Moving the Payload: Inside a Two-Track Sender-Obfuscation Toolkit
Moving the Payload: Inside a Two-Track Sender-Obfuscation Toolkit
Since December 2025, one operator has impersonated more than a dozen US brands by hiding scam keywords inside the email sender address itself. The technique is old, but the discipline behind it is not. This operator runs two parallel sending tracks off a single backend, rotates through more than 8,000 compromised business mail domains, and burns most of those domains within a single day of use. When header-address matching started to bite, it did not retreat. It moved the obfuscation payload from the address into the display name and kept sending. What follows is an anatomy of the kit: how the sender surface is manipulated, where the click-through infrastructure lives, and the byte-level tooling signatures that tie the two tracks to one author.
Key Takeaways
- One operator runs two parallel obfuscation tracks, one that injects scam keywords into the email address local-part and one that moves the same payload into the display name, unified by a single byte-identical backend.
- The display-name track was built as a counter-signature. After address-matching filters matured, the operator kept a spotless clean-token local-part and shifted every obfuscation character into the display name instead.
- Sending rides more than 8,000 compromised small-business, school, and nonprofit mail domains with valid SPF, DKIM, and DMARC, most of them used for a single day before rotation.
- The two tracks use separate click-through architectures with almost no overlap: coined insurance and lead-gen funnels for the address track, AWS S3 buckets and IPv6-mapped-IPv4 URL literals for the display-name track.
- The coined-funnel pool shows same-day batch registration behind WHOIS privacy, the strongest single-operator signal in the whole domain set.
- Both tracks embed links to real high-reputation sites beside the scam link, a camouflage habit aimed squarely at URL-reputation and AI content scoring.
Background
Email filters have keyed on the visible From for years, so attackers have spent just as long learning to poison it. The two moves in play here are standard vendor knowledge. Forging the display name works because users and many filters read the friendly name rather than the header address. Injecting characters into the address local-part works because naive pattern rules match exact strings, and car//shield is not carshield. What makes this operator worth writing up is not the primitives, it is how methodically the two are combined, iterated, and swapped when one starts to fail.
Three pieces of abused infrastructure carry the campaign, and each deserves a plain-English note before the technical walk-through.
Compromised sending domains are the delivery channel. The operator takes over legitimate but poorly secured mail domains belonging to small businesses, charities, and schools, then sends through them. Because the mail leaves the domain's own authorized servers, it passes SPF, DKIM, and DMARC and inherits the victim's aged, clean sending reputation. The real owner is a victim, not the author of the scam, which is why none of those domains appear in the indicator tables below.
AWS S3 buckets are one of the two landing options. S3 can serve a bucket's contents as a public static website on an amazonaws.com subdomain. The operator uploads a single credential-harvest page to a throwaway bucket and gets free, TLS-valid hosting under a trusted parent domain, with no domain to register and nothing to take down but a random string that will be abandoned within days.
IPv6-mapped-IPv4 URL literals are the other. A link written as http[:]//[::ffff:3f8f:3c05]/... is a raw IP address (here 63.143.60[.]5) encoded in hex inside IPv6 brackets. It resolves to an ordinary server but looks nothing like a dotted-quad address, so extractors and reputation engines that expect 1[.]2[.]3[.]4 patterns often fail to normalize or score it. The operator uses the encoding purely to slip a link past filters.
Discovery and Infrastructure
We first mapped the campaign through the sender surface. A sweep for injected separator characters in the email address surfaced hundreds of unique sending addresses, and clustering those by embedded brand and scam keywords produced 25 distinct sub-campaigns: auto insurance, payment-declined billing threats, Fidelity Life, GlobeLife, CarShield, Endurance warranty, debt relief, T-Mobile, Sam's Club, United Healthcare, clinical-trial recruitment, cloud-storage lockout, and roughly a dozen more. Each cluster impersonates a different brand or pretext, but they share sending domains, body templates, and header grammar, which is what pulls them into one operation rather than 25.
The sending domains themselves are the clearest tell of scale. More than 8,000 distinct domains appear across the window, and more than 14,000 sender addresses ride them once both tracks are counted, since the separator sweep catches only the address track and the display-name track carries no injected characters at all. Roughly nine in ten domains are used for exactly one day before the operator moves on. That burn rate is stable across months, which suggests the supply of freshly compromised mail accounts is not a constraint. A handful of domains carry traffic for several clusters at once, and two carried four clusters each, coordination that does not happen by accident across unrelated senders.
The click-through infrastructure splits cleanly in two. The address track pushes to a pool of coined insurance and lead-gen funnel domains. The display-name track pushes to AWS S3 buckets and raw IPv6-literal IP addresses. The two pools barely intersect: of everything we mapped, only six sending domains bridge the tracks. Separate front ends, one back end.
How It Works
A recipient receives a message that clears authentication and appears to come from a real, if obscure, business domain. The visible sender is where the manipulation lives. On the address track, the local-part carries the pitch: **fidelity__life**@, payment//declined@, #carshield*@. On the display-name track, the address is a bland noreply@ and the pitch sits in the friendly name instead: PAYMENT.DECLINED, Cloud//Storage, **Action Required**.
The subject line reinforces the pretext with deadline pressure, often with a specific calendar date baked in. The body is frequently a mismatch, a marketplace or customer-service template borrowed wholesale as cover, with the real call-to-action tucked inside. Clicking leads either to a lead-gen funnel that harvests personal and financial details under an insurance-quote pretext, or to a static credential-harvest page on an S3 bucket or a direct IP. Sprinkled through the body are links to genuine, well-known sites, there to dilute the message's aggregate reputation and nudge automated scoring toward benign.
Sample Lures
All samples are redacted. Sending and return-path domains, which belong to compromised third parties, are replaced with a placeholder. Recipient identifiers are replaced with placeholders.
Address track, double-slash injection, auto-insurance lead-gen pretext:
From: "Auto/Insurance" <**auto//insurance@[hijacked-domain][.]com>
Subject: Driver Weekly Briefing
Return-Path: <noReply_[8-random]@[hijacked-domain][.]com>
Address track, brand name split across underscores to defeat exact-match, impersonating a life-insurance brand:
From: "Fidelity Life" <**fidelity__life**@[hijacked-domain][.]com>
Subject: RE: [recipient] Welcome To Your Fidelity Life Offer [tracking id]
Return-Path: <BounceEmail@[hijacked-domain][.]com>
Address track, payment-declined urgency with a hard deadline:
From: <payment//declined@[hijacked-domain][.]com>
Subject: Your Account May Expire at 11:59 Tonight
Return-Path: <noReply_[8-random]@[hijacked-domain][.]com>
Display-name track, clean local-part with the entire payload moved into the display name, pointing at an S3-hosted credential page:
From: "PAYMENT.DECLINED" <noreply@[hijacked-domain][.]com>
Subject: Please Review: Access Expiring Soon
Return-Path: <noReply_[8-random]@[hijacked-domain][.]com>
Address track, the same separator trick carried into the subject line, impersonating a vehicle-warranty brand:
From: "CarShield" <#carshield*@[hijacked-domain][.]com>
Subject: CONGR|ATS YO|UR ELIGIBLE F-OR(2026) DISCOUNNTs
Return-Path: <noReply_[8-random]@[hijacked-domain][.]com>
Technical Analysis
Sender-Surface Obfuscation Grammar
The sender surface is a two-track grammar. Both tracks encode the same intent, a brand or scam keyword plus urgency, but they place the encoded payload in different header fields so that a rule tuned to one track is blind to the other. On the address track, the payload sits before the @ and brand names are split across separators so exact-match rules miss them. On the display-name track, the local-part is drawn from a clean six-token vocabulary (noreply, no-reply, contact, info, support, hello), free of keywords, digits, and special characters, and the payload moves wholesale into the display name.
| Observed behavior | Example (defanged) | Track |
|---|---|---|
| Double-slash injection | auto//insurance@, payment//declined@ |
Address |
| Asterisk wrap | **endurance**@, *auto/insurance*@ |
Address |
| Tilde separator | autoinsurance~*@, quote~wizard@ |
Address |
| Exclamation injection | *autoinsurance!!**@, ndr/partner!!@ |
Address |
| Hash prefix | #auto/insurance*@, #carshield*@ |
Address |
| Underscore padding | **fidelity__life**@, _____________X*@ |
Address |
| IP-literal prefix on local-part | 162.245.186[.]166car//shield@ |
Address |
| Brand-keyword splitting | fidelity__life, car//shield, globe*life |
Address |
| Clean local-part, payload in display name | noreply@ displaying PAYMENT.DECLINED or Cloud//Storage |
Display name |
| IP-prefixed display name | noreply@ displaying 51.89.124[.]51PAYMENT_DECLINED |
Display name |
The display-name track draws from a compact set of recurring strings, PAYMENT.DECLINED, LAST*/WARNING, Cloud//Storage, Cloud/Security/Team, **Action Required**, Cloud_Access_Team, and a long tail of casing and separator permutations on the same handful of concepts.
Registration Cohorts and the Coined-Funnel Pool
Public WHOIS separates the operator-owned landing pool into three cohorts, and one of them is a gift to attribution. The purpose-built auto-insurance funnels were registered through Namecheap behind "Withheld for Privacy," and three of them, diamondautoinsurance[.]com, cleverautoinsurance[.]com, and autoinsurancegalaxy[.]com, were created on the same day, 2025-04-18. Same registrar, same privacy service, same day, adjacent coined names: that is a batch, not a coincidence. Alongside the batch sit older coined funnels from 2021 through 2024 and a newer band of throwaway-TLD coinages registered in 2026.
| Domain (defanged) | Registrar | Created | Cohort |
|---|---|---|---|
diamondautoinsurance[.]com |
Namecheap | 2025-04-18 | Purpose-built coined (same-day batch) |
cleverautoinsurance[.]com |
Namecheap | 2025-04-18 | Purpose-built coined (same-day batch) |
autoinsurancegalaxy[.]com |
Namecheap | 2025-04-18 | Purpose-built coined (same-day batch) |
autoinsurancesimple[.]com |
Namecheap | 2025-06-05 | Purpose-built coined |
insuranceink[.]com |
Namecheap | 2024-06-10 | Purpose-built coined |
autoinsurancepulse[.]com |
Namecheap | 2024-01-25 | Purpose-built coined |
autoinsuranceking[.]com |
Namecheap | 2021-10-26 | Purpose-built coined (older) |
zervantorix[.]fun |
Namecheap | 2026-03-27 | Throwaway-TLD coinage |
foodycreek[.]com |
(bulk registrant) | 2025-01-02 | Coined, young |
The coined pool is small and deliberate, and it stands apart from the sending domains. The sending pool is compromised victim infrastructure, aged and reputable and not owned by the operator at all. The landing pool is the reverse: freshly coined, privacy-registered, and disposable. Reading the two pools together is what distinguishes operator-built infrastructure from the victims it borrows.
Two Click-Through Architectures
The address track and the display-name track serve different final destinations, and the near-total absence of shared click-through infrastructure between them is itself evidence of deliberate design.
| Click-through family (defanged) | Track | Destination type |
|---|---|---|
insuranceink[.]com, diamondautoinsurance[.]com, cleverautoinsurance[.]com, autoinsurancegalaxy[.]com and siblings |
Address | Coined lead-gen insurance funnel |
malcompol[.]com, with a real-brand link as cover |
Address | Coined funnel plus reputation mask |
Random-string AWS S3 buckets, e.g. 0elyodwa44fp8fko2v4z.s3.us-east-1.amazonaws[.]com |
Display name | Static credential-harvest page |
IPv6-mapped-IPv4 URL literals, e.g. http[:]//[::ffff:3f8f:3c05]/qs=r-<token> |
Display name | Direct-IP landing and tracker relay |
The address track funnels victims toward affiliate insurance and lead-gen pages on coined keyword domains. The display-name track leans on S3 buckets and IPv6 literals for what reads much more like straight credential harvest. The operator did not merely add a second obfuscation surface; it paired that surface with a second payoff mechanism.
The Byte-Level Backend
When the sender surface changes, the backend does not. Full message decodes from both tracks share the same tooling fingerprints down to the byte, which is what re-links the tracks after the visible header has been rewritten. When address grammar stops being a reliable signal, these are the artifacts to pivot on.
| Signal | Pattern (defanged) |
|---|---|
| Return-Path | noReply_<8-lowercase>@<sending-domain> |
| MIME boundary | =-_-<3-letter>_-_<hex> |
| List-Unsubscribe | https[:]//<sending-domain>/unsubscribe?email=abuse@<sending-domain> |
| Click-through token triplet | qs=r-, qs=ua-, qs=op- (referrer, user-agent, opt-out trackers for one landing) |
| Landing URL style | IPv6-mapped-IPv4 literal with a base64-tokenized path |
| Body reputation shell | Real high-reputation URLs sprinkled through the body as cover |
Iteration Over Time
The address track is the original, live since late 2025 and built as a multi-vertical sprayer across its brand clusters. Over the following months the operator layered on separator variety, adding tilde, double-exclamation, hash, IP-literal prefixes, and long underscore and hash runs, all aimed at defeating exact-match and fixed-offset parsing of the address.
The display-name track is the interesting move. It emerged as a deliberate answer to address matching: keep a clean six-token local-part that no address rule will flag, and relocate the entire payload into the display name. It grew from a handful of trial messages in mid-March 2026 to a sharp peak weeks later, and it brought a different click-through architecture with it, a shift from lead-gen toward credential harvest. New pretexts have kept budding off both tracks since, covering account-security lures against universities, billing-reactivation, membership renewals, marketplace-brand impersonation, loyalty-reward bait, bounce-abuse, and data-removal themes. Through all of it the backend held constant. The operator rotates the surface, the pretext, and the payoff, and leaves the plumbing alone.
Detection Observations
The signal that separates this traffic from legitimate mail is structural, not lexical. Any single obfuscated address or display name can be written off as sloppy formatting, but the byte-level backend is uniform in ways real senders never are. A self-referential List-Unsubscribe that points at abuse@ on the sending domain, a noReply_ return-path with an eight-character lowercase suffix, and a fixed MIME boundary grammar together describe one tool, not one message.
At the address surface, the combination of injected separators with a split brand keyword is a strong marker, because legitimate brands do not fracture their own names across slashes and underscores in the envelope. At the display-name surface, a clean transactional local-part paired with an urgency-laden, separator-stuffed display name is the equivalent tell. The camouflage habit is worth calling out for defenders: a message whose links are mostly to reputable sites but whose one operative link is an S3 bucket or an IPv6 literal is behaving exactly opposite to how a genuine notification behaves. The reputable links are the disguise, and the odd one out is the point.
Because the operator controls the sender surface completely and rewrites it on demand, surface features age quickly. The durable pivots are the click-through mechanics and the backend fingerprints, which the operator has left untouched across every surface change we have watched.
Indicators of Compromise
All indicators are defanged. Compromised victim sending domains are deliberately excluded; they are victim infrastructure, not operator-owned. Recipient data has been removed.
Domains (Operator Landing and Funnel)
| Value | Role | Notes |
|---|---|---|
diamondautoinsurance[.]com |
Funnel | Namecheap, 2025-04-18 same-day batch |
cleverautoinsurance[.]com |
Funnel | Namecheap, 2025-04-18 same-day batch |
autoinsurancegalaxy[.]com |
Funnel | Namecheap, 2025-04-18 same-day batch |
autoinsurancesimple[.]com |
Funnel | Namecheap, coined, 2025-06-05 |
insuranceink[.]com |
Funnel | Namecheap, coined, 2024-06-10 |
autoinsurancepulse[.]com |
Funnel | Namecheap, coined, 2024-01-25 |
autoinsuranceking[.]com |
Funnel | Namecheap, coined, 2021-10-26 |
foodycreek[.]com |
Landing | Bulk registrant, young, no brand owner |
zervantorix[.]fun |
Landing | Namecheap, coined nonsense, 2026-03-27 |
piell[.]pro |
Landing | Coined throwaway-TLD label |
malcompol[.]com |
Landing | Coined, later dropped |
iwdfrfduifhqdsdbj[.]com |
Landing | Random-string throwaway, later dropped |
| … | Representative subset; dozens of verified operator landing and funnel domains observed |
Hosts (Credential-Harvest Landing)
| Value | Role | Notes |
|---|---|---|
0elyodwa44fp8fko2v4z.s3.us-east-1.amazonaws[.]com |
Landing | Static credential page on a throwaway S3 bucket |
65hgqhp10nc9k7qir6.s3.amazonaws[.]com |
Landing | Throwaway S3 bucket |
jwvkwu0kkjmm11hxo4.s3.amazonaws[.]com |
Landing | Throwaway S3 bucket |
nuewf9edhgdx0dh2.s3.us-east-1.amazonaws[.]com |
Landing | Throwaway S3 bucket |
eqg3ihgvfnz4sb73.s3.us-east-1.amazonaws[.]com |
Landing | Throwaway S3 bucket |
| … | Representative subset; dozens of random-string buckets observed |
IPs (Direct-Literal Landing)
| Value | Role | Notes |
|---|---|---|
63.143.60[.]5 |
Landing | Reached via IPv6-mapped-IPv4 URL literal |
51.89.124[.]51 |
Landing | Seen both as literal CTA and IP-prefixed display name |
54.38.220[.]215 |
Landing | Direct-IP click-through |
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE Fight Fraud Framework (F3) (https://ctid.mitre.org/fraud). Technique labels follow the framework's vocabulary; the operator's behavior sits across four tactics.
| Tactic | Observed behavior | How it appears here |
|---|---|---|
| Resource Development | Acquire Infrastructure | Coined funnel domains registered in privacy-protected batches; throwaway S3 buckets |
| Resource Development | Compromise Accounts | Takeover of small-business, school, and nonprofit mail domains for authenticated sending |
| Initial Access | Phishing Message | Mass email delivery through compromised, authentication-passing domains |
| Initial Access | Brand Impersonation | Local-part and display-name spoofing of more than a dozen consumer brands |
| Execution | Urgency and Scarcity | Deadline subjects with baked-in calendar dates and lockout threats |
| Stealth | Obfuscate Infrastructure | Separator injection, keyword splitting, IPv6-literal links, and reputation-mask camouflage links |
Conclusion
The durable lesson here is not the obfuscation, it is the composure. This operator treats the visible sender as a disposable surface and the backend as the asset, so when address matching improved it rewrote the surface and kept the plumbing. Defenders who chase the separator-of-the-week will always be a step behind, because the operator controls that field and will keep changing it. The signals that held across every pivot are the ones worth building on: the self-referential unsubscribe, the return-path grammar, the click-through token triplet, and the habit of hiding one hostile link inside a crowd of reputable ones.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.