Five Dashes and a Token: Inside a Multi-Brand Sweepstakes Email Kit
Five Dashes and a Token: Inside a Multi-Brand Sweepstakes Email Kit
Since January 2026, one operator has run a multi-brand sweepstakes email kit that tags every message with a tracking token buried after five dashes in the sender name. The token is the tell. A message might read Costco-Member-Surprise-----mictac2013 one minute and Endurance-Auto-Partners-----mictac2013 the next, the brand out front swapping constantly while the same trailing string rides along untouched. That string is not decoration. It is an operator bookkeeping artifact that survives every change of sending account, every change of impersonated brand, and every rotation of infrastructure, which makes it the single most durable way to follow the kit. We have tracked at least eleven of these tokens across more than twenty Gmail accounts and over 580 short-lived Amazon S3 buckets, and the operator is still sending today.
Key Takeaways
- Every message carries a fixed
-----<token>suffix on the From display name, an operator label that persists across sender, brand, and infrastructure rotation and links otherwise-unrelated sends into one kit. - The mail comes from genuine Gmail accounts that pass SPF, DKIM, and DMARC. This is brand impersonation from a real mailbox, not header spoofing, so authentication verdicts alone do nothing against it.
- First-stage landing pages live in random-named Amazon S3 buckets that JavaScript-redirect through a URL fragment to an unidentified affiliate network. There is no intermediate redirector domain.
- The affiliate fragment carries a per-token publisher seat (1586, 1589, 1590, 1757) that stays constant while everything else rotates, making it a stronger operator fingerprint than any sender or domain.
- A newer cohort runs one bucket per message, so per-host reputation can never catch up. The durable detection surface is the sender-name grammar, the subject template, and the fragment schema, not the hosts.
- Live infrastructure confirms one operator behind tokens once treated as separate: the July token
outrez1reusesmictac2013's publisher seat and sending accounts.
Background
Prize and sweepstakes lures persist because they are cheap to send, they exploit a durable hope of winning, and they pay per result. Fake prize, sweepstakes, and lottery fraud sits among the top categories reported to the U.S. Federal Trade Commission every year. The economics behind this particular kit are lead generation: a cost-per-action affiliate network pays a publisher each time a referred person completes an action, such as submitting a form or opting into a list, and prize bait is the classic incentive to make someone hand over their details. The personal data captured on the landing page becomes a lead that gets sold and remarketed.
Two pieces of abused infrastructure make the delivery work, and both deserve a plain explanation because the kit leans on the trust they carry.
Amazon S3 is object storage that can serve static HTML and JavaScript directly from an amazonaws[.]com subdomain over an Amazon-issued TLS certificate. A landing page hosted there inherits the clean parent domain and valid certificate of a major cloud provider, which helps it slip past reputation checks and look legitimate to a recipient. A bucket is a one-line spin-up and costs almost nothing, so pages are disposable. When a bucket is reported and removed, the operator rotates to a fresh random-named one, a burn-and-rotate rhythm that stays ahead of reactive, per-URL takedown.
The sending accounts are ordinary Gmail mailboxes. Because they are real accounts rather than spoofed headers, the mail is legitimately signed and aligned, so SPF, DKIM, and DMARC all pass. The deception lives entirely in the display name and the body, not in forged envelope fields. Any control keyed on authentication failure sees nothing wrong. Free-provider signup is low friction and easy to farm at volume, which is why the operator can afford to treat accounts as consumable.
Discovery and Infrastructure
The kit surfaced from a single seed: the token mictac2013 appearing in a gift-card lure. Pivoting on the literal token would have found one stream. Pivoting on the shape of the token, a five-dash suffix anywhere in the display name, turned one operator into a kit of parallel streams in a single pass. That shape is the discovery lesson worth keeping. When an operator plants a fixed-position label in a header field, hunt the grammar of the label, not its current value.
The infrastructure divides into three layers, each disposable on its own schedule.
| Layer | What it is | Rotation behavior |
|---|---|---|
| Sending accounts | Genuine Gmail mailboxes, farm-registered, auth-aligned | Burned after roughly a 60-day active window, then a fresh pair reactivates the same token |
| First stage | Random-named *[.]s3[.]<region>[.]amazonaws[.]com buckets serving landing HTML |
Shared across a few messages in early cohorts, one bucket per message in later cohorts |
| Monetization | An unidentified cost-per-action affiliate network reached through a URL fragment | Network slot churns weekly; the publisher seat behind it stays fixed per token |
The operator also separates the visible sender from the bounce handler. The address a recipient sees in the From field and the SMTP envelope sender that absorbs bounces are different Gmail accounts. The bounce handlers never appear as a visible sender, so they stay invisible to any telemetry keyed on the From address, yet they are operator infrastructure and map cleanly onto the visible accounts they serve.
How It Works
A representative message is almost empty. The From display name carries a brand-decorated string, five dashes, and the operator token. The subject follows a rigid template. The body has been reduced to a token marker and a single link into an S3 bucket.
From: "BenefitsDepot-Unclaimed-Stimulus-----mictac2013" <lofhorrohamankajol303@gmail[.]com>
Subject: RE: 77---Fast-Find-Funds-To-day----9051960060390
--mictac2013--(hxxps://sfjsdhfjsjdhfjsdqgd[.]s3[.]eu-central-1[.]amazonaws[.]com/<rand>.html#cl/268362_md/3/322261/5454/1586/10089)
The recipient who clicks lands on the S3 page. That page runs JavaScript that reads its own URL fragment, everything after the #, and immediately redirects onward to the affiliate network. The fragment matters because browsers keep it client-side and never send it to the server. A URL-reputation crawler that fetches the base S3 address sees a benign shell. The routing that turns the click into a paid lead is only ever read by the visitor's browser, a form of client-side cloaking that hides the monetization step from anything that is not a live victim.
The subject template does its own social-engineering work. The leading RE: fakes a pre-existing conversation, so the message reads as an expected reply rather than cold outreach, and the long trailing number poses as a reference or case ID to reinforce the illusion of an ongoing transaction. Neither is real. Both are generated per send.
Sample Lures
The samples below are real messages with all recipient data removed. In practice this kit carries no recipient content to remove, because the body is reduced to the token marker and the link. Every URL and domain is defanged. Each example shows a different pretext riding the same grammar.
Financial lead-gen, fake stimulus:
From: "BenefitsDepot-Unclaimed-Stimulus-----mictac2013" <lofhorrohamankajol303@gmail[.]com>
Subject: RE: 77---Fast-Find-Funds-To-day----9051960060390
Body: --mictac2013--(hxxps://sfjsdhfjsjdhfjsdqgd[.]s3[.]eu-central-1[.]amazonaws[.]com/<rand>.html#cl/268362_md/3/322261/5454/1586/10089)
Real-estate lead-gen:
From: "Liz-Buys-Houses-----valerieknowlton56" <rohimkhan645@gmail[.]com>
Subject: RE: 29---They-actually-were-super-open-about-other-options----5228793615583
Landing: hxxps://sfosdiogfisdogsdgs[.]s3[.]eu-central-1[.]amazonaws[.]com/<rand>.html#cl/268302_md/3/325808/5427/1589/5316
Auto-warranty impersonation:
From: "Endurance-Auto-Protection-----mictac2013" <noyonmd9715@gmail[.]com>
Subject: RE: 10---You-need-an-auto-protection-from-Endurance----4669145897279
Non-English survey funnel, a one-off German variant:
From: "Aldi-Member-Gift-----christineahall18" <smd245150@gmail[.]com>
Subject: RE: 49---Willkommen-zur-FizzClean-Umfrage!----7605423150278
Live July build, same grammar, current infrastructure:
From: "<brand-decorated>-----valerieknowlton56" <rohimkhan645@gmail[.]com>
Body: --valerieknowlton56--(hxxps://qdqsfqsfqskfkqskfkqsfqsf[.]s3[.]eu-central-1[.]amazonaws[.]com/<rand>.html#cl/283528_md/3/524509/5500/1589/5316)
Technical Analysis
The Display-Name Token and Subject Grammar
The kit signs itself twice. Every From display name matches -----[a-z0-9_]+$, exactly five hyphens followed by the operator token, and every subject matches ^RE: \d{2}---<dash-joined-words>----\d{10,13}$. A single account will fire unrelated brand prefixes back-to-back within one day. On 12 July, one account carried Ace-Hardware-Deals, Lowe's-Loyalty-Offer, USPS-Member-Surprise, Prime-Support, Netflix-Member-Services, and Endurance-Partners in a single burst, spanning retail sweepstakes, subscription phish, and auto-warranty in minutes. The brand churns to defeat keyword blocklists. The token does not move.
Impersonation From Genuine Mailboxes
The sending accounts are @gmail[.]com throughout, and the local parts follow a farm convention of romanized names plus a numeric suffix, such as rohimkhan645, jutheaktherjue, and lofhorrohamankajol303. Because the accounts are genuine, they authenticate correctly. The visible From account and the envelope bounce handler are deliberately separate mailboxes. One bounce handler commonly serves two visible senders, which keeps the bounce-processing and list-hygiene machinery off the addresses that recipients and telemetry actually see.
S3-Only Delivery and the Bucket-per-Message Lifecycle
The S3 page is the only host between the inbox and the affiliate network. There is no second-stage redirector domain, a deliberate simplification that removes a link a defender could pivot on. Bucket names are pseudo-random consonant-heavy strings with no dictionary content, roughly 15 to 26 characters, in two visible families: a keyboard-cluster style (sqdqfqsfgsdggdg, djqskjdkjqskjdkqskdq) and a repeating-syllable style (nezjfeuzguegezyyezgz). No brand token ever appears in a bucket name. Early cohorts shared a bucket across two to seven messages. From late April 2026 onward the live cohorts run one bucket per message, a near 1:1 ratio of hosts to sends. That lifecycle change is the point that defines defense: per-host reputation cannot flag buckets faster than the operator creates them, so the host layer is a losing surface and the durable signal sits in the message grammar.
Region choice is itself an indicator. The primary region is eu-central-1 in Frankfurt, with eu-west-1 in Ireland as a secondary and a single stray us-east-1 bucket. Pinning storage for a U.S.-targeted campaign to European regions offers no legitimate benefit and reads as deliberate diversification away from U.S.-centric abuse-reporting reflexes.
The Affiliate Fragment and the Publisher-Seat Fingerprint
The fragment carries the whole monetization contract in one line: #cl/<clickid>_md/<seg>/<network_id>/<offer_id>/<pub_id>/<sub_id>. The click ID is per-impression. The _md/<seg>/ value toggles between 2 and 3 and is a kit-internal switch, since both appear on the same token and publisher on the same day. The network ID rotates weekly. The offer ID selects the brand decoy. The publisher and sub-affiliate IDs are where attribution lives, because the publisher seat stays constant per token across every other rotation.
| Token | Publisher seat | Sub-affiliate | Sample network IDs | Sending accounts | Status (2026-07-14) |
|---|---|---|---|---|---|
valerieknowlton56 |
1589 | 5316 | 300365, 297349, 524509 | rohimkhan645, jutheaktherjue |
Active today |
mictac2013 |
1586 | 10089 | 296175, 322261, 345317 | noyonmiabd046, noyonmd9715, rabbihassan1208, lofhorrohamankajol303 |
Rotated to outrez1 |
outrez1 |
1586 | 9643 | 507981 | rabbihassan1208, lofhorrohamankajol303 |
Active 2026-07-12 |
jramosmuller |
1590 | 8342 | 225181, 304259, 225182 | apurbosagor7, mdjubayer1051 |
Trailing |
lisar185 |
1590 | 5448 | 225451, 225455, 225457 | apurbosagor7, mdjubayer1051 |
Retired |
joyoden19 |
1757 | 490 | 286085 | smd245150, mdomrfaruk788 |
Retired |
christineahall18 |
1757 | 2003 | 298591, 285875 | smd245150 |
Retired |
lebronze5454 |
1585 | 1935 | 256175, 289018 | shahjahanbkash2019, bablumohammed576 |
Retired |
mikijenkins3 |
1659 | 259139, 259138 | y1125667, joyb3514 |
Retired | |
wa3nga |
1773 | per-token cluster | rummanshohely10, mukteremon733 |
Retired |
The seat reuse tells the attribution story. Tokens joyoden19 and christineahall18 share seat 1757, which links two streams once handled as separate. Tokens jramosmuller and lisar185 share seat 1590 and the same two sending accounts, which ran the accounts sequentially under one token and then the other. Most decisively, the July token outrez1 uses seat 1586, the mictac2013 seat, and is carried by mictac2013's own accounts. That is one operator rotating a token on warm accounts, observed live.
Vertical Expansion and Build Evolution
The lure set has broadened over the campaign's life while the plumbing stayed constant. Alongside the original retail sweepstakes, prize, and financial lead-gen pools, 2026 traffic added subscription and account phish (Netflix, Prime, USPS), home and auto warranty (American Home Shield, Endurance), lending and credit bait (Destiny card, equity cash-out, bad-credit loans, burial insurance), and health clickbait.
| Pretext vertical | Sample display-name prefixes |
|---|---|
| Retail sweepstakes and free gift | Ace-Hardware-Deals, Lowe's-Loyalty-Offer, Exclusive-from-Walmart, Dear-Omaha-Steaks-Customer, Tractor-Supply-Promo |
| Subscription and account phish | Netflix-Member-Services, Netflix-Reactivation-Team, Prime-Support, USPS-Member-Surprise |
| Cloud-lockout phish | Cloud-Account-Support, Cloud-System-Message, Cloud-Storage-Alert, storage-limit-exceeded |
| Home and auto warranty | American-Home-Shield-Today, Home-Warranty-AHS, Endurance-Auto-Partners, Endurance-Warranty-Services |
| Lending, credit, insurance | Apply-for-Destiny-Now, Cash-Out-Equity, Lending-For-Bad-Credit, Liz-Buys-Houses |
| Health and supplement clickbait | Fat-Burning-Pantry, Energy-Secret, Get-Sonic-Glow-Brush |
The build has evolved in small, visible steps. Late April 2026 moved the S3 link from inside the hosted HTML into the email body next to the token marker, and switched to one bucket per message. Around 30 April the operator ran a one-day experiment with roughly ten numeric-only tokens, all under the mictac2013 publisher seat, then abandoned it. In May the storage drifted to eu-west-1 and a single us-east-1 bucket appeared, and one message replaced the cleartext fragment with a single base64-opaque hash. By summer the region reverted to eu-central-1 only and the fragment reverted to cleartext. The experiments came and went. The grammar and the publisher seats did not.
Detection Observations
The signal that separates this traffic from legitimate mail sits in the grammar, not in any single field a brand could also use. A display name ending in five hyphens and an alphanumeric token, on a freemail account, is close to a standalone tell. Pair it with the subject template, RE: followed by a two-digit number, a dash-joined phrase, and a ten-to-thirteen digit trailing number, and the combination is high precision. The body reduced to a --<token>-- marker beside a lone S3 link is a third independent signal.
Because the hosts turn over one per message, host reputation is the weakest place to fight this. The stronger pivots are the message grammar above and the affiliate fragment, where the stable per-token publisher seat is the most durable cross-cluster anchor the kit exposes. Authentication tells a defender nothing here, since the mail is properly signed from real accounts. The recognition has to come from content and structure.
Mitigation and Guidance
- Treat a five-dash-plus-token suffix on a freemail display name as a strong standalone signal, and escalate sharply when it co-occurs with the
RE:numeric subject template. - Do not rely on authentication verdicts. This mail passes SPF, DKIM, and DMARC because the accounts are genuine, so alignment is not evidence of legitimacy.
- Prioritize message-grammar and fragment-schema rules over per-host reputation, because the one-bucket-per-message model outpaces host blocking by design.
- Where infrastructure signals are used, weight the stable per-token publisher seat in the affiliate fragment over the weekly-rotating network ID.
- Report abusive object-storage buckets to the hosting provider, and recognize that takedown reduces but does not stop a burn-and-rotate operator.
- Where an affiliate or lead-gen network can be identified downstream, an abuse complaint at the network cuts monetization across every token at once, which sender or host action cannot.
MITRE Fight Fraud Framework Mapping
The mapping below aligns to MITRE CTID's fraud framework (F3, https://ctid.mitre.org/fraud). Identifiers use the framework's fraud series (F####) and reused ATT&CK techniques where the framework references them. It is an approximate alignment, and the monetization step is called out as a genuine gap rather than force-fit.
| Tactic | Observed behavior | ID |
|---|---|---|
| Initial Access | Phishing message as first contact | T1566 |
| Reconnaissance | Gather customer information via lead capture | F1029 |
| Resource Development | Create fake website (S3 landing pages) | F1020.002 |
| Initial Access | Impersonate official (brand impersonation via display name) | F1032 |
| Stealth | Geographic diversification of hosting | F1030 (loose fit) |
| Monetization | Affiliate and lead-gen resale | No clean framework match; noted as a gap |
Header spoofing techniques do not apply, because the mail authenticates from genuine mailboxes rather than forged envelopes.
Indicators of Compromise
All indicators are defanged. Recipient data has been removed. The sender list is a representative subset of 23 verified operator-controlled Gmail accounts, chosen to show the durable high-volume senders, the reactivated cohort, and the separate bounce-handler infrastructure.
Senders
| Value | Role | Notes |
|---|---|---|
rohimkhan645@gmail[.]com |
Sender | Token valerieknowlton56; active 2026-07-14 |
jutheaktherjue@gmail[.]com |
Sender | Token valerieknowlton56; active 2026-07-14 |
rabbihassan1208@gmail[.]com |
Sender | Tokens mictac2013, outrez1; reactivated cohort |
lofhorrohamankajol303@gmail[.]com |
Sender | Tokens mictac2013, outrez1; reactivated cohort |
noyonmiabd046@gmail[.]com |
Sender | Token mictac2013; burned ~2026-04-01 |
noyonmd9715@gmail[.]com |
Sender | Token mictac2013; burned ~2026-04-01 |
mdjubayer1051@gmail[.]com |
Sender | Tokens jramosmuller, lisar185 |
apurbosagor7@gmail[.]com |
Sender | Tokens jramosmuller, lisar185 |
smd245150@gmail[.]com |
Sender | Tokens joyoden19, christineahall18 |
mdmir704@gmail[.]com |
Bounce handler | Serves rohimkhan645, jutheaktherjue |
jumuhoque1985@gmail[.]com |
Bounce handler | Serves rabbihassan1208, lofhorrohamankajol303 |
aasrafali33@gmail[.]com |
Bounce handler | Serves noyonmiabd046 |
md.tarekollslam88@gmail[.]com |
Bounce handler | Serves apurbosagor7 |
Hosts
| Value | Role | Notes |
|---|---|---|
*[.]s3[.]eu-central-1[.]amazonaws[.]com |
First-stage landing | Primary region; random-named burner buckets; shared cloud platform, flag at the specific bucket only |
*[.]s3[.]eu-west-1[.]amazonaws[.]com |
First-stage landing | Secondary region for the May cohort |
*[.]s3[.]us-east-1[.]amazonaws[.]com |
First-stage landing | Single observed bucket; minor drift |
URLs
| Value | Role | Notes |
|---|---|---|
hxxps://sfjsdhfjsjdhfjsdqgd[.]s3[.]eu-central-1[.]amazonaws[.]com/<rand>.html#cl/268362_md/3/322261/5454/1586/10089 |
Landing | Token mictac2013; publisher seat 1586 |
hxxps://sfosdiogfisdogsdgs[.]s3[.]eu-central-1[.]amazonaws[.]com/<rand>.html#cl/268302_md/3/325808/5427/1589/5316 |
Landing | Token valerieknowlton56; publisher seat 1589 |
hxxps://qdqsfqsfqskfkqskfkqsfqsf[.]s3[.]eu-central-1[.]amazonaws[.]com/<rand>.html#cl/283528_md/3/524509/5500/1589/5316 |
Landing | Live July build; publisher seat 1589 |
Message Patterns
| Value | Role | Notes |
|---|---|---|
Display name -----[a-z0-9_]+$ |
Signature | Five-dash operator token suffix on a freemail sender |
Subject ^RE: \d{2}---.*----\d{10,13}$ |
Signature | Fake-reply prefix plus fake reference number |
Fragment #cl/\d+_md/[23]/\d{6}/\d{4}/\d{4}/\d{4,5} |
Signature | Affiliate routing with stable per-token publisher seat |
Conclusion
The pieces a defender would naturally reach for are the ones this operator treats as disposable. Sending accounts burn on a schedule, buckets last a single message, brands rotate by the minute, and even the fragment format has been swapped out and back as an experiment. What stays fixed is the grammar the kit signs itself with and the affiliate publisher seat that keeps the money flowing. Those are the anchors worth watching, and the live July activity under a fresh token on old accounts says the operator has no plans to stop.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.