Anatomy of a DigitalOcean Spaces Bucket Phishing Kit
Anatomy of a DigitalOcean Spaces Bucket Phishing Kit
Since January 2026, one operator has run a brand-impersonation phishing kit that hides landing pages inside disposable DigitalOcean Spaces buckets. Each phishing email carries a single link to a short-lived storage bucket, that bucket serves a small HTML page, and the page reads a token from the URL fragment to bounce the victim onward to a survey or reward-harvest destination. The email itself never contains the final scam URL. The operator pairs every bucket with a throwaway Gmail account, rotates both faster than any reputation feed can keep up, and skins the lures as Costco, AAA, Starbucks, and more than a dozen other trusted retail and service brands. This is a study of the kit: how the buckets are named, how the regions are used, how the redirect works, and what the toolkit changed as it ran.
Key Takeaways
- The operator hosts every landing page in a short-lived DigitalOcean Spaces object-storage bucket and pairs each bucket with a one-shot Gmail sender, so neither side accumulates reputation before it is discarded.
- The final scam destination never appears in the email. The bucket page reads a URL-fragment token in client-side JavaScript and redirects from there, so anything parsing the message sees only a trusted-looking cloud-storage host.
- Bucket names fall into stable families (keyboard-mash gibberish, Costco brand-squats carrying a
48/49infix, and all-numeric date strings) that fingerprint distinct sub-clusters running the same kit. - A shared affiliate-tracking fragment (
#cl/<id>_md/…) and a small set of kit HTML paths (/1.htmlthrough/4.html) tie otherwise-unrelated buckets back to one toolkit. - The operator built more than 2,000 distinct buckets across 11 storage regions, cycled through several thousand Gmail sender accounts, and rotated roughly 18 impersonated brands.
- Later waves add homoglyph display names and fake unsubscribe anchors pointing at reputable third-party domains, meant to blunt string-based brand matching and link-reputation checks.
Background
DigitalOcean Spaces is an S3-compatible object-storage service. Every bucket gets its own hostname under a regional endpoint, in the shape <bucket>.<region>.digitaloceanspaces[.]com, served over DigitalOcean's own TLS certificate. That shape is exactly what makes it attractive to a phishing operator. A bucket spins up in seconds, static HTML drops straight into it, the URL sits under a well-known cloud provider's parent domain, and the whole thing can be abandoned the moment it draws attention. The abuse pattern is not new. Netskope Threat Labs has tracked a sharp rise in malicious pages hosted on DigitalOcean, including Spaces buckets used as intermediate landing pages inside phishing redirect chains, and public blocklists have struggled to act on the shared digitaloceanspaces[.]com endpoints without harming legitimate traffic, because the platform carries real customer content and blunt apex-level blocking is not an option.
The lure theme is equally well-trodden. Fake Costco, Starbucks, and gift-card "reward survey" emails have been a fixture of consumer phishing for years, and vendors including KnowBe4 and Costco's own fraud-awareness pages document the same funnel: a trusted-brand reward offer, a short survey, then a page that harvests personal and payment data behind a small "shipping fee." What sets this operation apart is not the pretext but the delivery machine behind it. The campaign has run continuously since 20 January 2026, still active more than five months later and delivering tens of thousands of phishing emails, and it treats the cloud-storage bucket as the disposable unit of the whole system.
Discovery and Infrastructure
The operation surfaces as a wall of near-identical email: a brand name in the display field, a plain gmail[.]com address behind it, one or two sentences of body, and a single link to a DigitalOcean Spaces bucket. Mapping it starts from that link. Every message carries exactly one scannable URL, and it is always a Spaces bucket host, so the bucket inventory is the backbone of the campaign.
Two properties stand out immediately. First, the per-bucket volume is flat: no single bucket carries much traffic, and the operator clearly prefers many short-lived hosts to a few durable ones. Second, the sender side is just as disposable. Nearly every Gmail address sends a small handful of messages and never returns, with the display name carrying the brand and the underlying freemail address carrying nothing. That mismatch, a strong brand name on a generic Gmail mailbox, is the first structural tell.
| Indicator | Role | Notes |
|---|---|---|
digitaloceanspaces[.]com (apex + regional endpoints) |
Abused platform | Legitimate DigitalOcean object storage; never operator-owned. Only per-bucket subdomains are operator infrastructure. |
<bucket>[.]<region>[.]digitaloceanspaces[.]com |
Landing | Operator-controlled buckets; each hosts a redirect page and is rotated quickly. |
gmail[.]com one-shot accounts |
Sender | Throwaway burners, brand name in display field, a few sends each. |
jcpenny[.]org |
Sender / relay | Aged-dropped typosquat apex used by a secondary path-style delivery variant. |
How It Works
A representative chain runs as follows. The victim receives a brand-skinned email from a Gmail burner. The body is short, references a reward, survey, order, or storage alert, and contains one link into a Spaces bucket ending in /1.html with a # fragment appended. The bucket page is small. Its JavaScript reads the fragment, which the browser never sends to the server, and redirects the victim to the real scam destination, typically a survey funnel that collects personal details and payment-card data. Because the fragment stays client-side, anything inspecting the email or fetching the bucket sees only the trusted-looking storage host and a static HTML file. The onward hop is invisible to server-side URL extraction.
From: "Costco" <[gmail burner]@gmail[.]com>
Subject: Re: Order Inquiry
Return-Path: <[gmail burner]@gmail[.]com>
[recipient token], ..
hxxps://rfdepl787hjcvsdfgh[.]sfo3[.]digitaloceanspaces[.]com/1.html#[user token]
Sample Lures
The campaign is email-only. The samples below are real lures with all recipient data removed and every host defanged; only attacker-side content remains.
Costco post-purchase reward, the dominant brand skin:
From: "Costco" <[gmail burner]@gmail[.]com>
Subject: Re: Order Inquiry
[recipient token] ..
hxxps://rfdepl787hjcvsdfgh[.]sfo3[.]digitaloceanspaces[.]com/1.html#[token]
AAA loyalty and travel survey, with a prepended junk token used as filler:
From: "AAA Loyalty Bonus" <[gmail burner]@gmail[.]com>
Subject: How did we do?
K1Afo0XJDpFR This is making travel more simple
hxxps://zertyuioe2[.]sfo3[.]digitaloceanspaces[.]com/1.html#[token]
Generic cloud-storage scareware, carried with no brand skin at all:
From: "CONFIRMATION PAYMENT CLOUD FAILED: STORAGE ACCESS AT RISK" <[gmail burner]@gmail[.]com>
Subject: Cloud Storage
System Alert: Uploads have failed... Data Lifecycle Notice: Files...
hxxps://[random-bucket][.]sfo3[.]digitaloceanspaces[.]com/1.html#[token]
Health clickbait using homoglyph display names, where lowercase l is swapped for uppercase I:
From: "CNNHeaIth" <[gmail burner]@gmail[.]com>
Subject: RE: BiII Gates Science
[token] ...
hxxps://[random-bucket][.]sfo3[.]digitaloceanspaces[.]com/1.html#[token]
Technical Analysis
Bucket-Naming Taxonomy and Sub-Clusters
Bucket names are not random in the way they first appear. They cluster into a few generation styles, and those styles line up with distinct sub-operators sharing one kit. The dominant style is high-entropy keyboard-mash, strings of adjacent-key runs with no dictionary content. A second style is brand-squatting, most often on Costco, with a recurring 48/49 numeric infix that acts as an operator marker. A third style, tied to a different sub-cluster, is long all-numeric strings that embed date fragments such as 2026.
| Naming template | Defanged examples | Sub-cluster | Primary region(s) |
|---|---|---|---|
| Keyboard-mash gibberish | fsfsfs, sddcfsdf, dfghjkoiuytrertyui, jfd6dhfhmfdgh85gdg |
Core operator | sfo3 |
| Character-family runs | plomhgf…, ploplomaz…, reg9r6g5rg…, drg3rg3r2g5rg6r |
Core operator (scripted) | sfo3 / lon1 |
Costco brand-squat (48/49 infix) |
bestofcostco48, costco43best, ya3acostcobeach, costconew1day |
Brand-squat variant | sfo3 / sfo2 / nyc3 |
| Other brand-squat | paymentus, researchgatecontent, economy |
Brand-squat variant | nyc3 / sfo3 / sgp1 |
| Date-string all-numeric | 900110242026036201854637, 2873405119001403202676 |
Date-string sub-operator | sfo2 / tor1 |
Region Grammar and Footprint
The operator has used all 11 DigitalOcean Spaces regions, but the distribution is lopsided. Roughly two-thirds of the operator's buckets sit in sfo3, which reads as the kit's default region, with a long tail spread thinly across the rest. Over the campaign's life the concentration in sfo3 tightened further, ams3 fell away sharply, and two regions absent early on, atl1 and syd1, came online mid-run. The counts below come from the campaign's baseline mapping window and sample the larger inventory.
| Region | Operator bucket hosts (observed) | Share of footprint |
|---|---|---|
| sfo3 | 923 | ~64% |
| nyc3 | 118 | ~8% |
| ams3 | 101 | ~7% |
| fra1 | 79 | ~5% |
| tor1 | 60 | ~4% |
| lon1 | 59 | ~4% |
| sfo2 | 55 | ~4% |
| sgp1 | 21 | ~1% |
| atl1 | 14 | ~1% |
| syd1 | 13 | ~1% |
| blr1 | 3 | <1% |
The Affiliate Fragment and Client-Side Redirect
The URL fragment is the operator's tracking layer and the reason the campaign is so hard to follow past the bucket. The primary fragment format is #cl/<affiliate_id>_md/<nums>/<nums>/<user_token>/0/0. The affiliate ID sits in discrete batches that span from low three-digit values up past 340,000, and the same batches show up across different bucket-naming families, which is one of the strongest signals that the gibberish and brand-squat buckets belong to one toolkit rather than to unrelated actors. A second fragment format, an opaque 60-character token with no cl/ prefix, appears on a minority of lures. Because the fragment is a URL anchor, the browser resolves it locally and never transmits it, so the redirect it drives is opaque to any server-side fetch of the bucket.
Kit Versioning and Rotation
The kit is versioned, and the changes are visible in the URL path and the fragment batches. Early buckets served /1.html; over time /2.html, /3.html, and a newer /4.html appeared, each a variant of the same redirect page. The affiliate-ID batches drifted upward as the campaign ran, with the earliest batches retired and higher ranges taking the largest share, consistent with an affiliate ID space that simply advances over time. The 60-character fragment format gained ground in later samples. None of this changes what the kit does; it is the ordinary churn of a maintained toolkit.
Content-Level Evasion
Three evasion tricks sit on top of the delivery machine. Display names use homoglyph substitution, swapping uppercase I for lowercase l to render a brand string that looks identical to a human but does not match on exact string comparison, as in the CNNHeaIth and BiII Gates health-clickbait cluster. Bodies are padded with short random token strings and filler sentences to dilute the signal available to content analysis. And later waves inject fake unsubscribe anchors that point at reputable third-party domains, a major social platform and a university among them, all sharing one constant trailing token, which suggests a single list-management or open-redirect substrate abused to borrow those domains' reputation.
The Secondary Custom-Apex Variant
Alongside the bucket kit, a smaller variant delivers from custom sender apexes rather than Gmail and uses path-style Spaces URLs (nyc3[.]digitaloceanspaces[.]com/<bucket>/) instead of subdomain-style bucket hosts. Its apexes split into two registration cohorts: freshly registered .org and .com names from late 2025, and an aged-dropped-domain cohort re-registered from long-idle names, including the typosquat jcpenny[.]org (a single-e misspelling of the real JCPenney domain). This variant looks like a separate affiliate running a lead-generation monetization model on the same underlying kit rather than the core reward-survey operator.
Detection Observations
The campaign's traffic separates from legitimate DigitalOcean Spaces usage on a handful of behavioral signals that a defender can key on. A strong brand name in the display field sitting on a plain gmail[.]com address is the first: real brands do not send loyalty mail from freemail. The single body link is a Spaces bucket host with a numeric HTML filename and a # fragment (/1.html through /4.html, followed by a #cl/…_md/… anchor), a shape that ordinary customer content on the platform rarely takes. Bucket labels themselves carry signal, either high-entropy keyboard-mash with no dictionary tokens or a brand string squatted under a region endpoint. Homoglyph substitution in a display name, an uppercase I where a lowercase l belongs, is a deliberate marker. And a fake unsubscribe anchor on a reputable third-party domain that shares a fixed trailing token across unrelated messages is a reliable cross-message pivot. The affiliate fragment and the shared kit HTML paths are the strongest links for clustering buckets to one operator.
Indicators of Compromise
All indicators are defanged. Victim data has been removed. The apex digitaloceanspaces[.]com and its regional endpoints are legitimate shared infrastructure and are not indicators.
Senders
| Value | Role | Notes |
|---|---|---|
hdhdgdjduhusbs@gmail[.]com |
Sender | One-shot burner |
hamiuyeoorss@gmail[.]com |
Sender | One-shot burner |
ghfxttgiugfd@gmail[.]com |
Sender | Costco skin |
abouannar@gmail[.]com |
Sender | One-shot burner |
analhh073@gmail[.]com |
Sender | One-shot burner |
tonk7812@gmail[.]com |
Sender | One-shot burner |
sunainah5538@gmail[.]com |
Sender | One-shot burner |
ptrschisomo@gmail[.]com |
Sender | One-shot burner |
nermin2661998@gmail[.]com |
Sender | One-shot burner |
ankitkumar80756622@gmail[.]com |
Sender | One-shot burner |
alokk852043@gmail[.]com |
Sender | Costco skin |
akoladeola99@gmail[.]com |
Sender | One-shot burner |
meyragnhild012@gmail[.]com |
Sender | Brand-rotation burner |
farceuse2@gmail[.]com |
Sender | Costco skin |
tondam341@gmail[.]com |
Sender | Costco skin |
| … (representative subset; the operator ran more than 3,000 one-shot Gmail sender accounts) |
Domains
| Value | Role | Notes |
|---|---|---|
jcpenny[.]org |
Sender / relay | Aged-dropped typosquat apex (real brand is jcpenney[.]com); secondary path-style variant |
Hosts
| Value | Role | Notes |
|---|---|---|
jfd6dhfhmfdgh85gdg[.]sfo3[.]digitaloceanspaces[.]com |
Landing | Keyboard-mash bucket |
apm67hgyjt9jhpmf[.]sfo3[.]digitaloceanspaces[.]com |
Landing | Keyboard-mash bucket |
hngbfmmldpfdoosfl[.]nyc3[.]digitaloceanspaces[.]com |
Landing | Keyboard-mash bucket |
gvhjftgyhdfgfxg[.]ams3[.]digitaloceanspaces[.]com |
Landing | Keyboard-mash bucket |
drg3rg3r2g5rg6r[.]lon1[.]digitaloceanspaces[.]com |
Landing | Character-family bucket |
mqpalagsht11cdfhg2jhil[.]fra1[.]digitaloceanspaces[.]com |
Landing | Keyboard-mash bucket |
bestofcostco48[.]sfo3[.]digitaloceanspaces[.]com |
Landing | Costco brand-squat |
ya3acostcobeach[.]sfo3[.]digitaloceanspaces[.]com |
Landing | Costco brand-squat |
costconew1day[.]sfo2[.]digitaloceanspaces[.]com |
Landing | Costco brand-squat |
paymentus[.]nyc3[.]digitaloceanspaces[.]com |
Landing | Brand-squat bucket name |
researchgatecontent[.]sfo3[.]digitaloceanspaces[.]com |
Landing | Brand-squat bucket name |
economy[.]sgp1[.]digitaloceanspaces[.]com |
Landing | Brand-squat bucket name |
| … (representative subset; the operator built more than 2,000 distinct bucket hosts across 11 regions) |
URLs
| Value | Role | Notes |
|---|---|---|
hxxps://<bucket>[.]<region>[.]digitaloceanspaces[.]com/1.html#<fragment> |
Landing | Dominant kit signature |
hxxps://<bucket>[.]<region>[.]digitaloceanspaces[.]com/1.html#cl/<id>_md/<nums>/<nums>/<token>/0/0 |
Landing | Affiliate fragment (format A) |
hxxps://<bucket>[.]<region>[.]digitaloceanspaces[.]com/[1-4].html#<60-char-token> |
Landing | Affiliate fragment (format B) + path variants |
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE Fight Fraud Framework (F3) (https://ctid.mitre.org/fraud).
| Tactic | Observed behavior | Campaign behavior |
|---|---|---|
| Resource Development | Acquire infrastructure | Cloud object-storage buckets and one-shot freemail accounts spun up and rotated as disposable units |
| Initial Access | Phishing message | Brand-skinned reward, survey, order, and storage-alert emails |
| Initial Access | Impersonate trusted brand | Display-name spoofing of roughly 18 retail and service brands, reinforced by homoglyph display names |
| Execution | Direct to attacker-controlled resource | Single bucket link, client-side fragment redirect to a survey funnel |
| Monetization | Harvest credentials and payment data | Survey funnel collects personal details and payment-card data |
| Stealth | Rotate and obscure infrastructure | One-shot bucket and sender rotation, client-side fragment redirect, borrowed-reputation unsubscribe anchors |
Conclusion
The bucket is the disposable unit here, and that is what makes the operation durable. Individual buckets and senders burn out in days, but the kit behind them is stable: the same fragment schema, the same handful of HTML paths, the same naming families across a shifting set of storage regions. Defenders watching this pattern should track it at the kit level rather than chasing hosts, because the fingerprint outlives any single bucket. Expect the naming families and region mix to keep drifting, and expect the client-side redirect to remain the operator's main tool for keeping the final destination out of view.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.