Four Funnels, One Kit: Phishing on Linode Object Storage
Four Funnels, One Kit: Phishing on Linode Object Storage
Since December 2025, one operator has run four phishing funnels from a single kit, staged on burn-and-rotate Linode Object Storage buckets. The lures look unrelated at street level: a cloud-storage lockout warning, a Costco reward, a Bill Gates "Alzheimer's cure," a weight-loss pharmacy pitch. Underneath they share one delivery chain. Every message ships from a disposable Gmail account, points at a random-string bucket on linodeobjects[.]com, and carries the same client-side URL-fragment token. The operator registers no domains, spins up no servers, and rotates buckets faster than any single one can be blocklisted. What ties the campaign together is not a brand or a pretext but a build: the same infrastructure grammar shows up under English, French, and Swedish templates and across four separate ways of turning a click into money.
Key Takeaways
- A single operator drives four monetization funnels (cloud-storage credential theft, reward/sweepstakes affiliate lures, health and elderly supplement bait, and insurance/loan/pharmacy lead-gen) through one shared kit.
- Every lure is hosted on Linode (Akamai) Object Storage buckets under
linodeobjects[.]com, chosen over the more heavily monitored AWS S3, Google Cloud Storage, and DigitalOcean Spaces. - Bucket labels are machine-mashed junk (keyboard walks, held-key runs, consonant gibberish) with zero brand tokens; the brand deception lives entirely in the email body, never in the URL.
- Each CTA ends in a fixed-length, per-recipient base64 fragment that stays client-side and never reaches upstream URL scanners.
- The operator uses no domains of its own: more than 800 disposable Gmail senders and over 550 burner buckets across eight Linode regions, with the primary bucket-farm migrating from Amsterdam and Osaka to Atlanta over the run.
Background
The operation surfaced when routine scam-domain triage flagged linodeobjects[.]com as a fast-accelerating source of credential-phishing traffic that had not yet been categorized as hosting infrastructure. That gap is the whole point of the technique. Linode Object Storage is an S3-compatible service, now under the Akamai and Linode umbrella, that lets anyone publish an internet-reachable "bucket" of files served over a *.<region>.linodeobjects[.]com URL with a valid TLS certificate. A static HTML phishing page dropped into one of those buckets inherits the trust signals of a large cloud provider: the padlock, a recognizable parent domain, and no attacker-registered domain for a reputation system to burn. Buckets are cheap and disposable, so an operator can burn and replace them the moment one is flagged.
Choosing Linode specifically is an evasion decision. The dominant object-storage providers (AWS S3, Google Cloud Storage, DigitalOcean Spaces) are watched more closely, taken down faster, and crawled harder by reputation vendors. A lower-friction, less-policed storage backend buys more uptime per bucket before detection catches up. The pattern is not unique to this operator: public sandbox and reputation feeds show a steady stream of credential-harvest and redirect pages served from S3-compatible endpoints, and linodeobjects[.]com appears often enough that at least one major endpoint vendor now maintains a standing detection for the domain, with public sandbox reports going back to 2024 that show the same per-victim URL-fragment structure this kit uses.
The senders reinforce the same borrow-don't-build posture. Messages ship from freshly created, single-use Gmail accounts, so SPF, DKIM, and DMARC all legitimately pass. Those checks only prove the mail really came from the claimed Gmail mailbox, not that the mailbox or its content is trustworthy. Authentication "pass" is trivially satisfied by anyone who can open a free inbox, and here the account is discarded after roughly one send. Domain-level and sender-authentication signals therefore give a defender almost nothing to work with, which pushes the entire detection burden onto content and URL structure.
Discovery and Infrastructure
Mapping the operation started from the one durable anchor it has: the object-storage apex. Pivoting on linodeobjects[.]com traffic and clustering by bucket host, region, sender, and body content produced a coherent single-operator footprint rather than scattered unrelated abuse. Three properties hold across the entire set and distinguish it from ordinary bucket-hosted phishing.
First, scale without ownership. The operator has cycled through more than 800 disposable sender addresses (almost entirely Gmail, with a stray pair of Hotmail accounts) and over 550 distinct buckets, and has registered no domains of its own. Every piece of infrastructure is either free webmail or rented object storage, and that fleet has carried thousands of messages across the run.
Second, region rotation. The buckets span eight Linode regions, and the primary farm has moved over time. Early in the run the operator lived on Amsterdam (nl-ams-1) and Osaka (jp-osa-1); from spring 2026 onward Atlanta (us-southeast-1) became the dominant home while Amsterdam continued and Osaka decayed. The migration tracks hosting-account availability, not victim geography: language and region show no correlation.
Region (linodeobjects[.]com) |
Buckets, early run | Buckets, recent |
|---|---|---|
us-southeast-1 (Atlanta) |
0 | 257 |
nl-ams-1 (Amsterdam) |
90 | 153 |
jp-osa-1 (Osaka) |
41 | 22 |
eu-central-1 (Frankfurt) |
2 | 0 |
us-east-1 (Newark) |
0 | 1 |
it-mil-1 (Milan) |
0 | 1 |
us-lax-1 (Los Angeles) |
1 | 0 |
in-maa-1 (Chennai) |
1 | 0 |
Third, near-one-bucket-per-sender churn. Roughly 69 percent of buckets are one-shot, tied to a single sender; the remaining 31 percent are touched by more than one sender, and even the busiest bucket tops out at five or six senders. This is a burn-and-replace posture, not a stable stash. It also explains why classifying senders one at a time has almost no forward value: the address that sent yesterday's blast will not send tomorrow's.
How It Works
A representative chain is short. A disposable Gmail account sends a message whose display name carries the pretext ("YOUR CLOUD STORAGE IS FULL. ACCESS AT RISK," "Costco Bonus," "ABC Health News"). The body carries the emotional hook and a single call to action. That CTA points at a random-string bucket on linodeobjects[.]com, with a base64 fragment appended after a #. The victim's browser loads the static HTML page from the bucket, client-side JavaScript reads the fragment to personalize the page or stamp a conversion token, and the funnel takes over from there: a fake login form for the cloud-panic lures, a multi-step "answer a survey to claim your gift" flow for the reward lures, a long-form supplement or lead-gen landing for the health and insurance lures.
The subject line is often deliberately disconnected from the display name to defeat correlation logic. A "Storage Alert" display name arrives under a "Closing Ceremony" subject; a "Cloud Storage Team" display name arrives under "Appointment Reminder." A recurring calendar-style subject family ("Appointment Reminder," "Visit Reminder," "Your Scheduled Appointment") acts as a benign-looking decoy across multiple funnels.
Sample Lures
The samples below are attacker-side content only. Recipient addresses, per-recipient tracking fragments, and unsubscribe tokens have been removed; all hosts and sender domains are defanged.
Cloud-storage lockout, the dominant funnel, with a sextortion overtone:
From: "YOUR CLOUD STORAGE IS FULL. ACCESS AT RISK" <arnisaagolliu80@gmail[.]com>
Subject: Programs
Body: FINAL REMINDER: Your photos have been leaked. Stop deletion before it's too late.
CTA: http[:]//f5ds4f2d12.jp-osa-1.linodeobjects[.]com/ [per-recipient fragment removed]
Reward / sweepstakes affiliate funnel, brand-impersonation shell:
From: "Costco Bonus" <howdolikemeus11@gmail[.]com>
Subject: Your order is in progress
Body: Image Map Page ... Answer a brief survey to claim your reward.
CTA: http[:]//fds8gf7d5454.nl-ams-1.linodeobjects[.]com/fds8gf7d5454.HTML [fragment removed]
Health / elderly funnel, deepfake-celebrity clickbait feeding a supplement scam:
From: "ABC Health News" <bc798196@gmail[.]com>
Subject: UPLOADED
Body: Bill Gates: "It's over for Alzheimer's"
CTA: http[:]//otetaabas.nl-ams-1.linodeobjects[.]com/otetaabas.html [fragment removed]
Insurance / loan / pharmacy lead-gen funnel:
From: "DirectMeds Weight Loss" <laurenmorales795@gmail[.]com>
Subject: Login successful
Body: GLP-1 by DirectMeds
CTA: http[:]//fsdfds87f8d7.nl-ams-1.linodeobjects[.]com/fsdfds87f8d7.HTML [fragment removed]
French-language cloud-panic variant, same kit, swapped-language body:
From: "Alerte stockage, Mise a niveau requise" <jusfsbsiushszgz@gmail[.]com>
Subject: Bouge Maintenant
Body: Vos photos et fichiers dans le cloud seront supprimes ce soir.
CTA: http[:]//plocnbdfzaqw.nl-ams-1.linodeobjects[.]com/ [fragment removed]
The Bill Gates "Alzheimer's cure" lure is not a one-off. It feeds a widely fact-checked, cross-platform deepfake-celebrity supplement scam that public researchers have tied to a family of products marketed as a honey-based memory cure. Fact-checkers at Snopes, JordanLiles, and MalwareTips, along with mainstream outlets, have all documented the pretext and the fabricated endorsements behind it.
Technical Analysis
The kit's signature is legible in its infrastructure choices. Each of the following is an operator-build detail, observed across the full footprint.
Bucket-Naming Grammar
Bucket labels are machine-mashed junk with no dictionary words and no brand-suggestive tokens whatsoever. Four overlapping generative patterns account for nearly all of them:
| Pattern | Defanged examples |
|---|---|
| Keyboard walk / row runs | zxcvcxvxc21v2c5x4g54df, wsdwgwdgwjklik, lkmklmklmertertvcbqa, mklmkmlkbvnbvnbv |
| Held-key / tail mash | df5sdfsdfsdfsdfffffff, def5gfgfdvfftttttttttttt, 9z9z855555da, sqdqsdqd555555 |
| Consonant-cluster gibberish | hfdxhfxhfxrere, dghkvfzehvfzkeh, fdxgfchsqgvdsqhgjvdhk, vdghsvshvkhgv |
| Short random alphanumeric | 4t56uk, 0d54a98d58a8, 0c11a88ad5a, cds56f4ds1f21c |
The consistency of the junk grammar is itself the fingerprint. The operator never once tries to make a bucket look brand-legitimate, because the brand deception is delivered in the email body, not the URL. A bucket named dghkvfzehvfzkeh under a message impersonating Costco is a per-message mismatch between the claimed brand and the destination host, and that mismatch holds across every funnel.
The Per-Victim URL Fragment
The strongest kit tell is the CTA structure. Most bucket links carry a # fragment of a fixed-length base64 blob, unique per recipient, appended to the bucket URL:
http[:]//<bucket>.us-southeast-1.linodeobjects[.]com/<bucket>/#<144-char base64 token>
Everything after the # is a URL fragment, which by web design stays on the client and is never sent to the server in the HTTP request. Upstream mail gateways, proxies, and server-side URL scanners see only the shared base URL; the personalized payload is invisible to them. Client-side JavaScript on the landing page reads the fragment to pre-fill the victim's email, tailor the lure, or stamp affiliate-conversion tracking. The token's fixed length and per-recipient uniqueness make it a reliable structural signal even when the bucket host is brand new.
Legitimacy Borrowing
The kit dresses each blast as compliant marketing mail. It attaches a List-Unsubscribe header, an unsubscribe link, and additional benign-looking URLs, and it embeds an open-tracking pixel on a /oc/ path. The unsubscribe and pixel URLs point at unrelated, legitimate-looking third-party domains, and the body is padded with URLs scraped from real universities, government sites, and small non-profits. The purpose is to dilute the ratio of suspicious to benign links and lower the message's spam score. The presence of those trustworthy-looking URLs does not mean the referenced organizations are involved: the technique borrows others' reputation without their participation, and the decoration domains are not treated here as operator-controlled.
Four Funnels, One Delivery Chain
The same infrastructure feeds four distinct cash-out paths. Ranked by prevalence, cloud-storage credential phishing is dominant, followed by reward affiliate lures, then health and elderly bait, with insurance and loan lead-gen the smallest.
| Funnel | Display-name families (defanged examples) | Monetization |
|---|---|---|
| Cloud-storage panic (dominant) | "YOUR CLOUD STORAGE IS FULL. ACCESS AT RISK", "Storage warning, files at risk", "ACTION REQUIRED: Data protection disabled", "Cloud Subscription Services" | Credential theft, account takeover, recurring "upgrade" billing |
| Reward / sweepstakes | "Costco Bonus", "Harbor Freight Rewards Club", "Sam's Club Rewards Club", "Macy's Free Gift Estee Lauder", "Oral-B Dental Kit", "ULTA 2026" | Affiliate CPL/CPA, PII resale, "shipping fee" card capture |
| Health / elderly | "AARP Gift Get Your Health Monitoring Kit", "ABC Health News", fake "M.D." personas, glucose-monitor bait, Bill Gates Alzheimer's | Recurring-billing supplement fraud, medical PII resale |
| Insurance / loan / pharmacy | "Provide Insurance - Find Savings", "Car insurance rates as low as $19/mo", "Tax-Relief-Services", DirectMeds GLP-1 | Lead-gen CPL, pharmacy charge fraud |
The reward funnel carries a recognizable body shell (a literal "Image Map Page" token followed by a survey CTA), and a persistent sub-thread spoofs subscription renewals with spaced-letter brand strings to slip past keyword matching.
Multilingual Template Recycling
Three languages appear, all reusing the identical bucket-CTA kit with swapped body strings. English is the base and majority. French variants carry cloud-panic bodies ("Vos photos et fichiers dans le cloud seront supprimes") and reward bodies ("Lidl : Votre cadeau confirme," "recupere ton cadeau"). Swedish appears as a cloud-panic body token ("Varning om kritisk lagring") under English-looking display names. Same funnels, same buckets, localized strings: the templates are recycled from a shared base rather than rebuilt per locale.
A Distinct Operator
Cross-checking sender addresses against the reward-survey kits already documented on DigitalOcean Spaces, AWS S3, and Google Cloud Storage returns zero overlap. This is a Linode-specialized operator running in parallel to those groups, not a pivot of any of them, which is consistent with the deliberate choice of a less-monitored storage backend.
Detection Observations
The campaign's traffic separates from legitimate mail on structure rather than reputation. The single strongest signal is the CTA itself: a random-string subdomain on a cloud-object-storage provider, terminating in a fixed-length client-side base64 fragment. Legitimate marketing rarely routes a call to action to a raw object-storage bucket, and almost never with a per-recipient fragment token.
A second signal is the mismatch between a brand-heavy body and a brand-empty host. When a message impersonating a national retailer or a health authority points at a bucket whose name is keyboard-walk gibberish, the claimed brand and the destination host disagree. The decoupling of display name from subject line is a related tell, as is the recurring calendar-style subject family used as a decoy.
Sender-side signals are weak by design. Fully aligned SPF, DKIM, and DMARC on a Gmail-origin message says nothing about intent, and one-shot sender churn defeats per-sender reputation. Content-level and URL-structure signals carry the load here, and the multilingual body tokens ("Vos photos et fichiers," "Varning om kritisk lagring," "Image Map Page") are operator-specific enough to serve as durable, brand-agnostic anchors.
Mitigation and Guidance
- Treat a CTA that resolves to a raw
*.linodeobjects[.]combucket (or any S3-compatible object-storage host) as high-risk when the sending domain is unrelated free webmail, and weight random-string bucket labels heavily. - Key on the structural signal, not the brand: a fixed-length client-side base64 fragment on an object-storage CTA is a reliable, brand-agnostic anchor that survives bucket rotation.
- Flag the brand-body versus brand-empty-host mismatch, and the display-name versus subject decoupling, as correlated content signals rather than relying on either alone.
- Do not treat aligned SPF/DKIM/DMARC on a freemail sender as exculpatory; pair sender analysis with URL and content structure.
- Track object-storage phishing as a cross-provider pattern. An operator forced off one backend will move to another (Backblaze B2, Wasabi, Cloudflare R2, OVH, Vultr), so pre-categorize object-storage apexes as hosting infrastructure and classify at the bucket-host level.
- Report abusive buckets to the storage provider's abuse channel for upstream takedown, and watch for the same kit fingerprint reappearing under new regions and languages.
MITRE Fight Fraud Framework Mapping
This mapping aligns to the MITRE Fight Fraud Framework (F3, https://ctid.mitre.org/fraud). Technique names describe the observed behavior; the framework's numeric technique IDs are still being reconciled and are omitted rather than approximated.
| Tactic | Technique (as observed) |
|---|---|
| Initial Access | Unsolicited mass phishing email from disposable webmail accounts, linking to object-storage-hosted lures |
| Initial Access | Brand, authority, and celebrity impersonation (reward brands, fake medical personas, deepfake endorsements) plus manufactured urgency |
| Execution | Urgency and false-scarcity pressure ("deleted tonight," "photos leaked") to drive click-through and form completion |
| Monetization | Credential harvesting via fake login pages and PII capture via multi-step lead-gen forms |
| Positioning | Per-recipient base64 URL-fragment tokenization for personalization and conversion tracking ahead of cash-out |
| Monetization | Affiliate-conversion payouts, resale of harvested credentials and PII, and recurring-billing supplement fraud |
| Stealth | Burn-and-rotate buckets, throwaway senders, client-only URL fragments, region rotation, and legitimacy-borrowing headers |
Indicators of Compromise
All indicators are defanged. Victim data has been removed. Bucket hosts are recorded as hosting infrastructure rather than standalone malicious indicators, so the shareable set below is the operator's verified senders and a representative set of landing URLs.
Senders
| Value | Role | Notes |
|---|---|---|
arnisaagolliu80@gmail[.]com |
Sender | Cloud-panic, "photos leaked" |
shabbiralisathiya3@gmail[.]com |
Sender | Cloud-panic, Storage Alert |
thaibinhvuong3@gmail[.]com |
Sender | Cloud-panic, subscription |
vohaibinh645@gmail[.]com |
Sender | Cloud-panic, Stop Deletion |
howdolikemeus11@gmail[.]com |
Sender | Reward, Costco |
abhsgwyswnsbhwys@gmail[.]com |
Sender | Reward, Oral-B |
ddinsmorey@gmail[.]com |
Sender | Reward, Macy's / Estee Lauder |
bc798196@gmail[.]com |
Sender | Health, ABC / Bill Gates |
dangg6821@gmail[.]com |
Sender | Health, AARP wellness |
danielashley2343@gmail[.]com |
Sender | Health, AARP wellness |
laurenmorales795@gmail[.]com |
Sender | Lead-gen, DirectMeds GLP-1 |
choudryedsalma482@gmail[.]com |
Sender | Lead-gen, DirectMeds (FR) |
jusfsbsiushszgz@gmail[.]com |
Sender | Cloud-panic (FR) |
kamleshbariyarayshing@gmail[.]com |
Sender | Reward, Lidl (FR) |
thaitoanp86@gmail[.]com |
Sender | Cloud-panic, Product Warning |
| ... | representative subset; 100+ verified-malicious senders of the 800-plus observed |
URLs
| Value | Role | Notes |
|---|---|---|
http[:]//fds8gf7d5454.nl-ams-1.linodeobjects[.]com/fds8gf7d5454.HTML |
Landing | Reward, Costco |
http[:]//bgf5bfgbgbbg.nl-ams-1.linodeobjects[.]com/bgf5bfgbgbbg.HTML |
Landing | Reward, Oral-B |
http[:]//otetaabas.nl-ams-1.linodeobjects[.]com/otetaabas.html |
Landing | Health, Bill Gates |
http[:]//fsdfds87f8d7.nl-ams-1.linodeobjects[.]com/fsdfds87f8d7.HTML |
Landing | Lead-gen, DirectMeds GLP-1 |
Conclusion
The operator's advantage is that it owns nothing worth taking down. No domain to seize, no server to raid, just rented buckets and free inboxes that cost nothing to replace. That makes takedown a treadmill and reputation-blocking a blunt instrument against a trusted parent domain. The durable weakness is structural: the kit's random-string buckets, its client-side fragment token, and its brand-empty hosts under brand-heavy bodies do not change when the region, the language, or the pretext does. Defenders who anchor on that build, rather than on the brand of the week, will keep pace as the operator rotates regions and adds the next funnel.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.