The Double-Slash Phishing Toolkit: One Body, Many Pretexts
The Double-Slash Phishing Toolkit: One Body, Many Pretexts
Since early 2026, one operator has run a phishing toolkit that hides its pretext behind double slashes and one malformed MIME header. The lure on the surface keeps changing: a declined payment, an expiring McAfee subscription, a support ticket waiting on a reply, a data-deletion countdown, a plasma-donation welcome, a T-Mobile rewards prize. Underneath, the build barely moves. The same eight-character return-path scheme, the same three-way click-tracking link, the same self-referential unsubscribe header, and on most rails a malformed MIME body that no real mail client would emit. That invariant core is what tied more than seventy compromised mail servers, a fleet of coined throwaway domains, and roughly twenty VPS click-servers back to a single operator running one kit behind many masks.
Key Takeaways
- One operator carries a single message build across six interchangeable pretext rails, so the visible lure is disposable and the build is the durable fingerprint.
- The kit's sharpest static tell is a malformed
multipart/form-dataMIME body, a content-type defined for web form uploads and never valid in email, carried on most rails. - Delivery rides more than seventy compromised legitimate mail servers, which hands the operator clean SPF, DKIM, and DMARC on domains with real sending history.
- Click destinations are mostly IPv6-mapped-IPv4 literal URLs that carry no domain reputation, with an AWS S3 static-bucket landing as a per-batch sibling.
- Display names mutate their separators (
//,///, the registered-trademark symbol, single-space padding, full letter-spacing) to keep brand and pretext words out of reach of naive keyword matching. - Two registration cohorts separate cleanly: aged, privacy-free compromised victims against a fresh Namecheap-privacy batch of operator-coined apexes.
Background
Email authentication answers one question: was this message sent from infrastructure the domain authorized. It says nothing about intent. When the sending domain itself is compromised, a phishing message passes SPF, DKIM, and DMARC cleanly, because it really was sent by the domain's own authorized servers. Auth-based filtering has no failing signal to work with, and the message inherits the standing of a genuine, previously-clean business. That is the foundation this operator builds on. Delivery runs through more than seventy hijacked WordPress and small-business mail servers, most of them aged domains with years of legitimate reputation.
The click destinations are chosen to have no reputation at all. Most CTAs are IPv6-mapped-IPv4 literal URLs, shaped like http[:]//[::ffff:5ccc:f083]/qs=r-<token>. The bracket notation marks a literal IPv6 address, the ::ffff: prefix marks an IPv4-mapped address, and the two trailing hex groups are the four IPv4 octets written in hexadecimal. [::ffff:5ccc:f083] resolves to 92.204.240[.]131. Many gateways and reputation engines pull domains and IPs out of a message with simple patterns that never expand a bracketed hex literal, so the link has nothing to score and no blocklist entry to match. The Internet Storm Center has documented the same IPv4-mapped-IPv6 trick in banking phishing (ISC diary 33090).
A minority of batches swap the literal for an AWS S3 static-website landing, served from s3.us-east-1.amazonaws[.]com/<20-char-bucket>/links.html. S3 buckets can host public static pages, so an attacker uploads a credential-capture page to a randomly named bucket and serves it from a trusted, widely-allowlisted AWS domain. The bucket names are twenty-character random strings and rotate per blast, which makes the apex un-flaggable and the individual bucket short-lived. Two other conveniences round out the kit. The body carries a multipart/form-data content-type, which belongs to HTTP form uploads under RFC 7578 and never appears in a well-formed email (legitimate multipart email is mixed, alternative, or related). And each message includes a List-Unsubscribe header, a legitimacy signal that major mailbox providers reward, pointed at a self-referential abuse@<domain> address or, on some batches, a random-label .edu host that borrows institutional trust.
The IPv4 backends behind the literal CTAs resolve to disposable instances on cheap VPS providers: OVH, ColoCrossing and M247, Hetzner, LeaseWeb, and Hostwinds. These are legitimate hosting businesses whose rapidly-provisioned instances are abused by the operator, not parties to the abuse.
Discovery and Infrastructure
Two anomalous sender clusters surfaced together: one running date-stamped data-deletion subjects, the other running fake-antivirus and cloud-storage renewal lures with double slashes stuffed into the display name. They shared senders. A handful of domains sent both pretexts inside the same window, which is what first suggested one operator rather than two. Decoding a single message from each cluster settled it. Both carried the identical malformed MIME boundary, the identical noReply_<8 lowercase alpha>@ return-path, and the identical three-way click-tracking link. From there the cluster kept growing every time we pulled the thread, first a reactivation wave of fresh compromised relays, then new pretext themes, then a set of operator-registered domains sitting alongside the hijacked victims.
The operator-registered apexes are the part worth naming, because everything else in the sending path is a compromised victim. These are coined, meaningless tokens with no brand resemblance, and they cluster into a clean registration cohort described in the Technical Analysis below.
| Operator-coined apex | Role | Notes |
|---|---|---|
jobsined.co[.]uk |
Coined sending apex | Expired registration, no WHOIS org, the only coined apex also flagged malicious at the domain level |
vexorantil[.]fun |
Coined sending apex | Plasma-donation "New Donor Welcome" rail |
procarelight[.]biz |
Coined sending apex | McAfee renewal rail |
collabpulse365[.]com |
Coined throwaway apex | Reward rail, multiple senders, Namecheap-privacy batch |
agrupacionponta[.]com |
Operator-pair From apex | Paired with agrupacionpontana[.]com as return-path, Costco reward rail |
mailrouteflow[.]net |
Relay-shaped coined domain | Named to mimic a mail-routing service |
lrfisqgkhl[.]xyz |
Throwaway unsubscribe host | Per-send List-Unsubscribe abuse address |
How It Works
A recipient gets a message that passes every authentication check, because it came from a real, compromised business. The display name reads Security//Alert, Mcafee//Account//Suspended, T-Mobile-US//Rewards, or P A Y E M E N T-D E C L I N E D, depending on the pretext of the day. The subject supplies urgency: a payment was declined, a subscription lapses today, a support case needs a reply, data will be deleted, a reward expires in ten minutes.
The body is short and vague, and it carries a single call to action repeated three times. Each copy of the link is emitted with an r, ua, or op suffix variant, a click-tracking triple the operator uses to distinguish render, user-agent, and open events. The link points either at an IPv6-mapped-IPv4 literal that lands on a VPS-hosted credential form, or at an S3 bucket serving the same front-end. Whichever host the batch uses, the destination is a credential and payment-data capture page dressed as the impersonated brand. The List-Unsubscribe header rounds off the disguise, and the return-path quietly reverts to the operator's canonical noReply_<8>@ scheme even when the visible From address wears a different mask.
Sample Lures
All samples are defanged and stripped of recipient data. Attacker-controlled content only.
Payment-declined rail, letter-spaced separator, sent through a compromised relay whose return-path apex differs from the From apex:
From: "P A Y E M E N T-D E C L I N E D" <cmslists@casinogamingtechnology[.]com>
Subject: Your payment was declined
Return-Path: noReply_smgsocay@empa.flixbus[.]de
Content-Type: multipart/form-data; boundary="=-_-MZ_-_f346f00...."
CTA (x3): http[:]//[::ffff:bf65:837b]/qs=[r|ua|op]-<token> (= 191.101.131[.]123)
Fused fake-AV and data-deletion pretext, IPv6-literal CTA:
From: "PAYMENT//FAILED" <noreply@hotfeaturefilms[.]com>
Subject: [LAST CALL] Data Deletion Sequence Initiated - No Recovery Possible
Return-Path: noReply_gbgrqoki@hotfeaturefilms[.]com
Content-Type: multipart/form-data; boundary="=-_-XEA_-_f44a2090...fe1"
CTA (x3): http[:]//[::ffff:9e45:7478]/fTqK.[r|ua|op]~J~<tokens>
List-Unsubscribe: hotfeaturefilms[.]com/unsubscribe?email=abuse@hotfeaturefilms[.]com
Cloud-storage pretext with the AWS S3 landing sibling:
From: "cloud//storage" <noreply@noreply.millbrookfiredept[.]org>
Subject: Your Data Could Be Exposed - Take Action
Return-Path: noReply_xpzrqqsp@noreply.millbrookfiredept[.]org
CTA (x3): http[:]//s3.us-east-1.amazonaws[.]com/bxanysljnjwwdapgakotaqmjh/links.html#HxR13/[r|ua|op]_XvX_<tokens>
Plasma-donation pretext on a coined .fun apex, dotted letter-spacing:
From: "N.e.w_D.o.n.o.r_W.e.l.c.o.m.e" <noreply@vie.vexorantil[.]fun>
Subject: New Donor Welcome
Return-Path: noReply_aditpfje@vie.vexorantil[.]fun
CTA (x3): http[:]//[::ffff:335b:e5ab]/qs=[r|ua|op]-<token> (= 51.91.229[.]171)
Carrier-rewards pretext, S3 landing variant:
From: "T-Mobile-US//Rewards" <no-reply@groovenexus[.]com>
Subject: Your T-Mobile Rewards Now Include HP Devices
Return-Path: noReply_fyvvgvlw@groovenexus[.]com
CTA (x3): http[:]//s3.us-east-1.amazonaws[.]com/gx7lset0k8arozc90tiixtwjd3bo/link1.html#qs=[r|ua|op]-<token>
Technical Analysis
The Invariant Body Fingerprint
Three markers appear on every rail, in every sending configuration, regardless of the pretext or the host. A fourth, the malformed MIME body, rides most of them. Together they are the operator signature, and each survives changes the others do not.
- Return-path envelope:
noReply_<8 lowercase alpha>@<domain>. The canonical single-token form appears in the Return-Path header even when the visible From local-part is dressed up as something else. - Click-tracking triple: every CTA is emitted three times with
r,ua, andopsuffix variants. - Self-referential unsubscribe:
<domain>/unsubscribe?email=abuse@<domain>, with per-batch variants pointing the abuse address at a random-label.edu, a throwaway.xyz, or a spoofed-brand subdomain. - Malformed MIME body, on most rails:
Content-Type: multipart/form-data; boundary="=-_-<2-3 alpha>_-_<40-80 hex>". A compliant mailer never emitsmultipart/form-dataas an email body, so it is the sharpest static tell wherever it appears.
The MIME content-type is the one marker that does move, and how it moves is itself evidence of a single operator. One domain sent both a fake-ticket message with the illegal multipart/form-data body and a rewards message with a standard multipart/mixed body, under one return-path scheme, in the same window. The content-type varies by pretext inside one operator, not across two.
Sending Infrastructure Taxonomy
The operator sends through five distinct configurations, all carrying the same body and CTA fingerprint. The classic payment, McAfee, and ticket rails run on single-domain compromised hosts. The reward rails introduced the coined-apex, operator-pair, and numeric-prefix models.
| Configuration | Defanged example | Notes |
|---|---|---|
| Compromised-legit SMB, single domain | noreply@mail.cap-tain[.]com |
Hijacked mail server, From apex equals return-path apex, aged legitimate WHOIS, burn and rotate |
| Coined throwaway apex, dotted two-token From | noreply_<8alpha>.<rand>@collabpulse365[.]com |
From is a dotted two-token local-part, return-path reverts to the canonical single-token form |
| Operator-pair chained relay | From agrupacionponta[.]com, return-path agrupacionpontana[.]com |
Both apexes operator-controlled, near-identical coined names, registered the same week |
| Numeric-prefix chained relay | noreply@352915.ephototemplates[.]com |
Six-digit label on a compromised SMB host, carries the Costco reward burns |
| Coined relay-shaped domain | noreply.baq@mailrouteflow[.]net |
Purpose-built to resemble a mail-routing service |
A separate bounce-relay pool (carnation4th[.]org, empa.flixbus[.]de, evolv[.]ca, and others) carries return-paths for this operator and for unrelated warranty and auto campaigns in the same windows. These are abused or compromised third-party mail hosts, not operator property, so a return-path apex alone is not a reliable operator attribution and should not be blocked at the apex. The body fingerprint is the reliable signal.
Display-Name Obfuscation Grammar
The visible display name is a product of a separator family crossed with a pretext-noun set. The separators started at // and drifted over successive waves into ///, the registered-trademark and degree symbols, single-space padding, and full letter-spacing (P A Y E M E N T, N.e.w_D.o.n.o.r, C.o.s.t.c.o). The nouns run from the original payment and antivirus vocabulary (Payment, McAfee, Norton, Cloud, Security, Device) into the reward set added later (Rewards, Giveaway, PromoGift, Surprise, Deals, Benifits, MemberAccess) and brand tokens (T-Mobile, Costco, UnitedHealthcare, HP).
One detail outlasts every separator change: a spelling error the operator never fixed. PAYMENT is consistently rendered PAYEMENT, and Benefits as Benifits. That misspelling survives every separator mutation, which makes it a durable, high-signal token even as the punctuation around it keeps changing. Local-part obfuscation mirrors the display name (payment/declined@, payment///declined@, data/destroyed@, mcafee///security@).
Registration Cohorts
Public WHOIS splits the sending domains into two cleanly separated cohorts. The compromised victims are old, registrar-mixed, and carry no privacy service. The operator's own domains are a tight, recent, single-registrar batch.
| Operator-coined apex | Registrar | Created | Notes |
|---|---|---|---|
aspencarpets[.]com |
Namecheap | 2025-07-02 | Privacy-registered, reward rail |
yojisecurity[.]com |
Namecheap | 2025-10-29 | Privacy-registered, reward rail |
lanciavyp[.]com |
Namecheap | 2026-01-28 | Privacy-registered, reward rail |
dheacigna[.]com |
Namecheap | 2026-02-26 | Privacy-registered coined lookalike (not Cigna-owned), same-day batch |
collabpulse365[.]com |
Namecheap | 2026-02-26 | Privacy-registered, same-day batch |
mailout[.]one |
Namecheap | 2026-04-14 | Relay-shaped coined domain |
mailrouteflow[.]net |
Namecheap | 2026-04-17 | Relay-shaped coined domain |
agrupacionponta[.]com |
Namecheap | 2026-04-24 | Operator-pair, registered the same week as its return-path twin |
guggulbolic[.]com |
Namecheap | 2026-05-26 | Privacy-registered |
jobsined.co[.]uk |
GoDaddy | 2024-04-30 | Expired, no WHOIS org, flagged malicious |
The purpose-built pool is a single-registrar signature: Namecheap, "withheld for privacy" contact, roughly one-year terms, creation dates clustered from mid-2025 through mid-2026, with tight same-day batches (two apexes on 2026-02-26, the relay-shaped domains within a fortnight in April). Coined TLDs skew to .fun, .io, .biz, .one, .ai, and .co.uk beyond .com. By contrast, the compromised victims spot-check to 2000 through 2018 creation, null WHOIS org, and mixed registrars with no privacy service. None of the compromised apexes carry a reputation flag, because they are victims, not operator property.
CTA Backends and Shared-Host Tells
The IPv6-mapped literal decodes directly to an IPv4 VPS backend, and a few of those backends give away the shared operator through host reuse. The seed-apex column names an associated sending domain, most of which are compromised victims rather than operator property.
| Defanged IPv4 backend | Provider / range | Seed apex |
|---|---|---|
5.135.51[.]176 |
OVH | guggulbolic[.]com |
51.91.229[.]171 |
OVH | vexorantil[.]fun |
23.254.204[.]193 |
Hostwinds | athruzrentalcenter[.]com |
162.255.85[.]125 |
Namecheap / Hostwinds | shreemncreation[.]com |
38.180.57[.]145 |
ColoCrossing / M247 | thedancedimension[.]com |
95.211.158[.]241 |
LeaseWeb | 4lovepoems[.]com |
92.204.240[.]131 |
GoDaddy / Secureserver | jobsined.co[.]uk and broad payment rail |
188.40.189[.]178 |
Hetzner | Carrier-rewards rail |
191.101.131[.]123 |
shared | casinogamingtechnology[.]com and tiernahrung-freund[.]com |
168.100.174[.]250 |
shared /24 | flourishcache[.]com |
168.100.174[.]251 |
shared /24 | bromexilo[.]com |
95.173.178[.]180 |
shared /24 | Carrier-rewards rail |
95.173.178[.]182 |
shared /24 | groovenexus[.]com (fake-ticket rail) |
Three reuse patterns are the strongest cross-rail links. One backend, 191.101.131[.]123, fronts two different seed apexes. 168.100.174[.]250 and [.]251 are consecutive addresses on one backend host. And 95.173.178[.]180 and [.]182 sit in the same /24, tying the carrier-rewards rail's backend to the classic fake-ticket rail's backend. The S3 sub-variant uses twenty-character lowercase random buckets serving links.html or link1.html with the same r, ua, op triple in the fragment; confirmed buckets include bxanysljnjwwdapgakotaqmjh, slmiyeittnehaabrdqplwtbvv, and gx7lset0k8arozc90tiixtwjd3bo.
How the Rails Diverge and Converge
The classic payment, McAfee, and ticket rails run on single-domain compromised hosts. The reward rails (Costco, T-Mobile, UnitedHealthcare) run on coined throwaway apexes, operator-pair chained relays, a numeric-prefix relay pool, and coined relay-shaped domains, backed by the shared bounce-relay pool. Sending topology and pretext noun change; the body, the CTA triple, and the return-path scheme do not. That is the whole design: a stable core kit with a swappable delivery skin and a swappable lure.
Detection Observations
The behavioral signals that separate this traffic from legitimate mail sit almost entirely in the message build, not in the pretext. The malformed multipart/form-data body is the cleanest of them, since well-formed mail never carries it. The noReply_<8 lowercase alpha>@ return-path, the three-way r/ua/op click triple, and the self-referential abuse@<domain> unsubscribe header each recur across every pretext and every host, so any two of them appearing together is a strong combined signal. The malformed multipart/form-data body, present on most rails, is the cleanest single tell when it appears, since well-formed mail never carries it. The PAYEMENT and Benifits misspellings hold their value across separator changes.
The operator's active evasion arc lives in the display name. Each new separator form (triple slash, symbol separators, single-space padding, letter-spacing) is an attempt to keep the brand and pretext keywords out of reach of matching that keys on clean tokens. The durable answer is to key on the invariant body markers rather than the mutating surface, and to normalize separators and known misspellings before any keyword comparison. The authentication paradox is worth stating plainly for defenders: a full SPF, DKIM, and DMARC pass on this traffic is expected, not reassuring, because the sending domain is a compromised victim. Auth results carry no weight here; content, URL shape, and header structure carry all of it.
Indicators of Compromise
All indicators are defanged. The sender list is a representative subset, and most sender domains are compromised legitimate mail servers, not operator property. Do not block a compromised apex at the domain level. Operator-coined domains and CTA backends are listed separately.
Senders (representative subset)
| Value | Role | Notes |
|---|---|---|
noreply@mail.cap-tain[.]com |
Sender (compromised) | High-volume classic rail |
payement.declined@mail.canadagrillhale[.]com |
Sender (compromised) | Payment-declined rail |
cmslists@guggulbolic[.]com |
Sender | cmslists@ prefix, payment-declined |
customersupport@808vacation[.]com |
Sender (compromised) | Fake-ticket rail |
mcafee.security.team@staging.marketingxxi[.]com |
Sender (compromised) | McAfee rail |
mcafee@procarelight[.]biz |
Sender (operator-coined) | McAfee rail |
noreply@vie.vexorantil[.]fun |
Sender (operator-coined) | Plasma-donation rail |
noreply@jobsined.co[.]uk |
Sender (operator-coined) | Payment//Required, domain flagged malicious |
no-reply@groovenexus[.]com |
Sender (compromised) | Carrier-rewards rail |
noreply@agrupacionponta[.]com |
Sender (operator-pair) | Costco reward rail |
noreply@352915.ephototemplates[.]com |
Sender (numeric-prefix relay) | Costco reward burns |
noreply.baq@mailrouteflow[.]net |
Sender (operator-coined relay-shaped) | Reward rail |
noreply@paste-card.komtekcommunications[.]com |
Sender (compromised) | Payment//Required clone |
noreply@knacka.liberalerna[.]se |
Sender (compromised) | PAYEMENT//declined |
noreply@indepthresearch[.]org |
Sender (compromised) | Payment-declined rail |
(Representative subset; 500+ verified-malicious sender addresses catalogued, the large majority compromised legitimate hosts.)
Operator-Coined Domains
| Value | Role | Notes |
|---|---|---|
jobsined.co[.]uk |
Operator sending apex | Coined, expired, flagged malicious |
vexorantil[.]fun |
Operator sending apex | Plasma-donation rail |
tonira[.]fun |
Operator sending apex | Payment rail |
procarelight[.]biz |
Operator sending apex | McAfee rail |
buildrz[.]io |
Operator sending apex | Payment rail |
collabpulse365[.]com |
Operator throwaway apex | Reward rail |
lanciavyp[.]com |
Operator throwaway apex | Reward rail |
aspencarpets[.]com |
Operator throwaway apex | Reward rail |
agrupacionponta[.]com |
Operator-pair From apex | Costco rail |
agrupacionpontana[.]com |
Operator-pair return-path apex | Costco rail |
mailrouteflow[.]net |
Relay-shaped coined domain | Reward rail |
Operator Throwaway Unsubscribe Domains
| Value | Role | Notes |
|---|---|---|
lrfisqgkhl[.]xyz |
List-Unsubscribe abuse host | Per-send throwaway |
txtlnlrsop[.]xyz |
List-Unsubscribe abuse host | Per-send throwaway |
CTA Backend IPs (representative subset)
| Value | Role | Notes |
|---|---|---|
5.135.51[.]176 |
CTA backend | OVH |
51.91.229[.]171 |
CTA backend | OVH |
23.254.204[.]193 |
CTA backend | Hostwinds |
162.255.85[.]125 |
CTA backend | Namecheap / Hostwinds |
38.180.57[.]145 |
CTA backend | ColoCrossing / M247 |
95.211.158[.]241 |
CTA backend | LeaseWeb |
92.204.240[.]131 |
CTA backend | GoDaddy / Secureserver |
188.40.189[.]178 |
CTA backend | Hetzner |
191.101.131[.]123 |
CTA backend | Shared across two seed apexes |
168.100.174[.]250 |
CTA backend | Consecutive /31 host |
168.100.174[.]251 |
CTA backend | Consecutive /31 host |
95.173.178[.]180 |
CTA backend | Same /24 as fake-ticket backend |
95.173.178[.]182 |
CTA backend | Same /24 as rewards backend |
(Representative subset; about twenty IPv6-mapped bare-IP CTA backends catalogued.)
URLs and Landing Patterns
| Value | Role | Notes |
|---|---|---|
http[:]//[::ffff:XXXX:XXXX]/qs=[r|ua|op]-<token> |
CTA (IPv6-literal) | Majority path, decodes to a VPS backend |
http[:]//[::ffff:9e45:7478]/fTqK.[r|ua|op]~J~<tokens> |
CTA (IPv6-literal) | Alternate token layout |
http[:]//s3.us-east-1.amazonaws[.]com/<20-char-bucket>/links.html#HxR13/[r|ua|op]_XvX_<tokens> |
Landing (S3 sibling) | Buckets rotate per blast |
satdxjdzxtfw-lkmzqn[.]edu |
Unsubscribe abuse host | Random-label .edu, no real institution |
MITRE Fight Fraud Framework Mapping
This maps to the MITRE Center for Threat-Informed Defense Fraud matrix (https://ctid.mitre.org/fraud). The mapping uses Fraud-matrix tactic and technique names; consult the live matrix for current technique identifiers.
| Tactic | Observed behavior |
|---|---|
| Resource Development | Acquire and compromise sending infrastructure (hijacked mail servers, coined domains, VPS backends) |
| Initial Access | Phishing message delivered by email across multiple pretext rails |
| Initial Access | Brand impersonation (McAfee, Norton, T-Mobile, Costco, UnitedHealthcare, HP) |
| Execution | Urgency and pressure (declined payment, lapsing subscription, expiring reward, open case) |
| Monetization | Credential and payment-data harvesting on VPS and S3 landing pages |
| Stealth | Delivery and landing obfuscation (IPv6-literal URLs, malformed MIME, display-name separators, compromised-relay authentication) |
Conclusion
The operator has treated the pretext as the cheap, disposable layer and the message build as the asset worth protecting. New lures, new separators, and new coined domains arrive wave after wave, while the eight-character return-path, the three-way click triple, and the self-referential unsubscribe header stay fixed, and a malformed MIME body rides most of them. That is exactly backward from where most detection effort points. Defenders watching this operator should anchor on the invariant build and the un-fixed misspellings, treat a clean authentication pass on aged domains as a neutral fact rather than a green light, and expect the next wave to change its face while keeping its skeleton.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.