cloudflare |
fundriff[.]com |
2025-08-19, NameCheap | armando.ns / teagan.ns cloudflare |
fundyze[.]com |
2025-08-19, NameCheap | armando.ns / teagan.ns cloudflare |
fundsygo[.]com |
2025-08-19, NameCheap | armando.ns / teagan.ns cloudflare |
cashluma[.]com |
2025-08-19, NameCheap | armando.ns / teagan.ns cloudflare |
lendlyst[.]com |
2025-08-19, NameCheap | armando.ns / teagan.ns cloudflare |
lendlyfe[.]com |
2025-08-19, NameCheap | armando.ns / teagan.ns cloudflare |
fundsparkz[.]com |
2025-08-19, NameCheap | armando.ns / teagan.ns cloudflare |
gimmelend[.]com |
2023-08-04 (aged) | armando.ns / teagan.ns cloudflare |
mityfunds[.]com |
2025-10-22 (re-registered) | armando.ns / teagan.ns cloudflare |
lendiftyhub[.]com |
cohort account | armando.ns / teagan.ns cloudflare |
lendiftypro[.]com |
cohort account | armando.ns / teagan.ns cloudflare |
Because the nameserver pair is assigned to the Cloudflare account rather than to any single domain, it holds steady while the operator cycles disposable sending domains and migrates between email providers. A new loan-brand domain that resolves to this pair is an immediate attribution match, without waiting for it to accumulate sending history or a reputation signal.
Hub-and-Spoke Click Routing
The SES rail separates sending from landing. A large set of "spoke" domains appear only as the From address and host no page of their own; every click they generate resolves through a hub tracker to one of the shared landing hubs. Each hub exposes a tr.<hub>[.]com/l/<opaque token> subdomain that the spokes point at.
| Spoke (sending only) | Resolves to hub |
|---|---|
fundflippr[.]com |
krediblefunds[.]com |
thebetterlend[.]com |
krediblefunds[.]com |
accountsclear[.]com |
krediblefunds[.]com |
hereforfunds[.]com |
fundyze[.]com |
lendylite[.]com |
fundriff[.]com |
brightbridgefund[.]com |
fundriff[.]com and krediblefunds[.]com |
lendingforfunds[.]com |
lendlyfe[.]com |
For a defender the tracker layer is the collapse point: dozens of unrelated-looking sender domains converge on a small set of hub trackers, so pivoting on the tr.<hub>/l/ pattern surfaces the shared backend far faster than enumerating senders.
Content-Level Evasion
The messages carry four interchangeable templates (an application-status update, a bonus claim, an "insider system" FOMO pitch, and a paid-study recruitment offer), which dilutes any single content fingerprint. Each one fabricates the trappings of a real application system: submission and transaction numbers, reference IDs, dates, and a profile-status line. Personalization with the recipient's real first name manufactures the sense of a prior relationship. One recurring tell is a fake copyright footer built from the sender's own domain, for example a "Copyright" line naming your.gofundspros[.]com, which no legitimate brand would render that way.
Detection Observations
The behavioral signal sits at the ecosystem level, not the individual message. Any one email resembles ordinary financial marketing, so per-message content features are weak on their own. The distinguishing patterns are structural:
- Sender addresses follow a rigid
firstname.initial@orfirstname.lastname@shape on finance-keyword domains, and a single domain carrying dozens or hundreds of these burner personas is a strong anomaly for what claims to be a lender. - The
tr.<hub>[.]com/l/<token>click pattern links many independent-looking sender domains back to a small hub set, so the tracker host is the strongest cross-cluster pivot. - The Cloudflare
armando.ns/teagan.nsnameserver pair clusters the landing hubs independently of any content or sending signal, and it holds across domain rotation and provider migration. - Same-day bulk registration of finance-keyword domains at a single registrar is a cohort marker that predates any sending activity.
Keying on the backend (nameserver pair and hub trackers) rather than the rotating front end (individual domains and senders) is what keeps pace with an operator whose entire strategy is front-end churn.
MITRE Fight Fraud Framework (F3) Mapping
The following maps the operation to the MITRE Center for Threat-Informed Defense Fight Fraud Framework (F3, https://ctid.mitre.org/fraud). Mapping is at the tactic and technique level.
| Tactic | Observed behavior | Observed behavior |
|---|---|---|
| Reconnaissance | Victim identity data gathering | Real first names sourced from scraped addresses or purchased lead lists to personalize lures |
| Resource Development | Acquire sending and hosting infrastructure | Bulk finance-keyword domain registration, multiple ESP accounts, self-hosted hub trackers |
| Initial Access | Phishing via email with impersonated pretext | Unsolicited application-status and pre-qualification emails using a fabricated lending brand |
| Stealth | Trusted-infrastructure abuse and rotation | Authenticated ESP delivery, rapid domain and persona rotation, interchangeable content templates |
| Positioning | Sensitive-data collection | Multi-step form harvesting identity, income, employment, and bank details |
| Monetization | Resale of harvested consumer data | Loan-application data auctioned into the lending lead market |
Indicators of Compromise
All indicators are defanged and drawn from the verified-malicious export set. Victim data has been removed. Where a type was capped for readability, the floor line states the verified-malicious total the subset is drawn from. Rows marked as an adjacent mini-cluster belong to a separate operator and surfaced alongside this campaign; they are not part of this operator's footprint.
Senders
| Value | Rail | Notes |
|---|---|---|
cooper.a@indafunds[.]com |
SparkPost | Template C sample sender |
diego.h@incansoft[.]com |
SendGrid to SparkPost | Earliest-rail origin sender |
ella.f@budgetadirect[.]com |
SparkPost | Template D (paid-study) sender |
douglas.lang@fundflippr[.]com |
SES | Spoke persona routing to krediblefunds[.]com |
jonatan.olson@cashluma[.]com |
SES | Hub burner persona |
jackson.stamm@thebetterlend[.]com |
SES | Spoke persona |
caleb.a@quickfinancialconcept[.]com |
SparkPost | Finance-keyword persona |
amelia.r@ezalerts[.]ai |
SparkPost | .ai TLD persona |
info@loangenieus[.]com |
SES | Fixed info@ portmanteau brand |
info@paydaynova[.]com |
SES | Fixed info@ portmanteau brand |
info@fundnestusa[.]com |
SES | Fixed info@ portmanteau brand |
info@snapfundnow[.]com |
SES | Adjacent mini-cluster (distinct operator) |
| ... (representative subset; 250+ verified-malicious senders) |
Domains
| Value | Role | Notes |
|---|---|---|
krediblefunds[.]com |
Landing hub | Primary SES hub; hosts tr. tracker |
fundriff[.]com |
Landing hub | 2025-08-19 NameCheap cohort |
fundyze[.]com |
Landing hub | 2025-08-19 NameCheap cohort |
fundsygo[.]com |
Landing hub | 2025-08-19 NameCheap cohort |
cashluma[.]com |
Landing hub | 2025-08-19 NameCheap cohort |
lendlyst[.]com |
Landing hub | 2025-08-19 NameCheap cohort |
lendlyfe[.]com |
Landing hub | 2025-08-19 NameCheap cohort |
gimmelend[.]com |
Landing hub | Aged domain (2023) on the same NS pair |
mityfunds[.]com |
Landing hub | Re-registered on the same NS pair |
lendiftyhub[.]com |
Landing hub | Same NS pair |
lendiftypro[.]com |
Landing hub | Same NS pair |
indafunds[.]com |
Sender | SparkPost one-sender-per-domain |
incansoft[.]com |
Sender | SendGrid-origin sender domain |
fundflippr[.]com |
Spoke | SES sending-only, routes to krediblefunds[.]com |
thebetterlend[.]com |
Spoke | SES sending-only |
snapfundnow[.]com |
Adjacent | Distinct operator (GoDaddy registration) |
| ... (representative subset; 250+ verified-malicious domains) |
Hosts
| Value | Role | Notes |
|---|---|---|
tr.krediblefunds[.]com |
Click tracker | Centralized SES hub tracker (/l/ and /cv2/ paths) |
go.snapfundnow[.]com |
Click tracker | Adjacent mini-cluster tracker subdomain |
mailing.simplemoneygoals[.]com |
Sending subdomain | CTA redirect infrastructure |
news.premiumtradingstrategy[.]com |
Sending subdomain | Finance-content sender subdomain |
your.gofundspros[.]com |
Footer host | Appears in fake-copyright footer pattern |
krediblefunds[.]com |
Landing host | Self-resolving hub |
| ... (representative subset; 250+ verified-malicious hosts) |
Conclusion
The front end of this operation is designed to be disposable, and it is: hundreds of domains and thousands of sender personas that come and go on a weekly cycle. The backend is not. One Cloudflare account, one nameserver pair, a stable set of hub trackers, and a fixed content playbook have carried the operation across three email providers and more than six months. Defenders who chase the domains will always be a step behind; the durable footholds are the registration cohort and the shared tracker layer, and that tracker grammar is the pivot most likely to surface the same operator if it expands into adjacent lead-generation verticals.
Related research
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.
Rented Storefronts: A Fake-Store Franchise on Facebook Ads
Across 2026 we mapped 100+ fraudulent storefronts fronted by disposable Facebook advertisers, increasingly hosted as tenants on legitimate builder platforms.