Creditável: Multi-Bank Impersonation on a Self-Authenticated Domain
Creditável: Multi-Bank Impersonation on a Self-Authenticated Domain
Since December 2025, a Brazilian operator has impersonated five US banks in email lures sent from a fully self-authenticated domain it owns outright. The lures put a real bank name in the sender display field, Wells Fargo | Creditavel, Chime Verification | Creditavel, Chase Limit Unlock | Creditavel, and pair it with a fake confirmation code and a specific pre-approved credit line, then route the recipient into the operator's own credit-offer funnels. The pretext is ordinary; the sending infrastructure is not. Every message passes SPF, DKIM, and DMARC cleanly, because the operator owns the entire DNS zone it sends from. There is no spoofed bank domain and no authentication failure to catch.
Key Takeaways
- The operator sends bank-impersonation mail from subdomains of an aged domain it controls, so SPF, DKIM, and DMARC all pass with full alignment. Authentication is not a trust signal against this operator.
- Real US bank names live only in the free-text display name. The envelope and header domain are the operator's own, which is exactly the field email authentication does not evaluate.
- The apex is a working WordPress credit-content publisher with a benign public site, a self-hosted logo, and ad monetization. Reputation scanners that score the apex read it as low risk while the lures ship from its subdomains.
- Sending rails follow a fixed grammar (
<label>.creditavel[.]comwithem<digits>bounce hosts andurl<digits>click hosts under each), so new rails are recognizable by shape before any indicator is known. - The same domain tree runs a Brazil-facing segment impersonating a local neobank, indicating one operator with region-segmented sending, not a single-market campaign.
Background
The domain at the center of this activity, creditavel[.]com, is not a throwaway. It resolves to a real, operating Brazilian credit-content site branded "Creditável" that reviews consumer credit cards, carries display advertising, and has a US-facing English arm. The name is the operator's own coined brand, unrelated to any bank it impersonates and distinct from established Brazilian fintechs. That legitimate front is part of the tradecraft rather than a distraction from it.
Bank-branded lures that dangle a large pre-approved credit line are a long-documented spam and phishing family. Consumer-protection guidance from the FBI and the FTC, and bank-published warnings such as Chase's own material on impersonation scams, all describe the same core move: alter the display name to read as a bank and attach an urgent verification pretext. Kaspersky's Securelist has profiled the specific "money lender" variant that offers generous credit limits to funnel recipients into monetized offers. The Creditável operation sits inside that family. Its distinguishing choice is how it sends.
Most bank-impersonation mail spoofs a bank's real domain and fails authentication as a result, which gives defenders a clean signal. This operator does the opposite. It sends from its own domain, publishes valid SPF and DKIM records, and sets a DMARC policy that passes, so the mail authenticates as genuinely from creditavel[.]com. Public reporting has flagged this pattern for years: Cloudflare's phishing research notes that authentication passing does not equal legitimacy, and Spamhaus has documented operators relocating flagged sending backends behind reputable infrastructure to launder reputation. The Creditável tree is a concrete, current example of that shift applied to consumer bank impersonation.
Discovery and Infrastructure
The operation surfaced during routine cross-channel hunting as a cluster of email senders sharing one apex and one display-name convention. Pivoting on the apex and its subdomains mapped a compact, self-consistent sending platform rather than a sprawl of disposable domains. The operation has run at sustained volume since December 2025, reaching hundreds of thousands of messages, with tens of thousands in its busiest single month.
Every sender uses the local part contato (Portuguese for "contact") at a rail subdomain, for example contato@pt.cc.creditavel[.]com. The operator brands its own envelope as "Creditavel" while the display name carries the impersonated bank. At least seven distinct sending rails have been stood up over the campaign: pt.cc, news, news4, news9, news20, br.ep20, and us.news14, with br.ep8 and br.ep9 seen in click hosts. Rails rotate for deliverability: pt.cc was the primary rail from January 2026, news came online in February, news9 carried the May and June volume, and the numbered and region-prefixed rails are newer additions.
Under each rail sit two fixed function hosts, a bounce or return-path host named em<digits>.<rail> and a click host named url<digits>.<rail>. A shared survey.creditavel[.]com host and an evx.<rail> variant round out the platform. The br. and us. region prefixes point to segmented sending off a single tree: a Brazil-facing arm (which also produces a Portuguese lure impersonating a local neobank) and a US-facing arm targeting the five American banks.
| Indicator | Role | Notes |
|---|---|---|
creditavel[.]com |
Operator apex | Aged domain, registered 2021, Namecheap, Cloudflare-fronted; benign WordPress credit-content site |
pt.cc.creditavel[.]com |
Sending rail | Primary rail from January 2026; full bank rotation |
news9.creditavel[.]com |
Sending rail | May and June workhorse rail |
em2408.news9.creditavel[.]com |
Return-path | Bounce host paired to the news9 rail |
url7373.pt.cc.creditavel[.]com |
Click host | Click and redirect host under the pt.cc rail |
How It Works
A recipient sees a message that appears to come from their bank about a pending credit-limit increase. The display name reads as the bank, the subject carries urgency and a step or verification cue, and the body offers a specific pre-approved figure, commonly around 2,700 dollars, personalized with the recipient's first name. A fabricated reference code (CH-2952, CUR-892, #LIMIT-08546) lends the message a transactional feel it does not earn. These codes are arbitrary operator strings and do not encode anything about the impersonated bank.
The call to action wraps inside the operator's own click host (url<digits>.<rail>.creditavel[.]com), so the surface link resolves within creditavel[.]com rather than to an obviously suspicious domain. From there the recipient lands in the operator's credit-offer content, where the business model is advertising and affiliate credit-card referrals. The deception that carries the recipient to that point is the impersonation itself: the recipient believes a real bank initiated contact about a real account.
Because the operator owns the whole zone, the message authenticates as legitimately sent from creditavel[.]com. The only genuinely fraudulent element in the header is the display name, and that is the one field authentication never checks.
Sample Lures
The samples below are redacted. All recipient identifiers have been replaced with placeholders and all domains defanged. Only attacker-side content remains.
Wells Fargo impersonation rail:
From: "Wells Fargo | Creditavel" <contato@pt.cc.creditavel[.]com>
Subject: VERIFY NOW: your limit upgrade is pending
Body: Hello [recipient name], Good news! Your limit may be available today.
Confirm code CH-2952 to continue request.
Chase impersonation rail:
From: "Chase Limit Unlock | Creditavel" <contato@news9.creditavel[.]com>
Subject: You have advanced from step 1 to pre-approval
Body: SECURE NOTICE. Your recommendation is ready. Reference #CUR-892.
A pre-approved credit line offer is waiting for your confirmation.
Chime and Current rail:
From: "Chime Verification | Creditavel" <contato@news9.creditavel[.]com>
Subject: ATTENTION: Mismatched info under your name
CTA: http[:]//url<digits>.news9.creditavel[.]com/... redirecting within creditavel[.]com
Technical Analysis
A Real Credit Publisher, Fully Authenticated
The apex is a real WordPress site. Its DNS records carry a self-hosted BIMI logo pointing at a wp-content/uploads path, a Google site-verification token, and DKIM selectors, the trappings of a genuine publisher. The operator did not spoof a bank and did not register a disposable domain. It sends bank-impersonation mail from the same authenticated domain that hosts its advertising business, and that is what lets the mail pass authentication cleanly.
Two SPF includes describe how the mail is delivered. The first, include:websitewelcome[.]com with a strict -all, is a shared hosting provider's mail infrastructure. The second, include:emsd1[.]com, is ActiveCampaign, a commercial email service provider the operator relays through. ActiveCampaign lets customers configure custom sending and bounce subdomains under their own domain, which is what the em<digits> and url<digits> hosts under each creditavel[.]com rail are. Mail is delivered through a mainstream provider yet still aligns fully to creditavel[.]com, so there is no unfamiliar sending domain to flag and no authentication failure to catch.
Rail and Function-Host Grammar
The platform is built from a small, repeatable grammar rather than ad hoc naming. A rail is a short label under the apex, sometimes region-prefixed, in one of a few shapes:
| Component | Grammar | Example |
|---|---|---|
| Sending rail (envelope-from) | <label>.creditavel[.]com |
news9.creditavel[.]com |
| Numbered rail variant | news<N>.creditavel[.]com |
news20.creditavel[.]com |
| Region-prefixed rail | <br|us>.<label>.creditavel[.]com |
us.news14.creditavel[.]com |
| Return-path host | em<digits>.<rail> |
em7552.pt.cc.creditavel[.]com |
| Click and redirect host | url<digits>.<rail> |
url353.br.ep8.creditavel[.]com |
The consequence for defenders is that the infrastructure is enumerable by shape. Any em<digits> or url<digits> host under a creditavel[.]com rail is operator infrastructure by construction, so a newly minted rail is recognizable before it appears in any indicator feed. New rails are created by incrementing the numeric suffix or adding a region prefix, which makes the naming itself the durable fingerprint rather than any single subdomain.
Registration Cohort and Sibling Domains
WHOIS separates the live operator infrastructure from lookalike noise. The apex and its .org sibling share a registrar and a 2021 vintage; a fresh 2026 same-registrar hold sits parked; and a similarly spelled dictionary-word domain on an unrelated registrar is a coincidental lookalike that should not be attributed to this operator.
| Domain | Registrar | Created | Status |
|---|---|---|---|
creditavel[.]com |
Namecheap | 2021-09-09 | Live operator apex |
creditavel[.]org |
Namecheap | 2021-12-13 | Same-registrar sibling, parked |
centralcreditavel[.]com |
Namecheap | 2026-04-17 | Recent same-registrar hold, dormant |
The aged apex matters. A domain registered years before the campaign, fronted by a reputable network and carrying a real content site, blunts the domain-age and host-reputation heuristics that catch freshly registered phishing domains. The operator is living off the reputation of its own established property.
Display-Name Rotation
The impersonation lives entirely in the display name. On top of a rotating pool of five US bank identities (Chime, Wells Fargo, Chase, Varo, and Current), the operator personalizes each display string with the recipient's first name, which produces a large and constantly varying set of display-name values. Chime and the two neobanks, Varo and Current, dominate the rotation, with Wells Fargo and Chase behind them. A separate Portuguese-language variant impersonates a Brazilian neobank on the same tree, confirming region-segmented sending from one operator.
Detection Observations
The clearest signal is a structural contradiction inside a single message: the display name reads as a US bank while the authenticated sending domain is creditavel[.]com. Mail from this operator authenticates cleanly, so an approach that treats an SPF, DKIM, or DMARC pass as evidence of legitimacy will accept it. The display-name-to-domain mismatch is visible independent of authentication.
Several attributes travel together across every rail and every impersonated bank and are strong when combined: a real bank name confined to the display field, a fabricated reference or confirmation code (CH-####, CUR-###, #LIMIT-#####), first-name personalization, and a specific pre-approved dollar figure. The em<digits> and url<digits> function-host grammar under any creditavel[.]com rail is another durable pivot, because it identifies operator infrastructure by naming shape rather than by prior sighting.
Reputation systems that evaluate the apex will misjudge this operator, because the apex is a benign, aged, ad-supported content site. The sending behavior lives on subdomains, and because delivery runs through a mainstream ESP, the transport is not itself a distinguishing signal. The operator's own rail and function-host naming grammar under creditavel[.]com is the durable pivot the apex reputation cannot provide.
Indicators of Compromise
All indicators are defanged. The set below is a representative subset drawn from the verified-malicious records for this campaign.
Senders
| Value | Role | Notes |
|---|---|---|
contato@pt.cc.creditavel[.]com |
Sender | Primary rail from January 2026; full bank rotation |
contato@news.creditavel[.]com |
Sender | Active February 2026 onward |
contato@news9.creditavel[.]com |
Sender | May and June workhorse rail |
contato@news4.creditavel[.]com |
Sender | Secondary rail |
contato@br.ep20.creditavel[.]com |
Sender | Lower-trust and early rail |
Hosts
| Value | Role | Notes |
|---|---|---|
creditavel[.]com |
Operator apex | Aged 2021 WordPress publisher; the sending identity for the campaign |
pt.cc.creditavel[.]com |
Sending rail | Primary rail |
news.creditavel[.]com |
Sending rail | February 2026 onward |
news4.creditavel[.]com |
Sending rail | Secondary rail |
news9.creditavel[.]com |
Sending rail | May and June workhorse rail |
br.ep20.creditavel[.]com |
Sending rail | Early and lower-trust rail |
em7552.pt.cc.creditavel[.]com |
Return-path | Bounce host for the pt.cc rail |
evx.news.creditavel[.]com |
Return-path | Bounce host variant for the news rail |
em2408.news9.creditavel[.]com |
Return-path | Bounce host for the news9 rail |
em1559.news4.creditavel[.]com |
Return-path | Bounce host for the news4 rail |
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE Fight Fraud Framework (F3, the current fraud matrix), which reuses ATT&CK technique IDs (T####) alongside fraud-specific IDs (F####). Two elements of this operation have clean techniques; the fabricated-urgency and lead-gen monetization elements have no dedicated F3 technique today and are noted as pretext content or as unmapped.
| Tactic | Technique | ID |
|---|---|---|
| Initial Access | Phishing | T1566 |
| Resource Development | Impersonate Official | F1032 |
| Initial Access | Fabricated urgency and fake reference codes | Pretext content within T1566, no dedicated technique |
| Monetization | Ad and affiliate lead-gen revenue | Unmapped in current F3 vocabulary |
Email spoofing is deliberately not mapped here. The operator sends from an owned, fully aligned domain rather than forging a bank's domain, so the spoofing technique does not apply.
Conclusion
The Creditável operation shows what bank impersonation looks like once an operator stops spoofing and starts sending from a domain it fully controls. Authentication passes, the apex looks like a legitimate publisher, and the only fraudulent field in the header is the one authentication ignores. Defenders should expect more of this shape: aged, authenticated, reputationally clean domains whose subdomains carry impersonation traffic that no auth-failure heuristic will flag. The durable signals are the display-name-to-domain contradiction and the operator's own naming grammar, and both are watchable long before a new rail earns a reputation.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.