Mail-Bounce Phishing Toolkit: From Cloudflare Workers to Burner Domains
Mail-Bounce Phishing Toolkit: From Cloudflare Workers to Burner Domains
Since December 2025, a phishing toolkit has pushed fake mail-delivery-failure notices to Gmail users through one-shot Microsoft burner accounts. Each message reads like an automated postmaster bounce, a "Delivery Status Notification (Failure)" or a "Returned Mail" ticket, and each one carries a single click-through to a landing page the operator controls. For months that landing page lived on Cloudflare Workers. Over roughly two weeks in the spring of 2026 the operator moved it onto a fleet of eleven throwaway domains, kept every other part of the kit intact, and layered on two new fingerprints: a degree-symbol subject prefix and a football-player decoy that had started with men's players and grew to include women's. We tracked hundreds of messages across the run, and the interesting part is not the volume. It is how little of the toolkit had to change for the operator to swap out its most exposed component.
Key Takeaways
- One toolkit drives the whole campaign: a mail-delivery-failure pretext, single-use
hotmail[.]comandoutlook[.]comburner accounts that pass SPF, DKIM, and DMARC natively, and Gmail recipients. - The click-through infrastructure pivoted from 18 distinct Cloudflare Worker accounts to 11 operator-controlled domains, and the migration was gradual rather than a hard cutover.
- The operator provisions a grab-bag of aged-acquired and freshly-registered domains unified by one privacy-WHOIS registrar rather than by registration date.
- Distinguishing signatures include football-player decoy names, a leading degree-symbol (U+00B0) subject prefix, and a two-anchor click-through where both links point at the same random subdomain and differ only by a URL fragment.
- Message bodies are padded with scraped legitimate text and salted with benign links to lower the ratio of scam content to trustworthy-looking content.
Background
Non-delivery reports are a durable phishing pretext. A bounce notice impersonates an automated system message the victim never asked for, manufactures a small jolt of urgency ("your message failed, review it here"), and mimics an email artifact almost everyone has seen. The lure does not need a brand to impersonate. The mail system itself is the authority.
What makes this toolkit worth a closer look is the delivery model and the hosting choices behind it. Rather than spoofing a sender, the operator sends from genuine Microsoft consumer mailboxes. Because the mail actually originates inside Microsoft's Exchange infrastructure, Microsoft DKIM-signs it, SPF authorizes the sending IPs, and DMARC aligns and passes. Authentication was designed to answer whether a message really came from where it claims. A burner-but-real Microsoft account answers yes, so the authentication stack has nothing to flag and detection falls back to content and behavior. Microsoft's security blog has documented Direct Send abuse, and the same disposable-tenant burn-and-churn pattern is well documented elsewhere.
The landing pages follow the same trust-borrowing logic. Cloudflare Workers is a serverless edge-compute platform where any free account can deploy code that is instantly reachable at a [name].[account].workers[.]dev subdomain, with valid TLS and Cloudflare's high-reputation parent domain attached for free. Vendors including Fortra and Netskope have tracked sharp year-over-year growth in workers[.]dev and pages[.]dev phishing abuse for exactly these reasons: instant, identity-free deployment and a reputable domain that URL-reputation systems are reluctant to block wholesale. The same properties draw operators to Cloudflare Pages, Vercel, Netlify, and similar developer platforms. A reliable defender heuristic falls out of this: banks, governments, and enterprises do not host login or document-release pages on *.workers[.]dev.
When this operator moved off Workers, it did not move to a more reputable host. It moved to privacy-WHOIS throwaway domains on cheap TLDs. Registrars now bundle free WHOIS privacy and budget TLDs cost a few dollars, so an operator can register disposable domains with no attributable registrant data and burn them per wave. Along the way the campaign also leaned on commodity file and relay hosts for first-stage content and decoy links: Supabase Storage public buckets, GitLab Pages, Mailchimp and Klaviyo click-redirectors, and mainstream CDNs. None of those platforms is the adversary. Each is a trust surface the operator rents by the click.
Discovery and Infrastructure
We first mapped the campaign through its Cloudflare Workers footprint. Every landing host matched a machine-generated grammar, [word]-[word]-[padding].[account].workers[.]dev, and each Worker account served a single landing page (occasionally two or three when the same page went to a small batch of recipients). Eighteen distinct Worker accounts appeared in the original cluster. Across full history, 30 distinct workers[.]dev hosts tie to this pretext family and its neighbors.
The senders told a consistent story. Across the campaign we observed 47 single-use Microsoft burner accounts, 21 in the original cluster and 26 in the later expansion, split almost evenly between hotmail[.]com and outlook[.]com, plus one compromised university student mailbox used the same way. No address ever sent twice. The correlation that held the cluster together was never the sender or the Worker account. It was the template: the pretext family, the decoy tradecraft, and the body structure.
The defining event was the CTA pivot. Between 2026-04-22 and 2026-05-09 the operator abandoned workers[.]dev as its primary landing host (only one residual Worker hit appears in that window) and stood up eleven operator-controlled domains in its place. Most front their landing pages with a random alphanumeric subdomain; a few serve straight from the bare apex.
How It Works
A representative message arrives from a plausible-looking English name or, just as often, from a display name that is itself a mail-system string such as "Returned Mail" or "Undeliverable Mail." The subject announces a delivery failure and appends a short code. The body opens with a one-line bounce notice, offers a click-through to "review" or "release" the message, and then runs pages of unrelated text scraped from a legitimate institution as filler. The single actionable link resolves to a Worker host in the early campaign or, later, to a random subdomain on one of the eleven operator domains. Alongside it sit benign links (a Microsoft help shortlink, a football statistics page) whose only job is to make the message look ordinary.
Sample Lures
All samples below are attacker-side content with recipient data removed and every URL defanged.
Plain "Returned Mail" variant, Cloudflare Workers era:
From: "Returned Mail" <gunner_494_etan@hotmail[.]com>
Subject: Returned Mail : FNB
Auth: SPF pass / DKIM pass / DMARC pass (native Microsoft Exchange)
Actionable link: hxxps://icy-boat-d16elle-...-boat[.]skola[.]workers[.]dev/#0b...
Benign cover links: hxxps://aka[.]ms/o0ukef , Gmail image-proxy pixel
Football-player decoy variant, Cloudflare Workers era:
From: "Woodward Michael" <myronortizlkbk@outlook[.]com>
Subject: Ryan Gravenberch :Send Network Issue:ABX
First-stage host: hxxps://[project-ref][.]supabase[.]co/storage/v1/object/public/...
Actionable link: hxxps://tiny-grass-...[.]rashadmustafa[.]workers[.]dev/
Benign cover link: hxxps://www.transfermarkt[.]com/... (stat page for the named player)
Degree-symbol prefix with decoy-theme injection, operator-domain era (real body excerpt, padding truncated):
From: "Loyola Konstantinidi" <loyolakonstantinidi6037@outlook[.]com>
Subject: °Failed delivery report-VISION HEALTH ALERT° QTB
We couldn't fully process your delivery update.
View Delivery Status ( hxxp://iki8oby[.]daoassist[.]com#cl/[recipient tracking token] )
Unsubscribe ( hxxp://iki8oby[.]daoassist[.]com#un/[recipient tracking token] )
[remainder of body: verbatim text scraped from an unrelated legitimate institution,
used as keyword-dilution padding]
Technical Analysis
Sender Provisioning and the Burner Template
Every send comes from a single-use mailbox. The hotmail[.]com and outlook[.]com accounts divide almost evenly, and the one compromised student.itera.ac[.]id account behaves identically: auth-clean, used once, then abandoned. Display names span three registers. Roughly 33 distinct plausible personal-name aliases (Jabez Hartley, Francis Simpson, Woodward Michael, and the like) rotate through the campaign. Five mail-system strings (Returned Mail, Undeliverable Mail, Delivery Status Notification, Delivery Status Notification (Failure), Failed Delivery Notification) get used directly as display names to reinforce the bounce pretext. A third register encodes a batch marker into the display name itself, a trailing single letter such as EnduranceB and EnduranceG, or Senior DiscountsG, Senior DiscountsJ, and Senior DiscountsP, that appears to index a send wave.
CTA Infrastructure: The Workers-to-Operator-Domain Pivot
The pivot is the clearest evidence of a toolkit rather than a one-off. When the operator swapped its most exposed component, the landing host, everything upstream stayed constant: the burner-account template, the pretext family, the decoy tradecraft, and the body structure. The migration was not a clean break. Worker hosts on the same template kept appearing after the operator-domain fleet came online, which also confirms that the workers[.]dev host shape is shared platform abuse across operators, not a signature unique to this kit.
Registration Cohorts and Provisioning
WHOIS pulls the provisioning story into focus. Six of the nine WHOIS-resolved domains sit behind one privacy-WHOIS registrar, and the eleven domains fall into two registration-age cohorts, plus two domains with no resolvable WHOIS, all coexisting inside the same two-week send window.
| Operator domain | Registrar | WHOIS created | Cohort | CTA shape |
|---|---|---|---|---|
masonicicons[.]com |
Dynadot (privacy) | 2011-04-17 | aged-acquired | bare apex |
daoassist[.]com |
Dynadot (privacy) | 2021-04-08 | aged-acquired | 2 alnum subs |
thebetterlifepieces[.]com |
Namecheap (privacy) | 2021-05-07 | aged-acquired | 2 alnum subs |
brve[.]in |
GoDaddy | 2022-09-22 | aged-acquired | bare apex |
king-of-fools[.]com |
Dynadot (privacy) | 2024-05-30 | aged-acquired | bare apex |
developmoaning[.]com |
Namecheap (privacy) | 2025-03-04 | fresh | 3 alnum subs |
lekein[.]com |
Dynadot (privacy) | 2025-05-09 | fresh | 1 alnum sub |
shamim[.]top |
Dynadot (privacy) | 2025-05-26 | fresh | bare apex |
keicarup[.]org |
Dynadot (privacy) | 2026-02-18 | fresh (~10 wk pre-use) | 1 alnum sub |
quantumshift[.]info |
(no WHOIS) | n/a | opaque | 2 alnum subs |
realinsight[.]info |
(no WHOIS) | n/a | opaque | apex + 1 sub |
A domain registered in 2011 and a domain registered ten weeks before its first use both appear in the same wave. The aged-acquired domains borrow registration age to slip past freshness heuristics; the fresh ones are provisioned close to launch. The unifying signal is the shared registrar and privacy posture. Domain-age scoring alone would clear the older half of this fleet.
Subdomain Grammar and CTA-to-Theme Mapping
The subdomain template is a 7-to-8-character alphanumeric label prepended to the operator apex, for example iki8oby.daoassist[.]com. Seven of the eleven domains front their landing pages this way, with two or three distinct subdomains each on the busiest domains; the remaining four serve from the bare apex. The labels are not typosquats of any real brand. They are neutral tokens, chosen so no brand owner has standing to pursue a takedown.
Pairing CTA hosts against subject themes surfaces a one-domain-per-vertical discipline in the expansion wave.
| CTA host family | Subject decoy theme |
|---|---|
daoassist[.]com (alnum subs) |
health lures: GOOD MORNING HEALTH, VISION HEALTH ALERT |
keicarup[.]org (1e87m5tf) |
carrier reward: T-MOBILE EXCLUSIVE REWARD |
lekein[.]com (4bn3ijte) |
PAYMENT NOTIFICATION |
developmoaning[.]com (3 subs) |
Senior Discounts |
quantumshift[.]info (2 subs) |
auto-warranty: Endurance |
realinsight[.]info (apex + sub) |
SYSTEM ADMINISTRATOR and generic codes |
king-of-fools[.]com (apex) |
women's-football decoy: Fran Kirby |
thebetterlifepieces[.]com (2 subs) |
generic degree-symbol codes |
masonicicons[.]com (apex) |
generic degree-symbol codes |
us16.list-manage[.]com (Mailchimp relay) |
T-MOBILE TECH BONUS |
ctrk.klclick[.]com (Klaviyo relay) |
Failed Delivery Notification: C |
img-host-a5aff6.gitlab[.]io (GitLab Pages) |
generic code |
Each send wave tends to bind one decoy vertical to one CTA domain. Health themes route to daoassist[.]com, payment themes to lekein[.]com, senior-discount themes to developmoaning[.]com, auto-warranty themes to quantumshift[.]info. The ESP redirectors (Mailchimp, Klaviyo) and the GitLab Pages host serve as decoy CTA wrappers, borrowing a trusted domain to carry or front the click.
Decoy Tradecraft and Fingerprint Evolution
Three signatures track the operator across the pivot. The football-player decoy is the most idiosyncratic. Early messages prepend the names of Ajax Amsterdam men's players (Ryan Gravenberch, Talles Magno, Alban Lafont, Arthur Vermeeren) to the bounce code and co-embed a matching transfermarkt[.]com statistics page. In the expansion wave the same shape extends to women's football (Jenni Hermoso, Fran Kirby), with the women's-decoy sends landing on king-of-fools[.]com. The second signature is a leading degree-symbol character (U+00B0) on the subject: °Failed delivery report ... <3-letter code>. The third is all-caps decoy-theme injection into the subject line (T-MOBILE EXCLUSIVE REWARD, VISION HEALTH ALERT, PAYMENT NOTIFICATION) wrapped around the same trailing code.
Body Structure: Two-Anchor CTA and Padding
The decoded body reveals a compact, repeatable structure. A single bounce sentence sits above a two-anchor click-through: a "View Delivery Status" link and an "Unsubscribe" link that both point at the same random subdomain on the same operator domain. The two anchors differ only by a URL fragment prefix (#cl/ for the click path, #un/ for the unsubscribe path) followed by a shared per-recipient tracking token. Below the anchors, the message runs verbatim text scraped from an unrelated legitimate institution (a campus directory, a postal address) purely as padding, diluting the proportion of scam-specific language in the message. We confirmed this same anchor-pair-plus-fragment-plus-padding structure across multiple operator-domain samples, which makes it one of the more reliable body-level fingerprints for the kit.
Detection Observations
The signals below describe what separates this traffic from legitimate mail. They are observations about the operator, not a commentary on any detection stack.
- A leading degree-symbol (U+00B0) on a delivery-failure subject is a high-precision anchor. Legitimate bounce notices do not open their subject with that character.
- A mail-delivery-failure notice whose only actionable link lands on a free developer-hosting subdomain or a privacy-WHOIS throwaway domain is anomalous on its face. Real non-delivery reports come from the recipient's own mail provider and do not route to
*.workers[.]devor a random subdomain on a cheap-TLD domain. - Two anchors that point at the same random subdomain and differ only by a URL fragment are a structural tell. Legitimate "view" and "unsubscribe" links resolve to different, stable hosts.
- Football-player surnames prefixed to a bounce code, and benign links (
aka[.]ms,transfermarkt[.]com) co-embedded beside a single actionable link, both raise the message's benign-to-actionable link ratio deliberately. That ratio is itself a signal. - Because the burner accounts authenticate cleanly, authentication and sender-reputation checks carry little weight here. Content shape and infrastructure shape do the work.
Mitigation and Guidance
- Treat a delivery-failure or "Returned Mail" message that originates from a consumer
hotmail[.]comoroutlook[.]commailbox as suspect. Genuine non-delivery reports come from mail-system addresses inside the recipient's own provider, not a personal consumer account. - Key on the actionable link's host, not the sender's authentication result. A bounce notice pointing at
*.workers[.]dev,*.pages[.]dev, or a privacy-WHOIS domain on a cheap TLD is not legitimate, regardless of a clean SPF, DKIM, and DMARC result. - Flag messages where multiple visible links resolve to the same random-labeled subdomain and differ only by URL fragment.
- Add the leading degree-symbol subject prefix and football-player-surname-plus-code subject shapes as high-precision content anchors.
- Do not blanket-block the abused platforms (Cloudflare, Supabase, GitLab, Mailchimp, Klaviyo). Scope enforcement to the operator subdomains and the eleven operator domains listed below.
MITRE Fight Fraud Framework Mapping
The behaviors map cleanly onto the MITRE Center for Threat-Informed Defense Fight Fraud Framework (F3), which imports ATT&CK techniques into a fraud-tactic vocabulary. IDs below are the ATT&CK techniques F3 incorporates.
| F3 Tactic | Technique | ID |
|---|---|---|
| Resource Development | Establish Accounts: Email Accounts (Microsoft burner mailboxes) | T1585.002 |
| Resource Development | Compromise Accounts: Email Accounts (the university mailbox) | T1586.002 |
| Resource Development | Acquire Infrastructure: Domains (the operator-domain fleet) | T1583.001 |
| Initial Access | Phishing (mail-bounce lure delivery) | T1566 |
| Reconnaissance | Phishing for Information (credential capture on the landing page) | T1598 |
| Stealth | Impersonation (postmaster / mail-system authority persona) | T1656 |
Indicators of Compromise
All indicators are defanged. Recipient data has been removed. The sender list is a representative subset of the burner accounts observed.
Senders
| Value | Role | Notes |
|---|---|---|
gunner_494_etan@hotmail[.]com |
Sender | Original cluster; "Returned Mail" display name |
faelaba@hotmail[.]com |
Sender | Original cluster |
myronortizlkbk@outlook[.]com |
Sender | Football-player decoy variant |
egacvehdunfcc@outlook[.]com |
Sender | Football-player decoy variant |
unjustitude756225manning@hotmail[.]com |
Sender | Original cluster |
muhammad.121210153@student.itera.ac[.]id |
Sender | Compromised university mailbox (sender only; the institution is not implicated) |
hardycormierflplq@outlook[.]com |
Sender | Expansion; degree-symbol subjects |
eryncarrolljae@outlook[.]com |
Sender | Expansion; women's-football decoy |
henchsheu6049@outlook[.]com |
Sender | Expansion; carrier-reward theme |
ottleyhelfin7349@outlook[.]com |
Sender | Expansion; health theme |
loyolakonstantinidi6037@outlook[.]com |
Sender | Expansion; health theme |
starovierstyboyd75@hotmail[.]com |
Sender | Expansion; payment-notification theme |
debbie.imprysonmente.1998@hotmail[.]com |
Sender | Expansion; system-administrator theme |
proffertakeda414@hotmail[.]com |
Sender | Expansion; auto-warranty theme |
freudpolio1902@hotmail[.]com |
Sender | Expansion; ESP-relay CTA wrapper |
| … | (representative subset; 47 single-use burner accounts observed: 21 original, 26 expansion) |
Domains
| Value | Role | Notes |
|---|---|---|
developmoaning[.]com |
CTA | Namecheap privacy, 2025-03-04; senior-discounts theme |
quantumshift[.]info |
CTA | No WHOIS; auto-warranty theme |
daoassist[.]com |
CTA | Dynadot privacy, 2021-04-08; health theme |
thebetterlifepieces[.]com |
CTA | Namecheap privacy, 2021-05-07 |
realinsight[.]info |
CTA | No WHOIS; system-administrator theme |
masonicicons[.]com |
CTA | Dynadot privacy, 2011-04-17 (aged-acquired) |
lekein[.]com |
CTA | Dynadot privacy, 2025-05-09; payment theme |
keicarup[.]org |
CTA | Dynadot privacy, 2026-02-18 (~10 wk pre-use); carrier-reward theme |
shamim[.]top |
CTA | Dynadot privacy, 2025-05-26; cheap-TLD throwaway |
king-of-fools[.]com |
CTA | Dynadot privacy, 2024-05-30; women's-football decoy |
brve[.]in |
CTA | GoDaddy, 2022-09-22; cheap-TLD throwaway |
Hosts
| Value | Role | Notes |
|---|---|---|
3jrwnuuo.developmoaning[.]com |
Landing | Random-alnum subdomain |
5n1ifnv9.developmoaning[.]com |
Landing | Random-alnum subdomain |
uaauxtlw.developmoaning[.]com |
Landing | Random-alnum subdomain |
dkemfya.quantumshift[.]info |
Landing | Random-alnum subdomain |
wkbaluvq.quantumshift[.]info |
Landing | Random-alnum subdomain |
iki8oby.daoassist[.]com |
Landing | Random-alnum subdomain |
jx0i5oj0.daoassist[.]com |
Landing | Random-alnum subdomain |
mbz5ggjm.thebetterlifepieces[.]com |
Landing | Random-alnum subdomain |
ojzuwni.thebetterlifepieces[.]com |
Landing | Random-alnum subdomain |
xbao7slx.realinsight[.]info |
Landing | Random-alnum subdomain |
1e87m5tf.keicarup[.]org |
Landing | Random-alnum subdomain |
4bn3ijte.lekein[.]com |
Landing | Random-alnum subdomain |
Conclusion
The operator behind this kit spent almost nothing to survive the loss of its landing infrastructure. When Cloudflare Workers became a liability, it swapped in a mix of aged and freshly-registered domains behind a single privacy registrar and carried on with the same burner accounts, the same bounce pretext, and the same decoy tradecraft. The lesson is straightforward: for a toolkit built on trusted-platform staging and disposable senders, the landing host is the cheapest part to replace. Defenders who anchor on the stable pieces, the pretext family, the two-anchor body structure, the decoy fingerprints, will track this operator across its next host far better than any single domain block will.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.