Subtraction as Evasion: A Google Drive Callback-Phishing Kit
Subtraction as Evasion: A Google Drive Callback-Phishing Kit
Between February and June 2026, one callback-phishing operator ran 234 one-shot Gmail burners and spent four months deleting its own lure. The kit started out looking like every other fake-invoice campaign: a rendered receipt, a fabricated merchant, a plausible charge, a link to a PDF on Google Drive holding the callback number. Then the operator began removing things. The pseudo-invoice number went first, at peak volume. The message body went next, until every send was empty. In June the subject line itself was cut down to a bare human name, and in one case to the word "Hi". Each deletion removed something a content classifier reads, and the last one removed the very words most hunting queries are written against.
Key Takeaways
- The operator ran a telephone-oriented attack delivery funnel with no attacker-owned domain anywhere in the chain. Sending is consumer Gmail, payload hosting is Google Drive, and the weaponized step is a phone number inside a PDF, so there is nothing for domain or URL reputation to score.
- Content was removed in three separately datable template edits rather than eroding gradually: pseudo-identifiers dropped in April, the body reached fully empty by May, and the subject collapsed in June.
- Message bodies are bimodal and never partial. A send has a fully rendered invoice or nothing at all, which means the operator deleted the template outright each time instead of trimming it.
- Two unrelated randomizers, the buyer-name draw and the Drive file upload, collide on exactly five days, reconstructing five discrete batch runs from a corpus that is otherwise one distinct lure per account.
- The kit keeps office hours. Across a 108-day window there is not a single weekend send, and 23 of the 50 working days are a Monday or a Thursday.
- A second call-to-action form, the
uc?export=viewdirect-render endpoint, runs alongside the standard Drive viewer link and is where the brand-free lures appear.
Background
Telephone-oriented attack delivery, or TOAD, is an email lure whose only call to action is a phone number. The victim who calls reaches a scripted agent who walks them into remote-access software, a bank login, or a fake refund that ends with money moving the wrong way. Because the email has no malicious link and no attachment to detonate, the controls most gateways are built around have nothing to inspect. Proofpoint's State of the Phish research has put TOAD volume in the millions of attempts per month, and Trustwave recorded a sharp surge in callback-phishing traffic through late 2024, so this is a mature category rather than a novel one.
This kit adds a wrinkle. The callback number is not in the email at all. It lives inside a PDF hosted on Google Drive, which means extracting it requires following the link, fetching the document, and reading text out of it. Cisco Talos has written about the same problem from the defender side: PDF-delivered lures push the decisive content behind a fetch-and-parse step that is expensive, slow, and inconsistently deployed at scale.
The delivery rail is worth stating plainly because it is doing a lot of work. Mail sent from a genuine Gmail account passes SPF, DKIM, and DMARC natively, since it really does originate from Google's own outbound infrastructure. Those checks were designed to catch domain spoofing, not to judge the intent of a legitimate freemail account, so authentication posture is no help here at all. Accounts are free and instantly provisioned, so an operator can mint them faster than abuse reporting retires them, and a fresh account per blast means sender reputation never has anything to accumulate against.
Google Drive supplies the other half. A public sharing link resolves under drive[.]google[.]com, with Google's certificate and Google's parent domain, and inherits the trust that reputation engines extend to Google as a whole. Researchers at Check Point and KnowBe4 have documented the same reputation-laundering pattern across Drive, Google Docs, Google Sites, and Google Cloud Storage buckets, with operators rotating between those surfaces as individual links get retired. Nothing in this kit is attacker-owned, which is the entire design.
Who gets hurt is not incidental. Callback and refund fraud lands hardest on older consumers. The FBI's Internet Crime Complaint Center attributed roughly $1.46 billion in tech-support fraud losses across all ages in its 2024 report, of which about $982 million came from victims aged 60 and over. The FTC's 2024 Consumer Sentinel data book logged approximately 845,000 imposter-scam reports, the largest fraud category by volume. A fabricated charge of a few hundred dollars is calibrated to alarm exactly that audience without straining belief.
Discovery and Infrastructure
There is no infrastructure to map in the usual sense. No operator domain, no relay, no redirector, no landing page, no C2. Across several thousand messages observed between February and June 2026, the entire attacker-controlled footprint is a set of Gmail addresses and a set of Drive file identifiers.
That forces the fingerprint to be structural rather than lexical, and the structure is unusually rigid. Every send pairs a one-shot Gmail account with a Drive-hosted PDF, a personal name reproduced in both the display-name field and the subject line, and a body that is either a complete fake invoice or completely empty. Every account carries a single distinct lure, with its own buyer name and its own uploaded PDF, and is then discarded; only one account across the 234 was reused for a second lure.
| Component | What the operator controls | What it inherits |
|---|---|---|
| Sending account | One-shot @gmail[.]com burner, machine-generated localpart |
Native SPF, DKIM, and DMARC pass |
| Payload host | Per-send PDF upload to Google Drive | Google TLS certificate and parent-domain reputation |
| Call to action | Phone number rendered inside the PDF | No URL to score, no page to crawl |
| Identity | Randomized buyer name in display name and subject | Plausibility of a routine transactional receipt |
Grouping the accounts by localpart shows a generator rather than a person choosing names, and grouping the sends by Drive file identifier shows the batches that generator was run in.
How It Works
A recipient gets a receipt for something they did not buy. In the early generation the message renders a full invoice with a merchant name, a date, a reference number, and an amount in the mid-hundreds of dollars, above a link captioned "View Invoice" or "VIEW RECEIPT". In the later generation the message is blank apart from the link.
Either way the link goes to Google Drive. The PDF behind it holds the callback number and repeats the fabricated buyer name. There is no site to visit and no credential form to fill, so a recipient who wants to dispute the charge has one route available, which is to phone the number. That call is the attack.
The buyer name is the connective tissue. It appears in the sender display name, in the subject line, and again inside the PDF, so the message coheres as a receipt addressed to a specific person. In roughly 95 percent of lures the display name is reproduced verbatim inside the subject. The remaining cases are where the machinery shows through, and they are covered below.
Sample Lures
All recipient identifiers are redacted. Buyer names are replaced with placeholders because the investigation established that some are paired with genuinely harvested recipient data and may correspond to real people. Merchant names are withheld because several collide with real trading companies unconnected to this activity. Fabricated order and reference numbers are shown as-is, since they are generator output rather than anyone's real transaction. URLs are defanged.
February Generation
A rendered invoice with a merchant, a reference number, and a charge amount.
From: "[buyer name]" <kxs603879@gmail[.]com>
Subject: [buyer name] - Your Recent Payment Receipt [637361311]
Thank You For Your Order via [merchant name] Pvt. Ltd.
Date: 24/Feb/26
Ref ID : 637361311
Amount : $549.99
View Invoice -> hxxps://drive[.]google[.]com/file/d/<file-id>/view?usp=sharing
March Generation
The same shape, with the recipient's own address written into the invoice as the billed party.
From: "[buyer name]" <sdghncfuinbsduojfsh46895@gmail[.]com>
Subject: [buyer name]: Your Latest Purchase Receipt- 64007311
Your Bill Receipt from [merchant name] Studio
BILLING SUMMARY - 6 MARCH 2026
To: [recipient email]
Receipt# 64007311
VIEW RECEIPT -> hxxps://drive[.]google[.]com/file/d/<file-id>/view?usp=sharing
Thank You, Please Do not Reply to this Email.
PayPal Account-Security Variant
Here the pretext is duplicated into the display-name field, and the body is the bare link with nothing else.
From: "Protect Your Account - PayPal Won't Ask for Personal Info"
<scaoiuamanabavacaloaojw972@gmail[.]com>
Subject: Protect Your Account - PayPal Won't Ask for Personal Info
hxxps://drive[.]google[.]com/file/d/<file-id>/view?usp=sharing
April Generation
By April the body is gone entirely. The subject and display name are all that remain.
From: "[buyer name]" <tstydyfufuvuvivkboboblb445@gmail[.]com>
Subject: INVOICE-[buyer name]
(no body content)
hxxps://drive[.]google[.]com/file/d/<file-id>/view?usp=sharing
Brand-Free Variant on the Alternate Endpoint
No transaction noun appears anywhere, and the call to action uses the direct-render Drive endpoint rather than the viewer link.
From: "[buyer name]" <phnkigbkignkoygn5364@gmail[.]com>
Subject: Happy if You Share. We're Grateful - [buyer name]
(no body content)
hxxps://drive[.]google[.]com/uc?export=view&id=<file-id>
June Terminal Template
The subject is reduced to the buyer name alone.
From: "[buyer name]" <hioxmjo@gmail[.]com>
Subject: [buyer name]
(no body content)
hxxps://drive[.]google[.]com/file/d/<file-id>/view?usp=sharing
Technical Analysis
Sender Localpart Generation
The 234 burner localparts fall into four generator modes, and none of them uses a separator. Not one address contains a dot, underscore, or hyphen, so Gmail's dot-normalization is never exercised. Every localpart but one is lowercase letters followed by optional trailing digits; the single exception interleaves a digit mid-string.
Shares are rounded and sum to 99 percent; the account counts are exact.
| Generator mode | Accounts | Share | Length | Representative localparts |
|---|---|---|---|---|
| Random concatenation, long | 113 | 48% | 14 to 30 | tstydyfufuvuvivkboboblb445, psjsgsgsgsgsgsgsgsgshsyhshx, zjzonsjsisnsnssjsbsuswbsbsgewy |
| Random concatenation, short | 21 | 9% | 7 to 13 | hioxmjo, acretvre, gxfjnxhjv |
| Short alphanumeric with numeric suffix | 50 | 21% | 7 to 13 | bbkhf50, rgs22982, tt0386696 |
| Dictionary-word and name combinations | 50 | 21% | 8 to 30 | countrybunnyhungconical, editorialtruck, divisibledocked |
The two random-concatenation modes are the same generator at different length settings and together account for 57 percent of the inventory. The dictionary mode is the interesting one, because it is where human choices leak in. Eight localparts contain a run of three or more identical characters, one of which stretches a two-word animal pairing across twenty-eight characters. Four accounts share a fixed prince prefix with random tails and two share a smitha prefix, which is a different construction from the rest and suggests a hand-seeded prefix list running alongside the random generator. Six localparts use apparent South Asian personal names, including a matched short-and-long pair built from the same name, and two use Indonesian names.
Brand tokens appear inside a handful of localparts, including strings resembling Costco, DHL, Tesco, and Verizon Fios. Those brands are impersonation targets, not parties to this activity. These are the only points in the entire corpus where an impersonated brand touches the sending identity, and even then only as a substring of a throwaway address.
Subject Template Grammar and Its Turnover
Nine template families cover every send. The mix does not drift. Each month has a dominant family that is close to absent in the adjacent months, which reads as discrete template swaps.
| Family | Canonical form | Share of traffic | Peak month |
|---|---|---|---|
| Generic billing status | [buyer name] - Payment statement has been verified and completed |
35% | April |
| Attachment assertion | Please find the invoice attached herewith - [buyer name] |
17% | April |
| Invoice notification | Invoice Notification - [buyer name] |
15% | March |
| Date-stamped | RE: 07/05/2026 -UPDATED BILLING STATEMENT-[buyer name]. |
10% | May |
| Approval assertion | Reminder: Purchase Authenticated and Recorded - [buyer name] |
8% | April |
| Receipt with pseudo-identifier | [buyer name]: Your Latest Purchase Receipt - 49508892 |
7% | February |
| Named vertical lure | Your Payslip Is Attached - [buyer name] |
3% | March |
| Benign gratitude | [buyer name] - Glad if You Join In. We Value You. |
3% | April |
Bare name or Hi |
[buyer name] |
2% | June |
Read down the peak-month column and the operator's thinking is visible. February is receipt-and-number grammar. March pivots to a noun phrase, Invoice Notification. April pivots again, to verb phrases asserting a completed action: attached, verified, authenticated, approved, processed. May pivots to date-stamping and shouting, with more than half of that month's subjects majority-uppercase. June removes grammar altogether, and mean subject length falls from 54 characters to 11.
Two ordering conventions coexist for the whole campaign and never resolve. Name-first and name-last forms appear side by side, and the separator is itself randomized: hyphen, en dash, colon, no space at all, and a trailing period all show up within the same family on the same day.
The named vertical lures are the small tail worth watching, because they show the operator testing pretexts outside billing: a payslip notification, an assigned-portfolio-manager message, a corporate accounting-lead message, a gift-card order confirmation, a shipping notice, and a Portuguese-language jewellery promotion.
The Pseudo-Identifier Layer
Twenty-eight fabricated order and invoice numbers appear in subject lines, and their distribution is the clearest evidence that stripping was deliberate. They concentrate in February and March, vanish completely in April, and reappear only twice in May. April is the peak-volume month. The operator removed the identifier from the template at the exact moment traffic was highest, which is a choice, not attrition.
| Identifier | Form | Note |
|---|---|---|
04575964 |
Numeric, 8 | Leading zero preserved, so drawn as a digit string rather than an integer |
83062483 |
Numeric, 8 | The dominant length |
831425024 |
Numeric, 9 | |
3825233737 |
Numeric, 10 | Longest numeric form observed |
GZUZ951I |
Alphanumeric, 8 | Uses the visually ambiguous I, so no glyph exclusion |
U9O4JGRNY |
Alphanumeric, 9 | Contains O; the set uses O and 0 interchangeably |
XCXA37XQ022H |
Alphanumeric, 12 | Upper cluster begins here |
FBI7IDHPJBWF76XG |
Alphanumeric, 16 | Longest observed |
CQTS-E4QPZ-44795<U+FEFF><U+FEFF><U+200B>30-2026 |
Hyphenated, 4 groups | The only structured identifier, and the only send carrying zero-width injection |
Numeric-only identifiers are always eight, nine, or ten digits, with eight dominant. Alphanumeric identifiers use uppercase letters and digits with no fixed prefix, no check-digit structure, and no exclusion of ambiguous glyphs, running from seven to sixteen characters with clusters at eight and at twelve to sixteen. Exactly one identifier has internal structure, and that same send is where the zero-width injection appears: two U+FEFF characters and a U+200B split a digit group. Those characters render as nothing to a human and break the token stream that keyword and fuzzy-matching rules depend on.
A richer identifier grammar runs in the body using prefixes the subject never touches, including INV-, INVOICE #, Reference Id-, Receipt Ref: #, and Order Num:. The hash-prefixed short numeric form is body-only and the bare eight-digit form is subject-only, so the two layers were written separately.
Randomizer Desync as a Batch Fingerprint
There are 229 distinct display names across the corpus, 87 shaped as First M. Last and 136 as First Last. In thirteen lures the display name and the subject disagree, and the disagreements are informative because they expose how the template is filled.
Three failure modes recur. The name slot is left unfilled in the subject while the display name is populated. A template with no name slot at all, such as the gift-card confirmation or the terminal Hi, leaves the display name orphaned. And two independent draws land on different names. That last mode shows up three ways: one send pairs a display name and a subject name sharing a surname but not a first name, which means first name and surname are drawn separately; another pair differs by a single character, an off-by-one in one of the two draws; a third has a raw token concatenated onto the end of the name.
One desync case is a category of its own. A send carries a pseudo-invoice token in the display-name field where the buyer name should be, and a victim's street address in the subject line alongside the same token. That is the clearest single piece of evidence that the operator works from a purchased or harvested list rather than generating recipients, and it is consistent with the recipient email addresses written into the early invoice bodies as the billed party.
Drive File IDs and Batch Reconstruction
Drive file identifiers are generated per lure. Ninety percent are 33 characters, Google's standard modern length, with the remainder spread between 31 and 35, which is consistent with genuine per-file uploads rather than fabricated strings. Most lures use the standard viewer link, with a small set using the uc?export=view direct-render endpoint instead.
Reuse is rare, and every reuse event is confined to a single day. No identifier is reused across two dates, and no account reused an identifier across its own sends. That makes each reuse a visible batch run.
| Date | Buyer name reused across accounts | Burner accounts | Drive PDF relationship |
|---|---|---|---|
| 2026-02-25 | Yes | 3 | One identical file across all three |
| 2026-03-02 | Yes | 2 | One identical file |
| 2026-04-13 | Yes | 2 | Two files at edit distance one |
| 2026-04-17 | Yes | 2 | One identical file |
| 2026-05-06 | Yes | 2 | One identical file |
This is the strongest result in the corpus. The buyer-name draw and the file upload are unrelated parts of the kit, yet all five buyer-name reuse events land on a shared or near-identical PDF on the same date. Two independent randomizers collide on the same five groupings, which reconstructs five batch runs out of a corpus that otherwise looks like 234 unrelated accounts.
Two practical notes for anyone reproducing this. First, the near-identical pairs matter as much as the exact matches: one 2026-04-13 pair differs by a single inserted character and a digit-for-letter swap near the tail, and the same signature recurs on two sends in June. Edit-distance clustering recovers batches that equality grouping cannot. Second, Drive identifiers must be case-folded before grouping, because case is not preserved consistently in logged URLs. Two of the four exact-reuse events above are invisible to a raw-string match.
Fabricated Merchant Grammar
The early invoices attribute the charge to a merchant that does not exist as the biller. Seven such names appear, all within a 37-day window, and then never again. We are not naming them, because several collide with real trading companies that have nothing to do with this activity, and the naming convention is the finding rather than the strings.
Four of the seven use a <Word> Studio form, two use an Indian private-limited Pvt. Ltd suffix, and one uses <Word> Consulting. The Studio block is contiguous, four personas across six days in March, and then abandoned. One stem appears twice, crossing conventions three weeks apart, which points at a small seed word-list rather than generation. The Pvt. Ltd suffix pairs suggestively with the South Asian localpart cohort noted above, though on its own that is weak evidence.
Two of the personas ship on the same day with a byte-identical body template differing only in the merchant slot. The merchant is a template variable, not an identity the operator maintains.
Content Decay, Measured
The decay is monotonic through May and reaches a terminal state there.
| Month | Distinct burner accounts | Bodies empty | Mean body length | Mean subject length |
|---|---|---|---|---|
| February 2026 | 13 | 0% | 107 chars | 55 chars |
| March 2026 | 63 | 56% | 54 chars | 45 chars |
| April 2026 | 121 | 95% | 8 chars | 53 chars |
| May 2026 | 33 | 100% | 0 chars | 54 chars |
| June 2026 | 4 | 75% | 21 chars | 11 chars |
Two refinements matter more than the trend itself.
Bodies are bimodal and never partial. In every month the count of bodies under forty characters equals the count of empty bodies exactly, so there are no short bodies anywhere in the corpus. A send has a fully rendered invoice of 40 to 313 characters, or it has nothing. The operator did not trim; the template was deleted outright, and the monthly average simply tracks the mix of generations still in flight.
Body decay and subject decay are also a month apart. Subject length holds flat between 45 and 55 characters while the body falls to zero across February through May, then collapses to 11 characters only in June, once the body has already been gone for a full month. Combined with the April disappearance of pseudo-identifiers, that gives three separately datable template edits rather than one gradual slide.
Operating Cadence
Across the 108-day window the operator worked 50 days, and not one of them was a Saturday or a Sunday.
| Weekday | Days worked |
|---|---|
| Monday | 12 |
| Tuesday | 10 |
| Wednesday | 10 |
| Thursday | 11 |
| Friday | 7 |
| Saturday | 0 |
| Sunday | 0 |
Monday and Thursday account for 23 of the 50 working days. Friday is the weakest, worked seven times against twelve Mondays. The busiest single day put fourteen distinct burner accounts into service. There is a clean six-day pause in late April and a three-week wind-down after mid-May before the four terminal June sends. The shape is a small human-operated shop on a five-day week, not a scheduled botnet.
Detection Observations
The useful signal here is structural, and it survives every template change the operator made.
The durable combination is a freemail sender, a cloud-storage document link as the only call to action, a personal name reproduced in both the display-name field and the subject, and a body that is empty or a bare URL. Any one of those is unremarkable on its own. Together they describe a shape that ordinary correspondence does not produce, because a real person sharing a real document writes something around the link and does not put their own name in the subject line.
Pretext vocabulary is the weakest thing to key on, and this campaign is the argument for why. An invoice-keyword query written in March would have matched the March traffic and returned nothing in June, while the operator was still sending. Any query gated on lure language has a shelf life set by the operator rather than by the defender.
Several artifacts are worth keying on directly. The one-to-one ratio between sender accounts and distinct lures is itself a signal at population scale. Zero-width characters inside a subject line have no legitimate purpose in transactional mail. A display name that is a pseudo-invoice token rather than a name, or that disagrees with the name in the subject, indicates template filling rather than a human sender. And cloud-storage document identifiers, case-folded and clustered by edit distance rather than equality, group otherwise-unrelated accounts into batches.
Coverage should include the uc?export=view endpoint alongside the /file/d/ viewer path. The brand-free lures ran on the former, and a query written only against the viewer path will not see them.
Indicators of Compromise
All indicators are defanged. Recipient data has been removed. The list below is a representative subset selected to span the generator modes rather than an exhaustive dump.
Sender Addresses
| Value | Role | Notes |
|---|---|---|
costcofha@gmail[.]com |
Sender | Dictionary mode; brand token in localpart, Costco is an impersonation target and not a party to this activity |
countrybunnyhungconical@gmail[.]com |
Sender | Dictionary mode |
divisibledocked@gmail[.]com |
Sender | Dictionary mode |
editorialtruck@gmail[.]com |
Sender | Dictionary mode |
countinghoning19@gmail[.]com |
Sender | Dictionary mode with numeric suffix |
audioeconomic12@gmail[.]com |
Sender | Dictionary mode with numeric suffix |
doggggggggggggggcatttttt5262@gmail[.]com |
Sender | Dictionary mode, repeated-character run |
tstydyfufuvuvivkboboblb445@gmail[.]com |
Sender | Random concatenation, long |
bxjjdiskwlwodjcmckjsheh7373@gmail[.]com |
Sender | Random concatenation, long |
psjsgsgsgsgsgsgsgsgshsyhshx@gmail[.]com |
Sender | Random concatenation, long |
gxfjnxhjv@gmail[.]com |
Sender | Random concatenation, short |
bbkhf50@gmail[.]com |
Sender | Short alphanumeric with numeric suffix |
fhafdg35@gmail[.]com |
Sender | Short alphanumeric with numeric suffix |
akola6716@gmail[.]com |
Sender | Short alphanumeric, paired with a longer sibling built on the same name |
rgs22982@gmail[.]com |
Sender | Short alphanumeric with numeric suffix |
| … (representative subset; the full burner inventory runs to over 200 addresses) |
No operator-owned domains, hosts, URLs, or IP addresses exist for this campaign. The sending carrier and the payload host are both legitimate Google services and are not indicators. Callback numbers live inside the hosted PDFs and are not present in message telemetry.
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE Fight Fraud Framework (F3) v1.1, the Center for Threat-Informed Defense's fraud-behavior model, rather than to enterprise ATT&CK. F3 is scoped to fraud behavior after initial compromise, and this campaign is a pre-access lure, so the mapping below is an alignment by analogy rather than a literal fit. Framework reference: https://ctid.mitre.org/fraud.
| F3 Tactic | Technique | ID |
|---|---|---|
| Reconnaissance | Gather Customer Information (recipient addresses, and one street address, held in advance and written into the lure as the billed party) | F1029 |
| Resource Development | Establish Accounts (234 one-shot Gmail burners with machine-generated localparts) | T1585 |
| Resource Development | Falsify Business Documents (invoice attributing the charge to a merchant that is not the biller) | F1027 |
| Resource Development | Create Fake Materials: Fake Documents (per-send PDF staged on Google Drive) | F1020.001 |
| Initial Access | Phishing (unsolicited fake receipt from an authentication-passing freemail account) | T1660 |
| Initial Access | Impersonate Official (fabricated merchant, and a payment brand in one branch) | F1032 |
| Stealth | Sequential deletion of pseudo-identifier, body and subject grammar; zero-width character injection; homoglyph display names; an alternate call-to-action endpoint | |
| Positioning | Callback number placed inside a hosted PDF rather than the message, moving the victim onto a channel with no email-side controls | |
| Execution | Dispute Legitimate Transaction (victim-initiated call to contest a charge they never made) | F1024 |
| Monetization | Refund fraud, remote-access takeover and bank-credential theft, the standard outcomes of this funnel |
Conclusion
Most kits get harder to catch by adding things: an encoding layer, a redirect hop, a new domain generation scheme. This one got harder to catch by subtraction, and it did so at the moment it was busiest, which suggests the operator was watching what happened to their own delivery and editing accordingly. The end state of that process is a message with no body, no pretext, no brand, and no attacker-owned infrastructure of any kind, which is close to the floor of what an email can be and still function as a lure. Defenders should expect the next incarnation to start at that floor rather than work down to it, and should key on the shape of the message rather than the words in it.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.