Borrowed Reputation: An Affiliate-Spam Toolkit Built on Hijacked Domains
Borrowed Reputation: An Affiliate-Spam Toolkit Built on Hijacked Domains
Since March 2026, one operator has run affiliate lead-gen spam from thousands of hijacked small-business domains, hidden behind underscore-padded senders. The operation sends insurance, auto-warranty, and debt-relief offers by the hundreds of thousands, and almost none of its visible infrastructure belongs to the operator. The sending domains are a yoga studio, a med spa, a food photographer, a bridal shop, a German church site: aged, legitimate businesses whose mail was quietly taken over. The click destinations are throwaway PHP scripts dropped onto more of the same hijacked sites. The actual affiliate offer pages sit one redirect further on and never surface in the mail. What ties the whole thing to one hand is not a domain or an address, because those are disposable by design. It is the toolkit: a unique-per-message address generator that pads local-parts with dozens of underscores, a uniform way of seizing DNS on a compromised domain, and a redirect kit deployed with the same naming convention across the entire fleet.
Key Takeaways
- The operator's observable footprint is almost entirely other people's property: more than 4,500 compromised, independently-registered small-business domains used as authenticated senders, plus a set of aged drop-catch domains repurposed as redirect hosts.
- Every hijacked sending domain carries a uniform DNS edit: one attacker-chosen sending IP injected into an otherwise-normal SPF record alongside
include:_spf.google.com, withDMARC ... p=reject. Mail from these domains passes SPF and DMARC alignment and inherits years of accumulated domain reputation. - Sender addresses are single-use and padded with long runs of underscores (roughly 4,400 distinct local-parts across eleven generation templates), which defeats per-sender reputation because no two messages share a scorable sending string.
- Clicks route through short, randomized PHP redirectors named
/r[hex4].phpdropped onto compromised sites, an indirection layer that lets the operator swap the downstream offer without touching the mail. - Domains burn fast: most sending domains appear for a single day and are abandoned, so domain-level blocklists never keep pace. The durable pivots are the redirect kit and the DNS-seizure fingerprint, not the domain of the day.
Background
Email authentication answers one question: is this mail authorized by the domain it claims to come from. It does not answer whether the domain owner is honest. That gap is the whole basis of this operation. An attacker who gains control of a legitimate, aged domain's DNS can publish SPF, DKIM, and DMARC records that make its mail fully authenticated, and that mail then inherits the reputation the real business built over years. Spamhaus tracks a dedicated "abused-legit" class of hijacked-but-legitimate hosts precisely because authenticated mail from a previously-clean domain slips past the reputation gates that would instantly reject a day-old look-alike. The defensive value of SPF and DMARC is real, but a passing result is a statement about authorization, not intent.
The monetization sits in the affiliate lead-generation economy. Insurance, vehicle-warranty, and debt-relief "offers" are lead funnels: each click or submitted contact record is sold on to affiliate networks and downstream buyers, so the revenue driver is volume and clicks rather than any sale. That economics explains the shape of the spam, high-volume, obfuscated, and built to hide its real destination. The pattern draws steady regulatory action. The FTC has penalized lead generators for indiscriminately reselling loan-applicant data (one settlement noted that the large majority of applications since 2016 were sold to marketers, debt-relief, and credit-repair sellers rather than lenders), and insurance lead generators including Assurance IQ and MediaAlpha drew a combined nine-figure penalty, with MediaAlpha later settling under the FTC Act, the Telemarketing Sales Rule, and the Impersonation Rule. Bolting recognizable insurance and warranty brand names onto the mail manufactures trust at the top of that funnel.
Two mechanics recur throughout. A PHP redirect kit is a small script dropped onto a hijacked website that takes an inbound click and bounces it onward to whatever offer page is live. Short, per-burst filenames are a disposable layer between the reputable-looking hijacked domain in the mail and the real destination, and the same "hijacked reputable host as redirector" trick has surfaced in large public spam campaigns before. Subject-line obfuscation, the second mechanic, substitutes look-alike characters or injects stray punctuation and spacing so a subject stays readable to a human while breaking the exact-string matches that content filters depend on, a SpamAssassin-evasion technique documented in academic work more than a decade ago.
Discovery and Infrastructure
The operation surfaced from a single anomaly in sender addresses: from-headers carrying long, unbroken runs of underscore characters. A pattern sweep on that signature returned far more than the handful of samples that prompted it, and the corpus resolved into one coherent operation running many pretexts at once.
The infrastructure has three layers, and the operator owns none of the first two. The sending layer is more than 4,500 compromised small-business domains. Virtually all of them appear nowhere else in our email data, which marks them as dedicated to this operation rather than a shared spam service, and the great majority are used for exactly one day before the operator rotates to fresh ones. The redirect layer is a smaller set of aged domains loaded with the PHP kit; clicks land here before bouncing onward. The offer layer, the actual affiliate landing pages, sits behind the redirectors and never appears in the mail itself, which is the point of the indirection.
The address layer is where the operator's tooling shows. Individual sender addresses are throwaway, roughly 4,400 distinct local-parts each used a single time. Their value is not as indicators but as a fingerprint of the generator that produced them: eleven distinct templates, all sharing the same signature of five or more consecutive underscores padding the local-part.
How It Works
The contact chain is built for one click. A recipient gets an authenticated email from a domain with a clean history, carrying a display name that reads as a known insurance or warranty brand and a subject engineered to survive content filters. The visible body is often decoy content: a verbatim government press release, a news article, or foreign-language filler, with the real offer delivered inside an embedded image so there is little analyzable scam text. The call to action is an image link or a short URL pointing back at a PHP script on a compromised domain. Clicking it bounces through that redirector to the affiliate offer, which is where the lead is captured. Because the sending domain is authenticated and aged, the mail arrives with borrowed credibility; because the address is unique and the domain is burned within a day, there is little for a per-sender or per-domain reputation system to hold onto after the fact.
Sample Lures
All samples below are attacker-authored email content, defanged, with every recipient identifier replaced by a placeholder. No recipient names, addresses, or per-recipient tracking tokens survive.
Fidelity Life insurance, the highest-volume pretext, using a government press release as decoy body and delivering the offer only inside an image:
From: "FidelityLifeOffer" <fidelitylifeoffer________________________________@2jiisland[.]com>
Subject: 2026: $250k Coverage for $16/Month. eqo
[+ ~600 characters of random alphanumeric padding after the visible subject]
Body: U.S. Department of Defense contract-award press release (verbatim
government filler); the actual offer appears only in an embedded image.
CTA (image link): hxxp://2jiisland[.]com/rd9ab.php?32=1o6069b954d37ec47_30y4[...]
Auto insurance, using punctuation insertion to break subject-line keyword matching:
From: "Auto-Insurance" <__auto.insurance_________@ctharrisonrealty[.]com>
Subject: $228 For 6 Mo Of......Auto...insurance.....check If You Q...
Body: obfuscated rate pitch interleaved with non-English paragraph filler.
CTA: PHP redirector on the sending domain (/r[hex4].php?32=[...])
CarShield vehicle-warranty impersonation, a template reused across many domains:
From: "CarShield Team" <carshieldteamad______________________@savetheunionflag[.]com>
Subject: Congrats! Your FREE Vehicle Service Quote is Available
Body: vehicle service-contract pitch carrying the CarShield brand name.
Multi-language camouflage variant, an auto-insurance offer wrapped in a full Hebrew-language paragraph block to defeat English-centric content analysis:
From: "Auto Insurance" <______________________@amjs123[.]com>
Subject: RE: 2026 Auto ProTec tioNQuotes
Body: coherent Hebrew-language paragraph filler surrounding an English
auto-insurance call to action.
Technical Analysis
No single domain or address in this operation is worth tracking on its own, because the operator throws all of them away. What holds up across the rotation is the tooling, and four fingerprints in particular tie the fleet to one hand.
Authenticated Hijack of Aged Domains
The strongest signal is how the operator seizes each sending domain. Every hijacked domain we examined carries the same DNS edit: a single attacker-chosen sending IP is injected as an ip4: mechanism into an otherwise-ordinary SPF record that also keeps the domain's legitimate include:_spf.google.com, closed with a hard -all, and paired with a strict DMARC ... p=reject. The mail passes SPF and DMARC alignment, so it arrives fully authenticated from a domain with years of clean history.
| Hijacked sending domain | SPF record (defanged) | DMARC |
|---|---|---|
foodphotographytampa[.]com |
v=spf1 ip4:78.159.114[.]56 include:_spf.google.com -all |
p=reject; pct=100 |
italligator[.]com |
v=spf1 ip4:85.209.176[.]203 include:_spf.google.com -all |
p=reject; pct=100 |
johnscbd[.]com |
v=spf1 ip4:192.3.63[.]150 include:_spf.google.com -all |
p=reject; pct=100 |
prepapa-hiroba[.]com |
v=spf1 ip4:107.6.168[.]245 include:_spf.google.com -all |
p=reject; pct=100 |
The injected sending IPs are unrelated to one another, which points at a rotating per-domain sending pool rather than one shared relay. The template of the edit, though, is identical everywhere, and that uniformity is the operator's most durable signature: it survives the domain rotation entirely, because the operator reapplies the same DNS recipe to each newly-seized domain.
Aged, Independently-Registered Domain Cohorts
Public registration data confirms these are hijacked legitimate businesses, not operator-minted domains. Across a sample of the sending fleet and the redirect hosts, every domain is aged, spread across ordinary retail registrars, with no bulk-registration or bulletproof-registrar concentration, and creation dates spanning roughly 2004 to 2018.
| Domain / host | Role | Registrar | Created | Age (2026-07) |
|---|---|---|---|---|
tamegar[.]com |
Compromised sender | eNom | 2004-12-17 | ~22 yr |
josephyoga[.]com |
Compromised sender | GoDaddy | 2006-01-19 | ~20 yr |
abcdirekt24[.]com |
Redirect-kit host | GoDaddy | 2009-02-06 | ~17 yr |
laktmap[.]com |
Redirect-kit host | GoDaddy | 2010-02-02 | ~16 yr |
getnetcash[.]org |
Redirect-kit host | Dynadot | 2013-02-06 | ~13 yr |
2jiisland[.]com |
Redirect-kit host | Porkbun | 2014-10-05 | ~12 yr |
rainforestmedspa[.]com |
Compromised sender | GoDaddy | 2015-01-15 | ~11 yr |
prepapa-hiroba[.]com |
Compromised sender | GoDaddy | 2016-01-15 | ~10 yr |
foodphotographytampa[.]com |
Compromised sender | GoDaddy | 2016-12-31 | ~9 yr |
abridalbargain[.]com |
Compromised sender | Dynadot | 2018-12-28 | ~7 yr |
The median domain in this sample is roughly a decade old. That age is the asset the operator is stealing: a ten-year-old med-spa or food-photography domain carries reputation a freshly-registered domain cannot buy. The redirect hosts follow the same aged profile, consistent with drop-catch re-acquisition or compromise rather than fresh purchase, and their registrant identity is privacy-masked, so nothing in the registration data points back at the operator.
Underscore-Padded Address Generation
The from-address is generated fresh for every message and padded with long runs of underscores. Eleven templates share that signature while differing in prefix, and the prefixes map to the campaign verticals.
| Template shape | Example (local-part) |
|---|---|
no_reply + hash padding |
______no_reply_______####xebykrj1______no_reply____xebykrj1####... |
| Leading-underscore + hash | ____________________9rck77u8t______________________9rck77u8t |
| Brand prefix (Fidelity Life) | fidelitylifeoffer______________________________________________ |
| Brand prefix (CarShield) | carshieldteam______________________-___-__________________________ |
| IP-address prefix | 69.197.154.22______________ |
| Keyword prefix (auto rates) | fast_rates______, __auto.insurance_________ |
Because each address is used exactly once and shares no repeatable string with any other, per-sender reputation has nothing to accumulate against. Later waves add curly-brace characters and IP-address prefixes to the same padding scheme, small mutations of one generator rather than a new tool.
The Redirect Kit
Clicks do not go straight to the offer. They route through a PHP script dropped onto a compromised domain, named with a consistent /r[hex4].php convention (/r1991.php, /ra27b.php?32=, /rf690.php?32=, /rd9ab.php). The four-hex-character filename changes per domain, but the shape is uniform across the fleet, which points at automated deployment of one kit. The redirector is a disposable indirection layer: the mail links to a reputable-looking hijacked host, the operator can swap the downstream affiliate offer without re-sending, and the throwaway filename is abandoned before crawlers catch up. The aged redirect hosts (abcdirekt24[.]com, getnetcash[.]org, laktmap[.]com, 2jiisland[.]com, ecleanenvironment[.]com) are the closest thing to durable operator infrastructure in the whole operation.
Content-Level Evasion
The mail is built to starve content classifiers of signal. The visible body is frequently decoy material, verbatim government press releases, news copy, or Wikipedia text, chosen to raise the ratio of benign to spammy tokens. A maturing variant wraps the offer in coherent, paragraph-scale non-English filler (Hebrew observed most clearly, with Croatian and Armenian also seen) to defeat English-centric analysis. A minority of messages carry the offer entirely inside an embedded image with no analyzable text at all. Subjects layer unicode injection, character substitution, punctuation insertion, and spacing abuse on top, and trail long strings of random alphanumeric or hex padding so each message is byte-distinct.
Detection Observations
The traffic separates from legitimate mail on structure, not on any one keyword, and the useful signals are the ones that outlast the domain rotation. The DNS-seizure template is the strongest: a lone ip4: mechanism grafted onto an otherwise-standard Google-based SPF record, on an aged domain whose historical mail never used that IP, is an anomaly a legitimate sender has no reason to produce. The address grammar is the next: a from-address padded with five or more consecutive underscores is effectively never legitimate, and the extreme padding makes false positives unlikely. At the infrastructure level, the small set of aged PHP-redirect hosts is a cross-message pivot that a rotation of front-end sending domains cannot erase, since every campaign vertical eventually points clicks at the same handful of redirectors. The content tricks, decoy government text, foreign-language filler, image-only bodies, and subject obfuscation, are individually weak but jointly telling, because a legitimate sender has no reason to combine benign filler with a hidden image offer and a homoglyph subject. Keying on the DNS fingerprint and the redirect hosts, rather than the disposable domain or address of the day, is what lets a defender recognize this operator after the next rotation.
Indicators of Compromise
All indicators are defanged. The compromised sending domains below are legitimate small businesses whose mail was hijacked; they are victims of this operation, listed so their owners and defenders can recognize the abuse, not operators of it. The tables are a representative subset of the durable, verified-malicious infrastructure.
Redirect-Kit Hosts
| Value | Role | Notes |
|---|---|---|
abcdirekt24[.]com |
Redirect host | Aged 2009 (GoDaddy); hosts /ra27b.php kit |
getnetcash[.]org |
Redirect host | Aged 2013 (Dynadot privacy); hosts /rf690.php kit |
laktmap[.]com |
Redirect host | Aged 2010 (GoDaddy); hosts the kit |
2jiisland[.]com |
Redirect host | Aged 2014 (Porkbun); hosts /rd9ab.php kit |
ecleanenvironment[.]com |
Redirect host | Aged 2011; hosts /r0064.php kit |
Compromised Sending Domains
| Value | Role | Notes |
|---|---|---|
tamegar[.]com |
Hijacked sender | eNom, 2004; high single-day volume |
josephyoga[.]com |
Hijacked sender | GoDaddy, 2006 |
prepapa-hiroba[.]com |
Hijacked sender | GoDaddy, 2016; multi-day, image-CTA variant |
foodphotographytampa[.]com |
Hijacked sender | GoDaddy, 2016; SPF ip4:78.159.114[.]56 |
italligator[.]com |
Hijacked sender | GoDaddy, 2015; SPF ip4:85.209.176[.]203 |
johnscbd[.]com |
Hijacked sender | GoDaddy, 2016; multi-day; SPF ip4:192.3.63[.]150 |
rainforestmedspa[.]com |
Hijacked sender | GoDaddy, 2015; DMARC p=reject |
abridalbargain[.]com |
Hijacked sender | Dynadot, 2018; high single-day volume |
christliches-im-netz[.]com |
Hijacked sender | GoDaddy, 2008 |
savetheunionflag[.]com |
Hijacked sender | CarShield + curly-brace variant cluster |
amjs123[.]com |
Hijacked sender | Hebrew paragraph-filler variant |
silkcherri[.]com |
Hijacked sender | Underscore-padded sender cluster |
abcdirekt24[.]com |
Hijacked sender | Also runs the redirect kit |
| ... (representative subset; more than 4,500 compromised small-business sending domains observed) |
Sender Addresses
| Value | Role | Notes |
|---|---|---|
carshieldteamad______________________@savetheunionflag[.]com |
Sender | CarShield template |
fastauto-notice_____________________@nfd-school[.]com |
Sender | Auto-rates template |
fast_rates______@hideyourpiercing[.]com |
Sender | Auto-rates template |
__auto.insurance_________@ctharrisonrealty[.]com |
Sender | Auto-insurance template |
yy-yy___________________@silkcherri[.]com |
Sender | Leading-underscore template |
ousssssssssssssssrf6_________________@phbfilms[.]com |
Sender | Keyboard-mash + padding |
69.197.154.22______________@xydfczj[.]com |
Sender | IP-prefix template |
70.35.200.59aa-aa______________________________@orysaudio[.]com |
Sender | IP-prefix template |
| ... (representative subset; roughly 4,400 single-use padded addresses observed) |
MITRE Fight Fraud Framework Mapping
The mapping maps to the MITRE Center for Threat-Informed Defense Fight Fraud Framework (F3), which reuses ATT&CK T#### technique IDs where applicable and adds fraud-specific techniques and a Monetization tactic. The IDs below are best-fit candidates against the published matrix.
| Tactic | Observed behavior | ID |
|---|---|---|
| Resource Development | Compromise Infrastructure: Domains (hijacked aged small-business senders) | T1584.001 |
| Resource Development | Acquire Infrastructure: Domains (drop-catch redirect hosts) | T1583.001 |
| Resource Development | Stage Capabilities (PHP redirect kit on compromised sites) | T1608 |
| Initial Access | Phishing: Spearphishing Link (spam carrying the redirector URL) | T1566.002 |
| Initial Access | Impersonate Official (insurance / warranty brand + government-style body) | F1032 |
| Stealth | Obfuscated Files or Information (unicode subjects, decoy and foreign-language body filler) | T1027 |
| Monetization | Lead-generation resale of clicks and contact data | T1657 |
Conclusion
The front of this operation is disposable on purpose. Sending domains last a day, addresses last a single message, and the brand of the week shifts with whatever draws clicks. What does not change is the method: seizing DNS on an aged, reputable domain with one uniform SPF edit, generating a fresh underscore-padded address per message, and routing clicks through a /r[hex4].php kit dropped onto more compromised sites. Every legitimate business whose domain is caught up in this is a second victim alongside the recipients. Defenders who key on the DNS-seizure fingerprint and the small set of aged redirect hosts, rather than the domain of the day, will still recognize this operator after the next rotation, and probably under the next brand's name.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.