Seventy Finance Newsletters, One Sending Fingerprint
Seventy Finance Newsletters, One Sending Fingerprint
Since early 2026, one operator has run roughly seventy fabricated finance newsletters behind a single shared Amazon SES and Iterable sending fingerprint. Each brand looks independent: its own domain, its own editor persona, its own investing angle. Underneath, they share a sender-address grammar, a click-tracking CNAME shape, a hard-coded SPF line, and a Cyrillic-homoglyph evasion trick that ties the whole set to one hand. The newsletters are the front. The revenue comes from two funnels running through the same senders: paid trading-service upsells, and personalized loan and credit-card lead-gen that harvests the reader's contact and financial details for affiliate payout.
Key Takeaways
- Roughly seventy fabricated finance-newsletter brands trace to one operator through a shared sender grammar, a per-brand Iterable custom-CNAME tracker, and a near-identical single-IP SPF record.
- The brands impersonate no real company. Each is an invented editorial persona ("Eric Davidson / ETF-Alerts", "J. Carter / Patriot Income Brief"), which keeps the operation off brand-abuse and trademark radar while it hides among the genuine Agora-family newsletter ecosystem.
- Every message authenticates cleanly. SPF, DKIM, and DMARC all pass on generic Amazon SES space, so transport-layer trust says nothing about the content.
- Two funnels run through the same senders: trading-service upsells and first-name-personalized loan and credit-card lead-gen, the latter monetized as affiliate leads to real lenders and dealers.
- The apex pool is recycled, not burned. Ten domains went dark on a single day, then reactivated months later with fresh local parts, and their registration dates span 2011 to 2026 across three registrars, so they were never a disposable batch.
- The one durable content fingerprint that survives domain rotation is a Cyrillic-homoglyph "Click here" string; a retired numeric body-snippet prefix marked the operator's earlier era.
Background
Deceptive finance-newsletter email hides inside one of the busiest legitimate niches in consumer marketing. The paid investment-newsletter industry is anchored by the Baltimore-based Agora network and its thirty-plus member publishers, including The Oxford Club, Banyan Hill, and Money Map Press, alongside independents like Wyatt Research and Investors Alley. That ecosystem runs well over a hundred paid newsletters and generates more than a billion dollars a year (Agora, Inc.). Its house style, a named editor, a "briefing" format, and bold return claims, is exactly what a fabricated-persona operator copies to blend in.
The regulatory line in that niche is disclosure. Under the anti-touting provision of the securities laws, anyone paid to promote a security has to disclose the nature, source, and amount of the compensation, and the SEC has repeatedly acted against undisclosed-compensation newsletters and independent-looking bullish articles, including a 2017 sweep charging twenty-seven firms and individuals over paid stock articles presented as neutral research (SEC press release 2017-79; Investor.gov: newsletters as fraud tools). The operator here goes a step past aggressive marketing. It fabricates the publisher entirely, then bolts a lead-gen harvesting layer onto the same list.
A few infrastructure names recur in the analysis, and they matter because none of them is itself the villain. Amazon SES is Amazon's bulk-email service; any customer can stand up an SES identity with SPF, DKIM, and DMARC all passing, so clean authentication proves only that the sender controls the identity, not that the pitch is honest. Iterable is a mainstream marketing-automation platform whose click tracking can be pointed at a customer's own subdomain through a CNAME, so wrapped links carry the brand's domain instead of a generic Iterable host. That vanity CNAME both lifts deliverability and hides the shared upstream Iterable account behind a per-brand name, so seventy "separate" brands ride one tenant while defeating simple host blocklists. A separate slice of the operation uses a Lob-style SMTP tracker (/ls/click?upn= redirect URLs) as a drop-in alternate rail. And beehiiv, a reputable independent-newsletter platform, appears only as a reminder of the boundary: a real newsletter running openly on a creator platform is not this operator. The tells here are fabricated identity, homoglyph evasion, apex recycling, and covert lead-gen injection, not the choice of sending tool.
Discovery and Infrastructure
The cluster surfaced from a sender-shape sweep rather than from any single bad domain. The operator uses a consistent three-level sender address, <word>@<2-4 char label>.<root>.<tld>, always on an Amazon SES return path. The local part is drawn from a small newsletter-register vocabulary (daily, morning, editor, newsletter, crew, brief, team, news, research), and the short subdomain label is a contraction of the root brand. Combined with a finance vocabulary in the root domain, that shape alone enumerated dozens of sibling brands sharing the pattern.
The tracking layer confirmed the link. Every brand wraps its outbound CTAs through an Iterable custom-CNAME of the shape links.<label>.<root>.com, reusing the same short label as the sending subdomain. daily@that.etf-alerts[.]com tracks through links.that.etf-alerts[.]com; crew@your.atlantisinvestors[.]com tracks through links.your.atlantisinvestors[.]com. The CNAME grammar is identical across the pool, and the same grammar appears on genuine Agora-family publishers that are Iterable customers too, so the shape by itself is a network-wide signal that has to be narrowed by domain shape and sender vocabulary to avoid collateral damage on legitimate senders. The operator brands separate from the legitimate ones on fabricated identity and on the lead-gen payload, not on the tracker.
| Indicator | Role | Notes |
|---|---|---|
amazonses[.]com |
Relay | Generic Amazon SES return path across all senders; SPF, DKIM, DMARC all pass |
links.<label>.<root>.com |
CTA tracker | Per-brand Iterable custom-CNAME; label reused from the sending subdomain |
trk.stockmarkethour[.]com |
Redirect router | Carries recipient email plus an affiliate product code to the offer |
tracking.prtradinginfo[.]com |
CTA tracker | Lob-style SMTP /ls/click?upn= rail, a distinct sub-stack, not Iterable |
gbmmediagroup[.]com |
Redirector | Third-party affiliate CTA terminus shared across brands |
wealth-live[.]com |
Redirector | Affiliate landing terminus shared across brands |
How It Works
A recipient sees a plausible finance newsletter. The From line carries a fabricated editor and brand ("Scott C. from Investing Trends"), the subject runs a fear or curiosity hook tied to current events, and the body reads like a market briefing. Every visible link points at the brand's own links. subdomain, so a quick hover reassures rather than warns. The click passes through the Iterable CNAME, and on some brands through a second operator router that appends the recipient's email address and an affiliate product code before handing off to the advertiser.
The same senders carry a second, quieter funnel. Interleaved with the newsletter blasts, the operator sends first-name-personalized loan and credit-card lures from the identical brand infrastructure: "Verify your account to access funding options [recipient name]", "Money in Your Account as Soon as One Business Day". These are lead-gen injections. The newsletter persona builds the list and the trust; the loan and credit-card messages convert that list into affiliate leads by pushing readers to submit contact and financial details. The advertisers at the end of the chain, lenders, gold-IRA dealers, and established research publishers among them, are frequently real and paying businesses that never see how the upstream traffic was generated. The deception lives entirely in the acquisition layer.
Sample Lures
Representative messages, defanged, with recipient data replaced by placeholders. Attacker-side content only.
Clickbait newsletter front, funneling to a trading-service offer:
From: "Scott C. from Investing Trends" <morning@news.investingtrendstoday[.]com>
Subject: Iran is Testing Trump - Will He Even Respond?
Return-Path: <bounce@amazonses[.]com>
Body (excerpt): ... the briefing goes out in an hour. Tap Сⅼіϲkhеrе to read it before the market opens ...
CTA wraps through: http[:]//links[.]news[.]investingtrendstoday[.]com/...
The Сⅼіϲkhеrе string renders as "Click here" to a human but is built from Cyrillic and other lookalike codepoints (U+0421 U+217C U+0456 U+03F2 U+04BB U+0435 U+0440 U+0435), which sidesteps naive text rules that match the literal ASCII phrase.
Loan lead-gen injection from the same brand infrastructure:
From: "Your Finance R." <editor@wealth.yourfinancerules[.]com>
Subject: Verify your account to access funding options [recipient name]
Return-Path: <bounce@amazonses[.]com>
Body (excerpt): Money in Your Account as Soon as One Business Day. Check your options [recipient name] ...
Paid trading-service upsell:
From: "Stealth Trades" <thestealthtrades@e.stocksurgedaily[.]com>
Subject: Live Stealth Trades session starting soon
Return-Path: <bounce@amazonses[.]com>
Technical Analysis
The operation is worth studying because its brands are engineered to look unrelated and still leak a common hand at four independent layers: the SPF record, the sender and tracker grammar, the WHOIS cohorts, and the body-level evasion. Any one of them can be spoofed by a careful imitator; carrying all four is the attribution.
The Sending Fingerprint
The strongest network-wide pivot is not the click tracker but the SPF record. Nearly every apex publishes the same template, v=spf1 +mx +a +ip4:<single IPv4> ~all, authorizing one hard-coded sending IP on shared-hosting ranges, and the same DKIM default-selector marker recurs across the pool. Because this fingerprint sits in DNS rather than in the message body, it survives content rotation and links brands that otherwise share no visible text. The newest apexes add a registrar email-forwarding include, a small tell of how fresh domains are provisioned.
The sender grammar reinforces it. The short subdomain label is a contraction of the apex, and it is reused verbatim on both the sending host and the Iterable tracker: that.etf-alerts sends and links.that.etf-alerts tracks; igp.investorgrowthpath sends and the same igp label carries the tracker. That one-label-two-roles convention is a cheap, reliable correlator across the set.
Fabricated-Persona Naming
The brand names are generated from a fixed lexicon rather than invented freely. Finance roots (invest, trade, stock, etf, retire, wealth, income, market, portfolio, capital, gold, dividend, yield) combine with authority and cadence modifiers (daily, insider, secret, legacy, signals, alerts, report, brief, memo, path, compass, edge, hour, today) and a distinct patriot vertical (patriot, redstate, national, washington). A handful of templates recur: adjective-plus-finance-noun (goldenretirememo, insiderlegacysecret, theclassyinvestors), finance-noun-plus-format (etf-alerts, incomesignals, stockmarkethour, patriotincomebrief), and your-plus-goal (yourfinancerules, yourinvestingfoundation, yourinvestmentedge). Display names pair a fabricated first name and last initial with the brand alias, and no real person is impersonated, which keeps the operation clear of trademark and brand-abuse enforcement.
| Persona display name | Brand front | Sender |
|---|---|---|
| Eric Davidson (ETF-Alerts) | ETF-Alerts | daily@that.etf-alerts[.]com |
| Scott C. from Investing Trends | Investing Trends | morning@news.investingtrendstoday[.]com |
| J. Carter, Patriot Income Brief | Patriot Income Brief | j.carter@daily.patriotincomebrief[.]com |
| J. Morton, Retirement Report | Happy Retirement Report | j.morton@team.happyretirementreport[.]com |
| Your Finance R. | Your Finance Rules | editor@wealth.yourfinancerules[.]com |
| Michael D. at SMH (40+ rotating names) | Stock Market Hour | admin@e.stockmarkethour[.]com |
Registration Cohorts and the Recycle Model
Public WHOIS breaks the pool into age cohorts and settles how the operator manages its inventory. Registration concentrates on a single registrar for the modern build, with a second registrar on a pair of same-day twin acquisitions in 2020 and a third on one of the oldest aged-stash apexes. Same-day twin registrations recur (two apexes created on one day in 2020, another pair on one day in 2025) and betray batch provisioning. Ten apexes went dormant on a single day in March 2026, which first read as a burn. It was not. All ten came back months later with fresh local parts and the same homoglyph CTA, and their creation dates span 2011 to 2026 across three registrars. A disposable batch does not look like that. This is a pool of pre-warmed, reusable sending domains that the operator rotates in and out, which is far more resilient than register-and-burn because warm-up cost is paid once.
| Apex | Registrar cohort | Created | Recycled cohort |
|---|---|---|---|
prtradinginfo[.]com |
aged-stash | 2011 | distinct Lob sub-stack |
traderspledge[.]com |
aged-stash | 2011 | yes |
incomesignals[.]com |
aged-stash | 2017 | yes |
etf-alerts[.]com |
2020 twin | 2020-01-20 | no |
investingtrendstoday[.]com |
2020 twin | 2020-01-20 | no |
theclassyinvestors[.]com |
2020 | 2020-08 | yes |
stockmarkethour[.]com |
2021 | 2021-05 | no |
misterrichsolution[.]com |
2021 | 2021-11 | yes |
atlantisinvestors[.]com |
2022 | 2022-07 | no |
insiderlegacysecret[.]com |
2023 | 2023-06 | yes |
turbotradepro[.]com |
2025 twin | 2025-06-26 | no |
goldenretirememo[.]com |
2025 twin | 2025-06-26 | yes |
patriotincomebrief[.]com |
2026 purpose-built | 2026-01 | no |
Redirect Rails and Body Evasion
Most brands run two tracking hops. The Iterable custom-CNAME wraps the visible link, then a second operator-controlled router forwards the click to the advertiser. On the Stock Market Hour node the second hop is explicit: links.e.stockmarkethour[.]com hands to trk.stockmarkethour[.]com/<hex>?email=<recipient>&product=<code>, carrying the recipient's address and an affiliate product code straight into the URL. A separate node uses a JourneyTracks-style rail (jt.tracks.<apex>/?type=OF|SA&product=<id>) with the same two-hop mechanic, and the prtradinginfo sub-stack swaps the whole Iterable layer for a Lob-style SMTP tracker. Running more than one tracking vendor splits the infrastructure across parties and frustrates single-vendor takedown.
| Tracker prefix | Rail type | Example host |
|---|---|---|
links.<label>.<root> |
Iterable custom-CNAME, primary | links.that.etf-alerts[.]com |
trk.<root> |
Operator affiliate router with email and product code | trk.stockmarkethour[.]com |
jt.tracks.<root> |
JourneyTracks-style click layer | jt.tracks.swingtotrade[.]com |
tracking.<root> |
Lob-style SMTP /ls/click?upn=, non-Iterable |
tracking.prtradinginfo[.]com |
At the content layer the operator has walked through two fingerprints. Its earlier era opened every body with a fixed numeric prefix, a cheap correlator that has since been retired. The durable signal now is the Cyrillic-homoglyph "Click here" string, which survives sender and domain rotation because it is baked into how the CTA is written. One node extends the evasion further by padding message bodies with long passages of public-domain literary prose to dilute automated body scoring. The same operator playbook, identical sender shape and CNAME toolkit, also runs in the health and supplement vertical on a separate Iterable tenant, with a single crossover sender bridging the two clusters.
Detection Observations
The behavioral signals that separate this traffic from legitimate finance mail sit above the individual message.
- Clean authentication is worthless as a positive signal here. Every message passes SPF, DKIM, and DMARC on shared Amazon SES space, so any rule that leans on auth results waves the traffic through. The discriminator is identity and payload, not transport.
- The single-IP SPF template shared across dozens of "unrelated" apexes is the strongest cross-brand pivot, because it lives in DNS and does not change when the body does. Clustering by that record surfaces siblings that share no visible content.
- The one-label-two-roles convention, the same short subdomain contraction appearing on both the sending host and the
links.tracker, is a reliable structural tell that is hard for the operator to drop without re-architecting its ESP setup. - Homoglyph substitution in a call-to-action phrase is a high-value content signal. Legitimate senders do not write "Click here" in Cyrillic. Normalizing display text to a canonical script before matching turns this evasion into a detection.
- The loan and credit-card lead-gen layer is the hardest slice to catch per message, because each note resembles ordinary aggressive lending mail; the scam is visible at the ecosystem level, where the same brand infrastructure sends both a market briefing and a funding-options lure to the same list.
Mitigation and Guidance
- Cluster senders by their published SPF record and DKIM selector, not only by domain. A shared single-IP SPF template across many finance-branded apexes is a strong grouping key that survives content and domain rotation.
- Treat a reused short-label subdomain that appears on both the sending host and a
links.tracker CNAME as a structural correlator, and pivot from one confirmed brand to its siblings on that shape plus a finance root vocabulary. - Normalize CTA and display text to a canonical script before applying keyword rules, so homoglyph "Click here" and similar lookalike substitutions do not slip matching.
- Do not treat clean SPF, DKIM, and DMARC as evidence of legitimacy on shared ESP space. Weigh sender identity, disclosure, and payload instead.
- Watch for interleaved payloads from a single sender: a market-newsletter persona that also sends first-name-personalized funding or credit-card lures is running a lead-gen harvest, regardless of how benign any single message looks.
- When a redirect URL carries a recipient email address plus a product or offer code in its query string, treat it as a lead-gen monetization rail and pivot on the router host.
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE CTID Fight Fraud Framework (F3, https://ctid.mitre.org/fraud). The framework's public tactic vocabulary is used below; technique names follow the matrix, and readers should confirm current identifiers against the live matrix.
| Tactic | Technique (observed behavior) |
|---|---|
| Resource Development | Acquire and pre-warm a pool of sending domains; stand up per-brand Iterable CNAME trackers and SES identities |
| Resource Development | Establish fabricated editorial personas and brand identities with no real-world referent |
| Initial Access | Unsolicited bulk-email contact delivering the newsletter and lead-gen lures |
| Stealth | Homoglyph substitution in CTA text; literary body-padding to dilute automated scoring; retired numeric body prefix |
| Execution | Social-engineering lures using urgency, fear, and inflated-return hooks; personalized funding-options bait |
| Monetization | Convert deceptive traffic into paid affiliate leads and trading-service upsells via recipient-tagged redirect routers |
Indicators of Compromise
All indicators are defanged. Recipient and victim data has been removed. The lists below are representative subsets from the verified-malicious set, capped for readability; the counts noted are floors under partial visibility, not the operator's full inventory.
Senders
| Value | Role | Notes |
|---|---|---|
daily@that.etf-alerts[.]com |
Sender | ETF-Alerts persona, high volume |
morning@news.investingtrendstoday[.]com |
Sender | Investing Trends persona |
j.morton@team.happyretirementreport[.]com |
Sender | Retirement Report persona |
crew@your.atlantisinvestors[.]com |
Sender | Atlantis Investors persona |
editor@wealth.yourfinancerules[.]com |
Sender | Your Finance Rules; loan and credit-card lures |
capital@to.yourfinancerules[.]com |
Sender | Second sender on the same brand |
j.carter@daily.patriotincomebrief[.]com |
Sender | Patriot Income Brief; homoglyph CTA |
admin@e.stockmarkethour[.]com |
Sender | Stock Market Hour; single persona, 40+ display names |
check@igp.investorgrowthpath[.]com |
Sender | Investor Growth Path |
prosper@with.multigainstrade[.]com |
Sender | Multi Gains Trade |
uim@growth.usinvestmaster[.]com |
Sender | US Invest Master |
seen@safe.turbotradepro[.]com |
Sender | Turbo Trade Pro |
mail@edge.myinvestingcompass[.]com |
Sender | My Investing Compass |
info@core.strategicsuccessmoves[.]com |
Sender | Strategic Success Moves |
services@mail.swingtotrade[.]com |
Sender | Swing to Trade; JourneyTracks rail |
| ... | representative subset; 50+ verified-malicious senders |
Domains
| Value | Role | Notes |
|---|---|---|
etf-alerts[.]com |
Operator apex | 2020 twin registration |
investingtrendstoday[.]com |
Operator apex | 2020 twin registration |
happyretirementreport[.]com |
Operator apex | 2021 cohort |
atlantisinvestors[.]com |
Operator apex | 2022 cohort |
stockmarkethour[.]com |
Operator apex | Dual-tracker product-code rail |
yourfinancerules[.]com |
Operator apex | 2025 purpose-built |
patriotincomebrief[.]com |
Operator apex | 2026 purpose-built; patriot vertical |
investorgrowthpath[.]com |
Operator apex | Fabricated brand |
myinvestingcompass[.]com |
Operator apex | 2025 purpose-built |
turbotradepro[.]com |
Operator apex | 2025 twin registration |
usinvestmaster[.]com |
Operator apex | Fabricated brand |
strategicsuccessmoves[.]com |
Operator apex | Fabricated brand |
traderinsightmedia[.]com |
Operator apex | 2023 cohort |
insiderlegacysecret[.]com |
Operator apex | Recycled dormant cohort |
traderspledge[.]com |
Operator apex | Aged-stash; recycled dormant cohort |
gbmmediagroup[.]com |
Redirector | Shared affiliate CTA terminus |
wealth-live[.]com |
Redirector | Shared affiliate landing terminus |
| ... | representative subset; 100+ verified-malicious domains |
Sending Subdomains
| Value | Role | Notes |
|---|---|---|
that.etf-alerts[.]com |
Sending host | Label reused on links. tracker |
news.investingtrendstoday[.]com |
Sending host | |
team.happyretirementreport[.]com |
Sending host | |
your.atlantisinvestors[.]com |
Sending host | |
wealth.yourfinancerules[.]com |
Sending host | |
to.yourfinancerules[.]com |
Sending host | Second subdomain on the same apex |
daily.patriotincomebrief[.]com |
Sending host | |
edge.myinvestingcompass[.]com |
Sending host | |
igp.investorgrowthpath[.]com |
Sending host | |
safe.turbotradepro[.]com |
Sending host | |
growth.usinvestmaster[.]com |
Sending host | |
core.strategicsuccessmoves[.]com |
Sending host | |
with.multigainstrade[.]com |
Sending host | |
| ... | representative subset; one sending label per operator apex |
Hosts
| Value | Role | Notes |
|---|---|---|
links.that.etf-alerts[.]com |
CTA tracker | Iterable custom-CNAME |
links.your.atlantisinvestors[.]com |
CTA tracker | Iterable custom-CNAME |
links.team.happyretirementreport[.]com |
CTA tracker | Iterable custom-CNAME |
links.news.investingtrendstoday[.]com |
CTA tracker | Iterable custom-CNAME |
links.e.stockmarkethour[.]com |
CTA tracker | Iterable custom-CNAME rail |
e.stockmarkethour[.]com |
Sending host | SES sending subdomain |
trk.stockmarkethour[.]com |
Redirect router | Recipient email plus product code |
e.stocksurgedaily[.]com |
Sending host | Trading-service upsell node |
tracking.prtradinginfo[.]com |
CTA tracker | Lob-style SMTP rail |
tracking.dailyfinbrief[.]com |
CTA tracker | Operator rail |
| ... | representative subset; 50+ verified-malicious hosts |
Conclusion
The lesson of this cluster is that seventy independent-looking brands can be one operator, and the proof sits in the parts that are expensive to vary: a shared SPF line, a reused subdomain label, a homoglyph baked into the CTA, and a pool of warm domains that recycle rather than burn. Content changes cheaply and often here, so defenders who cluster on infrastructure and identity will keep pace where content rules fall behind. The pattern is portable across verticals, and the same toolkit already runs in health and supplements, so the next iteration is likely a new vertical on the same rails rather than a new technique.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.