Rented Storefronts: A Fake-Store Franchise on Facebook Ads
Rented Storefronts: A Fake-Store Franchise on Facebook Ads
Throughout 2026, we mapped 100+ fraudulent storefronts fronted by disposable Facebook advertisers and increasingly hosted as tenants on legitimate builder platforms. Between January and August, we tracked tens of thousands of sponsored ads whose click-through destination was a storefront on a cheap commerce top-level domain. From that traffic, we extracted a confirmed indicator set: store apexes, advertiser profiles, sending addresses, and two tenant hosts on a legitimate multi-tenant builder. Every count in this post is a floor, not a census, because we have only partial visibility into the ad surface and the operators register faster than anyone can enumerate. The infrastructure does not point to one operator. It shows a franchise pattern with regional lanes, shared templates, and a build that has been moving away from dedicated domains and onto rented space on somebody else's platform.
Key Takeaways
- The advertiser layer is disposable by design. Numeric
profile.php?id=accounts outnumber named pages by roughly five to one across the population we tracked, and four to fourteen separate advertiser identities routinely front a single storefront. - Reputation can no longer be scored at the apex. Operators rent tenant subdomains on legitimate storefront-builder platforms, where the shared apex serves thousands of unrelated real merchants. A verdict must apply to the individual tenant hostname, or it will blanket-block the platform's honest customers.
- Registration is deliberately unconcentrated. The 40 store apexes with a WHOIS record are distributed across nine registrar families with no dominant lane. Not one record identifies a party distinct from the registrar or a privacy service.
- Fabricated brands are generated rather than chosen. Five naming templates recur, and the same page template carries different invented trademarks with different specifications. The "brand" is a template field, not a business.
- Localization is where the operators invest. The same funnel appears in Thai, Bulgarian, Ukrainian, Arabic, Hungarian, and Serbian, paired with regional payment rails. This makes cash-on-delivery markets attractive and eliminates the chargeback that Western card fraud must account for.
- The top-level domain is not a discriminator. Legitimate direct-to-consumer brands register on the same cheap commerce namespaces, so any method based only on the domain suffix will sweep them up.
Background
Fake online stores are an old category, but the business has become industrialized. Two public research reports from early 2026 show the scale. Malwarebytes mapped a cluster of more than 20,000 fraudulent commerce domains resolving to just 36 IP addresses. Almost all were self-hosted WordPress sites built on a legitimate dropship platform, with two underlying themes repeatedly given cosmetic reskins ("Inside a network of 20,000+ fake shops", 18 March 2026). CTM360 documented 30,000+ brand-impersonating fashion storefronts across 80 or more countries. They impersonated 350+ apparel brands, and the operators registered 50 or more new domains a day ("FraudWear", February 2026). BogusBazaar, an earlier and independently discovered example of the same model, ran 75,000+ domains and reportedly took over a million orders from 2021 onward (SRLabs, May 2024).
All three describe the same structure: a core supplies servers, templates, and payment processing, while decentralized operators register domains and produce near-identical stores. That is a franchise, which explains why domain enumeration cannot keep pace. Netcraft measured Black-Friday-themed fraudulent registrations rising from roughly 54 a day in mid-October 2025 to around 306 a day by early November, with country-targeted top-level domain and brand pairings ("Inside the 2025 fake-shop shift", 2025).
Our traffic is a sample of that world, not a survey of it. It resembles several lanes following the same playbook rather than a single franchise. The regional spread is especially clear: storefronts localized for Bulgaria, Israel, Ukraine, Egypt, Algeria, Tunisia, Lithuania, Nepal, and Thailand, each adapted to the language, currency, and delivery habits of its market.
Before the technical sections, we need to name several parts of the infrastructure. All are legitimate services being abused, not property owned by the operators.
Dropship and fulfillment platforms. A turnkey dropship platform gives subscribers a pre-built storefront, curated catalog, warehouse fulfillment, and payment processing for a monthly fee, without requiring code. Putting sourcing, fulfillment, and the storefront into one subscription is genuinely useful for small merchants. It also suits fraud operators because they can create dozens of near-identical stores by changing a brand name and template skin. The platform's own order mail then appears behind a customer store, which is how we confirmed this backend in our corpus.
Multi-tenant storefront-builder SaaS. This vector matters most here. We found two builders: an Algeria-focused e-commerce and point-of-sale builder that provisions tenant stores in under a minute, includes local shipping and payment-rail integrations, and publishes tenants under a shared feeef[.]store namespace; and a US-registered creator-storefront builder that claims 200,000 or more users and publishes tenants under mychariow[.]shop. We see 115 or more tenant stores under the first and 2,340 or more under the second. Both apexes belong to legitimate SaaS products that serve overwhelmingly legitimate merchants. A reputation signal calculated at the registrable-apex level is therefore meaningless. It will always appear clean or mixed, regardless of how many fraudulent tenants are underneath it. This differs structurally from a single-tenant hosting platform and is why two of our indicators are hostnames rather than domains.
Commerce platforms and their shared ranges. A large hosted commerce platform serves merchant stores from shared address space and its own CDN edge. Fraudulent stores that use it as a backend inherit that high-reputation footprint, so blocking by address or ASN would remove enormous numbers of legitimate merchants. We also found self-hosted stacks: WooCommerce on WordPress, a regional OpenCart template build, and a custom PHP order kit answering on index.php?m=Order. A single purchased or cloned theme can be redeployed unchanged across thousands of domains, making self-hosted stacks the basis of template-farm reuse.
The email side is simpler. Bulk mail routed through a major transactional email service inherits the service's sending reputation and passes SPF, DKIM, and DMARC alignment cleanly. The abuse therefore appears in the message content and links, not in the sending infrastructure.
Cheap commerce top-level domains. .shop, .store, .online, and .top cost roughly a dollar under first-year promotional pricing, compared with ten or more for a legacy .com, and they come with steep bulk discounts. An operator can burn fifty domains a day and abandon them after they are flagged at trivial cost. The qualification matters: .shop and .store were designed for commerce, and many legitimate small direct-to-consumer brands use them. The suffix is a weak prior, not a signal.
One fake-delivery lure below links to a genuine logistics tracking aggregator. The service polls shipping status from thousands of carriers and displays consolidated results, but it ships nothing and handles no payment. That makes it useful to a scammer: a neutral, brand-agnostic tracking backend can make a bogus shipping notification look technically sound. The tracking numbers are fabricated or reused, while the platform providing the interface is entirely legitimate.
Finally, there are the advertiser accounts. A facebook.com/profile.php?id=<digits> URL is the fallback address for an account that has never claimed a vanity username. That is normal for new or low-effort accounts, but it also fits a burn-and-rotate ad operation: create the account, verify it just enough to run ads, fly a short campaign, and abandon it. The operator builds no durable identity, so nothing is lost when the account disappears. This interpretation is our inference from how the platform assigns profile URLs, not a published research finding.
Discovery and Infrastructure
We started with the click-through destination, not the ad copy. Ad text on this platform is often absent. When present, it usually looks like ordinary commerce marketing in a local language. The distinguishing feature was the destination: a storefront on a cheap commerce top-level domain, reached through a sponsored ad and backed by an advertiser account with no history.
Pivoting from the destination host to the advertiser profile revealed the first structural pattern. Stores and advertisers are not paired one to one. During a single 30-day window, we counted 481 distinct advertiser profiles pushing storefront destinations of this type, compared with a much smaller store population. The fan-out is consistent with disposable accounts.
| Store (defanged) | Advertiser profiles | Distinct page names | Reading |
|---|---|---|---|
home-fashon[.]store |
14 | 14 | Widest fan-out in the set, every profile its own persona |
buatom[.]shop |
6 | 6 | Six unrelated store personas, one destination |
nemimart[.]shop |
5 | 5 | Template farm; personas do not match the catalog |
aquasealpro[.]shop |
4 | 4 | Four invented product brands, three languages |
natiosteel[.]store |
4 | 1 | Account rotation under one fixed page name |
asics-running[.]online |
4 | 2 | Brand-impersonation front, one persona in glyph-substituted text |
bestfeel[.]shop |
4 | 4 | Per-product subdomain farm under a single operator apex |
Two rows warrant separate treatment. natiosteel[.]store has four accounts using the same page name. That indicates account replacement under a stable identity rather than persona churn. asics-running[.]online does the reverse: two page names claim to represent the same retailer, and one is written with mathematical bold Unicode characters instead of ordinary letters. The substitution defeats exact-string matching against the impersonated retailer's name while looking identical to a human reader.
Of the risky-suffix store hosts in our corpus, 173 of 183 resolved live. Their resolution placed the ecosystem firmly on legitimate platforms rather than on a dedicated block of scam infrastructure. Roughly 36% resolved into the shared range of one hosted commerce platform. The rest were distributed across major CDNs, cloud providers, shared web hosting, site builders, and one regional Ukrainian host. None resolved into the address blocks reported by the Malwarebytes research, so that particular sub-franchise is absent from our traffic. Hosting is not a useful clustering pivot here. The persistent correlators are the destination domain's shape, its registration cohort, and the storefront platform fingerprint.
How It Works
The chain is short and contains no malware.
A disposable advertiser account runs a sponsored ad for either one product or a general catalog, localized for one market. The ad offers a steep discount, often paired with a countdown, a stock-scarcity claim, or a fabricated review count. The click opens a storefront designed to resemble a small brand, complete with a logo, name, product grid, and testimonials. At checkout, the site requests a card and a full delivery identity.
The model then splits into several outcomes. The distinction matters because each branch leaves different evidence.
In a dropship outcome, the operator ships something. It is a cheap substitute obtained from a low-cost supplier. Both money and low-value goods move, chargeback rates remain below the level that prompts processor review, and the store can continue for months. In a non-delivery outcome, the operator takes payment but ships nothing. The goal is to maximize completed checkouts before burning the domain, leading to high registration velocity and short domain lifetimes. In a card-harvest outcome, the checkout page itself is the payload. Whether the operator later fabricates an order does not matter because the product is the card data. Dropship networks create logistics traces. Non-delivery networks create payment-gateway traces but no logistics. Card-harvest creates neither, leaving only checkout-form traffic.
The regional lanes favor a fourth variant. Cash on delivery accounts for a large share of transactions across North Africa and the Middle East and reportedly represents the overwhelming majority of Algeria's e-commerce because card penetration and trust in online prepayment are both low. With cash on delivery, there is no card to steal. The fraud instead involves shipping a substandard or counterfeit product and collecting cash before the buyer can evaluate it after unboxing, or collecting cash for a parcel the recipient never ordered. Cash on delivery also removes the chargeback entirely and transfers recovery risk from the payment processor to the courier. Every payment-side signal used against Western card-harvest campaigns is structurally absent.
The email tail is an order of magnitude smaller than the ad volume and follows two patterns. Own-domain support@<store> addresses send discount and fake-order messages for the operator's storefronts through a reputable transactional email service. Separately, a fake-delivery lure impersonates the regional arm of a footwear brand and directs clicks to a storefront through a shipping-notification pretext. It uses a real tracking aggregator for credibility and places the reply-to on a different operator domain from the domain in the from-header.
Sample Lures
All samples are redacted. They contain no recipient name, address, phone number, email address, account or order identifier, or per-recipient tracking token. Every domain and URL is defanged.
Facebook, brand impersonation. The advertiser account copies the social identity of a real sporting-goods retailer and sells through a storefront whose domain contains the footwear brand's name. The genuine product model names are accurate, which makes the offer convincing.
Page name: Supersports Thailand (also seen as: 𝗦𝘂𝗽𝗲𝗿𝘀𝗽𝗼𝗿𝘁𝘀 𝗧𝗵𝗮𝗶𝗹𝗮𝗻𝗱)
Destination: http[:]//www.asics-running[.]online/Sale-Off
ตอนนี้เลย! ลดราคาส่งท้ายฤดูกาล!
ลดสูงสุดถึง 65% สำหรับรองเท้ากีฬาพรีเมียมยอดนิยมจาก Asics
ช้อปออนไลน์ได้ที่: http[:]//www.asics-running[.]online/Sale-Off
สินค้าขายดีที่ทุกคนกำลังมองหา:
- ASICS Court FF3 Novak
- ASICS GEL-KAYANO 30
- ASICS SUPERBLAST™ 2
- ASICS NOVABLAST™ 5
[End-of-season sale, up to 65% off premium ASICS athletic shoes. Shop online at
the address above. Best sellers everyone is looking for: (real model names).]
The second page name is the same string rendered in mathematical bold Unicode rather than Latin letters.
Facebook, fabricated brand. This Ukrainian-language ad promotes a "German" air fryer. The same template appeared with two invented trademarks and two power ratings, providing the clearest evidence available that the brand is a template field.
Page name: Top-kitchen[.]store
Destination: http[:]//top-kitchen[.]store/
🇩🇪 Німецький аерогриль Zepline™, готуйте хрусткі страви БЕЗ краплі олії
вже за 10, 15 хвилин
• Потужність: 3500 Вт
• Об'єм чаші: 8 літрів (ідеально для всієї сім'ї)
• Технологія: TurboAir™, обдув 360° для ідеальної скоринки
• Матеріал: Нержавіюча сталь
[German Zepline™ air fryer, crispy food with no oil in 10-15 minutes.
3500 W, 8 L bowl, TurboAir™ 360° circulation, stainless steel.]
Same template, same store, different ad:
🇩🇪 Німецький аерогриль Rainberg™ ... • Потужність: 4200 Вт
[German Rainberg™ air fryer ... 4200 W]
Email, fake-deal storefront. This is a members-only discount pretext for the operator's store, relayed through a reputable transactional email service. The unsubscribe link contained a signed token that exposed the store's backend tenant name on a hosted commerce platform. Because the token is per-recipient, we do not reproduce it here.
From: quiokdeals <support@quiokdeals[.]shop>
Return-Path: <...@ca-central-1.amazonses[.]com>
Subject: 🛍 Shop Now and Save with Our Members-Only Discounts!
Member Appreciation Day Sale ... UP TO 50% OFF ...
🔥LIMITED SPECIAL OFFER🔥 Dobshow® ThermoFit Comfort...
CTA: http[:]//quiokdeals[.]shop/products/[product-slug]
Email, fake delivery into a storefront. This shipping-notification pretext impersonates the Mexican arm of a footwear brand and is localized to Spanish. It uses a real multi-carrier tracking aggregator for credibility. The from-domain and reply-to domain are separate operator properties, which is the distinguishing detail.
From: Crocs México <noreply@mailservice-huge[.]com>
Reply-To: services@dessxy[.]shop
Subject: Your order is on the way
[Fabricated order confirmation and shipping status, with a tracking link
pointing at a genuine logistics aggregator, track718[.]com]
CTA: http[:]//crocshotsale[.]shop/email/click?[tracking-parameters]
Technical Analysis
Registration Cohorts
Registration makes this population easiest to read, and the data is entirely public. We retrieved registration records for 62 store apexes. Forty have a WHOIS record, while 22 have none. That may reflect registration cycling faster than WHOIS refreshes or deliberate suppression.
| Registrar family | Apexes | Cohort note |
|---|---|---|
| Namecheap | 12 | Spread across 2024-08 to 2025-10 |
| Tucows | 9 | Spread across 2024-06 to 2025-07 |
| GoDaddy | 6 | Spread across 2024-06 to 2025-03 |
| Hosting Ukraine LLC | 4 | Three within 2025-03 to 2025-05, a fourth in 2026-04 |
| Enom | 2 | 2025-01, 2025-04 |
| GMO Internet | 2 | 2025-12 and 2026-03, both brand-token .online |
| OVH, Hostinger, INET Software, Alibaba Cloud, OnlineNic | 1 each | Scattered 2024-08 to 2026-01 |
| No WHOIS record | 22 | Undated |
The distribution across nine registrar families, without a dominant lane, is the finding. Concentrating registrations with one operator would create a single pivot capable of taking down the entire estate at once. This population avoids that concentration.
The privacy pattern is consistent. Fifteen of the 40 records use an explicit privacy product. Three name only the registrar's corporate entity as the registrant organization, and the remaining 22 omit the organization field. None identifies an individual or company separate from the registrar or privacy service. WHOIS silence alone proves nothing, but the complete absence of an attributable registrant across 40 records is consistent enough to document.
The useful detail is the batch clustering of registration dates. Four apexes were created within an 18-day period in October 2024 (yatwins[.]store, vexivo[.]store, veliza[.]shop, ambarwear[.]store). Five others were created within March 2025 (belisi[.]store, vidgadget[.]store, dereva[.]shop, brothers-store[.]store, flexdog[.]store). We also found same-day pairs: trenddelight[.]shop and papaja[.]shop on 2024-07-16, and vseeboxus[.]store and aluraluxury[.]top on 2025-04-20. One outlier, wesupport[.]online, dates to 2020 and predates the others by years.
The Ukrainian lane forms a separate cohort. Three of its four apexes were registered during a ten-week period from March to May 2025. A fourth appeared nearly a year later through the same registrar. This is a build lane that returns rather than a one-time batch, so it warrants continued monitoring instead of closure.
Domain Generation
Five naming templates recur, with two accounting for most of the population.
| Template | Examples (defanged) |
|---|---|
| Fabricated brand word, no lexical meaning | actora[.]shop, valuefy[.]store, klyra[.]store, vlamari[.]shop |
| Category descriptor plus commerce suffix | flexdog[.]store, meowverse[.]online, aquasealpro[.]shop, top-kitchen[.]store |
| Gibberish consonant run | rzgpr[.]shop, ogergdea[.]store, otbuyd[.]shop, mandrik[.]top |
| Real trademark token embedded | asics-running[.]online, nike-mind[.]online, crocshotsale[.]shop |
| Adjacent real-business name | nationalsteel[.]store, bricoma[.]shop |
The first two templates account for most examples. The last two form a smaller but recurring tail and appear more often in the later registration window than the earlier one. This suggests that impersonation is a newer part of the playbook rather than its original basis.
The fifth template is easy to misinterpret. Instead of squatting a global trademark, it borrows the name of a specific unrelated company. One example uses the name of a two-decade-old Moroccan home-improvement retail chain for a general-goods dropship funnel. Another uses a steel firm's name for a homeware storefront. The catalogs have no connection to the borrowed names, making the gap between a store's claimed identity and its products a practical signal.
Fabricated Brands Are Template Fields
The air fryer sample provides the clearest example in the corpus: one store, one Ukrainian-language template, one claimed country of origin, and two invented trademarks with different wattages. aquasealpro[.]shop demonstrates the same pattern across personas rather than ads. Four advertiser accounts promote four separate invented brands of waterproofing and cleaning compounds in Bulgarian, Hungarian, and Serbian. An invented name marked with a trademark symbol and placed beside a specification table substitutes for the history that a genuine brand would otherwise provide.
nemimart[.]shop demonstrates the template-farm version. Five advertiser personas with unrelated general-retail names all point to the same Thai-language storefront. Each uses the same ad structure: a product line with an emoji, an order link, a separator rule, and a problem-agitation-solution block. Product slugs across the store use one shared suffix convention, tying all five personas to the same build. We looked for that suffix convention elsewhere in the corpus and did not find it. It is therefore a within-store fingerprint, not a kit signature, and should not be treated as one.
Subdomain Grammar
One apex functions as a namespace manufactured by the operator rather than as a store. Under bestfeel[.]shop, we catalogued 25 single-product subdomains. Each hosts one product page under a short transliterated Cyrillic slug rather than a path on a shared storefront. Four carried ads during the period we reviewed:
spa.bestfeel[.]shop halat.bestfeel[.]shop ("robe")
sis-poliv.bestfeel[.]shop ("drip irrigation")
ups-komplekt.bestfeel[.]shop ("UPS kit")
This must be separated from the builder-SaaS vector, even though both produce broad subdomain namespaces under a single apex. In this case, the operator owns the apex and creates the subdomains, so the verdict applies to the apex. On a builder platform, the operator rents a single slot while somebody else owns the apex, so the verdict must not apply there. Distinguishing between the two is the practical problem. Ownership of the apex, not the namespace's shape, is the deciding factor.
The Tenant-Host Problem
The move onto multi-tenant builders was the most consequential change during the campaign window. It is a direct living-off-the-land technique: the operator gives up the reputation exposure of a dedicated domain in exchange for cover from a legitimate platform.
| Vector | Example (defanged) | Regional focus |
|---|---|---|
| Hosted commerce platform | quiokdeals[.]shop, glamtask[.]store |
Global fake-deal, Israel beauty |
| Regional OpenCart template build | vlamari[.]shop |
Bulgaria, broad catalog |
| Dropship platform backend (abused) | Customer store behind the platform's own order mail | Global |
| Multi-tenant builder, Algeria-focused | djawharet-elmadina.feeef[.]store, jawhart-2.feeef[.]store |
Algeria |
| Multi-tenant builder, US-registered | Tenant hosts under mychariow[.]shop |
Global |
| Custom PHP order kit | ogergdea[.]store |
Widest distribution of any single store here |
| Per-product subdomain farm | spa.bestfeel[.]shop and siblings |
Ukraine |
The two builder rows make apex-level reputation unusable. One has 115 or more tenants and the other has 2,340 or more. Their shared apexes will always aggregate to a mixed or clean signal, regardless of how many fraudulent tenants they contain. Applying a malicious verdict at that level would also remove every legitimate merchant on the platform. Both are real, operational SaaS businesses. The only defensible approach is to resolve and score the complete tenant hostname. That is why two indicators below are hosts rather than domains and why neither builder apex appears in the list.
Cross-Cluster Pivots
Four signals connect otherwise separate storefronts to shared build lanes. A shared registrar and registrant organization links the Ukrainian apexes, where the registrar's name substitutes for a privacy product. Two unrelated storefronts contain the same recycled corporate footer block, copied verbatim with a company registration and a product line unrelated to either store. This points to a shared template source rather than independent builds. We intentionally omit the company's name because it appears to be a real business whose footer was copied and is not part of this operation. Multiple advertiser profiles attached to a fixed destination connect the advertiser layer. Tenant relationships under the same builder apex connect stores whose names otherwise imply no relationship.
We would not use the brand-token naming convention as an attribution pivot. It appears across registrars, platforms, and regions. That pattern fits a convention copied among operators better than a signature belonging to one actor. Using it for attribution would combine groups that remain separate in the registration and hosting evidence.
Detection Observations
The destination carries the useful signal, not the ad copy. Ad text is often missing from this surface, and when it exists, it resembles ordinary local-language commerce marketing from a legitimate small merchant. Methods based on lure text will underperform when the lure is simply a discount.
The strongest single observation is structural rather than content based: many advertiser accounts point to one destination, while each account has no history and a page name unrelated to the destination's claimed brand. A legitimate merchant does not direct fourteen unrelated store personas to one storefront. This pattern appears at the ecosystem level but not within an individual message, which is the broader problem here.
Signals that hold up:
- Claimed identity against actual catalog. A store using the name of a steel firm while selling home decor, or the name of a home-improvement chain while selling general goods, creates a mismatch that a legitimate merchant does not produce.
- Invented trademark plus specification table. This pattern combines a trademark symbol on a brand name without an independent footprint and a precise specification list. It is especially informative when one template uses two different brand names.
- Registration cohort membership. Multiple apexes created within days of one another, through one registrar and without an attributable registrant, form a batch. Membership in that batch is a much stronger prior than the age of one domain.
- Tenant host resolution. The full hostname must be scored on a multi-tenant builder rather than the registrable apex. Scoring the apex on these platforms gives the wrong result in both directions.
- Glyph substitution in a page name. Mathematical bold and other Unicode variants of a real retailer's name look normal to a reader but defeat exact-string matching.
- Contact surface. A storefront that claims to represent an established brand but provides only free-mail or messaging-app support, with no physical address or company registration, has a mismatched contact surface.
Two signals fail, and a third is actively misleading. The top-level domain suffix alone does not distinguish the stores because many legitimate direct-to-consumer brands use the same commerce namespaces. Hosting address and ASN do not cluster this population because the stores deliberately use shared platform infrastructure. TLS is also uninformative because certificates are free.
No single signal is conclusive. A genuinely new small brand may have a fresh domain, no independent reviews, a cheap suffix, and a limited contact page. The distinction comes from a concurrent group of weak signals. Any method that acts on only one will misclassify real businesses.
MITRE Fight Fraud Framework Mapping
This mapping follows the MITRE Fight Fraud Framework (F3) v1.1, https://ctid.mitre.org/fraud. F3 focuses on financial-account fraud. Because a storefront operation directly reaches Monetization, the framework fits more closely than it does for a pure pre-access lure. We note stages without a discrete F3 technique rather than forcing a mapping.
| F3 Tactic | Technique | ID |
|---|---|---|
| Resource Development | Acquire Infrastructure: Domains | T1583.001 |
| Resource Development | Acquire Infrastructure: Malvertising | T1583.008 |
| Resource Development | Create Fake Materials: Fake Website | F1020.002 |
| Resource Development | Establish Accounts | T1585 |
| Resource Development | Create Fraudulent Merchant Account | F1021 |
| Reconnaissance | Gather Customer Information | F1029 |
| Initial Access | Impersonate Official | F1032 |
| Stealth | Renting tenant space on a legitimate multi-tenant platform so the shared apex absorbs the reputation footprint. No discrete F3 technique covers platform-tenancy cover. | |
| Monetization | Payment taken at a controlled checkout for goods not delivered as described. No discrete F3 technique covers merchant-side non-delivery; the framework models the adversary as purchaser rather than seller. |
The two blank rows expose the important gaps. F3 assumes that the adversary transacts against another party's account. An operator that becomes the merchant of record and collects money from willing buyers therefore falls outside the framework's technique set at the monetization stage, even though monetization is the campaign's purpose.
Indicators of Compromise
All indicators are defanged, and victim data has been removed. This representative subset favors durable infrastructure over throwaway accounts.
Store Domains
| Value | Role | Notes |
|---|---|---|
ogergdea[.]store |
Storefront | Custom PHP order kit; widest distribution of any single store here |
valuefy[.]store |
Storefront | Highest ad count; generic value-store funnel |
bestfeel[.]shop |
Storefront apex | Operator-owned per-product subdomain farm, 25 subdomains |
asics-running[.]online |
Storefront | Footwear brand token; advertiser impersonates a real retailer |
nike-mind[.]online |
Storefront | Brand token squat on a young .online |
crocshotsale[.]shop |
Storefront | Brand impersonation, reached via fake-delivery email |
dessxy[.]shop |
Operator property | Reply-to domain for the fake-delivery lure |
luxurytimepieces[.]store |
Storefront | Impersonates a real watch retailer's social identity |
brothers-store[.]store |
Storefront | Counterfeit eyewear |
bricoma[.]shop |
Storefront | Name-squats a real Moroccan retail chain, unrelated catalog |
nationalsteel[.]store |
Storefront | Steel-firm name fronting homeware |
home-fashon[.]store |
Storefront | 14 advertiser profiles, widest fan-out |
nemimart[.]shop |
Storefront | Template farm, five mismatched personas |
aquasealpro[.]shop |
Storefront | Four invented product brands across three languages |
top-kitchen[.]store |
Storefront | Two invented trademarks in one template |
| ... | representative subset; 100+ verified-malicious store domains |
Builder Tenant Hosts
These are scored at the hostname. The builder apexes belong to legitimate multi-tenant SaaS products and are intentionally excluded.
| Value | Role | Notes |
|---|---|---|
djawharet-elmadina.feeef[.]store |
Storefront tenant | Fraudulent tenant on a legitimate Algeria-focused builder |
jawhart-2.feeef[.]store |
Storefront tenant | Sibling tenant, same builder |
Sending Addresses
| Value | Role | Notes |
|---|---|---|
support@quiokdeals[.]shop |
Sender | Fake-deal store; leaked its own hosted-commerce backend tenant |
noreply@mailservice-huge[.]com |
Sender | Fake-delivery brand impersonation |
support@wesupport[.]online |
Sender | Own-domain store sender |
info@actora[.]shop |
Sender | Subscription trap |
support@rituallabs[.]shop |
Sender | Auto-ship trap |
info@vseeboxus[.]store |
Sender | Grey-market reseller, fake order and shipment mail |
hi@klyra[.]store |
Sender | Own-domain store sender |
hello@fleava[.]shop |
Sender | Own-domain store sender |
hello@velaxen[.]shop |
Sender | Own-domain store sender |
info@ambarwear[.]store |
Sender | Own-domain store sender |
info@trenddelight[.]shop |
Sender | Own-domain store sender |
info@veloma[.]store |
Sender | Own-domain store sender |
support@veliza[.]shop |
Sender | Own-domain store sender |
support@vexivo[.]store |
Sender | Own-domain store sender |
Advertiser Profiles
Numeric identifiers are the account's address on the platform. We withhold page display names when they identify an individual.
| Value | Role | Notes |
|---|---|---|
100000691609947 |
Advertiser | Fronts the widest-distributed store in the set |
61573689446551 |
Advertiser | Bulgaria, OpenCart broad catalog |
61586386711978 |
Advertiser | Brand-impersonation front, real retailer's identity |
61586326494025 |
Advertiser | Same destination, sibling account |
100082814531876 |
Advertiser | Impersonates a real watch retailer |
100090709394322 |
Advertiser | Name-squat of a real retail chain |
61568060526452 |
Advertiser | Per-product subdomain farm, Ukraine lane |
61575353814851 |
Advertiser | Ukraine lane |
61590380592188 |
Advertiser | Ukraine lane |
61555735432146 |
Advertiser | Invented-trademark kitchen goods |
61564858186392 |
Advertiser | Template farm persona |
61564869376666 |
Advertiser | Template farm persona |
61590298873155 |
Advertiser | Invented product brand, one of four on one store |
friendsretail |
Advertiser | Named page, counterfeit eyewear |
nationalsteelegy |
Advertiser | Named page, steel-firm name fronting homeware |
| ... | representative subset; 100+ verified-malicious advertiser profiles |
Conclusion
This ecosystem is moving away from infrastructure on which a defender can apply a clean verdict. A dedicated domain on a cheap suffix can be scored, blocked, and burned. A rented tenant slot on a legitimate builder cannot, at least not at the level where most reputation systems operate. The operators making that move are doing so deliberately. The share of tenant hosts should continue to grow. Registration cohorts will remain small and distributed across registrars, while the advertiser layer will remain disposable because replacing it costs nothing. The persistent evidence is the mismatch between what a store claims to be and what it sells, and between a single destination and the many unrelated identities promoting it.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.