One Operator Behind a Celebrity Death-Hoax Ad Network
One Operator Behind a Celebrity Death-Hoax Ad Network
Since mid-December 2025, one operator has run 1000+ fake Facebook pages posting AI-written celebrity death hoaxes to funnel fans toward fraud. The lures lean on country-music stars, George Strait and Alan Jackson most of all, with a parallel Emma Watson health-hoax cluster running on the same backend. Every page pushes the same shape of post: an emotional headline about a beloved performer, a link buried in the message body rather than the ad's call-to-action button, and a click-through to a rotating fleet of throwaway domains. We tracked this operator for more than seven months and found the clusters are not separate campaigns but one operation, stitched together by how it registers domains, names them, tags its URLs, and mangles its own text to slip keyword filters.
Key Takeaways
- One operator sits behind clusters that look distinct on the surface, tied together by same-day batch domain registrations, a consistent two-family naming grammar, affiliate tags embedded in URL slugs, and Cyrillic-homoglyph text obfuscation.
- The click-through link lives in the ad's message body, not the call-to-action button, so the payload destination sits in free text next to emoji and mangled headlines.
- Domains rotate on a roughly two-to-three-week cadence across 14 cheap top-level domains, all registered under WHOIS privacy through a small set of low-cost registrars.
- Country-music stars anchor the lures, with a parallel Emma Watson health-hoax cluster sharing the same registration patterns, slug grammar, and text-obfuscation tricks.
- Landing pages monetize through ad-fraud clickfarms, data-harvest forms, investment-fraud funnels, and fake-alert malware prompts.
Background
Celebrity clickbait is not new, but the volume and coordination behind this operator put it in the category of ad-fraud infrastructure rather than one-off hoaxing. The playbook is familiar to anyone who follows scam advertising on social platforms. In February 2026, Meta filed lawsuits against four scam advertisers who impersonated celebrities and brands with altered images and deepfakes, including a China-based operator running celeb-bait tied to investment fraud and a Vietnam group using ad-review cloaking, as The Hacker News reported. Meta also runs a facial-recognition program that compares suspected celeb-bait ads against the profile images of nearly 500,000 public figures, which the company says more than doubled its detection of such ads in testing. That program leans on faces. This operator leans on text, and text is harder to match.
The closest public parallel to what we observed is Bitdefender's March 2026 research, covered by Help Net Security, which documented roughly 310 malvertising campaigns on Meta platforms localized into 15+ languages, funneling victims into investment fraud through fake scandal clips and "celebrity will" narratives. That research called out one detail we saw firsthand: substituting Cyrillic look-alike characters for Latin letters to dodge keyword filters. Fact-checkers have chased the consumer-facing side of the same trend for years. Snopes has repeatedly debunked the Alan Jackson death hoax and tracks a wider network of celebrity death-hoax clickbait. The FTC, for its part, warns that scammers routinely pose as celebrities on social media, and reports that imposter scams stayed the top fraud category in 2025.
Two pieces of background make this operator's economics work. The first is generative text. AI writing collapses the cost of producing high-volume, unique celebrity-hoax articles, the same dynamic behind the "AI content farm" surge that NewsGuard tracks in the thousands of sites. The second is cheap domains. The lures ride entirely on inexpensive new generic top-level domains, 14 different ones in all (among them .top, .shop, .one, .blog, .info, .click, .best, .xyz, .live, and .life), namespaces that offer near-free bulk pricing, minimal registration friction, and weak abuse response. Interisle's 2025 phishing study found 42% of phishing domains sat in new gTLDs, up from 25% the year before. The operator registers through low-cost, ICANN-accredited registrars (Cosmotown, Porkbun, and Spaceship), all legitimate businesses that offer bulk tooling and free WHOIS privacy. Since GDPR, redacted registrant data is the default, so privacy strings like "withheld for privacy ehf" and "private by design llc" carry no signal on their own. That pushes attribution off the registrant record and onto infrastructure and behavior, which is where this operator gives itself away.
Discovery and Infrastructure
The pages announce themselves by theme before anything else. Names cluster around country music and nostalgia: "Country Hits Collection," "Pastoral Melodies," "Classic Oldies For All," "Midnight Country Radio," with a smaller set of entertainment and movie-culture names ("A Thoughtful Muse," "Movie Verse," "Gothic Symphony") carrying the Emma Watson lures. Nearly all run on numeric Facebook profile IDs, the shape of throwaway accounts spun up in bulk rather than aged personas. Across the tracking window we counted more than 1000 distinct pages pointing traffic at campaign domains, a number inflated by page churn and rebrands as accounts get taken down and replaced, and those pages placed tens of thousands of sponsored posts over the campaign's life. The celebrity subject rotates, but two country-music icons, Alan Jackson and George Strait, anchor the bulk of the lures ("before the first note, George Strait knew exactly where he was"), with a smaller Emma Watson health-hoax cluster running in parallel.
The link placement is the first structural tell. On a normal sponsored post, the click-through sits in the call-to-action button. Here the button is empty, and the destination URL sits in the message body instead, wrapped in emoji arrows and bold Unicode text like "Click to play Full Video." That choice moves the payload into free-form text the operator fully controls, and it is consistent across every cluster we examined.
Following those message-body links leads to the domain fleet, and the fleet is where the single-operator picture snaps into focus. The operator cycled through 500+ domains over the campaign's life, all on cheap top-level domains, all under WHOIS privacy, and many registered in tight same-day batches. Grouping the domains by registration date and registrar exposes the cadence:
| Registration date | Registrar | Domains | Notes |
|---|---|---|---|
| 2025-04-24 | Spaceship | tunenest[.]shop |
Aged staging, registered ~9 months before first use |
| 2025-11-05 | Spaceship | musicseatatsunset[.]click |
Aged staging |
| 2026-01-07 | Cosmotown | videyviraly[.]top, videy-viral[.]top, link-videy[.]top |
Same-day batch, video-bait cluster |
| 2026-01-18 | Spaceship | relaxmusic[.]shop |
|
| 2026-02-04 | Spaceship | listsong[.]best |
|
| 2026-02-09 | Porkbun | prolix[.]blog, ventra[.]blog, retivo[.]blog |
Same-day batch of coined words |
| 2026-03-10 | Porkbun | duskbloom[.]one, clayglow[.]one, mossgrow[.]xyz |
Same-day batch of coined words |
| 2026-04-01 | Porkbun | crispvale[.]blog |
The batches matter. Three domains registered through Cosmotown on a single January day, three more through Porkbun on one February day, three again on one March day. Independent hoaxers do not register in coordinated same-day lots on a monthly rhythm. One operator provisioning inventory ahead of need does.
How It Works
The contact chain is short and built for a single click. A fan scrolling Facebook sees a sponsored post from a music-themed page. The headline hits an emotional nerve: a farewell concert, a health scare, a death that did not happen. The body reads like a fragment of a news story, warm and specific, ending on a question ("What Alan Jackson song still feels alive in your life?") and a bold prompt to watch a video or read more. The link sits right there in the text.
Clicking it lands the victim on an AI-generated article hosted on one of the rotation domains. The article extends the emotional hook long enough to hold attention, and from there the monetization branches. Some pages are pure ad-fraud clickfarms, stacked with display ads that pay per impression. Some present registration or "continue watching" forms that harvest name, email, and phone for resale into lead-gen networks. Some redirect into investment-fraud funnels where a fake "account manager" walks the victim through deposits, the same endpoint Bitdefender documented in the broader celeb-bait ecosystem. And some throw a fake virus alert to push a malware download. The lure is the same regardless of which payout the operator is running that week, which is why the front-end pages are disposable and the back-end infrastructure is reused.
Sample Lures
All samples below are attacker-authored ad content. URLs are defanged and slugs truncated. No recipient or victim data appears in Facebook ad bodies, which are broadcast rather than addressed, so there is no personal data to redact here.
Country-music death-hoax, the dominant pretext. Note the empty call-to-action button and the link carried in the body text:
Page: "Country Roots Sound"
HE WALKED SLOWLY ONTO THE STAGE - THEN TOLD MORE THAN 50,000 FANS, "I'M NOT DEAD!"
That was Alan Jackson's final full-length Nashville concert. Not a funeral. Not a sad
goodbye wrapped in silence. Just a country man in a white hat, standing under the lights
one more time, even as the nerve disease he has battled for years made every step harder...
Alan Jackson didn't say goodbye like a legend leaving; he sang like a man still living.
What Alan Jackson song still feels alive in your life?
Click to play Full Video! http[:]//countrystardaily[.]site/im-not-dead-the-unexpected-declaration...
The same pretext run through homoglyph obfuscation. Cyrillic look-alikes replace Latin letters and letters are dropped, so keyword filters searching for "Just 30 minutes ago" or "Alan Jackson" miss it, while a human reader does not:
Page: "Hollywood Secrets"
"SAD NEWS: Jυst 30 miпυtes ago, Alan Jackson appeared with tearfυl eyes iп aп emotioпal
momeпt that left faпs completely heartbrokeп...
Learn more: http[:]//beatstationnews[.]com/sad-news-jst-30-mites-ago-ala-jackso-appeared...
The Emma Watson health-hoax cluster, running the same slug grammar on a different domain cohort:
Page: "A Thoughtful Muse"
Emma Watson is reportedly facing a serious battle with cancer, leaving her health in a
very critical condition...
To all supporters and people around the world, please keep her in your thoughts and prayers...
Read more: http[:]//crispvale[.]blog/posts/emma-watson-reportedly-facing-serious-battle-cancer...
Technical Analysis
The value of this operator as a case study is how many independent fingerprints converge on one attribution. No single tell is conclusive. Together they are.
Two-Family Domain Naming Grammar
The domains split cleanly into naming families, and both families run in parallel across the whole campaign rather than marking a shift over time.
| Family | Count | Pattern | Examples |
|---|---|---|---|
| Descriptive music / media compounds | 15 | Real English words describing music or news | allmymusic[.]shop, timelessmusic[.]life, relaxmusic[.]shop, listsong[.]best, tunenest[.]shop, countrystardaily[.]site, beatstationnews[.]com |
| Coined pseudo-word brandables | 14 | Invented, pronounceable, brand-generator style | clayglow[.]one, duskbloom[.]one, budbloom[.]one, mossgrow[.]xyz, meadowlyn[.]info, grovenly[.]info, moorbloom[.]info, crispvale[.]blog, prolix[.]blog, ventra[.]blog, retivo[.]blog, exiro[.]live, kalixo[.]info, datixa[.]live |
| Video-bait cluster | 3 | "videy/viral" video-download framing | videyviraly[.]top, videy-viral[.]top, link-videy[.]top |
The coined family is the more distinctive signature. Names like duskbloom, mossgrow, and crispvale share a two-syllable nature-and-texture aesthetic that reads like output from a single brandable-name generator, and they appear in the same registration batches. The descriptive family is what gets shown to the fan; the coined family is what gets registered in bulk when the operator needs fresh inventory fast.
Registration Cohorts and Aged Staging
The WHOIS record confirms the batch behavior visible in the domain list. The coined .blog and .one domains arrive in same-day Porkbun lots (three on 2026-02-09, three on 2026-03-10). The video-bait .top domains arrive as a single-day Cosmotown lot on 2026-01-07. Alongside the fresh batches, the operator keeps aged staging domains: tunenest[.]shop was registered in April 2025 and sat unused for roughly nine months before the campaign brought it live, and musicseatatsunset[.]click dates to November 2025. Aged domains carry less reputational suspicion than day-old ones, so mixing a few into an otherwise-fresh fleet buys the operator a little more runway before blacklisting catches up. Every domain in the fleet sits behind WHOIS privacy, across all three registrars, which is unremarkable on its own but complete in a way that fits deliberate bulk provisioning.
URL Slug Grammar and Affiliate Tags
The path structure is the strongest cross-cluster pivot. Slugs are long, lowercase, hyphenated renderings of the headline, and a large share carry the same homoglyph mangling the caption uses ("sad-news-jst-30-mites-ago-ala-jackso"). More telling, many slugs end in an operator or affiliate tag followed by a short hex hash:
crispvale[.]blog/posts/emma-watson-reportedly-facing-serious-battle-cancer-...-danghoa123-team-spark-81e0-sktg
beatstationnews[.]com/sad-news-jst-30-mites-ago-...-6imbug-nhungoc123-86a6cf311969
Tokens like danghoa123, nhungoc123, and team-spark look like affiliate or sub-operator identifiers threaded through the URL so the back end can attribute traffic and pay out. Their reuse across different domains and different celebrity pretexts is what welds the country-music and Emma Watson clusters into one operation. The path prefix itself splits by cohort rather than by cluster: the early .blog / .info / .xyz domains use a /posts/ prefix, the later .shop / .site / .com domains use a bare slug, and at least one domain uses a dated WordPress permalink, all pointing at a handful of shared publishing setups rather than dozens of independent sites.
Homoglyph and Emoji Obfuscation
The text obfuscation is consistent enough to be a signature. Captions substitute Cyrillic look-alikes for Latin letters (υ for u, п for n) and drop letters outright, so a keyword filter matching "minutes" or "Jackson" fails while the text stays legible to a fan. The same mangling carries into the URL slugs. Around it, the operator uses bold and script Unicode ranges for phrases like "Click to play Full Video" and emoji arrows to draw the eye to the link. Bitdefender documented the identical Cyrillic-substitution trick across the broader celeb-bait ad ecosystem, which places this operator inside a known tradecraft lineage even though the specific network is not itself publicly reported.
What Ties the Clusters Together
Read individually, the country-music pages and the Emma Watson pages look like separate efforts on separate domains. Five shared fingerprints say otherwise: the same-day batch registrations on a monthly rhythm, the dual naming grammar drawn from one generator aesthetic, the affiliate-tag-plus-hash slug structure reused across domains, the Cyrillic-homoglyph obfuscation in both captions and slugs, and the message-body link placement with an empty call-to-action button. Any one of these could be coincidence. All five converging is one operator.
Detection Observations
The traffic separates from legitimate entertainment-page activity on structure, not on any single keyword. The message-body link with an empty call-to-action button is unusual for a sponsored post and pairs reliably with the campaign. The URL slugs are distinctive: very long hyphenated headline strings, frequently ending in a short alphanumeric tag and a hex suffix, and often carrying the same homoglyph substitutions as the visible caption. The domains themselves cluster on cheap new gTLDs, arrive under WHOIS privacy in same-day registration lots, and split into the descriptive-music and coined-brandable naming families described above.
The single strongest cross-cluster pivot is the combination of the registration cohorts and the slug grammar. A page name and a celebrity subject rotate freely, but the affiliate-tag-and-hash slug structure and the batch-registration fingerprint stay stable across pretexts, which is what lets a defender collapse dozens of surface-distinct pages into one operator. The Cyrillic-homoglyph substitution is a useful secondary signal precisely because legitimate publishers have no reason to mangle their own headlines to evade a filter.
Indicators of Compromise
All indicators are defanged. Victim data has been removed. The domain list below is a representative subset of the durable, verified-malicious infrastructure; page identifiers are omitted because the operator's numeric-ID pages churn constantly and make poor long-lived indicators.
Domains
| Value | Role | Notes |
|---|---|---|
allmymusic[.]shop |
CTA / landing | Descriptive-music family, high-volume |
timelessmusic[.]life |
CTA / landing | Descriptive-music family |
relaxmusic[.]shop |
CTA / landing | Descriptive-music family |
listsong[.]best |
CTA / landing | Registered 2026-02-04 |
tunenest[.]shop |
CTA / landing | Aged staging, registered 2025-04-24 |
musicseatatsunset[.]click |
CTA / landing | Aged staging, registered 2025-11-05 |
clayglow[.]one |
CTA / landing | Coined family, 2026-03-10 batch |
duskbloom[.]one |
CTA / landing | Coined family, 2026-03-10 batch |
mossgrow[.]xyz |
CTA / landing | Coined family, 2026-03-10 batch |
prolix[.]blog |
CTA / landing | Coined family, 2026-02-09 batch |
ventra[.]blog |
CTA / landing | Coined family, 2026-02-09 batch |
retivo[.]blog |
CTA / landing | Coined family, 2026-02-09 batch |
crispvale[.]blog |
CTA / landing | Coined family, Emma Watson cluster |
meadowlyn[.]info |
CTA / landing | Coined family, Emma Watson cluster |
videyviraly[.]top |
CTA / landing | Video-bait cluster, 2026-01-07 batch |
| … (representative subset; 500+ malicious domains recorded for this campaign) |
Facebook Pages
| Value | Role | Notes |
|---|---|---|
facebook[.]com/thecountryalmanac |
Distribution | Country-music clickbait page; posts campaign lures |
| … (page inventory exceeds 1000 distinct profiles; published as naming/behavior patterns, since numeric-ID pages churn) |
MITRE Fight Fraud Framework Mapping
The mapping below aligns to the MITRE Center for Threat-Informed Defense Fight Fraud Framework (F3), which reuses ATT&CK T#### technique IDs where applicable and assigns fraud-specific techniques an F1### prefix. F3 is oriented toward financial fraud, so celebrity-clickbait initial access maps only approximately, and ad-fraud clickfarm monetization has no precise F3 analogue.
| Tactic | Technique | ID |
|---|---|---|
| Resource Development | Acquire Infrastructure: Domains (rotating disposable domains) | T1583.001 |
| Resource Development | Acquire Infrastructure: Malvertising (paid Facebook scam ads) | T1583.008 |
| Resource Development | Create Fake Materials: Fake Website (AI-generated landing pages) | F1020.002 |
| Initial Access | Phishing (malicious link in ad body) | T1660 |
| Initial Access | Impersonate Official (celebrity / public-figure lure) | F1032 |
| Initial Access | Drive-by Compromise (fake-alert malware push) | T1189 |
| Reconnaissance | Gather Customer Information (data-harvest forms) | F1029 |
| Stealth | Device / Fingerprint Spoofing (filter evasion, cloaking-adjacent) | F1023 |
| Monetization | Convert to Cryptocurrency (investment-fraud cash-out) | F1018 |
Conclusion
The front end of this operation is built to be thrown away. Pages get reported and replaced, domains get blacklisted and rotated on a two-to-three-week clock, and the celebrity of the week shifts with whatever draws clicks. What does not change is the plumbing: the batch registrations, the naming grammar, the affiliate-tagged slugs, and the homoglyph tricks. Defenders who key on those durable fingerprints instead of the disposable page names will still recognize this operator after the next rotation, and probably under the next celebrity's name.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.