Bogus-TLD Cloud-Storage Phishing: Anatomy of a Full-Stack Evasion Tier
Bogus-TLD Cloud-Storage Phishing: Anatomy of a Full-Stack Evasion Tier
Since March 2026 a phishing operator has sent iCloud account-lockout lures from email addresses on top-level domains that do not exist. The sender label reads like an ordinary domain, alert-2584@jrtca[.]mud, but .mud is not in the IANA root, so there is no DNS zone behind it, no SPF record to check, and no sending history for reputation to score against. That is one layer. Stacked on top of it are an image-only email body with no clickable link, a credential page parked in Google Cloud Storage and addressed by a URL fragment, and the operator's real click-through domain hidden inside the List-Unsubscribe header. Each layer removes a different signal a scanner would normally key on. Taken together they form a deliberate, reusable evasion tier that we have tracked continuously through mid-July 2026.
Key Takeaways
- Sender addresses ride on bogus, non-IANA top-level domains (
.ivx,.mud,.beq,.dfl, and dozens more), so there is no DNS zone and no sender-domain reputation to match. - The HTML body is a single image with no extractable anchor; the only working call-to-action sits in the
List-Unsubscribeheader, a field body scanners routinely ignore. - The credential page lives in operator-controlled Google Cloud Storage buckets and is selected by a URL fragment, keeping the operative parameters out of the fetched path and out of server logs.
- The SMTP return-path draws from an operator-coined reservoir under Ukraine's
.biz.uaregistry with a fixed(store|one).(ass|bss)NNNN.<label>host grammar; newer sends expand into Indonesia's.my.id. - A small pool of reused
Fromdisplay-name handles, led byladystar2419, is the strongest cross-tier pivot: it survives every TLD rotation, return-path swap, and infrastructure migration.
Background
Cloud-storage account-lockout phishing is a mature, publicly reported pretext, and 2026 brought a documented surge. The lure impersonates Apple or iCloud (some variants stay on a generic "Cloud Storage" brand to widen the target pool across Apple, Google, and Microsoft users) and warns the recipient that photos and videos will be deleted on a specific date unless they act. Consumer-security outlets including Forbes, TechRadar, and PCRisk have all described the "your iCloud photos and videos will be deleted" wave and the fake payment and credential pages it drives victims toward.
The operator we track chains that pretext to a set of infrastructure-abuse tricks that a general reader may not recognize:
- Google Cloud Storage buckets. Anything uploaded to a public bucket is served from
storage.googleapis[.]com/<bucket>/<object>on Google's own TLS certificate. Operators park landing pages there because the host is a high-reputation, widely allowlisted Google domain that many gateways will not block, so the page inherits Google's trust without the operator registering any domain of its own. Public analyses (Paubox, CyberSecurityNews) documented a March 2026 wave using exactly this bucket-as-redirect pattern. - The
.biz.uaregistry..biz.uais one of Ukraine's open commercial second-level domains, administered through the hostmaster.net.ua registry and created in 2003. It has effectively no registration vetting, which makes a reservoir of coined.biz.ualabels cheap, disposable, and unlikely to already sit on a blocklist: a rotating pool of "real enough" bounce domains. - Bogus, non-IANA sender TLDs. SMTP accepts whatever string appears in
MAIL FROMas an opaque envelope value. A receiving server is not required to resolve the sender domain before accepting the message, so aMAIL FROMon a TLD that does not exist in the root passes without any lookup ever failing. There is no domain, no zone, and therefore no reputation history to score. .my.id. An open Indonesian second-level domain offered at very low cost. Indonesia's own anti-phishing exchange repeatedly namesmy.idamong the most-abused.idSLDs, which is what makes it an attractive successor reservoir once.biz.ualabels start getting flagged.List-Unsubscribeheader abuse. TheList-Unsubscribeheader carries an opt-out URL that the mail client renders as a built-in "unsubscribe" affordance. Because many link-reputation layers parse the HTML body and treat headers as deliverability metadata, an operator can park the only attacker-controlled click-through there and it never reaches a body-only scanner.- URL-fragment payload loading. Everything after the
#in a URL is processed client-side and never sent to the server. Loading content by having JavaScript read a fragment such as#pid=...&vid=...keeps the operative parameters, and the specific rendered page, out of the fetched path and out of any static crawler that sees only a generic hosting URL.
Discovery and Infrastructure
The tier surfaced through its sender grammar. Every message uses a local part of alert- followed by four digits, and that pattern has no legitimate-mail collision in our corpus. Pivoting on it exposed the rest of the machine: more than fifty distinct one-shot sender addresses, most on their own five-letter label under a three-letter bogus TLD and a handful embedding a full envelope under a real SLD, each sending a single message and never reappearing. Across the tracked window the tier pushed thousands of messages through the same content template.
The return-path told a second story. While the visible sender domain does not exist, the SMTP return-path resolves to a live operator-coined host under .biz.ua, always shaped as (store|one).(ass|bss)<3-4 digits>.<label>.biz.ua. That host grammar is a precise operator fingerprint with no legitimate .biz.ua mail behind it. Across the tracked window we counted 54 distinct bogus sender TLDs and roughly 85 operator-coined return-path labels, all pouring into the same content template.
| Layer | Namespace | Registry / WHOIS | Status |
|---|---|---|---|
| Sender apex | Bogus non-IANA TLDs ([.]ivx, [.]mud, [.]beq ...) |
Not present in the DNS root | Cannot be resolved or reputation-scored |
| Return-path reservoir | *[.]biz[.]ua |
Ukrainian commercial registry (est. 2003) | Registry legitimate; operator labels ephemeral at host level |
| Return-path (newer) | *[.]my[.]id |
Indonesian PANDI SLD | Frequently cited among the most-abused .id SLDs |
| Covert CTA | Random 7-letter [.]com |
WHOIS privacy or absent | Purpose-built burners |
| Payload host | storage.googleapis[.]com buckets |
Google Cloud Storage | Platform legitimate; buckets operator-controlled, since rotated |
How It Works
A victim receives a message whose From display name is one of a handful of reused handles, most often ladystar2419. The subject warns that the account is blocked and the photos and videos will be deleted on a named date. The body renders as a single image, so there is nothing to read as text and no anchor to hover. A recipient who clicks the image, or the header-level "unsubscribe" affordance, is routed through the operator's .com redirect domain and lands on a page served from a Google Cloud Storage bucket. That page reads its URL fragment and renders the credential and payment form only when the expected parameters are present. The envelope that carried all of this never resolved in DNS, and the return-path that accepted the bounce belongs to a disposable .biz.ua label.
Sample Lures
All samples below are attacker-side content only. Recipient identifiers, tracking tokens, and fragment parameters have been redacted; every domain is defanged.
Cloud-storage plan-suspension pretext:
From: "Account-deletion" <alert-2584@jrtca[.]mud>
Return-Path: <...@store.ass0039.sightpop[.]biz[.]ua>
Subject: Your Cloud Storage Plan is suspended
Body: single image, no text, no anchor
Payload (fragment-loaded): hxxps://storage.googleapis[.]com/strow/strw_v3.html#pid=[redacted]
List-Unsubscribe: hxxps://dnftvux[.]com/[redacted]
Photos-deletion fear pretext:
From: "ladystar2419" <alert-3311@zvehc[.]ivx>
Return-Path: <...@store.ass0038.xernixo[.]biz[.]ua>
Subject: We've blocked your account! Your photos and videos will be deleted
Body: single image, no text, no anchor
Payload (fragment-loaded): hxxps://storage.googleapis[.]com/strow/strw_v3.html#pid=[redacted]
List-Unsubscribe: hxxps://ssarimk[.]com/[redacted]
Failure-notice pretext (full envelope embedded in the sender label):
From: "waugo1" <alert-0884@woajs.mail.store.bss0010.windtechhub[.]biz[.]ua>
Subject: Failure Notice
Body: single image, no text, no anchor
Payload (fragment-loaded): hxxps://storage.googleapis[.]com/hmdbox/hmd_v2.html#pid=[redacted]
List-Unsubscribe: hxxps://itjcmpv[.]com/[redacted]
Technical Analysis
Sender Grammar and the Bogus-TLD Trick
The sender local part is fixed to alert-\d{4}, and the apex is a five-letter random label on a three-letter random TLD. The operator never reuses a TLD: each bogus apex carries its own invented suffix, so a defender who blocks [.]mud gains nothing against the next send on [.]ivx. The point of the bogus TLD is not to look convincing to a human. It is to present a MAIL FROM value that no receiving server will resolve, which strips away SPF, DKIM alignment, DMARC, and every reputation signal keyed on the sender domain. There is simply no domain to have a reputation.
The .biz.ua Return-Path Reservoir
Where the sender apex is disposable and non-existent, the return-path is disposable but live. Every message routes bounces through (store|one).(ass|bss)NNNN.<label>.biz.ua. The ass/bss counter increments across the reservoir, and the label is an operator coinage (sightpop, xernixo, windtechhub, safegridnet, and many more). The .biz.ua apex itself is a legitimate 2003-era Ukrainian registry and is never the indicator: enforcement belongs at the operator host, never at the shared registry apex. That distinction matters, because flagging biz.ua would break unrelated legitimate Ukrainian mail.
Image-Only Body and the List-Unsubscribe CTA
The body is one image and nothing else. A body-only URL extractor finds no anchor, and a text classifier finds no text to score. The working link moves into the List-Unsubscribe header, where the mail client will happily render it as an unsubscribe control. This is the sharpest single trick in the tier: it relocates the call-to-action from the one place scanners look to a place they treat as deliverability metadata. The operator's real redirect domains (dnftvux[.]com, ssarimk[.]com, itjcmpv[.]com) appear only there.
Cloud-Storage Payload via URL Fragment
The redirect lands on a page served from an operator-controlled Google Cloud Storage bucket (historically strow and hmdbox, since rotated). The bucket path inherits Google's TLS certificate and domain trust. The page then reads a URL fragment, the part after # that never leaves the browser, to select and render the credential and payment form. A crawler that fetches the bucket URL sees a generic hosting path; the operative parameters live only in the fragment and only run client-side.
Display-Name Handles as the Attribution Spine
The one element that does not rotate is the pool of From display-name handles. A small set of reused handles ties every disposable apex and return-path back to one operator, and it survives infrastructure migrations that change everything else.
| Display Handle | Distinct Sender Addresses |
|---|---|
ladystar2419 |
35 |
malagobo |
9 |
dealexander1962 |
4 |
jamiemcguirk085 |
3 |
Additional single-use handles (waugo1, Account-deletion, cartonm1950, Support©) |
1 each |
The same address grammar has also carried other lure themes under separate handles, but the cloud-storage tier stays anchored to this handful. Handle reuse is the cheapest thing for an operator to fix and the last thing this one has.
Infrastructure Evolution
The tier has a visible migration history. Earlier sends used .uk.com and .uk.net return-paths before the reservoir moved to .biz.ua, and recent sends have begun appearing on .my.id. The label vocabulary has drifted too: alongside invented words, newer return-path labels pair recognizable brand tokens (retail and luxury names bolted together, for example) as fresh coinage. Those labels borrow well-known brand names but are not registered by or affiliated with any of those brands. The payload buckets have also rotated off their original names, which is the expected lifecycle for burn-and-replace cloud hosting. None of these shifts changed the underlying template, which is why the sender grammar, the return-path host pattern, and the display-name handles remain the durable signals.
Detection Observations
The defining trait of this tier is the absence of the signals a content scanner usually reads. There is no resolvable sender domain, no body text, no extractable anchor, and no URL in the fetched path. That absence is itself the signal. A message whose sender apex is a five-letter label on a non-existent three-letter TLD, carrying an alert-\d{4} local part and an image-only body, is not something legitimate mail produces. The (store|one).(ass|bss)NNNN return-path host grammar is likewise operator-unique and has no legitimate .biz.ua traffic behind it, which makes it a high-precision envelope-layer pivot. For defenders, the practical shift is away from body content and toward the envelope: the sender-domain shape, the return-path host pattern, the bogus-TLD suffix, and the reused display-name handles. The List-Unsubscribe header is also worth parsing, because that is where this operator keeps its only real click-through.
MITRE Fight Fraud Framework Mapping
The mapping below aligns to the current public MITRE Center for Threat-Informed Defense Fight Fraud Framework (F3, https://ctid.mitre.org/fraud). The F3 matrix references techniques by name rather than by stable numeric IDs, so techniques are named, not numbered.
| F3 Tactic | Technique (by name) | Campaign behavior |
|---|---|---|
| Resource Development | Acquire infrastructure (cloud storage, disposable domains) | GCS bucket hosting; .biz.ua/.my.id return-path reservoir; bogus-TLD sender labels |
| Initial Access | Phishing message / brand impersonation | iCloud/"cloud" account-lockout lure email |
| Initial Access | Impersonation with urgency and fear | "Account blocked, photos and videos deleted on " deadline pressure |
| Stealth | Trusted-infrastructure hosting; header and fragment concealment | Image-only body, List-Unsubscribe-only CTA, #-fragment payload, non-IANA sender TLD, high-reputation storage.googleapis[.]com |
| Execution | Credential harvesting via hosted page | JavaScript-rendered credential and payment form in the bucket |
| Monetization | Convert harvested credentials and card data to value | Account takeover; entered banking details |
Indicators of Compromise
All indicators are defanged. Victim data has been removed. The list below is a representative subset drawn from the verified-malicious, third-party-shareable tier.
Senders
| Value | Role | Notes |
|---|---|---|
alert-2584@jrtca[.]mud |
Sender | Display Account-deletion |
alert-3311@zvehc[.]ivx |
Sender | Display ladystar2419 |
alert-3786@amoeu[.]zuk |
Sender | "Failure Notice" variant |
alert-2647@wmaxy[.]sga |
Sender | Bogus-TLD apex |
alert-6720@tvhhf[.]dfl |
Sender | Bogus-TLD apex |
alert-8528@upbzk[.]ibr |
Sender | Bogus-TLD apex |
alert-4769@qzzwy[.]beq |
Sender | Bogus-TLD apex |
alert-3968@zirqu[.]uke |
Sender | Bogus-TLD apex |
alert-8074@fdycs[.]xgj |
Sender | Bogus-TLD apex |
alert-0884@woajs.mail.store.bss0010.windtechhub[.]biz[.]ua |
Sender | Full envelope embedded in sender label |
alert-7383@g7llw.mail.one.ass0031.flamengo[.]uk[.]com |
Sender | .uk.com precursor variant |
alert-2589@4ixbs.mail.one.ass0031.rabat-a[.]uk[.]net |
Sender | .uk.net precursor variant |
| ... (representative subset; dozens of verified-malicious sender addresses) |
Sender Domains
| Value | Role | Notes |
|---|---|---|
jrtca[.]mud |
Sender apex | Bogus non-IANA TLD |
zvehc[.]ivx |
Sender apex | Bogus non-IANA TLD |
amoeu[.]zuk |
Sender apex | Bogus non-IANA TLD |
wmaxy[.]sga |
Sender apex | Bogus non-IANA TLD |
tvhhf[.]dfl |
Sender apex | Bogus non-IANA TLD |
upbzk[.]ibr |
Sender apex | Bogus non-IANA TLD |
qzzwy[.]beq |
Sender apex | Bogus non-IANA TLD |
zirqu[.]uke |
Sender apex | Bogus non-IANA TLD |
fdycs[.]xgj |
Sender apex | Bogus non-IANA TLD |
ldijv[.]bys |
Sender apex | Bogus non-IANA TLD |
eicoh[.]dxb |
Sender apex | Bogus non-IANA TLD |
mbemt[.]kpy |
Sender apex | Bogus non-IANA TLD |
| ... (representative subset; dozens of verified-malicious sender domains) |
Redirect Domains
| Value | Role | Notes |
|---|---|---|
dnftvux[.]com |
Covert CTA | Random 7-letter .com in List-Unsubscribe header |
ssarimk[.]com |
Covert CTA | Random 7-letter .com in List-Unsubscribe header |
itjcmpv[.]com |
Covert CTA | Random 7-letter .com in List-Unsubscribe header |
Payload Hosts
| Value | Role | Notes |
|---|---|---|
hxxps://storage.googleapis[.]com/strow/strw_v3.html |
Landing | Operator-controlled GCS bucket path; fragment-loaded; since rotated |
hxxps://storage.googleapis[.]com/hmdbox/hmd_v2.html |
Landing | Operator-controlled GCS bucket path; fragment-loaded; since rotated |
Conclusion
This tier is a study in subtraction. The operator does not add convincing detail; it removes signals, one layer at a time, until a content scanner has almost nothing to read. What it cannot remove is structure: the alert-\d{4} local part, the five-letter-label-on-a-bogus-TLD sender shape, the (store|one).(ass|bss)NNNN return-path grammar, and the reused display-name handles all persist across every rotation. Defenders watching this operator should expect the namespaces to keep shifting, from .uk to .biz.ua to .my.id and onward, while the envelope grammar and the handle pool stay put. Those are the parts worth keying on.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.