One Domain, Three ESPs: A Multi-Brand Card-Activation Phishing Operator
One Domain, Three ESPs: A Multi-Brand Card-Activation Phishing Operator
Since mid-January 2026, one operator has impersonated over fifteen U.S. financial brands in card-activation phishing from one domain across three platforms. The lures promise a credit card on its way, a pending transfer, or an approval waiting to be claimed, and they arrive under the names of Amazon, Citibank, Chase, Wells Fargo, Capital One, Chime, and a dozen more. Every message traces back to a single sender address on one coined domain, sattape[.]com, yet the traffic fans out across eleven return-path subdomains and three separate email service providers. The operation is durable rather than disposable: one aged domain, a settled sending stack, and a display-name catalog deep enough to wear a new bank on any given day.
Key Takeaways
- A single operator runs a sustained multi-brand bank-card-activation phishing campaign from one long-lived domain, impersonating more than fifteen U.S. financial brands under 309 distinct display names.
- All rotation happens at the email-platform subdomain layer, not the domain layer. One sender address,
contact@sattape[.]com, fans out across eleven return-path subdomains. - The operator stacks three email platforms: Iterable for primary delivery through custom-CNAME
em-<account-id>subdomains, a secondary SendGrid account for a lower-brand-signal lure lane, and ActiveCampaign for click tracking. - Click-through links terminate at ActiveCampaign and SendGrid tracking hosts, hiding the real destination behind reputable redirector domains. The landing funnel is a set of geo-segmented eligibility quizzes on
quiz-usandquiz-uksubdomains. - A subset of messages embeds the recipient's real first and last name, which points to a purchased or breached contact list rather than a blind spray.
- The strongest correlator is the Iterable account ID baked into each
em-<id>subdomain. It stays constant while brands and geographies rotate around it.
Background
The operator surfaced during a review of high-volume senders, where one address, contact@sattape[.]com, stood out for the sheer breadth of brand names attached to it. The domain itself, sattape[.]com, is a coined word with no real-world brand behind it. Public reputation services blacklist it and its registration sits behind WHOIS privacy, while the site fronts a thin financial-news facade over the actual lead-generation funnel.
Card-activation and pending-transfer lures work because they borrow a routine moment. A consumer who has recently applied for a card, or simply holds several, has no strong reason to doubt a message that says the card is shipping or a balance is ready. The pretext asks for a small, plausible action, confirm your details, track your delivery, claim your transfer, and routes that action into a credential and PII capture flow.
Three legitimate platforms carry the traffic, and understanding why they appear matters for reading the infrastructure:
- Iterable is a marketing-automation and email platform. Customers can send under their own domain through a custom-CNAME return path shaped like
em-<account-id>.<customer-domain>, where the platform handles delivery while the mail still authenticates on the customer's domain. This is normal for a real sender. It also lets an operator wrap its own coined domain in an established platform's deliverability reputation. - SendGrid is a high-volume email delivery service. An operator can open an account, or several sub-accounts, and route a second stream of mail through a separate reputation pool.
- ActiveCampaign provides marketing automation with built-in link tracking. Every click on a tracked link resolves first to an ActiveCampaign redirector host, which then forwards to the real destination. Legitimate senders use this for click analytics. An operator uses it to keep the final landing page out of the visible link.
The campaign has run continuously since 17 January 2026, pushing hundreds of thousands of messages at both U.S. and U.K. recipients, the latter served by a dedicated geo variant of the quiz funnel.
Discovery and Infrastructure
One sender address anchors the entire operation. contact@sattape[.]com appears on every message, and the brand identity lives entirely in the From display name rather than the address. Mapping the return paths for that single sender surfaced eleven distinct sending subdomains, most of them Iterable custom CNAMEs on the operator's own domain, plus two return paths on shared mail hosts the operator also uses.
| Indicator | Role | Notes |
|---|---|---|
contact@sattape[.]com |
Sender | Single sender address behind every brand variant |
sattape[.]com |
Operator domain | Coined non-brand domain, Namecheap, registered 2023-03-05, WHOIS privacy |
em-<account-id>.sattape[.]com |
Delivery (Iterable) | Custom-CNAME return paths; account ID is the numeric label |
em2149.sattape[.]com |
Delivery (SendGrid) | Secondary rail carrying generic, brand-less display names |
go.sattape[.]com, lsm.sattape[.]com, ls.sattape[.]com |
Redirect / list management | Operator-owned funnel plumbing |
quiz-us.sattape[.]com, quiz-uk.sattape[.]com, quiz.sattape[.]com |
Landing funnel | Geo-segmented eligibility-quiz landing pages |
mail-42-196.acems2[.]com, d20c.emsend2[.]com |
Delivery (shared mail hosts) | Operator-linked return paths on shared infrastructure; attributable at host level only |
The click layer runs through ActiveCampaign tenant hosts on acemlna[.]com and acemlnb[.]com. Those parent domains are shared by many unrelated senders, so they are not operator infrastructure in their own right. The operator's tenant CNAMEs under them (for example jr19.acemlna[.]com) are the correct granularity for any reputation action, and the coined sattape[.]com domain and its subdomains are the operator-owned indicators.
How It Works
A representative message arrives under a bank's name, carries a card-delivery or pending-transfer subject, and authenticates cleanly because it is sent through a real email platform on the operator's own domain. The body offers a single tracked link. Clicking it lands first on an ActiveCampaign or SendGrid tracker, which forwards through the operator's redirect subdomains toward a geo-appropriate eligibility quiz on quiz-us.sattape[.]com or quiz-uk.sattape[.]com. The quiz frames itself as a card-eligibility or activation check and collects the credentials and personal data the operator is after.
Brand assignment is not fixed to a subdomain. Any given sending subdomain carries several brands over time, so there is no clean per-subdomain brand mapping to key on. The one constant is the sender address and the domain beneath it.
Sample Lures
All samples show attacker-side content only. Recipient names and other personal data have been replaced with placeholders, and every domain is defanged.
Card-delivery pretext under an Amazon display name, delivered on the Iterable rail:
From: "Amazon" <contact@sattape[.]com>
Subject: Update on your Amazon card delivery
Return-Path: <bounce@em-3654499.sattape[.]com>
Your card is heading your way. Confirm your details to track the delivery.
[tracked link -> http[:]//jr19.acemlna[.]com/lt.php?...]
Card-status pretext under a Citibank display name, a different Iterable tenant:
From: "CitiBank" <contact@sattape[.]com>
Subject: Your CITI card status can be checked
Return-Path: <bounce@em-3542066.sattape[.]com>
Brand-less lure on the secondary SendGrid rail, where the display name drops any bank name entirely:
From: "Delivery" <contact@sattape[.]com>
Subject: (3) new messages about your recommendation
Return-Path: <bounce@em2149.sattape[.]com>
Name-personalized pretext under a JPMorgan display name, routed through a shared mail host. The recipient's real name appeared where the placeholder now sits:
From: "JPM Manager" <contact@sattape[.]com>
Subject: [recipient name], $525.00 on your Card
Return-Path: <bounce@mail-42-196.acems2[.]com>
Technical Analysis
One Durable Apex, Rotation at the Platform Layer
Most high-volume phishing farms burn domains, registering throwaway names in bulk and using each once. This operator does the opposite. sattape[.]com was registered through Namecheap on 5 March 2023, sits behind WHOIS privacy, and has carried the campaign since January 2026. There is one apex, not a rotating stable. The churn that would normally show up as new domains instead shows up as new sending subdomains under that one apex, which keeps the operator's reputation investment intact while still giving each brand and each platform its own sending identity.
The Three-Rail Delivery Stack
Delivery splits across three platforms, each playing a distinct role.
| Rail | Sending shape | Role |
|---|---|---|
| Iterable (primary) | em-<account-id>.sattape[.]com |
Bulk delivery of the branded card-activation lures |
| SendGrid (secondary) | em2149.sattape[.]com |
Separate reputation pool for generic, brand-less lures |
| ActiveCampaign | Tenant CNAMEs (for example jr19.acemlna[.]com) |
Click tracking and link redirection |
Stacking platforms this way means the visible link chain terminates at a shared click-tracker or delivery host rather than at a landing domain. A reader following the resolved link sees an ActiveCampaign or SendGrid host and stops there, because those hosts re-resolve to themselves. The real funnel on the operator's quiz subdomains sits one hop past what the link exposes.
Subdomain Grammar and the Account-ID Correlator
The sending subdomains follow a readable grammar. The Iterable rails take the form em-<account-id>.sattape[.]com, where the digits are the operator's Iterable account identifier. The SendGrid rail drops the hyphen (em2149). The rest of the subdomains are functional.
| Subdomain shape | Function |
|---|---|
em-<6-7 digits>.sattape[.]com |
Iterable sending tenant; digits are the account ID |
em2149.sattape[.]com |
SendGrid sending tenant |
go. / lsm. / ls.sattape[.]com |
Redirect and list-management plumbing |
quiz. / quiz-us. / quiz-uk.sattape[.]com |
Geo-segmented eligibility-quiz landings |
uk.sattape[.]com |
U.K.-facing funnel entry |
The account ID is the strongest single correlator in the whole campaign. Iterable account identifiers are per-account and stable, so they do not change when the operator swaps a brand name or a target country. Any new domain that starts sending under one of this operator's known account IDs is almost certainly the same actor moving a tenant to fresh infrastructure. That property is what makes the em-<id> grammar worth tracking on its own, independent of the domain.
One Sender, Many Brands
The campaign cycles 309 distinct From display names over the single sender address. The catalog spans more than fifteen major U.S. financial brands (Amazon, Citibank, Wells Fargo, Chase, Capital One, Chime, Credit One, U.S. Bank, American Express, USAA, Fifth Third, Bank of America, Apple Card, Huntington, JPMorgan, and PenFed) alongside generic labels such as Delivery, Notice, Card Services, and Pending Transfer. The brand lives in the display name and nowhere else in the envelope, which is what lets one address impersonate a dozen banks without any change to the underlying mail path.
Geo-Segmented Quiz Funnels
The landing side splits by geography. quiz-us.sattape[.]com and quiz-uk.sattape[.]com are separate entry points into what reads as a card-eligibility quiz, a common lead-generation shape where an eligibility questionnaire collects personal data before, or instead of, a credential prompt. The U.K. variant, together with a dedicated uk. subdomain, confirms the operator segments delivery and landing by region rather than running a single global funnel.
A Convergent-Infrastructure Sibling
A parallel card-activation cluster targeting a Portuguese-speaking market runs on a strikingly similar build: the same Iterable, ActiveCampaign, and SendGrid combination, numerically adjacent Iterable account-ID ranges, shared mail hosts, and structurally identical multi-geo quiz funnels appearing in the same first-seen window. The overlap is consistent with a single operator or a tightly coupled affiliate reusing one playbook. We describe it as convergence rather than firm attribution: the indicator sets do not share an Iterable account ID, so the link is behavioral, not proven.
Detection Observations
The following are behavioral signals that separate this campaign's traffic from legitimate bank mail. They describe the adversary, not any detection stack.
- A single sender address cycling hundreds of brand display names is the defining anomaly. Real banks send under their own authenticated domains, not a shared coined domain wearing a rotating set of names.
- The mismatch between envelope and claim is visible in the grammar itself: an
em-<id>custom-CNAME on a coined, non-brand domain paired with a display name claiming a major bank. - Click-through links that resolve to a marketing click-tracker rather than a brand-owned domain are a strong structural tell, especially when the tracker is the terminal hop the link exposes.
- The generic-display-name lane on the secondary rail is the hardest slice to recognize by brand alone, because those messages carry no bank name to catch on. It ties back to the operation at the ecosystem level through the shared sender and shared apex, not per message.
- Content fingerprints persist for months. A misspelled subject line, "Verify your email adress", and a fixed set of card-activation templates recur verbatim across brands and rails, which makes the body text a persistent signal even as display names rotate.
- A subset of messages carries the recipient's real name in the subject, a personalization step that both raises victim trust and marks the operator as working from an acquired contact list.
MITRE Fight Fraud Framework Mapping
The behaviors map to the MITRE Center for Threat-Informed Defense Fight Fraud Framework (F3) matrix (https://ctid.mitre.org/fraud). Mapping is by tactic and technique name; consult the live matrix for current technique identifiers.
| Tactic | Observed behavior | Observed behavior |
|---|---|---|
| Resource Development | Acquire infrastructure | One aged domain plus accounts on three email platforms |
| Resource Development | Acquire victim contact lists | Recipient names embedded in a subset of subjects |
| Initial Access | Phishing message | Branded card-activation and pending-transfer emails |
| Initial Access | Brand impersonation | More than fifteen bank brands worn via display name |
| Execution | Pretext and urgency | Card-delivery, approval, and transfer framing |
| Monetization | Credential and PII harvest | Eligibility-quiz landing funnels capture data |
| Stealth | Redirect through trusted services | Click-trackers hide the landing domain |
Indicators of Compromise
All indicators are defanged. Recipient data has been removed. This is a representative set drawn from the verified-malicious indicators for this campaign.
Senders
| Value | Role | Notes |
|---|---|---|
contact@sattape[.]com |
Sender | Single sender behind every brand variant |
Domains
| Value | Role | Notes |
|---|---|---|
sattape[.]com |
Operator domain | Namecheap, registered 2023-03-05, WHOIS privacy |
Hosts
| Value | Role | Notes |
|---|---|---|
em-3654499.sattape[.]com |
Delivery (Iterable) | Sending tenant |
em-3542066.sattape[.]com |
Delivery (Iterable) | Sending tenant |
em-3602932.sattape[.]com |
Delivery (Iterable) | Sending tenant |
em-3632745.sattape[.]com |
Delivery (Iterable) | Sending tenant |
em-3602929.sattape[.]com |
Delivery (Iterable) | Sending tenant |
em-3770592.sattape[.]com |
Delivery (Iterable) | Sending tenant |
em-3770143.sattape[.]com |
Delivery (Iterable) | Sending tenant |
em-3553939.sattape[.]com |
Delivery (Iterable) | Sending tenant |
em2149.sattape[.]com |
Delivery (SendGrid) | Secondary brand-less rail |
go.sattape[.]com |
Redirect | Funnel plumbing |
lsm.sattape[.]com |
List management | Funnel plumbing |
ls.sattape[.]com |
Landing / redirect | Funnel plumbing |
quiz.sattape[.]com |
Landing funnel | Eligibility quiz (generic) |
quiz-us.sattape[.]com |
Landing funnel | Eligibility quiz (U.S.) |
quiz-uk.sattape[.]com |
Landing funnel | Eligibility quiz (U.K.) |
uk.sattape[.]com |
Landing funnel | U.K.-facing entry |
Conclusion
The operator's choice to settle on one aged domain and rotate at the platform layer is what makes this campaign worth watching. Burn-and-rotate farms leak new domains constantly; this one hides its churn inside an established sending reputation and a deep display-name catalog. The account IDs stamped into its Iterable subdomains are the thread to pull: they persist across every brand and geography change, and any fresh domain that starts sending under one of them is the same hand moving to new ground.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.