Your Photos Will Be Deleted: A Cloud-Lockout Phishing Toolkit
Your Photos Will Be Deleted: A Cloud-Lockout Phishing Toolkit
Since December 2025 one operator has run a cloud-storage account-lockout phishing kit that hides its payload in a URL fragment behind Google Cloud Storage. The lure is always the same threat wearing a different logo: your account is blocked, your photos and videos will be deleted tonight, renew now to save them. Behind that message sits a durable toolkit that rotates its sending domain every day, borrows Google's own TLS-protected storage domain to carry the first click, and localizes the same template across iCloud, OneDrive, Dropbox, Amazon Photos, Samsung Cloud, a Norton subscription crossover, and a Spanish-language edition. The delivery domain a victim sees stays trustworthy while everything attributable churns underneath it. The fingerprints that survive that daily rotation are what a defender can key on.
Key Takeaways
- The kit uses Google Cloud Storage buckets as a first-stage redirector and encodes the real destination in the URL hash fragment, which browsers never send to the server, so any inspection that fetches the bare link sees a benign page.
- Sending apexes are random-label strings registered under delegated second-level registries (.uk.com, .co.nl, .biz.id, .org.uk) plus .biz, each burned after roughly one day of use.
- One bucket serves every brand and both languages: the English photos-deletion lure and the Spanish variant point at the identical bucket and page, proving a single localized template engine rather than separate campaigns.
- Several toolkit fingerprints persist across the daily churn: a shared Return-Path label, decoy List-Unsubscribe headers pointing at unrelated legitimate brands, brand-token padding stuffed into the envelope, and a tinyurl fallback that mirrors the primary tracking parameters.
- The operator personalizes subjects and display names with handles drawn from a breached-username dataset, and the same handle dataset ties this cluster to a sibling cloud-abuse operator running casino and reward lures on shared bucket infrastructure.
Background
Cloud object storage has become a preferred phishing host because it hands an attacker three things at once: a globally trusted parent domain, a valid TLS certificate, and one-line publishing. Google Cloud Storage exposes any publicly readable file at storage.googleapis.com/<bucket>/<file>, so a link that lands in an inbox sits on Google's infrastructure and inherits the reputation of googleapis.com. A defender scanning the visible host sees Google, not a freshly registered scam domain. The same pattern shows up on Amazon S3 and Azure Blob Storage, and it has been documented publicly through 2026 by researchers at malwr-analysis.com, Paubox, and others who traced Google Cloud Storage pages acting as traffic-distribution redirectors that rotate destinations behind a stable link.
The second building block is the URL hash fragment. Everything after the # in a link is the fragment, and browsers keep it strictly client-side: it is never transmitted to the server. A redirector page reads that fragment with a line of JavaScript and forwards the browser to whatever destination it encodes. A link-rewriter, sandbox, or proxy that requests the bare URL receives only a harmless shell, because the part that matters never crosses the wire. The malicious redirect materializes only in a real browser that carries the full fragment.
The third building block is the sending infrastructure. Rather than register on mainstream generic TLDs, the operator buys names under delegated second-level registries. Zones like .uk.com and .co.nl are commercial namespaces sold by CentralNic-style private registries, meaning a company sells names under a label it controls rather than a country running an official TLD. .org.uk is a genuine Nominet second level and .biz.id is an Indonesian second level sold through local resellers. These zones are cheap, bulk-registerable, look superficially official, and are covered less consistently by reputation feeds than plain .com, which is exactly why they suit a burn-and-rotate model. Supplementing the apex fleet is a pool of Yandex freemail burners, which authenticate cleanly and cost nothing to replace as each one is spent.
Discovery and Infrastructure
We first mapped this family by pivoting from the account-lockout subject language to the Google Cloud Storage click destination, then clustering the senders that shared that destination. What surfaced was not a short campaign but a standing operation: more than 20 storage buckets, more than 40 distinct sender addresses, 18 Yandex freemail accounts, and roughly 20 sending apexes spread across five TLD families (four delegated second-level registries plus .biz), all feeding one template family. Across the run the operator has pushed hundreds of thousands of messages.
The sending grammar is layered. The registrable apex is a random pronounceable string (dynavoro[.]uk.com, novacrest[.]uk.com, roefcexanegay[.]co.nl), and the envelope stacks further random subdomains on top of it in a <random>.<random>.<apex> shape. A newer variant prefixes the apex with a brand word and a numeric identifier, producing hosts like google.<word>[.]biz.id. Display names rotate on every send, and the Return-Path host is padded with recognizable brand tokens to read as official, for example apple.shiori.net.<random>[.]com or netflix-samsung.playstation.gov.<random>[.]de.
| Indicator | Role | Notes |
|---|---|---|
dynavoro[.]uk.com |
Sending apex | Random-label .uk.com apex, ~1-day burn |
roefcexanegay[.]co.nl |
Sending apex | Random-label .co.nl apex |
raxilmatrix[.]biz |
Sending apex | Spaceship registration, purpose-built |
swagbucks[.]uk.com |
Sending apex | Brand-squat on a third-party registry |
mlpoydgzeg.homedepot[.]uk.com |
Sending host | Brand-squat carrying the shared toolkit label |
storage.googleapis[.]com/whilewait/ |
Redirector | Abused Google bucket, first-stage hash-fragment page |
The brand-squat apexes deserve a note. Names like swagbucks[.]uk.com, homedepot[.]uk.com, and codecademy[.]uk.com resemble real companies, but those companies operate on .com and .edu, not on the third-party .uk.com commercial registry. The real brands are impersonation targets here, not the registrants. The operator simply reserves brand-adjacent labels in a cheap namespace to gain a veneer of familiarity in the envelope.
How It Works
The contact chain is short and engineered for panic. A victim receives an email whose subject and body claim their cloud account is blocked or over quota and that their photos, videos, and backups will be permanently deleted within hours unless they renew. A storage gauge rendered near the top ("48.9 GB / 50 GB", "97% lleno") reinforces the scarcity. The single call-to-action button points at a Google Cloud Storage page. When clicked in a browser, that page reads the hash fragment appended to its URL and forwards the victim to the credential or payment-harvest destination the fragment encodes. A tinyurl link mirrors the same tracking parameters as a fallback path in case the bucket link is removed.
The operator personalizes the message with a handle pulled from a breached-username dataset. In many sends the recipient address, the display name, and an embedded greeting all echo the same handle, which raises the sense that the warning is account-specific rather than a blast. That handle dataset is also the strongest cross-campaign link we have: the same handles appear in casino and reward lures run by a sibling cloud-abuse operator on shared bucket infrastructure, which places both under one operator or a tightly coupled pair.
Sample Lures
All personal data has been redacted and every indicator is defanged. The samples show attacker-side content only.
Email, English photos-deletion lure (primary volume driver):
From: "[handle]" <nooreply@wxghawkwxxl[.]us>
Subject: We've blocked your account! 🚫 Your photos and videos will be deleted on [date] ⚠️ Renew your subscription for free now!
Return-Path: <[random]@apple.shiori.net.nublic[.]com>
List-Unsubscribe: <http[:]//thumbtack[.]com/LEAVE=To>
Cloud - Billing notice
We couldn't renew your cloud storage subscription.
48.9 GB / 50 GB
[ Renew now ]
CTA: http[:]//storage.googleapis[.]com/whilewait/brightway.html#index.php?search=4&d207727&...&page=[token]
Fallback: http[:]//tinyurl[.]com/[slug]/track/index.php?...&page=[token]
Email, Norton subscription crossover (payment-renewal pretext, "affiliate" disclaimer):
From: "Norton-Antivirus_Alert" <nooreply@fty.dqkczeoiujgrj[.]us>
Subject: Urgent Warning: [handle], Secure Your Norton Subscription - 67% Discount Available!
Return-Path: <[random]@netflix-samsung.playstation.gov.adlernestontour[.]de>
List-Unsubscribe: <http[:]//uber[.]com/LEAVE=To>
Norton Antivirus Account Information
Hi, your account is set to expire tonight. Please take action to avoid interruption.
ID: [redacted] Username: [handle] Status: Expired Discount: 67%
[ Renew Your Subscription ]
*Advertisement by an independent affiliate of Norton.
CTA: http[:]//storage.googleapis[.]com/prosperway/hoperise.html#index.php?search=4&d188041&...&page=[token]
Email, Spanish-language variant (same bucket and page as the English lure):
From: "[handle]" <nooreply@kszqqtfiakt[.]us>
Subject: Hemos bloqueado tu cuenta! 🚫 Tus fotos y videos seran eliminados el [date] ⚠️ ¡Renueva tu suscripcion gratis ahora!
Return-Path: <[random]@apple.shiori.net.ridenwine[.]com>
List-Unsubscribe: <http[:]//yelp[.]com/LEAVE=To>
⚠️ Tu almacenamiento en la nube ha alcanzado el limite critico
97% lleno | Plan: 250GB | Estado: Expirado
[ ACTUALIZAR ALMACENAMIENTO ]
CTA: http[:]//storage.googleapis[.]com/whilewait/brightway.html#index.php?search=4&d202600&...&page=[token]
The English and Spanish lures resolve to the same bucket and page (whilewait/brightway.html), differing only in the fragment's tracking values. One template engine, two localizations.
Technical Analysis
The Hash-Fragment Redirector Grammar
Every first-stage click follows one shape:
http[:]//storage.googleapis[.]com/<bucket>/<page>.html#index.php?search=<N>&d######&<5-random>=<N-NN>&lm=<digits><4-letters><digits>&sd=<N>&page=<random>
The portion before the # is a static, benign-looking Google Cloud Storage page. The portion after the # is the working payload: a d###### campaign identifier, a five-character random parameter, an lm token mixing digits and letters, and a page slug. Because the fragment stays client-side, fetching the pre-# URL yields nothing useful, which is the entire point of the design. The search parameter and its siblings are stable across brands and languages, so the same parser runs behind every lure. A tinyurl link carrying the same d######, lm, and page values serves as a redundant delivery path.
One Bucket, Many Brands
Buckets are shared across the brand and language matrix rather than dedicated per lure. The whilewait bucket carried both the English photos-deletion lure and the Spanish variant; the Norton crossover ran from prosperway. Bucket names themselves are throwaway (whilewait, prosperway, mv388, ous2gsjdhx, ousjasdsakhsgg, and a long tail of single-day buckets), and because they live under Google's shared domain they cannot be flagged at the host level without collateral damage, so the bucket path is the durable artifact, not the host.
Registration Cohorts
The purpose-built .biz sending pool tells a clear provisioning story. Registrar concentration is heavy and the registrations are fresh, blank-org, and disposable, consistent with an automated pipeline rather than aged or compromised inventory.
| Example apex (defanged) | Registrar | First registered | WHOIS org |
|---|---|---|---|
raxilmatrix[.]biz |
Spaceship | 2026-04-10 | (blank) |
zokirframe[.]biz |
Spaceship | 2026-04-10 | (blank) |
brandacceleration[.]biz |
Spaceship | 2026-01-17 | (blank) |
tradebizengine[.]biz |
Spaceship | 2026-01-17 | (blank) |
lumarodispatch[.]biz |
Porkbun | 2026-02-02 | (blank) |
nuxarodynamo[.]biz |
Porkbun | 2026-02-02 | (blank) |
Same-day pairs at a single registrar, no organization data, and a short operational life are the signature of batch provisioning. The delegated registries round out the picture, each carrying its own apex shape.
| Registry namespace | Observed apex shape |
|---|---|
.uk.com / .co.nl |
Random pronounceable label (CentralNic-style commercial second level) |
.org.uk |
Random-label one-day-burn apex (Nominet second level) |
.biz.id |
google.<word> dictionary shape (Indonesian resellers) |
.biz |
11 to 13-character random lowercase label |
Fingerprints That Survive Rotation
The apex and freemail account change daily, but the toolkit leaves marks that do not:
- A shared Return-Path label,
mlpoydgzeg, recurs across otherwise unrelated apexes and even on brand-squat hosts (mlpoydgzeg.homedepot[.]uk.com). It functions as a toolkit build signature: senders that carry it belong to the same infrastructure regardless of the apex in the From line. - Decoy List-Unsubscribe headers point at unrelated legitimate brands with a tell-tale
/LEAVE=Topath (thumbtack[.]com,uber[.]com,yelp[.]com). A real List-Unsubscribe marks well-behaved bulk mail; borrowing a reputable brand's URL nudges spam classifiers toward "commercial, not phishing" while adding a false gloss of legitimacy. - Return-Path hosts are padded with brand tokens (
apple.shiori.net.<random>[.]com,netflix-samsung.playstation.gov.<random>[.]de) so the envelope reads as brand-affiliated even though the registrable domain is random. - Bounce traffic is routed to
mtv-muenchen[.]de, a legitimate and unrelated German sports-club domain abused as a bounce sink so the operator never has to manage attributable bounce infrastructure. The domain is a victim of the abuse, not a participant.
Taken together these five markers, plus the shared bucket namespace and the fragment parameter schema, let a defender cluster the operator's traffic even on a day when every apex is one they have never seen before.
Detection Observations
The traffic separates from legitimate cloud-provider mail on structure rather than on any single field. Genuine Apple, Google, Microsoft, Dropbox, and Norton notifications originate from those companies' own authenticated domains; this operator sends brand-named lures from random-label apexes on delegated registries, with brand tokens confined to the Return-Path padding rather than the registrable domain. A List-Unsubscribe header whose host is an unrelated consumer brand and whose path ends in /LEAVE=To is a strong standalone anomaly, as is a message whose visible call-to-action lives on storage.googleapis.com with a long #index.php?... fragment. The combination of an account-deletion urgency subject, a recipient-handle greeting, and a cloud-storage bucket CTA is a high-confidence signal that individual features would miss. The hardest edges of the family are the ones that lean hardest on the trusted-host trick: because the visible click destination is Google's own storage domain, host-reputation alone cannot carry the decision, and the payload only reveals itself client-side.
Indicators of Compromise
All indicators are defanged and represent a curated, verified subset. Aggregate totals are floors under partial visibility.
Sender Addresses (representative subset)
| Value | Role | Notes |
|---|---|---|
1vydoe2qxi@wvyl.1vydoe2qxi[.]us |
Sender | High-volume .us apex |
ahxbznm@gzvcwlow.mlpoydgzeg.roefcexanegay[.]co.nl |
Sender | Carries the shared toolkit label |
jsubtim@ziadlese.eqa.dynavoro[.]uk.com |
Sender | Stacked-subdomain grammar |
fyktdym@rqcwprqe.qqa.novacrest[.]uk.com |
Sender | Stacked-subdomain grammar |
uylyppj@rokcjfah.yuiy.dynamizeu[.]uk.com |
Sender | .uk.com apex |
osecpis@vskihnhp.zder.dynafinder[.]uk.com |
Sender | .uk.com apex |
mvsupportqtr@vptjxlffbbnnfvubioyabuqy[.]com |
Sender | Cloud-full lure |
ywsupportydhp@tnatgnoutbjtutyotl[.]com |
Sender | Support-themed local part |
contact@arsvis[.]uk.com |
Sender | Persistent contact address |
bakesnop@yandex[.]ru |
Sender | Freemail burner |
team.s.upp.ort@yandex[.]ru |
Sender | Freemail burner, dotted evasion |
| ... (representative subset; 40+ verified-malicious sender addresses) |
Operator Sending Domains and Hosts (representative subset)
| Value | Role | Notes |
|---|---|---|
dynavoro[.]uk.com |
Sending apex | Random-label .uk.com |
novacrest[.]uk.com |
Sending apex | Random-label .uk.com |
roefcexanegay[.]co.nl |
Sending apex | Random-label .co.nl |
micl[.]uk.com |
Sending apex | Random-label .uk.com |
dynamizeu[.]uk.com |
Sending apex | Random-label .uk.com |
dynafinder[.]uk.com |
Sending apex | Random-label .uk.com |
arsvis[.]uk.com |
Sending apex | Persistent contact apex |
raxilmatrix[.]biz |
Sending apex | Spaceship, purpose-built |
zokirframe[.]biz |
Sending apex | Spaceship, purpose-built |
broteas[.]biz.id |
Sending apex | Indonesian second level |
swagbucks[.]uk.com |
Sending apex | Brand-squat, real brand uses .com |
mlpoydgzeg.homedepot[.]uk.com |
Sending host | Brand-squat plus toolkit label |
mlpoydgzeg.codecademy[.]uk.com |
Sending host | Brand-squat plus toolkit label |
| ... (representative subset; 40+ verified-malicious domains and hosts) |
One-Day-Burn Apexes (.org.uk cohort)
| Value | Role | Notes |
|---|---|---|
axgasdkjftrvsmixlx[.]org.uk |
Sending apex | Random-label burn apex |
erzqsfaasbcpmanyy[.]org.uk |
Sending apex | Random-label burn apex |
gzfvxaydvcuajdtrry[.]org.uk |
Sending apex | Random-label burn apex |
xfgdckztbqgejtojg[.]org.uk |
Sending apex | Random-label burn apex |
zwiiswwtjgohvthycw[.]org.uk |
Sending apex | Random-label burn apex |
Two envelope artifacts are useful pivots but are not flaggable indicators: the shared Return-Path label mlpoydgzeg, and the abused bounce-sink mtv-muenchen[.]de (a legitimate third party, listed here only so defenders recognize it as collateral, not as a target).
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE Fight Fraud Framework (F3) (https://ctid.mitre.org/fraud). Technique names are given; numeric identifiers are omitted where the live matrix could not be confirmed.
| Tactic | Observed behavior | Observed behavior |
|---|---|---|
| Resource Development | Acquire infrastructure and accounts | Burner apexes on delegated registries, Google Cloud Storage buckets, Yandex freemail, tinyurl fallback |
| Initial Access | Phishing message | Account-lockout and photos-deletion email lures across cloud brands |
| Initial Access | Brand impersonation | Cloud-brand and Norton pretexts, brand-token Return-Path padding, decoy List-Unsubscribe headers |
| Execution | Urgency and fear pressure | "Blocked account", "deleted tonight", storage-full gauge, recipient-handle personalization |
| Monetization | Credential and payment harvest | Fragment redirect to credential or subscription-payment capture page |
| Stealth | Infrastructure rotation and obfuscation | Hash-fragment payload, trusted-host front, daily apex burn, shared toolkit label across rotations |
Conclusion
The durable asset here is not any domain but the template engine and its rotation discipline. The operator has kept one recognizable lure alive for more than half a year by treating every attributable component as disposable and leaning on a trusted host to carry the first click. The parts worth watching are the ones that persist through the churn: the shared Return-Path label, the decoy unsubscribe headers, the brand-token envelope padding, and the reuse of a single bucket across brands and languages. A new brand skin or a new delegated registry should be read as the same operator moving, not a new one arriving.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.