Renting Reputation: An Email-Fraud Ecosystem Built on ActiveCampaign
Renting Reputation: An Email-Fraud Ecosystem Built on ActiveCampaign
Since January 2026, more than a dozen independent operators have rented paid ActiveCampaign accounts to send authenticated fake-payout email fraud. They do not spoof domains or hijack mailboxes. Each operator pays for a legitimate sender account, creates a throwaway domain that describes the lure, and uses the platform to sign and deliver the mail. The fraud passes SPF, DKIM, and DMARC while traveling over warm, reputable infrastructure. Over roughly five months, we observed tens of thousands of these messages across three overlapping fraud tiers: fake-payout and fake-card-delivery scams, deceptive make-money-online affiliate coaching, and Spanish- and Portuguese-language investment-webinar funnels. The operators have almost nothing in common beyond the platform they abuse. That shared dependency is what makes the cluster worth mapping.
Key Takeaways
- The operators spoof or compromise nothing. Each rents a legitimate ActiveCampaign account, so every message authenticates cleanly and uses the platform's shared sending reputation.
- The actual account boundary is the ActiveCampaign account slug found on the click-tracker and console subdomains, not the sending apex. A single operator often runs several coined apexes under one account slug.
- Each hop in the click chain launders reputation: reputable ESP sending IPs, followed by a reputable ESP click-tracker, then a reputable landing platform such as Hotmart or ClickFunnels. URL-reputation pivots dead-end on trusted infrastructure.
- Fraud-payout senders rotate impersonal finance-department display names, with one account cycling through 40 of them. Money-making senders retain a stable human coach persona.
- Domain registrations span three age tiers and seven registrar cohorts with no monoculture, consistent with many independent operators sharing only the platform.
- Two operators moved from a rented account to a self-hosted ActiveCampaign install. This escalation points toward more durable, operator-owned sending.
Background
We found the cluster indirectly. A previous investigation into a bank-card-activation scam operator flagged several unrelated senders as co-tenants on the same return-path domains, emsend2[.]com and acems2[.]com. The obvious interpretation was that they shared an operator or phishing-as-a-service backend. Verification of the two apexes disproved that interpretation: both belong to ActiveCampaign itself and are registered through MarkMonitor, the same family as the platform's other infrastructure domains. Co-tenancy on them proves only that two senders use the same email vendor, just as unrelated criminals might use the same postal service. That correction changed our view of the set from a single operator to an ecosystem of independent operators.
ActiveCampaign is a legitimate email-marketing and marketing-automation platform. Tenants pay to send bulk mail through the platform's shared IP pools, with messages signed by the platform's own DKIM keys. Vendors call this mechanic ESP account abuse: instead of forging a victim's domain or compromising a mailbox, an actor buys a sender account from a reputable provider and uses it to distribute fraud. Because the platform authorizes the send, SPF passes, DKIM validates, and DMARC aligns. The messages are not forged, so authentication-based filtering has nothing to catch, and they inherit warm, high-reputation IPs. Providers can suspend an abusive account in hours or days, but a blast lands in minutes. The account is designed to be disposable. Public research has documented this pattern, including a case in which attackers sent thousands of AI-generated small-business-loan phishing emails through ActiveCampaign specifically.
Every ESP rewrites outbound links to measure opens and clicks for each tenant. In this cluster, the click-tracker domains are acemlna[.]com, acemlnb[.]com, acemlnc[.]com, and emlnk1[.]com through emlnk9[.]com. This wrapping creates a problem for defenders. The visible hop is a shared, reputable redirector used by thousands of legitimate senders, which makes scoring or blocking it useless, while the actual destination sits behind one indirection on trusted infrastructure. The landing pages follow the same pattern. Fraud-tier clicks often end at go.hotmart[.]com, the affiliate layer of a large digital-product marketplace where anyone can create a commission-bearing link on a reputable commerce domain. Money-making funnels lead to ClickFunnels pages under myclickfunnels[.]com, a hosted funnel builder whose subdomains inherit platform trust and can be deployed in seconds. Security vendors have documented abuse of both platforms as redirect and landing layers in phishing campaigns.
Regulators have pursued this category of fraud for years. The US Federal Trade Commission has repeatedly taken action against make-money-online business-coaching schemes based on fabricated income claims, returning tens of millions of dollars to consumers in matters such as MOBE and Lurn. The warning signs in that guidance include guaranteed income, a "proven system," and large returns for little effort. Those signs map directly to the money-making and investment-webinar tiers in this cluster. The fake-payout tier uses a classic advance-fee and fake-prize structure disguised as customer service, with claims such as "your card is on its way" and "payout window closes," along with fabricated batch and ledger numbers.
Discovery and Infrastructure
Mapping the ecosystem required us to distinguish operators who all used the same platform. Two signals established those boundaries. The first was the return-path sub-host, which separated senders into two platform generations. The second and stronger signal was the ActiveCampaign account slug, a subdomain present in every account's console links and reproduced verbatim on its click-tracker subdomains. That slug is the account fingerprint, connecting multiple coined apexes to one operator account.
The cluster divides cleanly between the two platform generations. Older accounts return through d15c[.]emsend2[.]com up to d21c[.]emsend2[.]com. Newer accounts return through mailNN.use1[.]acems2[.]com, mailNN.use2[.]acems2[.]com, and mailNN.euc1[.]acems2[.]com. The generation split does not correlate with fraud tier. That pattern is consistent with independent operators onboarding at different times rather than one operator provisioning accounts in a batch.
| Sender | Tier | Return-path generation | ActiveCampaign account slug |
|---|---|---|---|
contact@transfer-updates[.]com |
Fake-payout | emsend2 (d18c) |
eft-system |
bill@cheapearnings[.]com |
Fake-payout | emsend2 (d17c) |
cheapearnings |
grace@yoursimplehelp[.]com |
Fake-payout | emsend2 (d18c) |
hellograce129 |
delivery@yourclickws[.]com |
Fake-payout | emsend2 (d18c) |
leonfootauyong |
support@glpwinner[.]com |
Fake-prize | acems2 (use2) |
glpwinner |
support@emlfstyl[.]net |
Money-making | emsend2 (d15c) |
emlfstyl |
jason@growth-express[.]com |
Money-making | acems2 (use1) |
ascendoramedia |
support@gotitanboost[.]com |
Money-making | emsend2 (d21c) |
grupolever |
support@finding-your-purpose[.]com |
Money-making | emsend2 (d16c) |
benebiz26 |
symone@govtechacademy[.]com |
Money-making | acems2 (use2) |
govtechacademy |
mauro@somosnum[.]com |
Spanish webinar | emsend2 (d19c) + self-hosted |
emailmarketing.somosnum[.]com (self-hosted) |
noreply@divisualproject[.]com |
Spanish course | acems2 (euc1) |
divisualproject95405 |
contato@ricosnaamerica[.]com |
Portuguese | emsend2 (d21c) |
ricosamerica |
escola@anovaelite[.]com[.]br |
Portuguese | acems2 + self-hosted |
suportedestinorico |
How It Works
A typical fraud-tier message begins with an operator-coined sender domain that names the lure, such as transfer-updates[.]com, cheapearnings[.]com, or yourclickws[.]com. Its display name impersonates a function rather than a brand, using names such as "Eft customer service" or "Account Services." Because it names no real brand, this approach sidesteps brand-impersonation checks. The message body invents both a status and a deadline: a card activation that expires in under two hours, a payout window that closes at 4 PM Eastern, or a batch that posted a specific dollar figure to the recipient's file. Many messages include the recipient's first and last name, obtained from purchased or breached contact lists, which gives the fabricated status a personal edge.
The message contains a single call to action in a wrapped link. The link passes through the account's ActiveCampaign click-tracker, such as eft-system.acemlnc[.]com or cheapearnings.emlnk9[.]com, before reaching a reputable downstream platform. The fake-card-delivery operator directs clicks to a go.hotmart[.]com affiliate link, making the visible destination a legitimate marketplace. The spiritual money-making operator uses a myclickfunnels[.]com funnel. Other links terminate on the operators' own coined-apex pages. The victim never encounters a domain that a reputation engine would flag on sight.
The money-making tier replaces fabricated payouts with fabricated progress. One operator sends fake affiliate-dashboard alerts such as "47 commissions processed" and "DEPOSIT PENDING" under rotating all-caps department names. Another uses a false-scarcity account-deletion hook signed by a named coach. A third rotates spiritual personas, including the display names "Buddhist Monk" and "God," to promote self-help funnels. The Spanish and Portuguese tiers use countdown urgency such as "ULTIMAS 2 HORAS" to steer recipients toward investment-webinar and get-rich course landers.
Sample Lures
All samples are defanged. Every recipient identifier, tracking token, and reference number has been redacted.
Fake-payout, fake-card-delivery (transfer-updates[.]com, account eft-system):
From: "Eft customer service" <contact@transfer-updates[.]com>
Subject: Your Card Activation Expires in 1h24mins
Hi! This is Peter from Support. I'm sending you this private email to let
you know that your card activation will expire in less than 2 hours. I
noticed on your dashboard that you already tried to activate it, but it
didn't go through. Click this link to complete your activation.
hxxps[:]//go.hotmart[.]com/[ref #]
Peter, Support Team
Fake-payout, fabricated ledger entry (cheapearnings[.]com, account cheapearnings):
From: "Account Services" <bill@cheapearnings[.]com>
Subject: Heads up: payout window closes 4 PM Eastern
The payout window holds until 4 PM Eastern today. A file entry is pending
against your profile. Confirm before the window closes.
Confirm entry >>
Funds Verification, Treasury
Fake-payout tier, get-rich commission-check hook (yourclickws[.]com, account leonfootauyong):
From: "Jude Mayers" <delivery@yourclickws[.]com>
Subject: Will you let ME do the work for YOU? (Totally free)
If you can follow a few simple instructions, you are on track to be
cashing a check in just a few short weeks... Get the simple profit
instructions here: hxxps[:]//leonfootauyong.acemlnc[.]com/lt.php?x=[token]
And you want to learn how to keep your checks coming in month, after
month like clockwork...
Jude Mayers
Money-making, false-scarcity account-deletion (growth-express[.]com, account ascendoramedia):
From: "Jason Bennett" <jason@growth-express[.]com>
Subject: I'm doing you a small favor
[recipient name] I'm doing you a small favor. Your account was supposed
to be deleted this morning. I saw your name on the removal list and I
manually stopped it. But the system will try once again to delete your
account in the next 24 hours. Save my account from deletion
hxxps[:]//tk.growth-express[.]com/trakass. If you don't save it, I can't
do anything more after this.
Your friend, Jason Bennett
Spanish investment webinar (somosnum[.]com, self-hosted install to academianum[.]com):
From: "Mauro Stendel" <mauro@somosnum[.]com>
Subject: ULTIMAS 2 HORAS
Enterate de mas en este email. A las 00:00 se cierra y no vuelve. Si lo
venias pensando, este es el momento exacto.
hxxps[:]//ingreso.academianum[.]com
Mauro
Portuguese get-rich teaser (anovaelite[.]com[.]br, account suportedestinorico):
From: "Clayson Felizola" <escola@anovaelite[.]com[.]br>
Subject: Preciso te ouvir, [recipient name]
A gente vai construir o proximo passo junto.
Technical Analysis
The Account Slug Is the True Fingerprint
Every ActiveCampaign tenant has an account slug. It appears on console and unsubscribe links and is reproduced verbatim on each of the tenant's click-tracker subdomains. The slug, rather than the sending domain, defines the account boundary. Within this cluster, the slug is often unrelated to the apex used for sending. This provides the clearest evidence that one operator can manage several throwaway domains through a single paid account.
| Sending apex | Account slug | Slug matches apex? |
|---|---|---|
transfer-updates[.]com |
eft-system |
no |
yoursimplehelp[.]com |
hellograce129 |
no |
yourclickws[.]com |
leonfootauyong |
no |
growth-express[.]com |
ascendoramedia |
no |
gotitanboost[.]com |
grupolever |
no |
anovaelite[.]com[.]br |
suportedestinorico |
no |
ricosnaamerica[.]com |
ricosamerica |
partial |
cheapearnings[.]com |
cheapearnings |
yes |
govtechacademy[.]com |
govtechacademy |
yes |
For defenders, the account slug is useful because it persists. Coined apexes are inexpensive and rotate frequently. The slug remains consistent across a tenant's sends until ActiveCampaign suspends the account, making it a much stronger cross-message and cross-apex pivot than any individual domain.
Two Return-Path Generations
The senders belong to two platform generations. The older generation returns through d15c[.]emsend2[.]com to d21c[.]emsend2[.]com. The newer generation returns through mailNN.{use1,use2,euc1}[.]acems2[.]com, where the region token reveals the sending region; US-East and EU-Central both appear. The split crosses every fraud tier instead of following a single one. This is consistent with independent operators onboarding at different times, rather than one actor provisioning a fleet.
From Rented Account to Self-Hosted Install
Two operators progressed beyond the rented model. The Spanish-webinar sender somosnum[.]com operates its own ActiveCampaign install at emailmarketing.somosnum[.]com. We identified it through the same lt.php, proc.php, and box.php link-handler fingerprint used by the hosted platform, and its clicks no longer pass through the shared trackers. The Portuguese sender anovaelite[.]com[.]br uses a dedicated self-hosted return-path, em-3738655.anovaelite.com[.]br, alongside a shared tracker. Self-hosting exchanges disposable convenience for control and continuity. This escalation warrants attention because it removes the platform's suspension lever from the operator's sending infrastructure.
Display-Name Grammar
Display-name behavior differs by tier. Fake-payout senders rotate impersonal department names designed to convey authority. One account, cheapearnings, used 40 distinct names, including "Account Services," "Ledger Services," "Payout Confirmation," "Funds Verification," "Treasury," and "Clearance Desk." Each was constructed to resemble a routine financial notice. Money-making and investment senders take the opposite approach, retaining one human persona such as "Jason Bennett," "Mauro Stendel," or "Clayson Felizola," because the coaching pitch relies on a relationship with a named person. Both high display-name churn on a finance-adjacent sender and a fixed persona on a get-rich sender form recognizable patterns.
Registration Cohorts and the Independent-Operator Thesis
If one operator controlled this activity, we would expect the domains to share a registrar and registration window. They do not. The apexes span seven registrar cohorts and three age tiers without a monoculture. This registration pattern is consistent with many unrelated actors converging on one platform rather than a single provisioning run.
| Apex | Registrar | Created | Age tier |
|---|---|---|---|
finding-your-purpose[.]com |
Namecheap | 2019 | aged |
cheapearnings[.]com |
Cloudflare | 2020 | aged |
ricosnaamerica[.]com |
Hostinger | 2020 | aged |
yourclickws[.]com |
Namecheap | 2020 | aged |
emlfstyl[.]net |
Namecheap | 2022 | mid |
divisualproject[.]com |
Tucows | 2023 | mid |
yoursimplehelp[.]com |
Namecheap | 2023 | mid |
govtechacademy[.]com |
Namecheap | 2023 | mid |
transfer-updates[.]com |
GoDaddy | 2023 | mid |
anovaelite[.]com[.]br |
Registro.br | 2018 | aged |
glpwinner[.]com |
GoDaddy | 2024 | recent |
somosnum[.]com |
Hostinger | 2024 | recent |
gotitanboost[.]com |
PublicDomainRegistry | 2024 | recent |
growth-express[.]com |
GoDaddy | 2025 | recent |
academianum[.]com (lander) |
Hostinger | 2026 | recent |
One sub-pattern does form a cluster. The Hostinger registrations, ricosnaamerica[.]com, somosnum[.]com, and academianum[.]com, correspond to the Spanish and Portuguese self-hosting sub-operator, the same actor identified in the self-hosted-install finding above. Most of the other apexes are coined-name registrations rather than genuinely aged brand acquisitions.
The Reputation-Laundering Click Chain
The downstream map shows how each tier borrows trust. Each tracker family carries multiple accounts, and the clicks from each account resolve either to a reputable third-party platform or to the operator's own coined-apex lander.
| Tracker family | Tiers routed | Downstream destination |
|---|---|---|
acemlnc[.]com |
Fake-payout, Portuguese | go.hotmart[.]com; operator self-landers |
acemlnb[.]com |
Money-making, Spanish, Portuguese | tk.growth-express[.]com; operator self-landers |
emlnk9[.]com |
Fake-payout, money-making | operator self-landers |
emlnk1[.]com |
Money-making | findingyourpurpose1.myclickfunnels[.]com |
self-hosted emailmarketing.somosnum[.]com |
Spanish | ingreso.academianum[.]com |
Detection Observations
Behavioral and structural signals carry the most weight here because authentication provides no basis for judging the message: the mail is cryptographically legitimate at the infrastructure layer. The account slug is the durable pivot. It persists through apex rotation and connects otherwise unrelated coined domains to one tenant, a correlation that a domain-by-domain view cannot provide. Display-name grammar offers another inexpensive signal. A finance-adjacent sender that rotates through many impersonal department names, or a get-rich sender that retains one human persona, differs from ordinary marketing mail in recognizable ways. The self-hosted ActiveCampaign fingerprint, consisting of lt.php, proc.php, and box.php handlers on an operator-owned subdomain, identifies operators that have left the rented model and merit closer tracking. The reputation-laundering chain also makes the terminal lander more useful than the wrapped tracker hop, because the tracker is shared, trusted, and inert as an indicator. These signals do not rely on authentication failure, which defines this ecosystem.
MITRE Fight Fraud Framework Mapping
This mapping uses the MITRE Center for Threat-Informed Defense Fight Fraud Framework (F3, released 2026), the successor to the earlier Fraud matrix. The IDs below are the framework's own technique identifiers.
| Tactic | Technique | ID |
|---|---|---|
| Resource Development | Acquire Infrastructure (coined sending domains) | T1583 |
| Resource Development | Establish Accounts (paid ESP sender accounts and personas) | T1585 |
| Resource Development | Create Fake Materials (fabricated dashboards, batch and ledger numbers, auth codes) | F1020 |
| Initial Access | Phishing (the lure email) | T1660 |
| Initial Access | Impersonate Official (payout-authority and support personas) | F1032 |
| Initial Access | Impersonate Account Holder (personalized identity-based social engineering) | F1031 |
| Monetization | Electronic Funds Transfer (fake-payout and card-activation flows) | F1025 |
| Monetization | Fraudulent Purchasing (affiliate conversions and paid programs) | F1028 |
Indicators of Compromise
All indicators below are defanged and come from the verified-malicious set. Legitimate platform infrastructure from ActiveCampaign, Hotmart, and ClickFunnels is deliberately excluded. These are abused shared SaaS platforms, not operator-owned infrastructure, and defenders must not block them.
Senders
| Value | Role | Notes |
|---|---|---|
contact@transfer-updates[.]com |
Sender | Fake-payout, fake-card-delivery; account eft-system |
bill@cheapearnings[.]com |
Sender | Fake-payout, fabricated ledger; 40 rotating display names |
grace@yoursimplehelp[.]com |
Sender | Fake-payout, fake auth-code; account hellograce129 |
delivery@yourclickws[.]com |
Sender | Fake-payout tier, get-rich check hook; account leonfootauyong |
support@glpwinner[.]com |
Sender | Fake-prize; account glpwinner |
support@emlfstyl[.]net |
Sender | Fake affiliate-dashboard and deposit alerts |
jason@growth-express[.]com |
Sender | Money-making false-scarcity; account ascendoramedia |
support@gotitanboost[.]com |
Sender | Fake purchase-approval; account grupolever |
support@finding-your-purpose[.]com |
Sender | Spiritual money-making funnels; account benebiz26 |
symone@govtechacademy[.]com |
Sender | Coaching money-making persona |
mauro@somosnum[.]com |
Sender | Spanish investment webinar; self-hosted install |
noreply@divisualproject[.]com |
Sender | Spanish course funnel; account divisualproject95405 |
contato@ricosnaamerica[.]com |
Sender | Portuguese get-rich; account ricosamerica |
escola@anovaelite.com[.]br |
Sender | Portuguese get-rich; account suportedestinorico |
Domains
| Value | Role | Notes |
|---|---|---|
transfer-updates[.]com |
Sender apex | Fake-payout; GoDaddy, 2023 |
cheapearnings[.]com |
Sender apex | Fake-payout; Cloudflare, 2020 |
yoursimplehelp[.]com |
Sender apex | Fake-payout; Namecheap, 2023 |
yourclickws[.]com |
Sender apex | Get-rich; Namecheap, 2020 |
growth-express[.]com |
Sender apex | Money-making; GoDaddy, 2025 |
gotitanboost[.]com |
Sender apex | Money-making; PublicDomainRegistry, 2024 |
emlfstyl[.]net |
Sender apex | Money-making; Namecheap, 2022 |
finding-your-purpose[.]com |
Sender apex | Money-making; Namecheap, 2019 |
govtechacademy[.]com |
Sender apex | Money-making; Namecheap, 2023 |
glpwinner[.]com |
Sender apex | Fake-prize; GoDaddy, 2024 |
somosnum[.]com |
Sender apex | Spanish; Hostinger, 2024; self-hosted install |
divisualproject[.]com |
Sender apex | Spanish; Tucows, 2023 |
ricosnaamerica[.]com |
Sender apex | Portuguese; Hostinger, 2020 |
anovaelite[.]com[.]br |
Sender apex | Portuguese; Registro.br, 2018; self-hosted return-path |
academianum[.]com |
Lander | Spanish webinar funnel; Hostinger, 2026 |
Conclusion
Clean authentication does not establish trust. It establishes only that the platform authorized the send. More than a dozen unrelated operators can each rent a reputable sender account and route every hop of the click chain through trusted SaaS. In response, the defensible signal shifts from the envelope to behavior: the durable account slug, display-name grammar, the terminal lander, and the fingerprint of operators that have started self-hosting. We expect that last group to grow because self-hosting is the one step that removes the platform's suspension lever from the equation.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.