Ten Exchanges, One Operator: A .digital Crypto-Impersonation Network
Ten Exchanges, One Operator: A .digital Crypto-Impersonation Network
Since January 2026, one operator has run Facebook ads impersonating TradingView, Binance, OKX and other exchanges to push fake crypto desktop apps. The ads promise free premium subscriptions, anniversary bonuses, and "official" desktop downloads, and they lean hardest on Thai-speaking traders, with Arabic, Chinese, Spanish, and English variants filling out the reach. Click through and the destination is never a brand-owned site. It is a throwaway domain where the exchange name has been bolted on as a subdomain, binance. or tradingview. sitting in front of a meaningless operator string. We tracked the infrastructure across more than a dozen activation waves and found that clusters which look independent on the surface, one on cheap .digital domains and one on co-registered .com domains, are a single operation. The proof is in how the operator registers domains, names its subdomains, and tags its own ad campaigns.
Key Takeaways
- One operator sits behind two surface-distinct domain clusters, welded together by an identical brand-token subdomain grammar, shared URL path slugs, a reused content-mismatch decoy, and two segregated UTM encoding schemes.
- The impersonation lives in the subdomain: the target exchange name is the leftmost label on a throwaway operator apex, so the visible brand string never touches a brand-owned domain.
- The
.comcluster of three domains was registered on a single day through one registrar under one privacy proxy, then aged roughly seven months before first use, which is the strongest single attribution signal in the set. - UTM campaign parameters leak operator structure, including a Cyrillic "Копия" (Russian for "Copy") ad-draft tag that places a Russian-speaking operator behind Thai-language creatives.
- Landing pages funnel victims into fake exchange desktop-app installs and bonus-claim flows, and the front-end domains rotate on a roughly biweekly wave cadence across
.digitaland.comnamespaces.
Background
Fake crypto-exchange ads on social platforms are one of the best-documented fraud patterns of the last two years, and this operator is a textbook instance of it. Bitdefender Labs has tracked a long-running Meta malvertising operation impersonating TradingView along with Binance, Bitget, MetaTrader, and OKX, using sponsored Facebook ads that offer free-premium or desktop-app downloads and funnel victims to look-alike sites that deliver info-stealers. That campaign started on Windows and expanded to macOS and Android, pulling in wallet extensions for MetaMask, Phantom, OKX, Bybit, and Binance through fake TradingView and Sora 2 ads. TradingView has publicly warned its users about fraudulent ads that mimic its branding and push malicious software. The financial stakes are large: the FBI Internet Crime Complaint Center reported a record $11.4B in crypto-related losses in 2025, with crypto investment fraud accounting for roughly $7.2B of that, and victims aged 60 and over absorbing about $4.4B.
The Thai targeting is not incidental. Thailand's Ministry of Digital Economy and Society has said fraudulent Facebook ads for crypto and fake-investment schemes duped more than 200,000 Thai users, and Thai regulators have gone as far as threatening a court-ordered Facebook shutdown over the volume of scam ads the platform carries. Meta faces its own pressure on this front, including a Santa Clara County suit and pump-and-dump class actions alleging it profits from fraud advertising, and it has publicized detection efforts such as facial-recognition matching against celebrity-deepfake investment ads.
Three pieces of infrastructure context make this operation cheap to run and hard to attribute from registration data alone. The first is the .digital top-level domain. Like most post-2013 new generic TLDs, .digital sells in bulk at low promotional prices with minimal registration friction, and the .digital registry publishes no WHOIS at all, so the entire primary domain pool carries zero registrant data. Interisle's phishing research has found that phishers deliberately register the large majority of the domains they abuse and cycle through a pool of roughly 40 cheap, unrestricted new gTLDs, with cryptocurrency-themed phishing rising sharply year over year. The second is WHOIS privacy. Since GDPR took effect in 2018, ICANN has required registrars to redact registrant data by default, so a privacy string like "super privacy service ltd c/o dynadot" is the normal state for legitimate and malicious domains alike and carries no attribution signal on its own. The third is Facebook's outbound Link Shim: every external ad click is rewritten to an l.facebook[.]com/l.php interstitial that strips referrer data and checks the destination before bouncing the user onward, which wraps the visible landing URL and is a normal fixture of any Facebook ad click. With registration data redacted or absent, attribution has to come from what the operator builds and how it labels it, and that is exactly where this operator gives itself away.
Discovery and Infrastructure
The infrastructure surfaced through a single high-volume .digital hub domain that carried hundreds of distinct sponsored ads from dozens of Facebook profiles, all resolving to the same crypto-download pretext. Pulling the profiles that pointed at that hub, then the domains those profiles used, unrolled the rest of the operation.
Every advertiser profile runs on a numeric Facebook ID rather than a vanity name, the shape of throwaway accounts spun up in bulk. Display names cluster on finance and trading themes, with many profiles sharing a name (multiple "Market Pulse", "Trade News", and "BIT News" pages), and across the tracking window more than 200 distinct profiles pushed traffic at campaign domains, running into the tens of thousands of ad placements over the operation's life. Profiles activate in waves and go dormant as older ones get reported, so the account layer is disposable by design.
The domains split into two clusters that look unrelated until you read their structure.
| Cluster | Namespace | Naming shape | WHOIS |
|---|---|---|---|
| A (primary) | .digital |
Descriptive tech-jargon compounds (netflowtch, clouddevice, throughput-zone) |
None published |
| B (co-registered) | .com |
Coined five-character strings (xlbic, rfjje, vjkgs) plus desktop-app compounds |
Redacted / privacy proxy |
Cluster A is the workhorse. The primary hub netflowtch[.]digital carries the full set of brand subdomains, and a rotating fleet of single-purpose .digital satellites (clouddevice[.]digital, throughput-zone[.]digital, cognitnodexhubly[.]digital, and more) each run one or two anniversary-bonus landers. Cluster B is smaller but structurally louder: xlbic[.]com, rfjje[.]com, and vjkgs[.]com were registered on the same day through the same registrar under the same privacy proxy. That co-registration is what first tied the two clusters to one hand, and the shared subdomain grammar sealed it.
How It Works
The contact chain is short and built for a single click. A trader scrolling Facebook sees a sponsored post from a finance-themed page. The copy promises something concrete and time-boxed: a free year of TradingView premium, a 150 USDT Binance bonus, an OKX anniversary reward, a ChatGPT Pro subscription. The call-to-action button reads "Download" or "Learn More", often in Thai ("ดาวน์โหลด", "เรียนรู้เพิ่มเติม").
Clicking it bounces through Facebook's Link Shim and lands on a brand-impersonation page hosted on binance.<operator-apex> or tradingview.<operator-apex>. The page mirrors the exchange's look and pushes a desktop-app installer or a bonus-claim flow that asks the victim to log in or connect a wallet. In the broader ecosystem Bitdefender documented, the payload at this stage is an info-stealer that lifts wallet-extension credentials, and the download-app framing this operator uses throughout is consistent with that endpoint. The front-end domain is disposable and rotates on a wave cadence, but the pretext and the subdomain grammar stay fixed, which is why the operation reads as one campaign across many domains.
Sample Lures
All samples below are attacker-authored ad content. URLs are defanged and paths truncated. Facebook ad bodies are broadcast rather than addressed, so no recipient or victim data appears in them; there is nothing personal to redact.
TradingView free-premium download, Thai, the dominant pretext:
Page: numeric-ID profile ("Chart Insight")
ดาวน์โหลด TradingView สำหรับ PC วันนี้ และรับ Premium ฟรี...
(Download TradingView for PC today and get Free Premium...)
CTA button: เรียนรู้เพิ่มเติม (Learn More)
Landing: hxxps://tradingview[.]netflowtch[.]digital/52qxk
Binance bonus lure, Thai, on the co-registered .com cluster. Note the UTM path code echoed in the landing slug:
Page: numeric-ID profile ("Thaigger")
🎁 รับ 150 USDT (โบนัส): ลิงก์ดาวน์โหลดอย่างเป็นทางการ
(Get 150 USDT bonus: official download link)
🔴 ข่าวด่วน: ยืนยันแล้ว Binance ประกาศแคมเปญพิเศษ...
(Breaking: confirmed, Binance announces a special campaign...)
Landing: hxxps://binance[.]xlbic[.]com/1cdg1
OKX anniversary reward, English, on a satellite .digital domain:
Page: numeric-ID profile ("Market Pulse")
Celebrate OKX's 10th Anniversary with exclusive rewards. D...
CTA button: ดาวน์โหลด (Download)
Landing: hxxps://throughput-zone[.]digital/...
Content-body mismatch decoy, English. The ad body is unrelated real-estate copy while the CTA points to a TradingView impersonation page, a deliberate evasion of body-content analysis:
Page: numeric-ID profile
Discover Umbra Residences, a contemporary residential com...
Landing: hxxps://tradingview[.]netflowtch[.]digital/...
Technical Analysis
No single indicator here is conclusive. What makes this operation a clean attribution case is how many independent fingerprints converge on one operator.
Brand-Token Subdomain Grammar
The core clustering signal is the subdomain. The operator places the impersonated brand as the leftmost label on its own apex, <brand>.<operator-apex>, and reuses the same grammar verbatim across both the .digital and .com clusters. That is what binds two otherwise-unrelated domain pools to one hand: independent operators do not converge on an identical naming convention by chance.
| Impersonated brand | Subdomain label | Apexes carrying it (defanged) |
|---|---|---|
| Binance | binance. (plus download-binance., bina-nce., bin-app.) |
netflowtch[.]digital, xlbic[.]com, rfjje[.]com, vjkgs[.]com, apps-desktops[.]com, windows-appps[.]com |
| TradingView | tradingview. |
netflowtch[.]digital, apps-desktops[.]com, windows-appps[.]com |
| Indodax | indodax. |
netflowtch[.]digital, xlbic[.]com, rfjje[.]com, vjkgs[.]com |
| Hyperliquid | hyperliquid. |
xlbic[.]com |
| Exness | exness. |
rfjje[.]com |
| Upbit | upbit. |
vjkgs[.]com |
| MercadoPago | mercadopago. |
netflowtch[.]digital |
| Luno | luno. |
netflowtch[.]digital |
| ChatGPT Pro | chatgpt. |
vjkgs[.]com |
| OKX / Bybit | bare-apex landers (no brand subdomain) | clouddevice[.]digital, throughput-zone[.]digital, cognitnodexhubly[.]digital, netcoreapi[.]digital |
The variant labels are their own tell. Alongside the plain binance. label the operator runs download-binance. (download framing), bina-nce. (a dash-inserted typosquat), and bin-app. (app abbreviation). Later waves extended the same trick to tradlngview. (an l-for-i swap) and view-wwindows (a doubled w), showing a consistent habit of near-miss typosquats layered on top of the exact-match subdomains.
Registration Cohorts and Aged Staging
Public WHOIS exists for only the .com cluster, and it is decisive.
| Registrar / org | Created | Domains (defanged) | Cohort |
|---|---|---|---|
| Dynadot / super privacy service ltd c/o dynadot | 2025-06-17 | xlbic[.]com, rfjje[.]com, vjkgs[.]com |
Aged staging, single operator |
| Hello Internet Corp / (no org) | 2026-01-27 | apps-desktops[.]com |
Purpose-built |
| (no published WHOIS) | — | windows-appps[.]com |
Purpose-built, registrar hidden |
.digital registry (no WHOIS) |
— | netflowtch, clouddevice, cognitnodexhubly, throughput-zone, softnet-portal, netcoreapi, connectweb, hiddenbonusflow |
No-WHOIS pool |
Three domains registered on one day, through one registrar, behind one privacy proxy, is not coincidence. It is a single operator provisioning inventory in a batch. The gap between that June 2025 registration and the cluster's first observed use in February 2026 is aged staging: a domain that has sat quietly for months carries less reputational suspicion than a day-old one, so pre-registering and parking buys runway before blacklisting catches up. The apps-desktops[.]com cohort is the opposite pattern, registered days before its late-January activity window, purpose-built and burned fast. The .digital pool sits outside registration analysis entirely because the registry publishes nothing, which is likely why the operator makes it the primary, highest-churn cluster.
Domain-Generation Families
The two clusters use two different naming aesthetics, and the split is consistent enough to be a generator signature. The .com cluster leans on coined five-character consonant strings with no meaning (xlbic, rfjje, vjkgs), the kind of output a bulk-registration script produces when it only needs something available and forgettable. The .digital cluster instead reads as descriptive tech-jargon compounds: netflowtch, clouddevice, throughput-zone, softnet-portal, netcoreapi, connectweb. Later waves stay inside that same compound aesthetic (note-core, backend-flux, deviceonportalx, network-attach, spark-nexus, depotgateway), drifting toward two-word "cloud / net / node / flux / core / gate" constructions. The desktop-app apexes carry their own theme, apps-desktops and windows-appps (with a doubled p), evoking the download pretext the landers deliver.
UTM Encoding Schemes
The utm_campaign parameters are the richest operator artifact in the set, and they segregate cleanly by cluster, which on its own would suggest two operators. Read closely, they reveal one.
The .digital cluster (Scheme 1) uses a plus-joined field structure: a DDMM launch date, an ad-set codename (drag, fast, moon, t2t, and uppercase creative tags DRAGON, MERAKE, AGC), a four-digit creative ID, a GEO code (TH, lat), and a product tag (trd, TRDVIEW, BINANCE, BW). A representative value reads 0102+drag+1548+TH+trd+V2.
The .com cluster (Scheme 2) uses a hyphenated series structure instead: a T-<n> campaign-series number, the URL path slug echoed into the parameter, and a country or audience code (TH, Thai, AL for Albania, CH, de, nu, ba). A representative value reads T-10-Thai-5TrjI, pointing at the landing path /5trji.
Two artifacts inside those schemes do the attribution work. First, the Scheme 2 slug is the landing-page path code verbatim: path /1cdg1 carries UTM 1CDG1, path /47hag carries 47HaG, path /mjvg5 carries MJVG5. That deterministic slug-to-UTM mapping is a fingerprint of one ad-generation pipeline. Second, both schemes carry ad-draft duplication tags, and some appear as — Копия, the Russian word for "Copy". A Russian-language draft tag threaded through Thai-targeted crypto creatives points to a Russian-speaking operator running localized campaigns, and it is the same operator hand across both UTM schemes.
Cross-Cluster Pivots
Five signals collapse the two clusters into one operation:
- The brand-token subdomain grammar is byte-identical across
.digitaland.com. - The Scheme 2 UTM parameter echoes the landing path slug, a single-pipeline fingerprint.
- Distinct advertiser profiles share URL path slugs from a common pool (
/8jese,/buhcc,/nniv0appear across separate numeric-ID pages). - The same real-estate decoy copy ("Discover Umbra Residences...") is reused as ad-body cover text across
netflowtch[.]digital,binance[.]netflowtch[.]digital, andtradingview[.]netflowtch[.]digitallanders. - Profiles activate on a biweekly wave cadence that swaps in fresh
.digitalapexes while preserving the subdomain grammar and UTM structure.
Any one of these could be coincidence. All five converging is one operator.
Detection Observations
The traffic separates from legitimate exchange advertising on structure, not on any single keyword. The strongest behavioral signal is the subdomain grammar: a real exchange serves its brand from its own registered domain, never as the leftmost label on an unrelated third-party apex, so binance.<something-else> or tradingview.<something-else> is inherently anomalous. The near-miss typosquat labels (bina-nce., tradlngview.) sharpen the same signal.
Beyond the hostname, the durable pivots are the ones that survive domain rotation. The .com cluster's same-day co-registration and aged-then-activated timing is a registration-cohort fingerprint that a rotation of front-end domains cannot erase. The UTM structure, especially the deterministic slug-to-parameter echo and the recurring Russian-language draft tag, ties campaigns to one pipeline regardless of which apex is live that week. The content-body mismatch, where an ad's visible copy is unrelated to its crypto destination, is a useful secondary signal precisely because legitimate advertisers have no reason to decouple their creative from their landing page. Keying on those durable fingerprints, rather than on the disposable domain of the day, is what lets a defender recognize this operator after the next wave rotates.
Indicators of Compromise
All indicators are defanged. Victim data has been removed. The tables below are a representative subset of the durable, verified-malicious infrastructure. Advertiser page identifiers are omitted deliberately: the operator's numeric-ID Facebook profiles churn constantly and make poor long-lived indicators, so the naming and behavior patterns above are the better detection surface for the account layer.
Domains
| Value | Role | Notes |
|---|---|---|
netflowtch[.]digital |
CTA hub / landing | Primary .digital hub; full brand-subdomain set |
xlbic[.]com |
CTA hub / landing | Dynadot co-registration, 2025-06-17 |
rfjje[.]com |
CTA / landing | Dynadot co-registration, 2025-06-17 |
vjkgs[.]com |
CTA / landing | Dynadot co-registration, 2025-06-17 |
apps-desktops[.]com |
CTA / landing | Hello Internet Corp, 2026-01-27 |
windows-appps[.]com |
CTA / landing | Purpose-built, no published WHOIS |
clouddevice[.]digital |
CTA / landing | OKX anniversary satellite |
cognitnodexhubly[.]digital |
CTA / landing | Tertiary CTA satellite |
throughput-zone[.]digital |
CTA / landing | OKX anniversary lure |
softnet-portal[.]digital |
CTA / landing | Satellite lander |
netcoreapi[.]digital |
CTA / landing | OKX anniversary lure |
connectweb[.]digital |
CTA / landing | Satellite lander |
hiddenbonusflow[.]digital |
CTA / landing | TradingView lure |
intellective[.]digital |
CTA / landing | Later-wave .digital apex |
| … (representative subset; 50+ verified-malicious domains tracked for this campaign) |
Hosts
| Value | Role | Notes |
|---|---|---|
tradingview[.]netflowtch[.]digital |
Landing | TradingView impersonation |
binance[.]netflowtch[.]digital |
Landing | Binance impersonation |
mercadopago[.]netflowtch[.]digital |
Landing | MercadoPago impersonation |
luno[.]netflowtch[.]digital |
Landing | Luno impersonation |
indodax[.]netflowtch[.]digital |
Landing | Indodax impersonation |
binance[.]xlbic[.]com |
Landing | Binance impersonation |
hyperliquid[.]xlbic[.]com |
Landing | Hyperliquid impersonation |
bina-nce[.]xlbic[.]com |
Landing | Binance dash-typosquat |
download-binance[.]xlbic[.]com |
Landing | Binance download lure |
binance[.]rfjje[.]com |
Landing | Binance impersonation |
exness[.]rfjje[.]com |
Landing | Exness impersonation |
bin-app[.]rfjje[.]com |
Landing | Binance app lure |
binance[.]vjkgs[.]com |
Landing | Binance impersonation |
tradingview[.]apps-desktops[.]com |
Landing | TradingView impersonation |
binance[.]windows-appps[.]com |
Landing | Binance impersonation |
| … (representative subset; 50+ verified-malicious hosts tracked for this campaign) |
MITRE Fight Fraud Framework Mapping
The mapping aligns to the MITRE Center for Threat-Informed Defense Fight Fraud Framework (F3), which reuses ATT&CK T#### technique IDs where applicable and assigns fraud-specific techniques an F1### prefix. F3's monetization techniques are framed around laundering already-stolen funds, so classic investment fraud, where the victim is socially engineered into depositing into a rigged platform, maps only approximately at the cash-out stage.
| Tactic | Technique | ID |
|---|---|---|
| Resource Development | Acquire Infrastructure: Malvertising (paid Facebook ads) | T1583.008 |
| Resource Development | Acquire Infrastructure: Domains (brand-token subdomains on throwaway apexes) | T1583.001 |
| Resource Development | Establish Accounts (throwaway numeric-ID advertiser pages) | T1585 |
| Resource Development | Create Fake Materials: Fake Website (exchange look-alike landers) | F1020.002 |
| Resource Development | Stage Capabilities (host the desktop-app installer) | T1608 |
| Initial Access | Impersonate Official (exchange / official-app impersonation) | F1032 |
| Initial Access | Phishing (malicious link in the ad CTA) | T1660 |
| Initial Access | Drive-by Compromise (fake-app download from the lure page) | T1189 |
| Reconnaissance | Gather Customer Information (credential / wallet / PII capture) | F1029 |
| Monetization | Convert to Cryptocurrency (victim deposit / wallet drain) | F1018 |
Conclusion
The front end of this operation is disposable by design. Advertiser pages get reported and replaced, .digital apexes rotate on a biweekly clock, and the exchange of the week shifts with whatever draws clicks. What does not change is the plumbing: the brand-token subdomain grammar, the same-day co-registration behind the .com cluster, the deterministic slug-to-UTM mapping, and the Russian-language draft tags threaded through Thai creatives. Defenders who key on those durable fingerprints rather than the domain of the day will still recognize this operator after the next rotation, and probably under the next exchange's name.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.