mv388: Multi-Vertical Reward Phishing From a Single Google Cloud Bucket
mv388: Multi-Vertical Reward Phishing From a Single Google Cloud Bucket
Since December 2025, an operator we track as mv388 has run a single Google Cloud Storage bucket as the delivery point for rotating reward and benefits lures. The name comes from the one artifact that never changes: storage.googleapis[.]com/mv388/, a bucket path that has anchored the campaign for more than seven months while everything around it churns. The sending domains are disposable, the display names shift, and the pretext rotates from veteran benefits to food stamps to prize giveaways to romance bait, but every message points back to the same two landing scripts in the same bucket. That stability, sitting underneath a deliberately unstable surface, is what makes mv388 worth documenting.
Key Takeaways
- One Google Cloud Storage bucket path (
mv388/) has been the campaign's single delivery endpoint continuously since December 2025, across more than a dozen distinct lure pretexts over time. - Sending domains follow a tight machine-generated grammar (random-string apex, single-use address) and are burned after one send, which defeats sender-reputation accumulation by design.
- Nearly the entire domain set carries no retrievable WHOIS record and no mail DNS. The absence of a registration trail is itself the fingerprint of a disposable-domain pipeline.
- Lure content rotates on a roughly weekly cadence, but the bucket path, the two landing-script names, and the tracking-parameter grammar stay constant, so the infrastructure is the durable pivot rather than the content.
- The operator recently decoupled its envelope: the visible From domain is a fresh burner apex, while the Return-Path resolves to an unrelated third-party mail domain, and the display name is spoofed to the recipient's own inbox handle.
Background
mv388 sits inside a broader family of phishing activity that abuses Google Cloud Storage as a landing-page host. Google Cloud Storage buckets are public object storage reachable at storage.googleapis[.]com/<bucket>/<file>, delivered over a valid Google-issued TLS certificate on a Google-owned parent domain. That combination is exactly why scammers reach for it: the first hop of the click looks first-party, so a storage.googleapis[.]com link inherits trust that an unknown apex would never get, and it slips past reputation checks that key on the hostname. The operator only has to park a lightweight HTML redirect or landing script in a bucket and let disposable sending domains carry the mail. Independent researchers have documented the same pattern repeatedly, including buckets serving HTML redirect scripts purpose-built to ride Google's reputation past filters (Paubox, GBHackers, Trustwave SpiderLabs).
What distinguishes mv388 from the general pattern is discipline. Where most cloud-bucket phishing spins up a fresh bucket per wave and discards it, this operator has kept one bucket, mv388/, in continuous service for more than seven months. The bucket path behaves like a stable namespace: the operator lives in it, and every lure it runs leads there. Around that fixed point it rotates domains and pretexts fast enough that no single lure or sending domain stays observable for long.
Discovery and Infrastructure
The campaign surfaced through its sending grammar. A population of sender apex domains matching a uniform random-string template kept landing on the same Google Cloud Storage bucket, and pivoting on the bucket path pulled the whole cluster together. The sending domains and the landing infrastructure form a deliberately flat, two-sided shape with no subdomain layer on either side.
On the send side, mail originates from bare apex domains: no subdomains, randomized local-parts, and one message per address before the address is abandoned. More than a hundred distinct burner apexes have cycled through rotation, at a cadence of roughly twenty-five fresh registrations a month, sustaining several thousand single-use sending addresses over the campaign's life. The apex grammar started as exactly six random alphanumeric characters on .com or .us and has since widened to ten- and twelve-character random strings, but the principle holds: no dictionary words, no brand tokens, nothing a human chose.
On the landing side, every lure resolves into the one bucket. The two scripts, nation.html and perdre.html, take a per-recipient tracking token as a query string. In the earliest cohorts that token was short, a seven-digit number followed by a single uppercase letter. In current traffic it has grown into a long multi-segment string, but it still rides the same two script names in the same bucket.
| Indicator | Role | Notes |
|---|---|---|
storage.googleapis[.]com/mv388/ |
Landing (bucket path) | Operator-controlled path on Google's shared storage host; single delivery endpoint since Dec 2025 |
mv388/perdre.html |
Landing script | Dominant current lander; takes a per-recipient tracking token |
mv388/nation.html |
Landing script | Second lander used interchangeably across cohorts |
^[a-z0-9]{6}\.(com|us)$ |
Sender apex grammar | Original template; later widened to 10-12 char random strings |
| Burner apex domains | Sender | Random-string, single-use, ~25 fresh/month, no brand resemblance |
How It Works
A recipient receives a message whose From address sits on a random-string domain they have never seen. The display name is set to something familiar: either a themed persona built for the pretext, such as the veterans-benefits persona "VeteransDiscountsLive," or, in the current cohort, the recipient's own inbox handle, which manufactures a sense that the message is somehow self-addressed or already trusted. The subject carries urgency and a fabricated reference number, and the body is a compact image-map creative rather than styled text, so most of the visible content is a single clickable graphic.
Every path through that graphic leads to the same place. The click opens perdre.html or nation.html in the mv388/ bucket with a tracking token appended, and from there the Google-hosted script carries the victim onward. Because the landing hop is a genuine storage.googleapis[.]com URL under a valid Google certificate, the part of the chain a cautious user might inspect looks legitimate.
The pretext on any given day is close to arbitrary. mv388 has run veteran benefits, food-stamp and stimulus benefits, subscription-expiry notices impersonating streaming and radio brands, prize giveaways for outdoor and kitchen brands, casino bonuses, health and weight-loss angles, astrology clickbait, and romance bait, all through the one bucket. The lure is a costume; the bucket is the body underneath.
Sample Lures
The samples below are redacted. Recipient identifiers, per-recipient tracking tokens, and reference numbers are replaced with placeholders, and all domains and URLs are defanged. Only attacker-side content is shown.
Veteran benefits (the campaign's signature pretext, themed persona):
From: "VeteransDiscountsLive" <hcyhillp3y6ds2t0ci@gpgcy5[.]com>
Subject: 2026 Veteran Update: 12 New Benefits _ [token]
Body: Official Announcement - 12 "Wild" Benefits For Veterans in 2026.
Here's the full list of benefits that could save you thousands...
CTA: http[:]//storage.googleapis[.]com/mv388/perdre.html?<tracking-id>
Government benefits (food stamps, current cohort with recipient-handle display name):
From: "[recipient handle]" <scxe6@gn9e946bln[.]com>
Subject: Food Stamps Status: We need your confirmation Now ID#<ref>
Body: Food Assistance Support - Food Stamps Status...
CTA: http[:]//storage.googleapis[.]com/mv388/perdre.html?<tracking-id>
Prize giveaway (outdoor-brand and hardware-store reward):
From: "[recipient handle]" <ijhsl@tfb4snx469[.]com>
Subject: Get the YETI PATRIOTIC Bundle - Free Today ID#<ref>
Body: Claim Your Reward - Limited Time Offer... Ace Hardware Reward, Pending Offer
CTA: http[:]//storage.googleapis[.]com/mv388/perdre.html?<tracking-id>
Insurance brand impersonation:
From: "[recipient handle]" <hu83o@jwycmjdzm9[.]com>
Subject: Policy Update: Premium Adjustment Notice
Body: Auto-Owners Insurance - policy/premium adjustment...
CTA: http[:]//storage.googleapis[.]com/mv388/perdre.html?<tracking-id>
Romance bait:
From: "[recipient handle]" <info@mzfpbxzlhtnj[.]com>
Subject: She's not "fine" - she just doesn't want to hurt your ego ______[token]
Body: Regain Your Power - Is Your Wife Really...
CTA: http[:]//storage.googleapis[.]com/mv388/perdre.html?<tracking-id>
Astrology clickbait (current high-volume pretext):
From: "[recipient handle]" <info@7vb62f[.]com>
Subject: Something Extraordinary Is About to Happen
Body: Your 2026 Horoscope - Your Shocking 2026...
CTA: http[:]//storage.googleapis[.]com/mv388/perdre.html?<tracking-id>
Technical Analysis
Registration Footprint and the Negative-Space Fingerprint
The most useful thing about mv388's domains is what is missing from them. Across the burner-apex set, nearly none carry a retrievable WHOIS record: no registrar, no creation date, no registrant organization. Their DNS is equally bare, with no SPF, DMARC, or MX entries ever captured. Legitimate senders and even most durable scam infrastructure leave a registrar trail and mail-authentication records; this operator leaves almost none, because each apex is used once and abandoned before any enrichment sticks. The single exception in the set is one apex registered through a privacy-proxy at a mainstream registrar roughly twenty months before it appeared in traffic, which reads as an aged or recycled domain pulled into the pipeline rather than a member of the fresh-burner cohort.
That void has a practical consequence. The registrar-concentration signal a defender would normally chase, where one reseller equals one pipeline, is suppressed here. There is no cohort to group on, so the absence itself becomes the discriminator: a random-string apex with no WHOIS and no mail DNS, sending exactly one message, is already anomalous before the content is even read.
| Registration attribute | Observation |
|---|---|
| Apex grammar | Random alphanumeric, no dictionary words or brand tokens; 6-char original template widened to 10-12 char |
| TLD split | Overwhelmingly .com, with a rare .us minority (both .us apexes are structurally special) |
| Registration cadence | Roughly 25 fresh apexes per month; sparse early ramp, sustained surge from spring 2026 |
| WHOIS availability | Nearly none crawlable; one aged privacy-proxy exception |
| Mail DNS (SPF/DMARC/MX) | Absent across the set |
| Lifecycle | Single-use address, one message per apex-address, then abandoned |
Envelope Decoupling and Display-Name Spoofing
Recent traffic separates the parts of the envelope that older cohorts fused. The visible From domain is a fresh burner apex, but the Return-Path resolves to an unrelated third-party mail domain, frequently a small-business address that appears to be compromised or spoofed rather than operator-registered. That decoupling lets the mail lean on a separate relay reputation while the burner apex carries the brand-free From address.
The display name is the other manipulation. Instead of a plausible corporate sender, the current cohort sets the display name to the recipient's own inbox handle, and injects that same handle into subject lines as a personalization token. A message that appears to come from your own name, referencing your own name in the subject, reads as familiar before a word of the pretext lands. Earlier cohorts used themed personas instead, so both a fixed persona and a recipient-mirroring trick are in the operator's repertoire.
The Bucket as Identity
Within the parent Google Cloud Storage phishing family, each operator works out of its own dedicated bucket path, and mv388 stays exclusively in mv388/. It never crosses into sibling buckets, which makes the bucket path a clean single-operator boundary. Two edge cases prove where that boundary sits. One long random .us apex breaks both the 6-character grammar and the bucket rule, landing at a different bucket path entirely, which reads as a parallel sibling operator on the same toolkit rather than mv388. Separately, one .us apex broke the single-use rule with a sustained two-day auto-warranty blast, the lone reuse in an otherwise fire-and-forget population.
Four independent joins bind the cluster together: the uniform naming template, the single shared bucket path, the two shared landing scripts, and the shared tracking-parameter grammar. Any one is suggestive; together they are a high-confidence single-operator attribution that holds up even though the registrant data is nearly empty.
Lure Rotation on a Static Backend
The content layer moves constantly while the backend does not. The table below groups the observed lure families and their delivery on the one bucket.
| Lure vertical | Example subject / identity | Delivery |
|---|---|---|
| Veteran benefits | "VeteransDiscountsLive" persona; "2026 Veteran Update: 12 New Benefits" | mv388/ |
| Government benefits | Food-stamp confirmation; federal stimulus | mv388/ |
| Subscription expiry | Streaming and satellite-radio renewal notices | mv388/ |
| Prize / reward | Outdoor-brand and hardware-store giveaways | mv388/ |
| Brand impersonation | Insurance premium-adjustment notice | mv388/ |
| Casino / gaming | Bonus and free-spin offers | mv388/ |
| Health / supplement | Weight-loss and wellness angles | mv388/ |
| Astrology | 2026 horoscope clickbait | mv388/ |
| Romance | Relationship and marriage bait | mv388/ |
The takeaway for classification is that the pretext carries almost no durable signal on its own, because it changes weekly. The stable identity lives one layer down, in the bucket path, the two script names, and the tracking-token shape.
Detection Observations
The characteristics that separate mv388 traffic from legitimate mail are structural, not semantic. The envelope-from apex matches a tight machine-generated grammar, a short random-string domain with no dictionary content, and it typically has no WHOIS and no mail DNS behind it. The From domain and the Return-Path domain diverge, one a fresh burner apex and the other an unrelated third-party relay. The display name mirrors the recipient's own handle or a throwaway persona rather than a real organization. Subjects lean on urgency, fabricated reference numbers, and decorative symbols, and the body is usually a single image-map creative rather than styled text.
The strongest and most durable signal is the destination. Every message, regardless of pretext, resolves into the same cloud-storage bucket path and the same two landing-script names, with a per-recipient token appended. A defender watching for that exact bucket-path-plus-script combination catches the operator across every lure vertical at once, because the operator changes the costume far more often than the body. The single-use nature of each sending address means content and header signals have to carry the first-contact decision, since there is no sending history to lean on by the time a domain is seen.
MITRE Fight Fraud Framework Mapping
The mapping below aligns to the MITRE Center for Threat-Informed Defense fraud framework (https://ctid.mitre.org/fraud). Technique IDs in that framework evolve, so the mapping is given by tactic and technique behavior rather than fixed numeric identifiers.
| Tactic | Observed behavior | Observed behavior |
|---|---|---|
| Resource Development | Acquire infrastructure | Bulk registration of random-string burner apexes; provisioning of a persistent cloud-storage bucket as the landing host |
| Resource Development | Stage capabilities | Two static landing scripts parked in the bucket, reused across every lure |
| Initial Access | Phishing message | Mass email from single-use apex addresses carrying benefit, reward, and impersonation pretexts |
| Initial Access | Impersonation / familiarity | Themed personas, real-brand impersonation, and display names mirrored to the recipient's own handle |
| Execution | Urgency and enticement | Fabricated reference numbers, deadlines, and prize or benefit offers driving the click |
| Stealth | Trusted-infrastructure abuse | Landing hop served from a Google-owned domain under a valid TLS certificate; single-use domains and per-recipient tokens limiting observability |
Indicators of Compromise
All indicators are defanged. Victim data has been removed. The lists below are a representative subset drawn from the verified-malicious set; large aggregate totals are given as floors.
Senders
| Value | Role | Notes |
|---|---|---|
hcyhillp3y6ds2t0ci@gpgcy5[.]com |
Sender | Veteran-benefits persona |
dmv01@9x2az3[.]com |
Sender | Veteran benefits |
wswxa@wfp1x8[.]com |
Sender | Prize giveaway |
djmvn@ly4tj2[.]com |
Sender | Subscription-expiry lure |
8pa0k@k7p6l8[.]com |
Sender | Subscription-expiry lure |
byf6r@yb77dt[.]com |
Sender | Gift-card reward lure |
hxzbk@meln5s[.]com |
Sender | Casino bonus lure |
bzeja@jl98qf[.]com |
Sender | Casino bonus lure |
gso6n@sb911w[.]com |
Sender | Health lure |
jvn6t@jkb0l4[.]com |
Sender | Prize / survey lure |
mh0stivm4wovzzt@s4g75f[.]us |
Sender | Auto-warranty burst outlier (single reuse) |
mqiyfio@lbtrhcwfqnreuajafcillgfkho[.]us |
Sender | Parallel-bucket outlier |
| ... | (representative subset; 50+ verified-malicious sender addresses) |
Domains
| Value | Role | Notes |
|---|---|---|
gpgcy5[.]com |
Sender apex | Random 6-char template |
9x2az3[.]com |
Sender apex | Random 6-char template |
36w26y[.]com |
Sender apex | Random 6-char template |
wfp1x8[.]com |
Sender apex | Random 6-char template |
ly4tj2[.]com |
Sender apex | Random 6-char template |
k7p6l8[.]com |
Sender apex | Random 6-char template |
yb77dt[.]com |
Sender apex | Random 6-char template |
meln5s[.]com |
Sender apex | Random 6-char template |
jl98qf[.]com |
Sender apex | Random 6-char template |
sb911w[.]com |
Sender apex | Random 6-char template |
s4g75f[.]us |
Sender apex | .us outlier (single reuse) |
lbtrhcwfqnreuajafcillgfkho[.]us |
Sender apex | Long .us outlier (parallel bucket) |
| ... | (representative subset; 100+ verified-malicious apex domains) |
URLs
| Value | Role | Notes |
|---|---|---|
http[:]//storage.googleapis[.]com/mv388/perdre.html?<tracking-id> |
Landing | Dominant lander; per-recipient token |
http[:]//storage.googleapis[.]com/mv388/nation.html?<tracking-id> |
Landing | Second lander |
Conclusion
mv388 is a study in what stays fixed when everything else is disposable. The operator treats sending domains and pretexts as consumables, burning through random-string apexes and cycling lures fast enough to stay ahead of content signatures, while quietly anchoring the whole operation to one Google Cloud Storage bucket it has held for more than seven months. Defenders will get the most leverage from that asymmetry: chasing the lures is a treadmill, but the bucket path, the two landing scripts, and the tracking-token grammar have outlasted every costume the operator has worn so far.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.