One Number, One Domain: A Brand-Less Settlement-Mill Smishing Ring
One Number, One Domain: A Brand-Less Settlement-Mill Smishing Ring
Since February 2026, one operator has run an elder-fraud smishing ring that pairs each burner number with its own disposable cheap-TLD domain. The lures name no company, no law firm, and no agency. They arrive as first-name-personalized texts about a legal settlement, a "senior inflation relief" payment, or a state-treasury asset recovery, each carrying a bare link to a freshly registered throwaway domain. Over roughly 180 days the operator burned about 1,200 US-mobile numbers and about 1,200 disposable apex domains, one number to one domain, to push tens of thousands of scam texts at a recycled list of senior-skewed first names. The vagueness is the point: with no brand to check, an elderly target has nothing to call and verify against.
Key Takeaways
- The operator pairs one burner US-mobile number with one freshly registered cheap-TLD apex per blast, so taking down a single number or domain exposes none of the rest of the fleet.
- Every lure URL is bare-root: a random five-character subdomain on a short coined wordmark, no path, no query string, no tracking token, which strips most substring and path-reuse indicators.
- Domains come from two registrar factories, NameSilo with PrivacyGuardian.org for the exotic TLDs and Namecheap with Withheld for Privacy for a
.compool, registered in rolling weekly batches. - The pretexts deliberately impersonate no brand, which removes the victim-side verification path and the trademark owner who would otherwise drive a fast takedown.
- With no shared hosting, backend, or CDN across the pool, attribution rests on registrar cohort, domain-generation grammar, a recycled victim name list, and a shared pretext toolkit.
Background
Smishing that targets older adults is now one of the costliest consumer-fraud vectors in the United States. The FTC reported $470 million lost to scams that began with a text message in 2024, roughly five times the 2020 figure, and imposter scams remained the single largest fraud category at about $2.95 billion. The damage concentrates among seniors: the FBI's Internet Crime Complaint Center recorded roughly $4.9 billion in losses from victims aged 60 and older across about 147,000 complaints in 2024, with around 7,500 of those victims losing more than $100,000 each. Government-imposter, treasury, asset-recovery, and settlement or refund pretexts delivered by SMS sit at the center of that trend.
This operator industrializes that pretext family on cheap, disposable infrastructure. New generic top-level domains such as .rest, .click, .autos, .world, and .top are the hundreds of ICANN name spaces beyond legacy .com. Many sell for under a few dollars a year, and several registries and resellers have historically slower abuse response than .com, so a domain can survive a short smishing burst before anyone acts. Independent measurement backs this up: Interisle's Phishing Landscape 2024 found 42 percent of all domains reported for phishing were registered in new gTLDs, up from 25 percent the prior year, and among the 35 gTLDs with the highest phishing rates, 33 cost under $5. The same study noted a 51 percent rise in phishing at subdomain providers, which mirrors how this operator multiplies hostnames off each apex with random subdomain labels.
Two registrars and their in-house privacy proxies carry the rest of the model. NameSilo and Namecheap are high-volume discount registrars with self-service, API-driven bulk registration. Each pairs with a WHOIS privacy service, PrivacyGuardian.org for NameSilo and Withheld for Privacy for Namecheap, that replaces the registrant's real identity in public records. Together they let an operator stand up hundreds of anonymous domains and rotate to fresh ones the moment old ones burn.
Discovery and Infrastructure
Analysts first mapped the ring from a set of 14 seed pairs, each a US-mobile number tied to a single cheap-TLD apex, all first seen inside a two-day burst in late April 2026. Expanding on the shape of that infrastructure, a number matching +1 followed by a US-mobile pattern, sending a bare-root link to a four-to-eight-character wordmark on a cheap TLD, surfaced about 1,200 sibling numbers and about 1,200 sibling domains across the 180-day window.
The infrastructure has one structural rule that defines the whole operation: one burner number sends to exactly one apex domain, and each apex resolves to itself. There is no shared hosting provider, no shared resolved backend, and no CDN overlap anywhere in the pool. That is a deliberate compartmentalization choice. Killing one number or one domain removes a single victim thread and yields no pivot to the rest of the fleet, because there is no common host or reused domain to cluster on. The operator trades cost, roughly 1,200 numbers and 1,200 domains, for takedown resilience.
The domains fall into three naming families that all feed one generator:
| Family | Shape | Examples (defanged) |
|---|---|---|
| Coined wordmark on exotic TLD | Consonant-heavy pseudo-words, 4 to 8 chars | orbora[.]rest, gigosi[.]rest, coobey[.]click, biogix[.]autos, souragu[.]pro |
| Descriptive settlement or legal apex | Dictionary compensation phrasing | legalclaim[.]rest, settlementnow[.]rest, getpaid[.]rest, quicksettle[.]click, suemycase[.]rest |
.com finance or law abbreviation pool |
Vowel-dropped abbreviations plus an affix family | wekndcrd[.]com, jacktins[.]com, payaofr[.]com, savzofr[.]com, getzofr[.]com |
Across the 180-day sibling footprint, the cheap-TLD distribution skews heavily to .rest and .click:
| TLD | Domains | Senders |
|---|---|---|
| .rest | 510 | 531 |
| .click | 341 | 356 |
| .autos | 76 | 77 |
| .link | 55 | 60 |
| 37 | 40 | |
| .top | 32 | 32 |
| .pro | 30 | 31 |
| .world | 26 | 27 |
| .biz | 11 | 11 |
| .xyz / .live / .icu | 5 combined | 5 combined |
How It Works
A target on the operator's list gets a short text that opens with their first name and a fragment of officialese: a case that "remains active," a "path sync" tied to a ten-digit reference, a "Senior Inflation relief" payment pending confirmation, or an asset the state treasury is about to reclaim. The message closes with a bare link to a random subdomain on one of the throwaway apexes and, often, a countdown ("You have 7 minutes to verify your status").
Nothing in the text names a real institution. That is the operation's core evasion. A recipient who wants to check has no company to call, because none is named, and the domain in the link is a coined word they have never seen. The link itself resolves to a page on a domain registered days earlier, with no path or parameter that a filter could have seen before. If the recipient hesitates, the next day brings a fresh number, a fresh domain, and a slightly different pretext drawn from the same toolkit.
The personalization is not random. First names repeat across otherwise unrelated senders, and fixed first-name and surname pairings recur, which points to a purchased or leaked senior-demographic lead list of roughly 20 to 30 recurring entries rather than a per-recipient generator. Embedded ten-digit reference numbers also reappear across independent burners, consistent with victim-phone fragments carried along on the same list.
Sample Lures
The samples below are attacker-produced SMS bodies. Every recipient identifier has been removed: first names, embedded reference numbers, and subdomain labels are replaced with placeholders, and all domains are defanged. Only the attacker's pretext structure remains.
SMS, case-active and legal-threat pretext:
[first name] | Still no reply on the [reference #] path fix. If you stay silent to...
hxxps://[label].spelum[.]rest
SMS, senior inflation relief pretext:
Hi [first name], pardon this interruption today, however, your Senior Inflati...
hxxps://[label].eleganix[.]email
SMS, priority-access and digital-twin pretext:
[first name], your priority access registered under [name] is pending confirm...
hxxps://[label].souragu[.]pro
SMS, transfer and last-phase pretext:
[first name] - We are in the last phase of the process. Your input is essent...
hxxps://[label].plihod[.]rest
SMS, religious-providence pretext:
God opened this for you. This wasn't random...
Technical Analysis
The operation's durable fingerprint is not any single domain or number, all of which rotate daily, but the machinery that produces them. Four signals distinguish this traffic from legitimate messaging, and each survives the operator's daily infrastructure churn.
Domain-Generation Grammar
Three vocabularies drive the apex generator. The dominant stream is consonant-heavy coined wordmarks, pronounceable but meaningless, in CVCVCV or CVCCVC shapes of four to eight characters: orbora, gigosi, plihod, coobey, souragu, muniri, kurare, croshe. The second stream is literal settlement and legal phrasing concatenated into an apex: legalclaim, settlementnow, getcompensated, injuryclaim, suemycase. The third is a .com pool of vowel-dropped finance abbreviations (wekndcrd for "weekend card," btmsms, mnclncl) plus a templated affix family where a fixed -ofr stem, short for "offer," takes rotating prefixes: payaofr, paynofr, paycofr, payxofr, payzofr, savnwoffr, savzofr, getzofr.
Sibling artifacts confirm a single generator emitting near-duplicates. The apex animum[.]click has a one-character mutation sibling animumx[.]click. The wordmark napsop was registered on both .rest and .click. The pay*ofr and sav*ofr cluster is itself a dense family of more than ten single-token permutations off one template.
Registration Cohorts
Public WHOIS resolves the pool to a small set of registrar and privacy-proxy factories, with creation dates clustering in rolling 2026 batches and a thin tail of aged assets reused from 2025.
| Registrar | Privacy proxy | Cohort | Examples (defanged) | Created |
|---|---|---|---|---|
| NameSilo | PrivacyGuardian.org | Fresh exotic-TLD batches | orbora[.]rest, gigosi[.]rest, coobey[.]click, biogix[.]autos |
Feb to Apr 2026 |
| NameSilo | none | Aged stash, reused | uhtnk[.]biz, vrmjh[.]biz, logicpic[.]rest |
Apr to Dec 2025 |
| Namecheap | Withheld for Privacy | .com finance and affix pool |
payaofr[.]com, getzofr[.]com, wekndcrd[.]com, jacktins[.]com |
Mar to Apr 2026 |
| registrar.eu | WHOIS Privacy Protection | Marginal | azotipa[.]top, edonavas[.]com |
Dec 2025, Mar 2026 |
| GoDaddy | none | Marginal | btmsms[.]com |
Mar 2026 |
The freshest registrations sit only days before observed activity. The exotic-TLD apex biogix[.]autos was created April 14 and the .com domain semiatos[.]com on April 17, both consistent with burst activation within a day or two of registration. This registrar cohort is the highest-specificity tie in the whole operation, and it is public data. A fresh-registration stream from these two factories, filtered to cheap-TLD targets with the wordmark shape below, would flag siblings before the first text goes out.
Subdomain Grammar
Every CTA host prepends a random lowercase five-character, consonant-heavy label to the apex. Each label stays confined to its own apex, with no cross-domain token reuse, and a repeated label only ever recurs under the same domain. Hosts are bare-root, with no path, no query string, and no tracking token.
Representative hosts (defanged):
gjqvt[.]spelum[.]rest
atiwi[.]orbora[.]rest
wlueo[.]biogix[.]autos
gbuui[.]eleganix[.]email
lbyce[.]coobey[.]click
vpyfh[.]gigosi[.]rest
nobsr[.]souragu[.]pro
sbdnl[.]animum[.]click
What Ties the Clusters Together
With no DNS or backend overlap, five signals bind the naming and registrar clusters to one operator: the registrar-plus-privacy-proxy factory registered in tight batches; the coined-wordmark-on-cheap-TLD grammar and its descriptive and affix siblings; the recycled senior-skewed first-name and surname pairings; ten-digit reference fragments reused across independent burners; and a shared pretext toolkit of eleven template families. Explicit sweeps of email and Facebook for the seed apexes returned nothing, which scopes the operation cleanly to SMS.
The pretext toolkit itself is stable across every naming and registrar cluster:
| Template family | Representative fragment |
|---|---|
| Case-active / path-sync | "this case remains active" / "path sync for [reference]" |
| Priority-access / digital-twin | "priority access registered under [name]" |
| Senior inflation relief | "Senior Inflation relief" / "benefit adjustment" |
| Transfer / last phase | "the transfer was made to" / "last phase of the process" |
| Check returned / state deposit | "check made out to [name] was returned" |
| Religious providence | "God opened this for you" / "Grace moves in quiet ways" |
| State-treasury reclaim | "the state treasury is stripping" / "recovery of your assets" |
| Case closure / abandonment | "CASE ABANDONMENT" / "CASE CLOSURE" |
| Urgency / balance | "You have 7 minutes" / "your balance remains unaffected" |
| Formal notice | "Dear Mr or Mrs [name]" |
| Access code | "Enter [4 digits] to access" |
Detection Observations
The traffic separates from legitimate messaging on shape rather than on any single reused artifact. A US-mobile number sending a bare-root link, where the hostname is a random five-character label on a four-to-eight-character coined word on a cheap gTLD, with no path or query string, is a strong composite signal that almost no legitimate sender produces. Legitimate branded links carry a real brand token, usually a path, and a stable registrable domain; this operator has none of those.
The registrar cohort is the single strongest early pivot. Cheap-TLD apexes with the wordmark shape, freshly registered through the NameSilo-PrivacyGuardian.org or Namecheap-Withheld-for-Privacy factories in weekly batches, form a high-specificity cluster available from public WHOIS before the domain ever appears in a message. The pretext toolkit gives a second, content-side pivot: phrases like "path sync," "Senior Inflation relief," and "priority access registered under" recur across otherwise unrelated senders even as the infrastructure rotates.
One caution matters for anyone building a shape-based rule on this pattern. Short labels on cheap TLDs are also used by legitimate brands for real branded shortlinks, so any rule keyed on TLD and label shape needs an allow-list of known-legitimate branded-shortlink services before it acts.
Indicators of Compromise
All indicators below are defanged and drawn from the verified-malicious set for this campaign. Recipient data has been removed. Each type shows a representative subset.
Sender Numbers
| Value | Role | Notes |
|---|---|---|
+1-210-347-3914 |
Sender | Burner, coined-wordmark apex |
+1-423-208-6898 |
Sender | Burner |
+1-713-542-2490 |
Sender | Burner, shared apex orbora[.]rest |
+1-346-406-6541 |
Sender | Burner |
+1-561-546-1915 |
Sender | Burner, senior-relief pretext |
+1-352-727-0173 |
Sender | Burner |
+1-917-245-8930 |
Sender | Burner |
+1-279-253-6314 |
Sender | Burner |
+1-312-350-5197 |
Sender | Burner, priority-access pretext |
+1-956-820-2389 |
Sender | Burner |
+1-405-435-9531 |
Sender | Burner |
+1-850-741-8236 |
Sender | Burner |
| ... (representative subset; 100+ verified-malicious sender numbers) |
Domains
| Value | Role | Notes |
|---|---|---|
orbora[.]rest |
CTA apex | NameSilo, coined wordmark |
gigosi[.]rest |
CTA apex | NameSilo, path-sync pretext |
plihod[.]rest |
CTA apex | NameSilo, last-phase pretext |
coobey[.]click |
CTA apex | NameSilo |
animum[.]click |
CTA apex | Sibling of animumx[.]click |
biogix[.]autos |
CTA apex | Registered days before use |
eleganix[.]email |
CTA apex | Senior-relief pretext |
souragu[.]pro |
CTA apex | Priority-access pretext |
reemit[.]world |
CTA apex | Coined wordmark |
legalclaim[.]rest |
CTA apex | Descriptive settlement family |
settlementnow[.]rest |
CTA apex | Descriptive settlement family |
getpaid[.]rest |
CTA apex | Descriptive settlement family |
quicksettle[.]click |
CTA apex | Descriptive settlement family |
payaofr[.]com |
CTA apex | Namecheap, pay*ofr affix family |
getzofr[.]com |
CTA apex | Namecheap, get*ofr affix family |
| ... (representative subset; 250+ verified-malicious domains) |
Hosts
| Value | Role | Notes |
|---|---|---|
gjqvt[.]spelum[.]rest |
CTA host | Random 5-char label |
atiwi[.]orbora[.]rest |
CTA host | Random 5-char label |
wlueo[.]biogix[.]autos |
CTA host | Random 5-char label |
ccumm[.]sippihri[.]email |
CTA host | Random 5-char label |
gbuui[.]eleganix[.]email |
CTA host | Random 5-char label |
lbyce[.]coobey[.]click |
CTA host | Random 5-char label |
wtyds[.]plihod[.]rest |
CTA host | Random 5-char label |
vpyfh[.]gigosi[.]rest |
CTA host | Random 5-char label |
nobsr[.]souragu[.]pro |
CTA host | Random 5-char label |
dxfcm[.]vrmjh[.]biz |
CTA host | Aged-stash apex |
sbdnl[.]animum[.]click |
CTA host | Random 5-char label |
plbfi[.]reemit[.]world |
CTA host | Random 5-char label |
| ... (representative subset; 50+ verified-malicious hosts) |
MITRE Fight Fraud Framework Mapping
The mapping below aligns to the MITRE Center for Threat-Informed Defense Fight Fraud Framework (F3). F3 reuses ATT&CK technique IDs where a behavior already exists there and assigns fraud-specific IDs otherwise. Two consumer-side social-engineering stages this campaign leans on, trust-building through feigned authority and manufactured urgency, do not have dedicated technique IDs in the public F3 matrix and are described behaviorally rather than mapped to invented IDs.
| Tactic | Technique | ID |
|---|---|---|
| Reconnaissance | Gather Customer Information (recycled senior lead list) | F1029 |
| Resource Development | Acquire Infrastructure: Domains (bulk cheap-TLD apexes) | T1583.001 |
| Resource Development | Establish Accounts (burner sending numbers) | T1585 |
| Resource Development | Create Fake Materials: Fake Website | F1020.002 |
| Initial Access | Phishing, smishing variant (unsolicited SMS lure) | T1660 |
| Initial Access | Impersonate Official (state-treasury / legal authority) | F1032 |
| Monetization | Electronic Funds Transfer | F1025 |
Conclusion
The operator's edge comes from disposability, not sophistication. One number, one domain, one pretext per blast, all registered anonymously days before use and abandoned after, leaves defenders with almost no reusable artifact to chase. What the operator cannot rotate away is the machinery: two registrar factories, a wordmark generator with a recognizable grammar, and a recycled victim list that keeps the same names in play across thousands of burners. Those are the signals worth watching, because the next batch of numbers and domains will look new while the factory behind them stays the same.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.