Two Hundred Redirect Domains, One Real Donation Page
Two Hundred Redirect Domains, One Real Donation Page
Since December 2025, a smishing operation has used 200+ throwaway domains to send deceptive political-fundraising texts that lead to one legitimate donation platform. Although the links appear unrelated, each redirects once to the same real fundraising platform. A URL scanner therefore lands on a genuine, reputable page. The deception is in the text message and the disposable intermediary domain, not the destination. We tracked more than 200 coined redirect domains and nearly 9,000 rotating sender numbers that collectively sent hundreds of thousands of messages. A shared destination platform and a small pool of shared sender numbers connect the infrastructure, while the operation's structure separates its traffic from legitimate political texting.
Key Takeaways
- The operation uses more than 200 coined redirect domains. Each redirects once to a legitimate donation platform, leaving the scanner to inspect a clean terminal URL.
- Delivery relies on nearly 9,000 burner numbers. Most are retired after one or two messages, producing the SMS equivalent of snowshoeing and bypassing per-number blocking.
- The redirect domains draw from a fixed election-themed vocabulary and are bulk-registered in same-day batches through one privacy-WHOIS registrar.
- More than 1,200 burner numbers sent through more than one redirect domain, tying the domain sprawl to one sending backend.
- The donation pages are genuine and belong to the committees named on them. About four in five messages land on pages for official party, candidate or sitting-member committees. The rest land on pages for independent PACs and advocacy groups.
Background
We found the operation during routine SMS sender triage, when high-volume burner activity began clustering around short, election-themed redirect domains. Following that connection exposed an architecture built around a simple idea: end the chain at a page nobody can block.
That page belongs to WinRed, the legitimate online fundraising platform that Republican campaigns and committees use to process donations. WinRed is a real, well-documented service operated by Revv LLC. Its donation pages have a valid TLS certificate and a clean reputation. The operator exploits that reputation rather than attacking the platform. When recipients tap a link, they pass through one throwaway hop before reaching a real secure.winred[.]com donation page associated with a specific campaign or committee. Automated link scanners that assess a message by its final destination see a trusted host and allow the text through. This is trust laundering: the operator uses the clean standing of a reputable endpoint to legitimize a deceptive delivery path. WinRed is an abused platform in this case, not a party to the scheme. The donation pages themselves are genuine. Each belongs to the committee named on it and operates through that committee's own WinRed account. About four in five messages land on pages for official party committees, candidate committees or sitting members' leadership PACs. The remainder land on pages for independent PACs and advocacy groups. We have not established the relationship between the operator of the redirect layer and the committees whose pages it fronts. What we can document is the delivery method: disposable redirect hops, rotating burner numbers, and copy designed to mislead.
Two other techniques support the volume. The first is a disposable redirector. Each short domain uses a ccTLD or gTLD such as .io, .co, .org, or .la and functions as a self-hosted URL shortener. It redirects once, hiding the final landing page from both the recipient and static filters while giving the operator a short, campaign-plausible string for the text. Registering hundreds of these domains through a privacy-WHOIS registrar supports a burn-and-rotate model. The domains are cheap, the registrant is masked, and the operator can abandon any domain that gets flagged. The second technique is burner-phone rotation. Each blast is spread across thousands of local numbers used only once or twice. This is the SMS version of snowshoeing: the operator spreads the load so thinly that no individual sender crosses the volume thresholds carriers use to identify bulk senders. U.S. carriers began hard-blocking unregistered application-to-person traffic in early 2025, and the rotation pattern is designed to remain below that enforcement threshold.
Deceptive political fundraising by text is a well-documented problem across the 2024 through 2026 U.S. cycles. Investigative reporting has linked aggressive recurring-donation programs to elderly donors whose retirement savings were drained through relentless match-multiplier framing and pre-checked recurring-donation boxes. The FCC and the FTC have also published guidance advising recipients not to tap links in unsolicited political texts or reply to them, because a reply confirms that the number is active. State attorneys general have issued separate warnings about inflated match promises in political fundraising. The delivery tactics examined here, including urgency, inflated match framing and misleading opt-outs, echo those warnings at infrastructure scale.
Discovery and Infrastructure
Two signals exposed the operation. First, nearly every redirect resolves to the same secure.winred[.]com platform, connecting otherwise unrelated domains through one shared endpoint. Second, sender numbers recur across domains. More than 1,200 burner numbers sent through two or more different redirect domains. That reuse is the main evidence that one sending backend sits behind the domain sprawl, rather than many parallel operators. The numbers are also segmented by client: 99.8% of them only ever sent for a single committee, so each committee's traffic moves through its own block of rotating numbers.
Four domains started the investigation: win26[.]io, 26vote[.]co, win-26[.]org, and voterep[.]co. Expanding from their shared destination uncovered more than 200 redirect domains, almost all of which led to WinRed donation pages. Most rotate out before accumulating enough history to be individually flagged. That is the point of the design.
A minority of redirect hops occasionally terminate somewhere other than WinRed. We observed sporadic redirects to other GOP-aligned donation endpoints, including secure.anedot[.]com, and to advocacy landing pages such as adflegal[.]org and americanvoice[.]org. These redirects indicate that the same operator reuses a redirect hop for adjacent political-donation platforms, rather than operating as a separate campaign.
How It Works
The contact chain is short. A burner number sends a text containing an urgent, authority-laden pretext and one link on a coined redirect domain. The link has a six-character alphanumeric path. When tapped, it redirects once to a secure.winred[.]com donation page with a slug that mirrors the pretext, such as a candidate committee paired with a survey or impact tag. The recipient arrives at a genuine donation form on a familiar platform, carrying the urgency created by the text directly into the payment step.
The pretexts are numerous and rotate regularly. They include false authority, such as messages attributed to party leadership or a decorated veteran; inflated donation impact multipliers such as "12X", "29X", and "50X boost"; fake voter-identity alerts formatted as official correspondence; low-commitment survey bait that ends at a donation page; deceptive opt-out notices that lead to a donation page instead of an unsubscribe flow; fabricated financial-status notices such as "Forbearance Applied" intended to create confusion; fabricated windfalls, such as a refund, dividend or rebate check said to be waiting on the recipient's answer; and fabricated account-status alerts claiming that a membership has lapsed, a payment is missing, or a one-time survey code has been issued.
Sample Lures
The samples below preserve real message structures. We removed all recipient identifiers, replaced named individuals with their roles, and defanged every link. They contain only attacker-side content.
Channel: SMS - Pretext: false authority + urgency
"Wait! The [party committee chair], a former [House leader], AND a
combat vet ALL contacted YOU! hxxps://win-26[.]org/1hghfp"
Channel: SMS - Pretext: inflated donation "impact" multiplier
"With one press, your contribution will have [50x impact]
hxxps://voterep[.]co/qnq05v"
Channel: SMS - Pretext: survey bait leading to a donation page
"No donation plea. Just a yes or no: [hot-button policy question]?
hxxps://26vote[.]co/1vej3i"
Channel: SMS - Pretext: deceptive opt-out
"Too many texts from [the party]? Update your profile & select
LOW CONTACT: hxxps://win26[.]io/[token]"
Channel: SMS - Pretext: fabricated financial-status notice
"Forbearance Applied #[digits] - Last chance
hxxps://win26[.]io/[token]"
Channel: SMS - Pretext: fabricated windfall
"Would you reject $5,000 [government] refund from [the President]? Because
that's what's happening on your survey, [recipient name] 60 mins to fix:
hxxps://25go[.]co/[token]"
Channel: SMS - Pretext: fabricated account status
"SYSTEM ERR: Payment Missing. Your [party] membership has been SUSPENDED
because we have not received your payment. Fix now: hxxps://red-win[.]io/[token]"
Channel: SMS - Pretext: false personalization + voter-ID framing
"[recipient name], this could decide the majority.
*Alert* Voter ID Update from [a named political figure]:
hxxps://voterep[.]co/[token]"
The redirect chain for those links resolves as follows. All links are defanged:
hxxps://win26[.]io/wvavag -> hxxps://secure.winred[.]com/[candidate-committee]/[slug]
hxxps://voterep[.]co/qnq05v -> hxxps://secure.winred[.]com/ors/50x-impact
hxxps://26vote[.]co/1vej3i -> hxxps://secure.winred[.]com/[candidate-committee]/[survey-slug]
Technical Analysis
Redirect Architecture and Path Grammar
Every message contains a link in the form <coined-label>[.]<tld>/<6-char-alnum>, which redirects once to secure.winred[.]com/<candidate-or-committee>/<slug>. The operator controls only the throwaway hop. Across the full domain set, the path follows the same pattern: a six-character lowercase alphanumeric token, as in win26[.]io/wvavag, voterep[.]co/qnq05v, and win-26[.]org/1hghfp. The terminal slug follows the social-engineering pretext rather than the sending domain, allowing one domain to front many different lures. This uniform path structure appears across otherwise unrelated domains and registrars and provides a fingerprint of the operation.
Domain-Generation Vocabulary
The operator builds coined labels from a small, fixed vocabulary, sometimes adding a hyphen. The same concepts recur in different spellings and across several TLDs, frustrating single-string blocklists.
| Token family | Vocabulary | Defanged examples |
|---|---|---|
| Election-year | 26, 2026, 25 |
win26[.]io, rep2026[.]co, 2026win[.]co, 25go[.]co |
| Win / victory | win |
win26[.]io, win-26[.]org, win-26[.]us, 26-win[.]org |
| Red / party | red, gop, rep |
red-win[.]io, truered[.]io, gop-way[.]com, rght26[.]io |
| USA / patriotic | usa, us, u5a |
usa-26[.]io, usa26[.]io, us-26[.]co, us4u[.]io, u5a[.]io |
| Vote / civic | vote, act, txt, impact |
26vote[.]co, voterep[.]co, act26[.]co, txt26[.]info, im-pact[.]io |
| Opaque shortener | (non-themed) | clkgo[.]co, clkgo[.]net, shor[.]la |
Three recurring generation habits are apparent. Variants of the same concept use different hyphenation: red-win appears alongside truered, win-26 alongside win26, and us-26 alongside us26 and usa26. The labels also use numeric and leetspeak compression: usa becomes u5a and 26u5a, right becomes rght, and impact becomes im-pact. The operator also rotates the same label across TLDs. The set includes red-win[.]io, red-win[.]co, and red-win[.]org, so blocking one string does not disable its siblings.
Registration Cohorts and Bulk Batches
The domains are concentrated at one registrar and use masked ownership. Tucows dominates the crawled subset, followed by GoDaddy, with isolated use of Name.com, 1API, IONOS, and Namecheap. Nearly every domain uses privacy or withheld WHOIS, including Contact Privacy Inc., WhoisProxy, Withheld for Privacy, and Domains by Proxy. The registrant organization is therefore concealed across the set. Privacy-proxy customer identifiers reveal same-day registration batches, while creation dates follow the pre-midterm calendar.
| Created | Registrar | Domains (defanged) | Batch signal |
|---|---|---|---|
| 2024-12-04 | Tucows | 25go[.]co, red-us[.]co |
consecutive proxy IDs |
| 2025-03-21 | Tucows | u5a[.]io, us4u[.]io |
same-day pair |
| 2025-07-21 | Tucows | red-win[.]io, red-win[.]org, 26-win[.]org, win-gop[.]org |
clustered proxy IDs |
| 2025-12-30 | Tucows | us-26[.]co, usa-26[.]io, rght26[.]io |
same-day triple |
| 2026-01 to 2026-03 | Tucows / GoDaddy / Name.com | 26txt[.]org, voterep[.]co, gop-poll[.]com, act26[.]co |
rolling pre-midterm cadence |
Several labels predate the operation and appear aged or repurposed rather than newly created: red-win[.]co (2022), the clkgo[.]co and clkgo[.]net shortener twins (2023), and shor[.]la (2025). Purpose-built registrations first appear as staging pairs in late 2024. They accelerate into same-day, multi-TLD batches during 2025, then settle into a rolling cadence in the first quarter of 2026 that follows the pre-midterm calendar.
Shared Opt-Out Page
The bare apexes of the redirect domains do not host their own content. At least 21 redirect to the same generic opt-out page, which uses one template with a single analytics container and no company identity beyond a phone-number form. That page was registered only a few months before we observed it. This single opt-out surface, shared by dozens of apexes that otherwise appear unrelated, further connects the domains to one operator of the redirect layer.
Sender Fan-Out
Most domains spread a blast across hundreds of burner numbers, each sending once or twice. win-26[.]org appeared from only four numbers, one of which repeatedly messaged a single recipient; with so few recipients observed, we cannot tell whether this reflects a different sending arrangement.
| Redirect domain | Distinct sending numbers | Pattern |
|---|---|---|
us-26[.]co |
~872 | mass burner rotation (largest fanout) |
usa-26[.]io |
~776 | mass burner rotation |
rght26[.]io |
~419 | mass burner rotation |
win26[.]io |
~277 | mass burner rotation |
26vote[.]co |
~161 | mass burner rotation |
voterep[.]co |
~65 | mass burner rotation |
win-26[.]org |
4 | few numbers observed |
Cross-Cluster Pivots
Five signals tie the domain set to one operation. Nearly every redirect ends on secure.winred[.]com. The same physical sender numbers appear under multiple redirect labels. Every domain uses the same six-character path grammar, regardless of token family or registrar. The Tucows-plus-privacy registration pattern recurs across same-day batches. The aged, non-themed shortener domains (clkgo[.]co, clkgo[.]net, shor[.]la) are also the likeliest overlap points between this ring and other campaigns, making them the strongest candidates for a shared-infrastructure pivot.
Activity has continued for roughly nine months. After declining through the spring, it increased again in August and September ahead of the midterm elections.
Detection Observations
The traffic differs structurally from legitimate political texting because the message content deliberately imitates genuine fundraising appeals.
- A legitimate campaign links directly to its own site or WinRed page. This operation consistently places a coined throwaway domain in front of that page. An unfamiliar short-domain redirect ending at a real donation page is therefore the single strongest signal.
- The six-character lowercase alphanumeric path remains consistent across the domain set and provides a durable cross-domain pivot.
- Election-themed coined labels based on the
win/red/usa/vote/26vocabulary form a tight cluster, particularly when they use hyphen or leetspeak variants and distribute the same label across.io/.co/.org. - Not every short, election-themed domain was coined by this operator. Party committees use their own registered shortlink domains, which are usually aged and send from one stable, publicly documented number. Ownership of aged domains paired with a single persistent sender should therefore be verified rather than automatically treated as part of the cluster.
- Burner numbers are segmented per committee. Each committee's messages rotate through its own pool, and almost no number ever sends for two committees. A redirect domain that fronts dozens of different committees, each through its own rotating pool, matches this operation's profile.
- The shared opt-out page at the bare apex provides a cheap pivot: fetch the apex of an unfamiliar election-themed short domain and compare it with a known member of the set.
- Most domains use enormous fanout from single-use burners. Numbers reused across domains are the most stable identifiers for clustering.
- The aged, non-themed shortener domains may connect this activity to adjacent campaigns.
Indicators of Compromise
All indicators below are defanged and come from the verified-malicious set. We removed recipient data. Because the redirect domains also function as the operation's redirector hosts at the bare apex, the domain and host tables contain the same set.
Redirect Domains
| Value | Role | Notes |
|---|---|---|
win26[.]io |
Redirector | Highest-fanout primary domain |
26vote[.]co |
Redirector | Primary domain |
win-26[.]org |
Redirector | Persistent-sender domain (4 numbers) |
voterep[.]co |
Redirector | Primary domain; Tucows, reg 2026-01-29 |
us-26[.]co |
Redirector | Largest burner fanout |
usa-26[.]io |
Redirector | Election-batch domain |
rght26[.]io |
Redirector | Leetspeak label |
red-win[.]io |
Redirector | Multi-TLD sibling family |
truered[.]io |
Redirector | Party-token label |
clkgo[.]co |
Redirector | Opaque shortener; possible multi-campaign pivot |
clkgo[.]net |
Redirector | Shortener twin of clkgo[.]co |
shor[.]la |
Redirector | Opaque shortener |
rep2026[.]co |
Redirector | Election-year label |
facts2[.]com |
Redirector | Aged (2024) redirect domain |
| ... (representative subset; 50+ verified-malicious redirect domains across the full operation) |
Sender Numbers
| Value | Role | Notes |
|---|---|---|
+1-202-649-4131 |
Sender | Burner |
+1-202-990-9684 |
Sender | Burner |
+1-301-278-8842 |
Sender | Burner |
+1-301-363-9765 |
Sender | Burner |
+1-301-842-6370 |
Sender | Burner |
+1-304-413-8580 |
Sender | Burner |
+1-330-274-4655 |
Sender | Burner |
+1-346-553-7589 |
Sender | Burner |
+1-412-887-3876 |
Sender | Burner |
+1-615-488-9278 |
Sender | Burner |
+1-928-235-2397 |
Sender | Burner |
| ... (representative subset; 50+ verified-malicious sender numbers; nearly 9,000 observed across the full operation) |
MITRE Fight Fraud Framework Mapping
This mapping follows the MITRE Fight Fraud Framework (F3) v1.1, https://ctid.mitre.org/fraud. F3 covers post-access fraud behavior, so this deceptive-delivery operation is mapped by analogy. Stages without a matching F3 technique have no ID.
| F3 Tactic | Observed behavior | ID |
|---|---|---|
| Initial Access | Phishing (SMS delivery) | T1660 |
| Initial Access | Urgency pressure, fabricated windfalls and account-status alerts | |
| Stealth | Disposable redirect hop and deceptive opt-out framing | |
| Monetization | Donations collected on the committees' own donation pages |
Conclusion
Deceptive delivery does not require a malicious landing page when every chain ends at a legitimate one. By ending each chain at a real committee's donation page, the operator keeps the only host trusted by a scanner permanently clean. The deception remains in disposable domains and burner numbers that the operator is prepared to lose. Single-indicator takedowns are therefore slow, while structural pivots remain useful. The uniform redirect-path grammar, sender numbers reused across domains, and aged shortener domains persist longer than any individual domain. As the operation shifts toward shortcode delivery ahead of the midterm cycle, those shorteners are the most likely connection to whatever the operator runs next.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.