No Domains of Their Own: A Targeted Meta Business-Page Phishing Operator
No Domains of Their Own: A Targeted Meta Business-Page Phishing Operator
For more than seven months, one operator has run a targeted Meta Business-Page phishing operation without registering a single domain of its own. From November 2025 through late June 2026, we tracked a low-volume, high-craft campaign that borrows every piece of its infrastructure: a Google AppSheet relay carries the mail, Gmail and GoHighLevel accounts fill in as backup senders, and each credential-harvest page lives on a throwaway subdomain at Vercel, Netlify, Cloudflare Workers, or sw[.]run. The subject lines are the giveaway that this is not a spray campaign. Every message names one of two specific monetized Business Pages, which makes the operator's chosen victims part of the lure itself.
Key Takeaways
- The operator registered zero domains, running the whole campaign on shared legitimate platforms: a Google AppSheet email relay, Gmail and GoHighLevel sender accounts, and one-shot landing pages on Vercel, Netlify, Cloudflare Workers, and sw[.]run.
- Every message authenticates cleanly because it genuinely leaves Google or an established ESP, so SPF, DKIM, and DMARC all pass and sender-reputation signals offer defenders nothing here.
- Subject lines name two specific monetized Business Pages in every message, marking this as targeted spear-phishing against chosen victims rather than a broadcast wave.
- Sender display names are mangled with a reusable obfuscation kit (whitespace injection, Unicode mathematical alphanumerics, Cyrillic homoglyphs) that the same relay account applies across Meta, LinkedIn, and Apple impersonations.
- Each landing page is a burner used exactly once, and the operator rotated hosting platforms over time (Vercel and Netlify first, then sw[.]run and Cloudflare Workers) while keeping the relay and the pretext constant.
Background
The investigation started from a dead end. A sender address supplied as a lead returned nothing in our corpus, so instead of matching on the from-address we pivoted to the brand pretext: display-name tokens and subject patterns that impersonate Meta. That pivot surfaced a pre-existing campaign hiding behind an address most filters would wave through, noreply@appsheet[.]com.
Google AppSheet is Google's no-code app and workflow-automation platform. Its free tier lets any account trigger automated email that leaves Google's own mail servers as noreply@appsheet[.]com, which means the message inherits Google's sending reputation and passes authentication by default. AppSheet also stamps a per-record identifier into automated mail, so an operator can vary a "Case ID" on every send and make each message slightly different. Public reporting through 2025 and 2026 tracked a broad wave of Meta-impersonation phishing riding AppSheet in exactly this way, with landing pages that proxy credentials and 2FA tokens in real time (KnowBe4, Paubox, NJCCIC). The operator we tracked fits that mold and adds a targeting layer of its own.
The other sending rails follow the same logic of borrowing trust. GoHighLevel, whose LeadConnector service sends under send.lcmsgsndr[.]com, is a marketing-automation suite; a scammer who spins up a sub-account can send fully aligned mail from an address like client+448400+meta.for.business@send.lcmsgsndr[.]com, encoding the brand pretext straight into the plus-tagged local part. Gmail one-shot accounts round out the sender set.
The landing pages sit on free developer platforms. Vercel (*.vercel[.]app) and Netlify (*.netlify[.]app) hand out instant subdomains with valid TLS and no identity check, which makes each URL a disposable credential-harvest page that inherits the platform's clean reputation and can be respun the moment one is taken down. Cloudflare Workers (*.workers[.]dev) and sw[.]run play the same role in the later phase of the campaign. Weaponized Google Forms (forms[.]gle) and Google Docs (docs.google[.]com) serve as no-infrastructure credential surfaces for the lower-craft variants, rendering on real Google URLs that users and filters rarely block.
None of these controls are broken. SPF, DKIM, and DMARC only prove that a message was authorized by, and unchanged from, the sending domain. They say nothing about intent. When the phish genuinely travels through Google or an established ESP, authentication returns pass and the entire abuse signal moves to content, behavior, and the destination link. The "policy violation, appeal within 24 hours or lose your account" pretext this operator leans on is itself a long-running staple against Page owners, documented repeatedly in public advisories (Bitdefender, Cybernews).
Discovery and Infrastructure
Mapping the campaign meant working backward from the pretext to the senders, then forward from the senders to the burner CTA hosts. Three sending rails carry the operation, and not one of them is a domain the operator owns.
| Sender rail | Role | Delivery pattern |
|---|---|---|
noreply@appsheet[.]com |
Primary relay hub (auth-clean Google infrastructure) | All three pretext families; higher-craft clones with embedded decoy assets |
*@gmail[.]com (three one-shot accounts) |
Burner senders | forms[.]gle / docs.google[.]com credential surfaces, no decoys |
client+448400+meta.for.business@send.lcmsgsndr[.]com |
GoHighLevel ESP sub-address | Brand pretext encoded in the plus-tagged local part |
From those senders, the click destinations fan out across four free developer platforms, seventeen distinct one-shot endpoints in all, each used exactly once and never reused. Across the tracked window the operator sent hundreds of messages, a small figure by broadcast-phishing standards but sustained and precisely aimed. The AppSheet relay stays constant throughout; only the burner-hosting platform rotates. That combination, a fixed trusted relay paired with disposable destinations, is what keeps the operation cheap and resilient: takedowns and blocklists chase URLs that were already discarded before they were flagged.
The impersonation itself is anchored on Meta assets that are entirely real. Higher-craft messages embed genuine Meta CDN images from static.xx.fbcdn[.]net, footer links to business.facebook[.]com, and a www.facebook[.]com/email_forward_notice link, so a recipient hovering over most of the message sees legitimate Facebook URLs. Exactly one link in the body points somewhere else: the burner CTA button.
How It Works
A Page admin receives a message that appears to come from Facebook or a Meta support team. The display name reads correctly at a glance but is broken up with spacing or look-alike characters, and the from-address is on AppSheet's relay rather than any Meta domain. The body carries a Meta logo pulled from the real CDN, a fake reference number, and a countdown: the account will be permanently disabled in 24 hours, or the Page is now eligible for monetization and needs review, or a verification badge has been approved and needs a final sign-in.
Every version funnels to a single action. A button labeled something like "Review & Submit Appeal", "Review Request in Business Manager", or "Proceed" hides the one non-Meta URL in the message, a burner subdomain on Vercel or Netlify (later Cloudflare Workers or sw[.]run) that hosts the credential-capture page. The lower-craft Gmail variants skip the decoy assets entirely and send the target to a Google Form or Google Doc instead. In all cases the destination is a page designed to harvest the admin's Facebook login and take over a monetized Business Page.
Sample Lures
All samples are defanged. Recipient and victim identifiers, including the two specific targeted Page names, have been redacted.
Email: DMCA Account-Disable Pretext (AppSheet Variant)
From: "Business Help Center" <noreply@appsheet[.]com>
Subject: Your account will be subject to permanent forbidden usage (DMCA)
Auth: SPF pass / DKIM pass / DMARC pass
Meta
Reference ID: 94758851
We are about to permanently disable your account.
The decision will be enforced in 24 hours.
Why was this action taken?
We have previously issued multiple copyright notices related to your account,
but no response or corrective action has been taken. As a result, the rights
holder has filed a complaint with Meta under the Digital Millennium Copyright
Act (DMCA) regarding the unauthorized use of protected intellectual property.
[Review & Submit Appeal] -> http[:]//clinquant-gelato-db7483[.]netlify[.]app/home
(c) 2026 Meta. Meta Platforms, Inc., 1601 Willow Rd. Menlo Park, CA 94025
Sent from AppSheet
Email: Monetization-Enablement Pretext (AppSheet Variant, With Decoy URLs)
From: "Facebook" <noreply@appsheet[.]com>
Subject: Your Business Page [targeted Business Page] is Eligible for Monetization
Auth: SPF pass / DKIM pass / DMARC pass
Business Manager
Review the request to enable monetization on the Page.
Your Business Page is eligible to enable monetization.
Allow Page: [targeted Business Page]
[Review Request in Business Manager] -> http[:]//suite-case10091775[.]netlify[.]app/protect
Once monetization is enabled on Facebook, you can start earning revenue from
your posts or videos through features like in-stream ads, branded content, and
bonuses.
Meta Platforms, Inc., Attention: Community Support, 1 Meta Way, Menlo Park, CA 94025
[Decoy links co-embedded, all real Meta assets:]
http[:]//business.facebook[.]com/settings/...
http[:]//static.xx.fbcdn[.]net/rsrc.php/...
http[:]//www.facebook[.]com/email_forward_notice/?mid=...
Email: Verified-Badge Approval Pretext (Gmail Burner Variant)
From: "Meta Notice" <shadmurray03@gmail[.]com>
Subject: Official Confirmation of Verification Approval - [targeted Business Page]
Auth: SPF pass / DKIM pass / DMARC pass
All verification approval checks for [targeted Business Page] have been
completed. Kindly sign in to the Account Management Center to finalize the
process.
Proceed using the verification link below:
http[:]//forms[.]gle/[form-id]
Sincerely,
Customer Assistance Department
Account Operations Unit
Ref ID: HHOHEV3W
Technical Analysis
Living Off Trusted Platforms
The defining feature of this operator is what it did not build. There is no operator-registered domain anywhere in the campaign. Every sender sits on a shared legitimate relay, and every landing page is a subdomain or path on a shared developer platform. That choice has a direct consequence for takedown: the platforms that host the burners carry infrastructure flags that make them un-actionable at the apex. A verdict on vercel[.]app or netlify[.]app would cross-apply to every tenant on the platform and break legitimate traffic globally, so the parent domains cannot be blocked wholesale. The operator is deliberately parking behind that shared-tenancy protection.
| Parent platform | Hosting infrastructure | Role in campaign |
|---|---|---|
vercel[.]app |
Yes (shared multi-tenant) | Primary burner CTA host |
netlify[.]app |
Yes (shared multi-tenant) | Secondary burner CTA host |
workers[.]dev |
Yes (shared multi-tenant) | Later-phase burner CTA host |
sw[.]run |
Path-based shared apex | Later-phase burner CTA host |
appsheet[.]com |
Google-operated relay | Primary sending hub |
send.lcmsgsndr[.]com |
GoHighLevel ESP | Backup sending rail |
Burner-Host Naming Grammar
The CTA hosts are not random noise. Each platform has a recognizable template, and the grammar itself is a fingerprint.
- Vercel random-prefix template,
^[a-z0-9]{10}-[a-f0-9]{10}\.vercel[.]app$: a 10-character alphanumeric label, a hyphen, and a 10-hex-character deploy hash. Examples:0446by7r4y-7644edabc5[.]vercel[.]app,csimq9nmyo-27c78671c1[.]vercel[.]app,j248stalfo-4598e1e906[.]vercel[.]app. - Vercel English-words variant:
fablethinkeraurora[.]vercel[.]app, concatenated dictionary words with no hash, an earlier and lower-craft template. - Netlify word-word-hex shape:
clinquant-gelato-db7483[.]netlify[.]app(adjective, noun, six hex) and the word-word-digits siblingsuite-case10091775[.]netlify[.]app. - Cloudflare Workers rotation: a word-word-hex label under a numeric
s#######subaccount, for exampleshrill-night-a7d8.s2119101.workers[.]dev. - sw[.]run rotation: a path on the shared apex,
http[:]//sw[.]run/update-new, rather than a dedicated subdomain.
Because every host is used once, URL reputation has no prospective value against this operator. The durable signal is the shape of the name, not any individual host.
The Cross-Brand Obfuscation Kit
The sender display names are broken up with a small, reusable toolkit, and the same kit shows up across more than one impersonated brand from the same AppSheet account. That reuse is the strongest attribution signal in the campaign.
- Whitespace-injected Latin:
F a c eb o o k,Face bo ok,Fac eb ook Ad s Sup port,Face book Ads T eam. - Unicode mathematical alphanumerics:
𝖭𝗈𝗍𝖺𝖻𝗅𝖾 𝖢𝗈𝗇𝗍𝖾𝗇𝗍, styled glyphs that read as Latin letters but occupy a different code range. - Cyrillic homoglyphs:
LinkedIn CаrееrsandMеtа | Global Recruitment, where theаandеare Cyrillic look-alikes (U+0430, U+0435).
The same relay account applied this kit not only to Meta and Facebook strings but to LinkedIn Cаrееrs, Apple | Recruitment, and other brand impersonations. One general-purpose obfuscation engine, repurposed brand to brand, sits behind the Meta-targeted subset we tracked here.
Content Cloning and Decoy Assets
The higher-craft AppSheet messages are near-clones of real Meta notifications. They pull genuine logo images from static.xx.fbcdn[.]net, link footers to business.facebook[.]com, and include a real www.facebook[.]com/email_forward_notice link, so the message is mostly authentic Meta content wrapped around a single hostile button. A recipient who checks a few links before clicking finds real Facebook URLs, which is exactly the reassurance the operator wants them to feel. The Gmail one-shot variants drop this entire decoy layer and settle for a bare Google Form or Doc link.
Across all three pretext families the structural tells are constant: a fabricated ticket token (Reference ID:, Ref ID:, CaseID, idref#, Violation Number: followed by an 8-to-12 character string), a 24-hour countdown, and a spoofed Menlo Park signature block citing 1 Meta Way or 1601 Willow Rd.
Platform Rotation Over Time
The operator kept the relay and the pretext stable while rotating the burner-hosting platform as older hosts drew attention.
| Window | Burner-host platform | Relay | Dominant pretext |
|---|---|---|---|
| Nov 2025 to Jan 2026 | Vercel (English-words, then random-prefix) | appsheet[.]com |
Monetization / DMCA |
| Jan to Apr 2026 | Vercel random-prefix plus Netlify word-word-hex | appsheet[.]com (plus Gmail / GoHighLevel one-shots) |
All three families |
| ~May 2026 | sw[.]run path rotation |
appsheet[.]com |
Advertising-policy compliance |
| ~Jun 2026 | Cloudflare Workers | appsheet[.]com |
Trademark / IP violation |
The rotation is the operation's survival mechanism. Retiring a hosting platform costs the operator nothing, and the relay that actually delivers the mail never changes.
Detection Observations
The behavioral signals that separate this traffic from legitimate Meta mail are consistent, and none of them depend on authentication outcome.
- A sender display name that reads as a Meta or Facebook brand while the return path lands on an unrelated relay (
appsheet[.]com, a Gmail account, a GoHighLevel sub-address) is the primary tell. Matching it reliably requires normalizing the display name first: strip injected whitespace, apply Unicode NFKC folding, and detect look-alike character sets before comparing against brand strings, because raw literal matching is defeated byF a c eb o o kand by Cyrillic homoglyphs. - A message that embeds real Meta CDN and
business.facebook[.]comassets yet carries exactly one actionable non-Meta URL is a strong composite signal. Legitimate Meta mail does not route its only clickable action through a Vercel or Netlify subdomain. - The burner CTA hosts follow a template, so the durable pivot is the host shape (random-prefix subdomains and word-word-hex names on free developer platforms) rather than any single host, which will already be dead by the time it is observed.
- Fabricated ticket tokens paired with a 24-hour countdown and a Menlo Park signature block recur across every pretext family and cluster well together.
- The two named Business Pages appear in essentially every subject line, so subject-token matching on the targeted Page names catches this specific operator with high precision even as the hosting rotates.
Indicators of Compromise
The indicators below are a representative, export-safe subset, defanged, with victim data removed. The sending relays and the one-shot burner hosts are shared-platform infrastructure and are deliberately excluded from this block-list subset; the operator-controlled sender accounts are the durable, safely-actionable indicators.
Senders
| Value | Role | Notes |
|---|---|---|
irlandkim872@gmail[.]com |
Sender | One-shot Gmail burner; "Meta For Business" display name; Google Docs CTA |
canovasroxy@gmail[.]com |
Sender | One-shot Gmail burner; "Verified Badge Businesses" display name; Google Docs CTA |
shadmurray03@gmail[.]com |
Sender | One-shot Gmail burner; "Meta Notice" display name; Google Forms CTA |
client+448400+meta.for.business@send.lcmsgsndr[.]com |
Sender | GoHighLevel ESP sub-address; "MetaProTeam" display name; brand pretext in the local part |
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE Center for Threat-Informed Defense fraud framework (https://ctid.mitre.org/fraud), which uses native F#### technique IDs alongside reused ATT&CK T#### IDs.
| Tactic | Technique | ID |
|---|---|---|
| Initial Access | Phishing | T1660 |
| Initial Access | Impersonate Official | F1032 |
| Resource Development | Create Fake Materials: Fake Website | F1020.002 |
| Initial Access | Account Takeover: Exposed Login Credential | F1006.002 |
The urgency and 24-hour-countdown manipulation is carried inside the Phishing and Impersonate Official techniques rather than mapping to a standalone ID, and the reliance on shared legitimate platforms for delivery and hosting maps conceptually to the framework's Stealth tactic.
Conclusion
This operator shows how little infrastructure a patient, targeted phisher now needs. There are no purchased domains and no self-hosted servers, which leaves nothing to seize: a free Google relay, a handful of throwaway accounts, and disposable pages on developer platforms that cannot be blocked at the apex. The durable defensive signals are behavioral, not reputational: normalized display-name analysis, the mismatch between a brand name and a developer-platform destination, and the naming grammar of one-shot burners. When one hosting platform gets uncomfortable, an operator built this way simply moves to the next, so defenders should expect the burner rail to keep rotating while the relay and the pretext stay put.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.