One Lure, Many Rails: Inside a Lead-Gen Domain-Rotation Operator
One Lure, Many Rails: Inside a Lead-Gen Domain-Rotation Operator
Since early 2024, one operator has run the same verify-your-email lure across a rotating fleet of throwaway domains and at least six sending rails. Each domain wears a different invented lender or fintech brand, none of them real, and every message funnels the recipient through an identical click-through built from the operator's own attribution taxonomy. The mail authenticates cleanly, carries no spoofed brand, and drips out in low per-domain volume, so it slips past the signals defenders usually lean on. What ties the whole thing together is not any single message but the machinery behind it: a uniform subdomain grammar, a shared DNS fingerprint spanning nineteen months of registrations, and a click URL that carries the victim's own address as a tracking token.
Key Takeaways
- A single lead-generation operator rotates at least eleven throwaway domains (plus continuation registrations), each fronting a different invented finance brand, all delivering one verify-your-email pretext.
- The operator owns every sending domain and routes through legitimate email service providers, so SPF, DKIM, and DMARC all pass. Authentication success is not a legitimacy signal here.
- Delivery fans across six or more sending rails, chosen per domain, so no single provider takedown stops the operation.
- The click-through URL embeds the recipient's own email address as a
utm_termvalue, doubling as lead attribution and silent live-address validation. - The strongest cross-domain ties are structural, not content-based: a uniform
hi.<domain>CTA topology, a shared self-hosted SPF sending panel across seven domains, and a common DMARC report mailbox across six.
Background
Deceptive lead generation is an established fraud economy. Operators stand up fleets of sites and email flows that solicit consumer PII (name, contact details, income, bank, sometimes Social Security data) under loan, credit-repair, or debt-relief pretexts, then sell or ping-tree those records into affiliate and marketer networks regardless of who buys them. The Federal Trade Commission's 2022 action against ITMedia Solutions is the reference case: the agency alleged that a network of loan-application sites promised data would reach only trusted lenders, while roughly 84% of applications collected since 2016 were instead disseminated to marketers, debt-relief sellers, and resellers, priced by credit score. It settled for a $1.5 million penalty.
The verify-your-email framing is the funnel's front door. A message that looks like a routine account-confirmation step does two things at once: it earns the click, and it frames the PII form that follows as a benign final step rather than a fresh application. Consumer-protection guidance from the FTC, the FBI, and major mailbox providers has long flagged "confirm your account" and "verify your email" wording as a staple urgency pattern.
The delivery side leans on trusted infrastructure. Public research from Kaspersky's Securelist, Wiz, and Datadog documents scam operators routing through Amazon SES and Brevo precisely because owned-domain mail sent through a real provider authenticates cleanly and inherits that provider's sending reputation. A few service definitions worth stating plainly before the technical walk-through:
- Amazon SES (Simple Email Service) is AWS's pay-as-you-go bulk-email API. New accounts start sandboxed and are raised to production sending after a light review, at which point an operator gets warm, trusted AWS sending IPs and full authentication alignment on any domain it owns.
- Brevo (formerly Sendinblue) is a mainstream email service provider. Its sending subdomains take the shape
<digits>.brevosend[.]com, where the numeric label is a Brevo sending-subaccount identifier, a stable operator fingerprint that survives domain rotation. Its click-tracking and redirect hosts (sendibt3[.]com,tsp1-brevo[.]net) rewrite every CTA link, andsender-sib[.]comcarries the bounce path. - Namecheap with "Withheld for Privacy ehf" (an Iceland-based WHOIS privacy proxy) is a cheap, fast registrar-and-privacy pairing that shields the real registrant, which makes it a default choice for burn-after-use domains.
- The
.site,.us, and.emailTLDs are cheap, often promo-priced registrations. Deliverability research repeatedly flags them as spam-heavy, which fits a buy-once-and-discard model.
Discovery and Infrastructure
The cluster does not surface from any one sender or subject. Individual messages look like mildly generic transactional mail, and the operator burns each domain slowly to keep provider reputations clean. The anchor is the click-through URL, which holds its shape across every brand:
http[:]//hi.<domain>/c/?utm_term=<recipient email>&utm_campaign=<tag>
http[:]//hi.<domain>/p/?utm_term=<recipient email>&utm_campaign=<tag>
Pivoting on that hi.<domain>/[c|p]/?utm_term= signature, rather than on any sender address, maps the fleet. The domains resolve to a small, repeating grammar of subdomains and a shared set of mailbox names, and their published DNS records expose the sending rails and a common reporting fingerprint. The observed footprint:
| Indicator | Role | Notes |
|---|---|---|
admoons[.]org |
Landing and send (hi.) |
Cloudflare registration, 2025-01-06, brand string "Lending Solution", Amazon SES rail |
earndipity[.]com |
Landing and send (hi., ta.) |
Namecheap, 2024-02-08, Amazon SES rail |
capitalsyield[.]com |
Landing and send (hi., hello.) |
Namecheap, 2024-02-24, brand string "ClearNest", self-hosted panel rail |
sarizh[.]site |
Landing and send (hi., hiv.) |
Namecheap, 2024-12-17, brand string "FundLift", Amazon SES rail |
makebeautys[.]us |
Landing and send (hi., jit.) |
Namecheap, 2025-01-15, multi-rail |
rynnox[.]com |
Landing and send (hi., send.) |
Namecheap, 2025-08-19, Google Workspace rail |
tymis[.]email |
Landing and send (hi., up.) |
.email registry hides WHOIS, brand string "Nymis Department" |
sweetsso[.]net |
Landing and send (hi., ma., s.) |
Namecheap, 2024-10-11, brand string "Sweetcash", Brevo rail |
sewingmo[.]com |
Landing and send (hi., s.) |
Namecheap, 2024-10-10, brand string "Sewnvest", Brevo rail |
touristti[.]com |
Landing and send (hi., s.) |
Namecheap, 2025-02-13, Brevo rail |
ruchyar[.]com |
Landing and send (hi., s.) |
Namecheap, 2024-01-14, brand string "Ruchyar Group", Brevo rail |
Continuation registrations carrying the same fingerprints have kept appearing (vynixy[.]com, maktino[.]com, boruske[.]email), which shows the rotation is ongoing rather than a closed set.
How It Works
Each message presents itself as the last step of something the recipient supposedly started. The subject usually embeds the recipient's real name, which makes it read as transactional and defeats simple subject-pattern matching. The body thanks the reader for a request, asks them to verify their email to keep moving, and drops a single call-to-action button that resolves to hi.<domain>/[c|p]/?utm_term=<their own address>. Once the address is confirmed live and click-responsive, the record is worth more to a downstream buyer whether or not a form is ever submitted.
The invented brands rotate freely (Lending Solution on admoons[.]org, ClearNest on capitalsyield[.]com, FundLift on sarizh[.]site, Sewnvest, Ruchyar Group, Treasure, Sweetcash, Lattice on makebeautys[.]us, Nymis Department on tymis[.]email, FinoPulse on rynnox[.]com, and more), but the template underneath does not change. Footers cite plausible-looking California business addresses to complete the impression of a real lender. Across the fleet we observed hundreds of these messages, sent in deliberately low per-domain volume to stay under provider abuse thresholds.
Sample Lures
Three representative emails, one per major rail. Every recipient identifier has been redacted and every operator domain defanged. Only attacker-controlled content remains.
Email, Amazon SES rail, "Lending Solution" brand:
From: "Lending Solution" <hi@admoons[.]org>
Subject: One Last Step - Verify Your Email [recipient name]
Return-Path: <bounce@amazonses[.]com>
Quick Email Verification Needed
Hi [recipient name],
Your request is almost complete. Click below to verify your email address.
Verify Email -> http[:]//hi.admoons[.]org/c/?utm_term=[recipient email]&utm_campaign=admoons_aws
Once completed, the next step will continue automatically.
Email, Brevo rail, "Sewnvest" brand:
From: "Karen Bernard" <karen@8885433[.]brevosend[.]com>
Reply-To: "Karen Bernard" <karen@sewingmo[.]com>
Subject: Just one more step - verify your email
Return-Path: <bounces@gz.d.sender-sib[.]com>
We've received your request and started reviewing it. To make sure we can
stay in touch safely, please verify your email address by clicking below.
Verify -> http[:]//hi.sewingmo[.]com/p/?utm_term=[recipient email]&utm_campaign=brevosewingmo
The Sewnvest Team, [redacted business address], Los Angeles, CA
Email, Brevo rail, "Sweetcash" brand:
From: "Sweetcash group" <daniel@8884738[.]brevosend[.]com>
Reply-To: <daniel@sweetsso[.]net>
Subject: Please Verify Your Email [recipient name]
Thank you for reaching out! Before we move forward, please take a moment to
confirm your email address. This helps protect your information and ensures
you'll receive important updates from us.
Confirm -> http[:]//hi.sweetsso[.]net/c/?utm_term=[recipient email]&utm_campaign=sweetssobrevo
Daniel Garcia, Sweetcash group
Technical Analysis
The operation's value to a defender is in its structure. Any one throwaway domain is disposable, but the way the operator builds and configures each domain is consistent enough to fingerprint the whole fleet, including domains that have not been used yet.
Registration Cohorts and Aged Staging
The domains fall into two clear age tiers across a nineteen-month window. An aged tier registered through 2024 (ruchyar[.]com in January, earndipity[.]com and capitalsyield[.]com in February, then maktino[.]com, sewingmo[.]com, sweetsso[.]net, and sarizh[.]site through the second half of the year) sits alongside a 2025 tier (admoons[.]org, makebeautys[.]us, touristti[.]com, and the rhyming pair rynnox[.]com and vynixy[.]com registered one day apart in August). Eleven of the twelve WHOIS-exposed domains sit at Namecheap, several behind "Withheld for Privacy ehf"; admoons[.]org is the lone Cloudflare registration. Every domain publishes a p=none DMARC policy, a report-only posture consistent with an operator that wants monitoring visibility without enforcement getting in the way of its own sends.
| Domain | Registrar | Created | Invented brand / utm tag | Primary rail |
|---|---|---|---|---|
ruchyar[.]com |
Namecheap (privacy) | 2024-01-14 | Ruchyar Group / ruchyar_Brevo |
Brevo |
earndipity[.]com |
Namecheap | 2024-02-08 | / awsearndipity |
Amazon SES |
capitalsyield[.]com |
Namecheap | 2024-02-24 | ClearNest / capityieldwebmail |
Self-hosted panel |
maktino[.]com |
Namecheap | 2024-08-26 | (continuation) | Self-hosted panel |
sewingmo[.]com |
Namecheap (privacy) | 2024-10-10 | Sewnvest / brevosewingmo |
Brevo |
sweetsso[.]net |
Namecheap (privacy) | 2024-10-11 | Sweetcash / sweetssobrevo |
Brevo |
sarizh[.]site |
Namecheap (privacy) | 2024-12-17 | FundLift / sarizhmailamazon |
Amazon SES |
admoons[.]org |
Cloudflare | 2025-01-06 | Lending Solution / admoons_aws |
Amazon SES |
makebeautys[.]us |
Namecheap | 2025-01-15 | Lattice / jit |
Multi-rail |
touristti[.]com |
Namecheap | 2025-02-13 | Treasure / touristtibrv |
Brevo |
rynnox[.]com |
Namecheap | 2025-08-19 | FinoPulse / (send.rynnox) |
Google Workspace |
vynixy[.]com |
Namecheap (privacy) | 2025-08-20 | (continuation) | Google Workspace |
Multi-Rail Sending Fan-Out
The two rails visible in message headers, Amazon SES and Brevo, undersell the setup. The domains' published SPF and DMARC records show delivery fanning across six or more sending lanes, chosen per domain: Amazon SES, Brevo, MailerLite (_spf.mlsend[.]com), SendPulse (mxsspf.sendpulse[.]com), Google Workspace (_spf.google[.]com), and self-hosted mail panels reachable through shared SPF includes. Brevo activity is confirmed by numeric <digits>.brevosend[.]com sending subdomains and by DMARC reports routed to Brevo's aggregate mailbox on three of the domains. This breadth is the resilience play: taking one provider offline reroutes rather than stops the campaign.
Subdomain Grammar and CTA Families
Every domain publishes the same host topology. hi.<root> is the primary CTA and send host and is live on all of them. Additional send hosts appear as hello., jit., hiv., up., and send., while unsubscribe and list-management hosts take s., d., ta., and ma.. The CTA itself comes in two path families off that hi. host: a /c/ majority and a /p/ minority. When multiple otherwise-unrelated domains share this exact subdomain vocabulary, the shared build is the tell.
Attribution Taxonomy and Victim-List Reuse
The utm_campaign value leaks the operator's own internal channel labels. Tags name both the destination brand and the rail: admoons_aws, awsearndipity, and sarizhmailamazon mark the SES lane; ruchyar_Brevo, sweetssobrevo, and brevosewingmo mark the Brevo lane; capityieldwebmail marks a self-hosted webmail lane. The utm_term value is the recipient's own email address, which means the operator recycles its target list as the tracking token across every brand and rail. That same list reuse shows up in recycled mailbox local-parts (hi@, karen@, daniel@, noha@, teno@, hoora@) reappearing on unrelated brand domains.
Cross-Cluster DNS Fingerprints
The load-bearing tie between domains registered nineteen months apart is in their DNS configuration. A shared self-hosted SPF sending-panel include recurs across seven of the domains, and a single DMARC aggregate-report mailbox spans six. These configuration fingerprints, which an operator sets once and reuses out of convenience, bridge the aged 2024 tier and the 2025 tier to one hand far more reliably than any content feature. The internal Brevo account numbers recovered from the base64-encoded unsubscribe payloads (1671, 2084, 2089, 2100, 2365, and 6194), distinct from the longer sending-subaccount identifiers seen in the brevosend[.]com hosts, give a second durable fingerprint that survives domain rotation entirely.
Detection Observations
The behavioral signal here lives at the ecosystem level, not in any single message. A lone verify-your-email note from a freshly registered domain that passes authentication looks like ordinary transactional mail, which is exactly the point. The patterns that separate this traffic from legitimate mail are structural:
- The
hi.<domain>/[c|p]/?utm_term=<email>&utm_campaign=<tag>CTA shape is a strong cross-domain anchor because it holds constant while the sending domain and brand rotate. - A recipient's own email address appearing as a
utm_termvalue in an outbound CTA is unusual for genuine transactional mail and points to lead attribution rather than account confirmation. - Shared SPF-include and DMARC-report fingerprints across otherwise-unrelated domains cluster the fleet independently of message content.
- The same handful of mailbox local-parts and the same subdomain grammar appearing on domains with no other apparent relationship is a single-operator indicator.
- Recycled recipient-name tokens recurring across unrelated brand domains is a near-zero-noise tie when combined with throwaway-domain infrastructure.
Authentication passing on every message is worth restating as a non-signal: it confirms only that the mail genuinely came from the sending domain, not that the domain or the sender is trustworthy.
MITRE Fight Fraud Framework Mapping
MITRE's Center for Threat-Informed Defense released the Fight Fraud Framework (F3) in April 2026. It reuses ATT&CK Txxxx technique IDs directly alongside native fraud techniques. F3 is transaction-fraud-centric, so the cleanest matches for an email PII-harvest lead-gen operation fall in the resource-development and reconnaissance rows, anchored to the reused ATT&CK techniques below. The verify-email call-to-action and the downstream PII resale have no dedicated technique and are described narratively rather than forced onto an ID.
| Tactic | Technique | ID |
|---|---|---|
| Resource Development | Acquire Infrastructure (throwaway domains, ESP subaccounts) | T1583 |
| Resource Development | Establish Accounts (ESP and provider sending accounts) | T1585 |
| Resource Development | Stage Capabilities (landing pages, click-tracker redirects) | T1608 |
| Reconnaissance | Phishing for Information (the verify-your-email solicitation) | T1598 |
Indicators of Compromise
All indicators below are defanged and drawn from the verified subset of the campaign's indicator set. Recipient data has been removed.
Senders
| Value | Role | Notes |
|---|---|---|
hi@admoons[.]org |
Sender | "Lending Solution", Amazon SES |
hi@earndipity[.]com |
Sender | Amazon SES |
teno@hello.capitalsyield[.]com |
Sender | "ClearNest" |
hoora@hiv.sarizh[.]site |
Sender | "FundLift", Amazon SES |
reply@jit.makebeautys[.]us |
Sender | Multi-rail |
hi@up.tymis[.]email |
Sender | "Nymis Department" |
hi@rynnox[.]com |
Sender | Google Workspace rail |
karen@8916680[.]brevosend[.]com |
Sender | Brevo subaccount |
karen@8885433[.]brevosend[.]com |
Sender | Brevo subaccount, "Sewnvest" |
noha@8017808[.]brevosend[.]com |
Sender | Brevo subaccount |
daniel@8884738[.]brevosend[.]com |
Sender | Brevo subaccount, "Sweetcash" |
karen@touristti[.]com |
Sender | Reply-to pivot, "Treasure" |
karen@sewingmo[.]com |
Sender | Reply-to pivot, "Sewnvest" |
noha@ruchyar[.]com |
Sender | Reply-to pivot, "Ruchyar Group" |
daniel@sweetsso[.]net |
Sender | Reply-to pivot, "Sweetcash" |
Domains
| Value | Role | Notes |
|---|---|---|
admoons[.]org |
Landing and send | Cloudflare, 2025-01-06 |
earndipity[.]com |
Landing and send | Namecheap, 2024-02-08 |
capitalsyield[.]com |
Landing and send | Namecheap, 2024-02-24 |
sarizh[.]site |
Landing and send | Namecheap, 2024-12-17 |
makebeautys[.]us |
Landing and send | Namecheap, 2025-01-15 |
rynnox[.]com |
Landing and send | Namecheap, 2025-08-19 |
tymis[.]email |
Landing and send | .email, WHOIS hidden |
sweetsso[.]net |
Landing and send | Namecheap, 2024-10-11 |
sewingmo[.]com |
Landing and send | Namecheap, 2024-10-10 |
touristti[.]com |
Landing and send | Namecheap, 2025-02-13 |
ruchyar[.]com |
Landing and send | Namecheap, 2024-01-14 |
Hosts
| Value | Role | Notes |
|---|---|---|
hi.admoons[.]org |
CTA | Primary click host |
hi.earndipity[.]com |
CTA | Primary click host |
hi.capitalsyield[.]com |
CTA | Primary click host |
hi.sarizh[.]site |
CTA | Primary click host |
hi.makebeautys[.]us |
CTA | Primary click host |
hi.rynnox[.]com |
CTA | Primary click host |
hi.tymis[.]email |
CTA | Primary click host |
hi.sweetsso[.]net |
CTA | Primary click host |
hi.sewingmo[.]com |
CTA | Primary click host |
hi.touristti[.]com |
CTA | Primary click host |
hi.ruchyar[.]com |
CTA | Primary click host |
send.rynnox[.]com |
Send | Sending subdomain |
CTA URL Patterns
| Value | Role | Notes |
|---|---|---|
http[:]//hi.admoons[.]org/c/?utm_term=<email>&utm_campaign=admoons_aws |
CTA | SES lane |
http[:]//hi.sarizh[.]site/c/?utm_term=<email>&utm_campaign=sarizhmailamazon |
CTA | SES lane |
http[:]//hi.rynnox[.]com/p/?utm_term=<email>&utm_campaign=FinoPulseresend |
CTA | Google Workspace rail |
http[:]//hi.sweetsso[.]net/c/?utm_term=<email>&utm_campaign=sweetssobrevo |
CTA | Brevo lane |
http[:]//hi.sewingmo[.]com/p/?utm_term=<email>&utm_campaign=brevosewingmo |
CTA | Brevo lane |
http[:]//hi.ruchyar[.]com/c/?utm_term=<email>&utm_campaign=ruchyar_Brevo |
CTA | Brevo lane |
Conclusion
This operator has kept one lure and one funnel alive for well over a year by treating everything else as consumable. Domains, brand names, and sending providers rotate on a schedule while the subdomain grammar, the CTA structure, and the DNS configuration stay fixed. That is the weakness worth pressing on: the disposable layer is cheap to replace, but the build conventions are not, and they fingerprint domains the operator has staged but not yet fired. Watching for the hi.<domain>/[c|p]/?utm_term= shape and the shared DNS fingerprints will surface the next rotation before the first message lands.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.