Sixty Brands, Hundreds of Domains: A Single Loan Lead-Gen Operator
Sixty Brands, Hundreds of Domains: A Single Loan Lead-Gen Operator
Since late 2025, one operator has run a multi-vertical loan and lead-gen scam network from hundreds of rotating domains and dozens of disposable brand names. What looks, from any single inbox, like a scatter of unrelated loan offers, tax-relief pitches, and reward notices is a single operation. The senders change with every message, the brand names cycle week to week, and the domains burn and rebuild at a rate of dozens per month. Underneath that churn sits a small, stable spine: an aged front domain, a self-hosted redirect rail, and a set of registration and mail-authentication fingerprints that stitch more than 770 domains back to one actor.
Key Takeaways
- One operator ties together more than 770 domains, more than 300 of them active in mail traffic, fronting 60 or more rotating brand names across at least seven verticals through a single aged hub domain registered in 2002.
- The sending model has two layers: single-use
[brand][10-digit]@throwaway addresses that defeat sender-reputation history, and a handful of persistent addresses on the operator's own rail domains that are the true stable identities. - Click-through runs on a self-hosted redirect rail with numeric, random, and vertical-named CTA subdomains instead of third-party shorteners, giving the operator full control of both the landing chain and the unsubscribe relays.
- The strongest cross-cluster pivots are a shared WHOIS registrant-organization value, a recurring
SD:...1919...List-Unsubscribe token, Mailjet-dominant published SPF whoseinclude:chains cross-reference sibling domains, and a uniform Google site-verification TXT record across the fleet. - Domain generation follows a compound-English-plus-misspelling grammar organized into themed token families, with the same label registered across multiple TLDs and near-identical typo siblings as a registration-time signature.
- Brand vocabulary bridges the clusters: loan brands minted as sender display names on the hub reappear as vertical-named CTA subdomains on a sibling content-farm domain.
Background
The network first surfaced through its tracking layer. A redirect host, mail.foodycreek[.]com, kept appearing as the single click destination inside loan-offer emails whose sender addresses never repeated. Pulling on that thread led outward to the sending domains, and a WHOIS pivot on their shared registrant-organization value led to the full footprint: more than 770 domains registered under one organization string, more than 300 of them live in mail traffic within a 90-day window.
The operation is a lead-generation and brand-impersonation business. Each message is a lure for one of several financial verticals, and each lure funnels a recipient toward a form that collects personal and financial details. Those details have real resale value: a completed loan-application profile, with income, employment, and contact data, is a sellable lead in predatory-lending and affiliate-commission markets. The brand names split two ways. Several impersonate or closely echo real financial companies, including Optima Tax Relief, J.G. Wentworth, National Debt Relief, Lexington Law, First Premier Bank, Destiny Card, and Fortiva Card, which are the operation's impersonation targets and not participants. Others are generic lead-gen brand names with no established company behind them. Either way the names are disposable, rotating continuously across the same infrastructure.
Two pieces of infrastructure context matter for what follows. Delivery runs through Amazon SES in the us-west-2 region: Amazon's Simple Email Service is a legitimate bulk-sending platform, and routing through it means the mail carries valid SES signing and lands from Amazon's sending ranges. The message bodies are built with Klaviyo MJML templates, using Klaviyo's hosted custom-font assets. Klaviyo is a mainstream marketing-email builder; its templates render as clean, professional HTML, which is exactly why they are useful for making a scam loan offer look like a real lender's newsletter.
Discovery and Infrastructure
The spine of the network is diamondskyinc[.]com, a domain originally registered in 2002 and now repurposed as the primary sending hub. Age is the point. A domain with two decades of history carries reputation weight that a freshly registered domain does not, so an operator who can acquire an aged, dropped domain inherits a head start against new-domain filters. On that hub the operator minted more than 485 distinct sender addresses, each used for roughly one message and then discarded.
Around the hub sits a set of purpose-built rail domains, each with a defined job:
| Indicator | Role | Notes |
|---|---|---|
diamondskyinc[.]com |
Hub / sender | Aged 2002 drop-catch; 485+ single-use senders across 60+ brands |
foodycreek[.]com |
Tracking / redirect | mail. subdomain serves the in-body redirect URLs |
lendfinity[.]net |
Sender + self-hosted CTA | Persistent operator brands; numeric and preview CTA subdomains |
purecarenet[.]com |
CTA redirect | Numeric and functional-word landing subdomains |
credibleland[.]net |
Early sender + CTA | Random 8-character CTA subdomains |
mediclinicnews[.]com |
Health-rail sender | Persistent veronica@ persona; scraped-content camouflage |
netbasketshopping[.]com |
Shopping-vertical sender | Word-prefixed subdomain sender rotation |
jennertrendzz[.]net |
Unsubscribe relay | List-Unsubscribe domain for the health rail |
gamehealthreport[.]org |
Snowshoe sender | Vertical-named loan subdomains; feeds a sibling CTA hub |
forumcolloquynews[.]com |
CTA hub | Landing/redirect backbone for the snowshoe cluster |
The registrant-organization pivot is what turns that shortlist into a network. The rail domains share a single WHOIS registrant-organization value, and re-running that value across the reputation store returns more than 770 domains. Not every network member carries the string: some use privacy or scrubbed WHOIS, and at least one rail (mediclinicnews[.]com) is registered under a second identity string, so the true footprint is larger than the org pivot alone shows. The registrant value is also an imperfect pivot in the other direction. It is not exclusive to this operator; a minority of genuine, unrelated businesses sit under the same string, most of them in the pre-2020 aged cohort, so the value is a lead, not a verdict. The durable cross-identity ties are the mail-authentication and template fingerprints described below.
How It Works
A recipient receives an email that presents as a loan company, a tax-relief service, a debt-relief agency, or a rewards program. The sender address is a throwaway of the form [brand][10-digit-number]@diamondskyinc[.]com, built for one send and never reused. The visible brand may sit in the address prefix, or, for a large share of the volume, only in the From display name while the address prefix stays generic.
The body is a professional-looking HTML template, often padded beneath a run of invisible soft-hyphen characters and followed by scraped filler text: a paragraph lifted from a finance-news article or a recipe blog, sitting under the actual pitch. The filler is content variation, meant to make each message look a little different from the last and to dilute the ratio of lure text to surrounding prose.
Every message carries a single call to action, routed through the tracking rail (mail.foodycreek[.]com) with a long, randomized URL path. The redirect layer means the operator can swap the destination without touching the email content, and it hides the eventual landing page from anyone reading only the message. The click resolves to a self-hosted CTA subdomain on one of the operator's own rail domains, where a form asks for the details that make the lead: name, income, employment, contact information, and, depending on the pretext, bank or tax specifics. From there the profile is monetized as a sold lead.
Brand rotation is continuous. A recipient who sees "MySunriseLoans" one week may see "Lendfly" or "HarrisonFinancial" the next, all from the same hub. The rotation keeps any single brand from accumulating a reputation history worth blocking.
Sample Lures
All samples are attacker-side content, defanged. Per-send numeric suffixes are shown as <10-digit id>. No recipient data is present.
Loan lure, throwaway hub sender:
From: "MYSUNRISELOANS" <mysunriseloans<10-digit id>@diamondskyinc[.]com>
Subject: Feel Empowered to Seek Financial Support
Return-Path: <...@us-west-2.amazonses[.]com>
[Klaviyo HTML loan template; scraped finance-news paragraph appended as filler]
CTA: http[:]//mail.foodycreek[.]com/<random-path>
Tax-relief impersonation, timed to filing season:
From: "OptimaTax" <optimatax<10-digit id>@diamondskyinc[.]com>
Subject: Owe Back Taxes to the IRS That You Can't Pay?
Return-Path: <...@us-west-2.amazonses[.]com>
[impersonates Optima Tax Relief; IRS "fresh start" pretext]
The display-name-carries-the-brand trick, generic local part:
From: "HarrisonFinancial" <contact<10-digit id>@diamondskyinc[.]com>
Subject: APPROVED IN MINUTES. FUNDED FAST.
Return-Path: <...@us-west-2.amazonses[.]com>
[address prefix is generic "contact"; the brand lives only in the display name]
Persistent operator identity on a self-hosted rail domain:
From: "Finopulse" <superloans@lendfinity[.]net>
Subject: A Wealth of Common Sense
List-Unsubscribe body token: SD:<6-char>1919<mixed>
[non-throwaway address; reused across sends; CTA on lendfinity's own subdomains]
Technical Analysis
Registration Cohorts
The registrant-organization footprint splits cleanly into a large purpose-built pool and a small, deliberate aged tail. Roughly nine in ten org-tagged domains were registered in 2022 or later, in a steady monthly cadence rather than one bulk batch. The remainder are older acquisitions used for reputation weight, the 2002 hub being the clearest example.
| Cohort | Years | Approx. domains | Character |
|---|---|---|---|
| Aged-stash | 1999-2010 | 37 | Drop-catch reputation laundering; dictionary and nonsense labels |
| Mid | 2011-2021 | 46 | Secondary aged stash |
| Purpose-built | 2022-2026 | 688 | Bulk churn; roughly 130 in 2024, 230 in 2025, 240 in a partial 2026 |
The registrar mix is concentrated. Name.com carries roughly four in five of the org-tagged domains, Namecheap most of the rest, with eNom, GoDaddy, and Squarespace in a thin tail. The rail domains follow the same split: the lendfinity and purecarenet rails are Namecheap, the foodycreek and forumcolloquynews hubs are Name.com. First-seen-in-traffic timing shows the network ramping hard in December 2025 and January 2026, then holding a continuous burn-and-replace churn through mid-2026.
Domain-Generation Grammar
Domain names are compound English concatenations, two or three tokens joined without separators, seeded heavily with deliberate misspellings and, in the aged and burner pools, pure dictionary or nonsense labels. The tokens cluster into themed families that map onto the operation's verticals. The health and wellness family is now the single largest by domain count, a sign of where the operator has been expanding.
| Token family | Vertical | Approx. size | Example domains (defanged) |
|---|---|---|---|
health* / wellness* / care* / med* |
Supplement-health, wellness | ~90-100 | healthlydays[.]net, wellnessconnectnow[.]com, purecarenet[.]com, mediclinicnews[.]com |
loan* / credit* / fund* / cash* / fino* |
Payday loans, credit, finance-newsletter | ~70-80 | lendfinity[.]net, quickloanleap[.]com, creditadvantagepro[.]com, finonewsdaily[.]net |
home* / realty* / roof* |
Home-remodel, real estate | ~40 | dreamhomebenefits[.]com, homedesignroofing[.]com, reailtysearch[.]net (typo) |
news* / film* / gossip* |
Content-farm news and entertainment fronts | ~40 | forumcolloquynews[.]com, filmbiee[.]com, gosschipstalks[.]com |
travel* / world* / explore* |
Travel | ~25-30 | worldtraveltales[.]net, aerotraveler[.]com, worldtavelguides[.]com (typo) |
shop* / store* / cart* / bag* |
Shopping, fake-store | ~20-25 | netbasketshopping[.]com, bagworldshop[.]com, shopingsites[.]com (typo) |
auto* / car* / drive* |
Auto, auto-warranty | ~20 | autoloanpulse[.]com, autonovadrive[.]com, motorsphere[.]org |
senior* / elder* / caring* |
Senior-savings, gold-IRA | ~12 | seniorsavingshelp[.]com, caringseniorssave[.]com |
A registration-time signature runs through the whole set: the operator registers the same label across multiple TLDs and mints near-identical misspelled siblings. Concrete clusters include a recipecreeks set spanning .net and .org alongside recipescreeks[.]com; seven gosschip* variants across .com and .net; a paprclips group of four across three TLDs; a fino* cluster (finopuls, finopulses[.]net, finonewsdaily[.]net); and a healthlyday* group built on the misspelling "healthly" (healthlydays[.]net, healthlydayszone, healthlydayshub). Same-label-across-TLDs and typo-sibling density are both cheap to check at registration time and hard for the operator to avoid.
Subdomain Grammar and the Self-Hosted Redirect Rail
Click-through does not run on third-party shorteners. The operator hosts its own redirect rail on rail domains it controls, which keeps the entire landing chain and the unsubscribe relays in-house. Four subdomain conventions coexist across the rail:
| Convention | Shape | Example hosts (defanged) |
|---|---|---|
| Numeric | short digit label | 5415.lendfinity[.]net, 888.purecarenet[.]com |
| Random 8-char | random alnum label | bos8mx6xfg.credibleland[.]net |
| Vertical-named | loan-vertical label | flexloans.gamehealthreport[.]org, mobileloans.gamehealthreport[.]org |
| Functional | tracking/utility label | mail.foodycreek[.]com, readmore.purecarenet[.]com, preview1865.lendfinity[.]net |
The CTA URLs themselves are long, delimiter-heavy strings on those subdomains, of a shape like http[:]//5415.lendfinity[.]net/<token>=!~<digits>.
Sender Taxonomy
The sending model has two distinct layers. The front layer is disposable: [brand][suffix]@diamondskyinc[.]com, where the suffix is usually a 10-digit number but sometimes a short random alpha string (personalloanespik@, mysunriseloansgnivg@, quickcashsolutionsk0tle@). Because each address sends roughly once, sender-history reputation has nothing to accumulate against. A large share of the front layer uses the generic contact prefix and carries the brand only in the display name, so parsing the local part alone misses the impersonation entirely. Display names are ALL-CAPS or CamelCase brand strings, occasionally carrying a template artifact where a stray character trails the brand before the domain.
The back layer is persistent. A handful of addresses on the rail domains do not rotate: superloans@lendfinity[.]net and moneyview@lendfinity[.]net on the finance rail, and a first-name persona veronica@mediclinicnews[.]com on the health rail. These are the operation's stable identities, and they are the higher-value indicators because they persist across the throwaway churn.
Provisioning and Authentication Fingerprints
The fleet is provisioned to a template, and the template is the fingerprint. Several signals recur across otherwise-unrelated-looking domains:
- Uniform Google site-verification TXT. Several hundred org-tagged domains carry a Google site-verification token, a uniform Search Console or Workspace provisioning step applied across the fleet.
- Mailjet-dominant published SPF with cross-referencing includes. Published SPF records lean on Mailjet, with smtp.com and Mailgun secondary, even though observed live send is through Amazon SES. More useful for clustering, the SPF
include:chains cross-reference sibling operator domains, so one domain's authentication record names others in the network. - DMARC
p=rejectwith a recurring copy-paste typo. The core cluster publishes a reject policy pointingruaat a self-hosted unsubscribe mailbox, and ap=rjectmisspelling recurs across the fleet as a copy-paste artifact. - Klaviyo MJML templates built on a shared custom-font asset set, which gives the messages their consistent professional look.
- The
SD:...1919...List-Unsubscribe token. The List-Unsubscribe body carries a token whose middle segment is a shared constant,1919, across the network, with a5757variant marking a sub-cluster. Treat1919as the dominant, not the only, constant.
Cross-Cluster Pivots
The diamondskyinc / foodycreek core and the gamehealthreport / forumcolloquynews snowshoe cluster present as separate operations. They are not. The strongest link is content, not infrastructure: the loan brands that appear as hub sender display names (FlexLoans, MobileLoans, HarrisonFinancial) reappear as vertical-named CTA subdomains on the snowshoe hub (flexloans.gamehealthreport[.]org, mobileloans.gamehealthreport[.]org, harrisonfinancial.gamehealthreport[.]org). One cluster mints the senders; the other hosts their landers, using the same brand set. On top of that sit the shared registrant-organization value, the shared SD:...1919... token, matching registrars and registration windows, and the common SES-plus-Google-verification provisioning.
Escalation and Change Over Time
Three shifts stand out. The redirect layer moved from generic tracking onto the operator's own self-hosted numeric and random subdomains, trading convenience for control. Aged drop-catch domains were adopted alongside the purpose-built churn, run in parallel to launder sending reputation. And the vertical mix broadened: the operation reads as loan and tax heavy in its sender evidence but has expanded its domain footprint most into health and wellness, now the largest token family, which points to where the next wave of lures is being staged.
Detection Observations
These are observations about the operator's traffic, framed for defenders deciding what to key on. The single-use sender addresses on an aged, high-reputation apex are built to defeat address-history signals, so the durable indicator is not the address but the apex plus the registrant-organization and authentication fingerprints behind it. Where the brand lives only in the From display name, header parsing that reads the local part alone will miss the impersonation, so display-name-to-address-domain coherence is the useful check. Bodies padded with scraped news or recipe filler beneath runs of invisible soft-hyphen characters produce a subject-to-body mismatch that a legitimate lender's mail does not have. On the infrastructure side, the self-hosted numeric and random CTA subdomains, the SD:...1919... unsubscribe token, the Mailjet SPF include: chains that name sibling domains, and the same-label-across-TLDs and typo-sibling registration clusters are all cross-message pivots that survive the per-address churn. No single message is the strong signal here; the operation is visible at the network level, in the shared registration and authentication grammar rather than in any one lure.
Indicators of Compromise
All indicators are defanged. Victim data has been removed. The domain list is a representative subset of a much larger footprint.
Senders
| Value | Role | Notes |
|---|---|---|
lendfly<10-digit>@diamondskyinc[.]com |
Sender | Throwaway loan-brand address on the hub |
mysunriseloans<10-digit>@diamondskyinc[.]com |
Sender | Throwaway loan-brand address |
aidnavigator<10-digit>@diamondskyinc[.]com |
Sender | Throwaway aid/funding-brand address |
contact<10-digit>@diamondskyinc[.]com |
Sender | Generic prefix; brand carried in display name |
mailto@diamondskyinc[.]com |
Sender | Hub utility/probe address |
quickloans@diamondskyinc[.]com |
Sender | Persistent loan prefix |
taxsolutions@diamondskyinc[.]com |
Sender | Persistent tax prefix |
parties@diamondskyinc[.]com |
Sender | Persistent prefix |
superloans@lendfinity[.]net |
Sender | Persistent operator identity (Finopulse display name) |
moneyview@lendfinity[.]net |
Sender | Persistent operator identity |
unsubscribe@lendfinity[.]net |
Relay | List-Unsubscribe address |
veronica@mediclinicnews[.]com |
Sender | Persistent health-rail persona |
veronica@bounce.mediclinicnews[.]com |
Relay | Bounce return-path persona |
unsubscribe@jennertrendzz[.]net |
Relay | Unsubscribe relay domain |
Domains
| Value | Role | Notes |
|---|---|---|
diamondskyinc[.]com |
Hub / sender | Aged 2002 drop-catch; primary hub |
lendfinity[.]net |
Sender / CTA | Persistent brands; self-hosted CTA subdomains |
foodycreek[.]com |
Tracking | mail. redirect rail |
purecarenet[.]com |
CTA | Numeric/functional landing subdomains |
credibleland[.]net |
Sender / CTA | Random 8-char CTA subdomains |
treatmenties[.]com |
Sender | Predecessor sending domain |
mediclinicnews[.]com |
Sender | Health-rail; second registrant identity |
netbasketshopping[.]com |
Sender | Shopping-vertical subdomain sender |
jennertrendzz[.]net |
Relay | Unsubscribe relay |
gamehealthreport[.]org |
Sender | Snowshoe; vertical-named subdomains |
forumcolloquynews[.]com |
CTA | Snowshoe landing/redirect hub |
edu-co-in[.]com |
Sender | Brand-prefix rotation domain |
epithecal[.]com |
Sender | Recent operator domain |
lendprecision[.]org |
Sender | Recent operator domain |
smartfinanceschool[.]com |
Sender | Recent operator domain |
financebenefitzone[.]com |
Sender | Recent operator sender |
| ... | Representative subset; several hundred verified-malicious domains catalogued |
Hosts
| Value | Role | Notes |
|---|---|---|
mail.foodycreek[.]com |
Tracking / redirect | In-body CTA redirect host |
5415.lendfinity[.]net |
CTA | Numeric self-hosted landing subdomain |
888.purecarenet[.]com |
CTA | Numeric landing subdomain |
bos8mx6xfg.credibleland[.]net |
CTA | Random 8-char landing subdomain |
MITRE Fight Fraud Framework Mapping
Mapped to the MITRE Center for Threat-Informed Defense Fight Fraud Framework (the MITRE Fight Fraud Framework (F3), https://ctid.mitre.org/fraud). Techniques are named from the fraud-matrix vocabulary; consult the live matrix for current identifiers.
| Tactic | Observed behavior | Observed behavior |
|---|---|---|
| Resource Development | Acquire Infrastructure (domains) | 770+ registrant-org-linked domains, aged drop-catch plus purpose-built churn |
| Resource Development | Establish Sending Accounts | 485+ single-use hub addresses; persistent rail identities |
| Initial Access | Phishing Message | Bulk email lures across loan, tax, debt, and rewards pretexts |
| Initial Access | Brand Impersonation | Generic lead-gen brands plus impersonation of real financial brands |
| Execution | Solicitation of Personal / Financial Data | CTA forms collecting income, employment, contact, and financial details |
| Monetization | Harvest Lead Data | Completed application profiles captured on self-hosted landers |
| Monetization | Sale of Fraudulent Leads | Profiles resold into predatory-lending and affiliate markets |
| Stealth | Rotate Infrastructure | Per-send sender churn, brand rotation, monthly domain burn-and-replace |
Conclusion
The scale here is not in any one message; it is in the registration and authentication grammar that repeats across hundreds of domains. An operator who burns senders and brands as fast as this one still has to register, provision, and authenticate the infrastructure underneath, and those steps leave a template: shared registrant strings, cross-referencing SPF includes, a repeated unsubscribe token, a copy-paste DMARC typo. Defenders watching this actor should expect the front end to keep changing and should anchor instead on the spine. The health and wellness token family is now the largest, which is the clearest signal of where the next batch of lures will come from.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.