Four Verticals, One Encrypted Tracker: A Lead-Gen PII Toolkit
Four Verticals, One Encrypted Tracker: A Lead-Gen PII Toolkit
Since early 2026, one operator has used a single encrypted click-tracker kit and one nameserver pair to run auto, home, health, and loan lead-gen email campaigns. From the inbox, the verticals appear unrelated: an auto-insurance quote follow-up, a home-coverage notice, a health-plan estimate, or a personal-loan approval. Beneath that surface, they use the same manufactured senders, Amazon SES delivery, coined NameCheap domains, and distinctive call-to-action. Each self-hosted tracking subdomain encrypts its redirect target with AES, preventing scanners from reading where the click lands. We track the toolkit through that tracker grammar and the Cloudflare nameserver pair shared by every domain in the cluster. During the first half of 2026, it grew from a couple dozen auto-insurance domains into a four-vertical PII-harvesting operation.
Key Takeaways
- One operator runs auto, home, health, and personal-loan lead-gen email through a shared toolkit identified by a single Cloudflare nameserver pair and an identical encrypted click-tracker.
- Every call-to-action passes through a self-hosted
tr.<apex>ortrack.<apex>subdomain. Its/cv2/path contains a CryptoJS AES-CBC payload, preventing a URL scanner from resolving the final landing page. - The apex domains are coined insurance and loan word-salad registered in same-day NameCheap bulk lots, including an eleven-domain loan lot purchased on a single day.
- Delivery uses Amazon SES across ten-plus regions, with SPF, DKIM, and DMARC all passing. Each message uses a one-shot, Faker-generated
firstname.lastnamesender that never builds a reputation. - The redirect returns to the sending domain's own
/form/page, a polished "insurance referral site" displaying major-carrier logos. Its multi-step form harvests driver's license, VIN, date of birth, and banking data for resale.
Background
Lead generation is a legitimate business. Quote-comparison and referral sites ask consumers shopping for auto insurance or a car loan to complete a multi-step web form, then sell the resulting "lead" to participating lenders, advertisers, and networks, usually for payment per lead or completed application. Regulators have documented for years how little separates that model from abuse. The FTC's 2022 action against lead generator ITMedia Solutions alleged that sensitive data from millions of loan applicants went to marketers and data resellers rather than lenders. The CFPB's Circular 2024-01 warned that comparison tools can steer consumers based on payment rather than fit. The operator described here copies the legitimate model's language and interface exactly, then keeps the PII and monetizes it entirely through resale. No real quote or lender sits behind the form.
The delivery and hosting rely on commonly abused infrastructure, which helps make the cluster effective. Amazon SES is AWS's elastic email service. SES signs SPF and DKIM for its own domains by default, and DMARC aligns after a custom MAIL FROM is configured, so every message the operator sends authenticates cleanly. Authentication shows that the sender controls an SES account, not that the message is honest. SES also requires setup in each region. An operator can therefore distribute volume across many regions and rotate the region-specific amazonses[.]com return-path, frustrating reputation systems that depend on a single envelope sender. The apex domains are registered through NameCheap and use its "Withheld for Privacy" service, an Iceland-based privacy entity that replaces every registrant field and prevents WHOIS-based attribution. NameCheap privacy does not hide the nameservers. When a domain joins a Cloudflare account, Cloudflare assigns it a fixed, account-specific pair of authoritative nameservers, which the account reuses across all its zones. An uncommon nameserver pair repeated across hundreds of otherwise unrelated domains provides a strong pivot to a single operator and forms the basis of our clustering.
Discovery and Infrastructure
Content alone does not bind the cluster together. Each message looks like a mildly pushy quote follow-up, while the sending domains share no obvious naming relationship beyond generic insurance terms. Two signals connect them. First, every apex across all four verticals uses the Cloudflare nameserver pair armando.ns.cloudflare[.]com and teagan.ns.cloudflare[.]com. Second, every message follows the same call-to-action grammar, routing clicks through a first-party tracking subdomain in the form tr.<apex>[.]com/cv2/<token>/<payload> or, later, track.<apex>[.]com/cv2/.... A pivot on that /cv2/ tracker path reveals sibling apexes faster than a domain list because a brand-new sending domain appears on the tracker as soon as it begins sending.
The toolkit covers four product verticals, all built from the same closed naming vocabulary.
| Vertical | Word-stems combined | Representative apexes (defanged) |
|---|---|---|
| Auto insurance | quote, auto, motor, car, drive, ride, policy, cover, insure | apolloquote[.]com, rapidquotegenie[.]com, motorquotewise[.]com, autoquoteedge[.]com, insuredrivesmart[.]com, insurequickride[.]com |
| Home insurance | home, cover / coverage, policy, safety, shield | homescoverage[.]com, shieldhomepolicy[.]com, thehomesafety[.]com, accesshomepolicy[.]com |
| Health insurance | health, care, plan, quote | healthcoverestimate[.]com, heritagehealthquote[.]com, quotemyplannow[.]com, lumacarex[.]com |
| Personal loans | lend, fund, cash | lendlyfe[.]com, lendlyst[.]com, krediblefunds[.]com, cashluma[.]com, fundsygo[.]com |
At its widest point in a single month, the cluster operated roughly ninety-six active sending apexes. Across the first half of 2026, it sent hundreds of thousands of these application-pretext messages. The verified inventory includes more than forty distinct tracking subdomains in addition to the sending apexes. Auto insurance is the oldest and largest vertical. Home, loan, and health launched later on the same infrastructure. Two aged NameCheap domains, sysytemtracks[.]com and typetracking[.]com, both registered in mid-2023, identify an earlier prototype in which several sending apexes used one shared tracker. The operator later moved to the isolated per-apex model used now.
How It Works
The same funnel appears across all four verticals. Only the product noun changes.
- Lead seeding. Some subject lines say
Received for: <phone>, suggesting that the operator has a lead list indexed by phone number, most likely purchased and recycled across both the insurance and loan verticals. - Delivery. A message arrives from
firstname.lastname@<apex>through Amazon SES. SPF, DKIM, and DMARC all pass, while the return-path rotates across regions. - Pretext. The subject and body imitate the back end of a quote platform:
We've reviewed your details,Application status,Your Updated Quote is Ready. A first-name greeting scraped from the recipient's address makes the message look like part of a workflow the victim already began. - The click. The call-to-action leads to
tr.<apex>[.]com/cv2/<token>/<payload>. The tracker records the open and click before redirecting. - Landing. The redirect returns to
<apex>[.]com/form/on the same domain that sent the email. The page describes itself as an "online insurance referral site" and displays logos for major carriers such as Liberty Mutual, Safeco, Farmers, Allstate, Progressive, and Nationwide as partner badges. Those carriers are not involved. Their brands appear without authorization to create trust. - Harvest. A multi-step form ("3 to 5 minutes to complete, have your driver's license handy") collects name, address, date of birth, driver's license, VIN, and driving history on the insurance verticals. On the loan vertical, it collects loan amount, email, and banking details.
- Monetization. The apex disclaimers state the plan directly: the operator will "share the information you provide with participating lenders, advertisers, networks, and other partners," including "entities that may not be actual lenders, such as debt settlement companies."
Sample Lures
The following are three representative messages, one from each major variant. Recipient data has been replaced with placeholders, and every domain is defanged. Attacker-side display names are personas manufactured by the operator.
From: "Eino Hayes" <[firstname].[lastname]@autoquotebeam[.]com>
Subject: Application status
Return-Path: <...@eu-west-2.amazonses[.]com>
Auth: SPF pass / DKIM pass / DMARC pass
Body: "Hi [recipient], We reviewed your application again and refreshed ..."
CTA: hxxps://tr[.]autoquotebeam[.]com/cv2/<token>/<U2FsdGVkX1...payload>
From: "Gilda Mraz" <[firstname].[lastname]@fasthelpy[.]com>
Subject: Thank you for your application
Return-Path: <...@us-west-1.amazonses[.]com>
Body: "Unsubscribe Hey [recipient], Application Recived Your request has been ..." (sic: "Recived")
CTA: hxxps://tr[.]fasthelpy[.]com/cv2/<token>/<U2FsdGVkX1...payload>
From: "Alicia Lockman" <[firstname].[lastname]@quotetrailauto[.]com>
Subject: We've reviewed your application
Return-Path: <...@eu-central-1.amazonses[.]com>
Body: "FOR YOUR REVIEW Hi [recipient], Your submission came through and ..."
CTA: hxxps://tr[.]sysytemtracks[.]com/cv2/<token>/<U2FsdGVkX1...payload> (shared legacy tracker)
Technical Analysis
Registration Cohorts and the Aged-Account Stash
WHOIS creation dates provide the clearest fingerprint for this operator. They show a buyer purchasing apexes in bulk lots while warming a separate reserve of aged domains for a reputation lift. The registrar is consistent across nearly the entire fleet: NameCheap, with only a handful of GoDaddy and NameSilo outliers. Every registrant organization field is either empty or "withheld for privacy ehf." No named organization appears anywhere in the cluster.
Grouping the domains by creation date reveals repeated same-day batches, with many operator domains registered together in a single lot. The launches of each vertical correspond with these lots.
| Cohort date | Batch size | Vertical | Notes |
|---|---|---|---|
| 2023-06-13 | 2 | Legacy trackers | sysytemtracks[.]com, typetracking[.]com, later repurposed |
| 2025-02-26 | 7 | Auto | First large auto lot |
| 2025-03-14 | 7 | Auto | apolloquote[.]com and siblings |
| 2025-04-18 | 6 | Auto | diamondautoinsurance[.]com and siblings |
| 2025-06-25 | 2 | Home | homescoverage[.]com, shieldhomepolicy[.]com |
| 2025-08-19 | 11 | Loans | Single-day loan bulk lot |
| 2025-09-11 | 7 | Auto | motorquotewise[.]com and siblings |
| 2025-11-25 and 11-26 | 3 + 3 | Health | Back-to-back health lots |
A stash registered years before deployment sits alongside the fresh lots: autoinsuranceking[.]com from 2021, policyacquire[.]com from 2022, fasthelpy[.]com from 2023, and the two 2023 legacy trackers. The operator assigns these older, reputation-aged domains to flagship duty while the same-day lots absorb the churn.
Domain-Generation Grammar
Every apex follows a [modifier] + [product-stem] pattern drawn from a fixed vocabulary. This creates substantial internal collision: dozens of *policy and *quote* names; an autoquote* family (autoquotebeam, autoquoteedge, autoquoteforge, autoquoteflow, autoquoteelite); and near-twin siblings such as quoteoriginal[.]com and originalpolicy[.]com, or carquoteflow[.]com and carquotefusion[.]com. The loan vertical adds lend*, fund*, and cash* stems, along with sibling pairs of its own (lendifty[.]com to lendiftypro[.]com). Another recurring tell appears on the cheaper generic top-level domains: an insure* ring on .co and .net (insureline[.]co, insuremax[.]co, insurepal[.]co, insurenow[.]net, insureplus[.]net, insurezone[.]net). Even the two aged trackers contain deliberate misspellings, sysytemtracks for "systemtracks" and typetracking. That makes them easy to overlook during a casual review and easy to fingerprint once identified.
The cv2 Encrypted Tracker
The tracker sits at the center of the kit. Every call-to-action uses tr.<apex>[.]com/cv2/<7-char token>/<payload>. The token is a short mixed-case alphanumeric string, and the payload always begins with U2FsdGVkX1. This prefix is the base64 encoding of Salted__, the eight-byte magic header that CryptoJS and OpenSSL place before the AES-CBC ciphertext in a passphrase-encrypted blob. The actual redirect target is therefore encrypted server-side and decrypted only in the browser with a hardcoded key. An automated scanner that retrieves the tracker URL without running JavaScript receives opaque ciphertext and cannot pre-classify the destination. The redirect does not go to a third-party host. It returns to the sending apex's own /form/ page, making the email sender and data-harvesting domain the same.
Each apex hosts its own tracker. Every sending domain has a separate tr. subdomain, so blocking one apex or tracker does not intercept the next domain's call-to-action. Later in the campaign, the operator introduced a second namespace, track.<apex>, alongside the older tr. prefix. This directly counters hunts limited to tr.*. It also marks the move away from the 2023 shared-tracker prototype, when tr.sysytemtracks[.]com and tr.typetracking[.]com handled multiple apexes at once.
Sender Manufacture
The senders are intentionally disposable. Each apex sends from firstname.lastname@<apex> addresses produced by a Faker-style library, at nearly one address per message, so individual senders never accumulate a history. The scale is substantial: flagship apexes use hundreds to low thousands of distinct burner local-parts each. The generated display names have a recognizable pattern, with rare surnames and occasional double-barreled forms. Observed examples include Dorothea Schmeler, Burdette Kautzer, Drake Fahey-Paucek, Berenice Pfannerstill, Dayne Kassulke, and Marguerite Harris. Subject lines rotate through a small set of application-lifecycle templates: Quote status, Application status, We've reviewed your details / information / application, Your application has been processed, Application successfully accepted, Regarding your application, Your submission came through.
One refinement indicates where the operator is heading. On the home-insurance flagship homescoverage[.]com, static no.reply@ and hello@ "support" identities operate alongside the Faker burners. They give the landing page a customer-service identity absent from the apexes that use only burners. The same hello@ identity has also sent under two different home-insurance display names, directly linking those two apexes to one operator without relying on infrastructure signals.
Cross-Vertical Pivots
Five signals connect the four verticals to one operator, although no single message contains more than a couple of them:
- Every apex uses the Cloudflare nameserver pair
armando.ns.cloudflare[.]comandteagan.ns.cloudflare[.]com. - Auto, home, health, and loan apexes all use the same
/cv2/<token>/U2FsdGVkX1...CryptoJS tracker grammar. - The entire fleet uses NameCheap with "withheld for privacy" or an empty registrant organization field.
- Amazon SES multi-region delivery is the sole sending backbone.
- The apex-is-the-landing funnel is consistent: the redirect always returns to
<apex>/form/on the sending domain, using the same referral-site template and carrier-logo wall in every vertical.
Detection Observations
This cluster's signal appears at the infrastructure level rather than in any single message. Viewed alone, each email is ordinary: valid authentication, a plausible quote-follow-up subject, a human-looking sender name, and a call-to-action hosted on a previously unseen domain. The repeated combination separates it from legitimate insurance marketing. The /cv2/ path carrying a base64 U2FsdGVkX1 payload is a narrow, high-confidence behavioral marker; almost no legitimate service uses OpenSSL-salted ciphertext as a click destination. The shared Cloudflare nameserver pair provides the strongest cross-vertical pivot because it connects a brand-new apex to the known cluster before the apex has established its own reputation. Defenders should focus on the repeated combination of first-party tracking subdomains with encrypted redirects and one-shot firstname.lastname senders on newly coined insurance and loan domains, rather than on any single field.
Indicators of Compromise
All indicators are defanged. The domain and host tables contain a representative subset of a much larger verified set; the operator's true inventory exceeds what appears here.
Senders
| Value | Role | Notes |
|---|---|---|
hello@homescoverage[.]com |
Sender | Mixed-persona "support" identity on the home flagship |
no.reply@homescoverage[.]com |
Sender | Static no-reply persona alongside Faker burners |
In addition to these addresses, each sending apex uses hundreds to thousands of one-shot firstname.lastname@<apex> Faker addresses.
Domains
| Value | Role | Vertical |
|---|---|---|
apolloquote[.]com |
Sending apex / landing | Auto |
rapidquotegenie[.]com |
Sending apex / landing | Auto |
motorquotewise[.]com |
Sending apex / landing | Auto |
diamondautoinsurance[.]com |
Sending apex / landing | Auto |
fasthelpy[.]com |
Sending apex / landing | Auto (aged stash) |
homescoverage[.]com |
Sending apex / landing | Home |
shieldhomepolicy[.]com |
Sending apex / landing | Home |
thehomesafety[.]com |
Sending apex / landing | Home |
healthcoverestimate[.]com |
Sending apex / landing | Health |
heritagehealthquote[.]com |
Sending apex / landing | Health |
lumacarex[.]com |
Sending apex / landing | Health |
krediblefunds[.]com |
Sending apex / landing | Loans |
lendlyfe[.]com |
Sending apex / landing | Loans |
cashluma[.]com |
Sending apex / landing | Loans |
| ... (representative subset; 250+ verified-malicious domains) |
Hosts
| Value | Role | Notes |
|---|---|---|
tr.apolloquote[.]com |
Click tracker | cv2 encrypted redirect |
tr.rapidquotegenie[.]com |
Click tracker | cv2 encrypted redirect |
tr.motorquotewise[.]com |
Click tracker | cv2 encrypted redirect |
tr.fasthelpy[.]com |
Click tracker | cv2 encrypted redirect |
tr.diamondautoinsurance[.]com |
Click tracker | cv2 encrypted redirect |
tr.healthcoverestimate[.]com |
Click tracker | cv2 encrypted redirect |
tr.heritagehealthquote[.]com |
Click tracker | cv2 encrypted redirect |
tr.thehomesafety[.]com |
Click tracker | cv2 encrypted redirect |
track.coveragecompass[.]com |
Click tracker | Later track. namespace |
track.driveshieldquote[.]com |
Click tracker | Later track. namespace |
track.insuredge[.]net |
Click tracker | Later track. namespace |
track.speedquotehub[.]com |
Click tracker | Later track. namespace |
tr.sysytemtracks[.]com |
Click tracker | Legacy shared tracker (2023) |
tr.typetracking[.]com |
Click tracker | Legacy shared tracker (2023) |
| ... (representative subset; 150+ verified-malicious hosts) |
URL Pattern
| Value | Role | Notes |
|---|---|---|
hxxps://tr[.]<apex>[.]com/cv2/<token>/<U2FsdGVkX1...> |
CTA redirect | CryptoJS AES-CBC payload; also track.<apex> variant |
MITRE Fight Fraud Framework Mapping
This mapping follows the MITRE Fight Fraud Framework (F3) v1.1, https://ctid.mitre.org/fraud. F3 technique identifiers use an F#### prefix for fraud-native techniques and an inherited T#### prefix for ATT&CK techniques; no FT prefix exists. The Monetization tactic applies to moving stolen funds, so the PII and lead-resale stage at the end of this funnel has no corresponding F3 technique. The nearest F3 and ATT&CK mappings for the observed flow appear below.
| Tactic | Technique | ID |
|---|---|---|
| Initial Access | Phishing: Spearphishing Link | T1566.002 |
| Initial Access | Phishing for Information (multi-step PII form) | T1598 |
| Resource Development | Acquire Infrastructure: Domains | T1583.001 |
| Resource Development | Create Fake Materials: Fake Website | F1020.002 |
| Resource Development | Impersonate Official (carrier-logo referral site) | F1032 |
| Monetization | Lead / PII resale | Not modeled in F3 (funds-transfer scoped) |
Conclusion
The operator remains durable by separating the infrastructure defenders can block from the part that causes harm. The blockable components, sending domains and tracker subdomains, are inexpensive, coined in bulk, and rotated according to a schedule visible in the same-day registration lots. The harmful component remains unchanged across every vertical and rebrand: an encrypted redirect that returns to the sender's own PII form. The durable signals are the shared nameserver pair, the /cv2/ salted-ciphertext tracker grammar, and the first-party tracking subdomain that separates the call-to-action from an apex-level block. The next vertical will almost certainly appear as another bulk NameCheap lot using the same nameservers and the same encrypted click.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.