The Amazon Recall Smishing Kit and the Limits of Domain Shape
The Amazon Recall Smishing Kit and the Limits of Domain Shape
Between March and April 2026, Amazon-branded product-recall texts each burned a single throwaway .top domain registered a day or two before use. The lure tells a shopper that an item from a recent order has been added to a safety recall list, asks them to stop using it, and offers a full refund behind a link. The infrastructure is deliberately forgettable: a five-character random domain, one send, then abandonment. That disposability makes the operator look easy to fingerprint, and it is the reason we could not. This post is about the three pivots we tried on that infrastructure, what each one measured, and why all three turned out to describe the internet rather than the operator.
Key Takeaways
- The recall-and-refund pretext borrows consumer-safety authority rather than fear or greed, which is why it reads as procedural to the recipient. The FTC has published a consumer alert on this exact lure.
- Each send used its own five-character random-label
.topdomain, registered one to two days beforehand and never reused. One send hid the lander behind a public link shortener. - Same-day, same-registrar registration cohorts around each lander contained no other infrastructure we ever observed in use. Bulk registration at a discount registrar is ordinary throughput, not an operator stockpile.
- A non-redacted WHOIS registrant-organization string on one lander looked like a genuine registrant identity. It appears on 123 unrelated domains spanning crypto scams, typosquats, adult sites and benign SaaS. It is a reseller artifact, not a fingerprint.
- Short random-label
.topdomains are malicious roughly 0.6% of the time. As a standalone indicator, the shape produces on the order of 160 benign matches for every real one. - What survives measurement is the composite: pretext plus channel plus registration age plus lander path grammar. No single element of that composite is worth acting on alone.
Background
Fake Amazon recall texts are not obscure. The FTC issued a consumer alert on scam texts offering refunds for Amazon purchases, and the pretext has been documented publicly through 2026 by Trend Micro, Bitdefender and mainstream outlets, with Amazon maintaining its own guidance on identifying and reporting scam messages. The sends examined here are a small local slice of something running at consumer scale.
What makes the recall framing effective is the posture it adopts. Most smishing either threatens the recipient (an account is locked, a toll is unpaid) or tempts them (a prize, a rebate). A recall notice does neither. It presents the sender as acting on the recipient's behalf, which converts the request for account details into something that reads as a safety procedure rather than a solicitation. The refund is the incentive; the safety language is what lowers the guard.
The infrastructure sits on well-understood economics. .top is a new gTLD marketed almost entirely on price, with registrations frequently under a few dollars a year and bulk discounts on top of that. Spamhaus has repeatedly ranked it among the most-abused TLDs, and Krebs on Security has written on why cheap new gTLDs attract phishers. Both registrars of record in this campaign, gname.com and NameSilo, are legitimate ICANN-accredited businesses that compete on volume and self-service. A registrar that sells cheap domains in bulk with minimal signup friction will appear in scam WHOIS as a matter of arithmetic. Their presence in these records says nothing about awareness or complicity, and we do not present it as though it does.
One variant reached its target through shorturl[.]at, a public link shortener operated by NameSilo. Shorteners are useful in SMS for the obvious reason that they fit the character budget, and for the less obvious one that a generic short link looks less alarming to a recipient than a raw five-character .top address. They also impose a research cost, discussed below.
Discovery and Infrastructure
Three sends, seven weeks apart at the extremes, three domains. Nothing is shared between them at the hosting or content layer that we can see. The table below is the whole observable estate.
| Indicator | Role | Registrar of record | Registered | First used | Gap |
|---|---|---|---|---|---|
82ghi[.]top |
Lander, on the apex | Gname.com Pte. Ltd. | 2026-03-11 | 2026-03-13 | 2 days |
b1m8v[.]top |
Lander, on the apex | Gname.com Pte. Ltd. | 2026-03-16 | 2026-03-17 | 1 day |
ezfez[.]top |
Lander, served from the rukg. subdomain |
NameSilo, LLC | 2026-04-29 | 2026-04-30 | 1 day |
Registration dates are apex-level, since subdomains are not separately registered.
The pattern is legible immediately. Register, send, abandon. Every domain was live for roughly the length of a single campaign burst, and none was reused. All three origins are now unresponsive.
That legibility is seductive. A per-send burner estate looks like it should have a manufacturing process behind it, and a manufacturing process leaves traces: a registration batch, a nameserver, a registrant identity, a hosting account. We went looking for each of those. The rest of this post is what we found, which was mostly the absence of the thing we expected.
How It Works
The recipient receives a text that presents itself as an official Amazon safety notice concerning a specific past order. The message names a month ("your January 2026 order"), supplies a fabricated order number, and instructs the recipient to stop using the product. A link is offered for recall details and refund processing. The lander harvests Amazon credentials, and in one variant, payment details.
Two of the three sends reached us as screenshots rather than as text, which is consistent with recipients forwarding a text they found suspicious. That has a practical consequence for research: a screenshot carries no machine-readable body, so the extracted link is the only thing left to pivot on.
Sample Lures
SMS, March 2026. Spoofed alphanumeric sender ID reading as the Amazon brand.
Important Safety Recall Notice for Your Amazon Order
Dear Amazon Customer,
During our routine 2026 product quality and safety review, we identified
that an item included in your January 2026 order (Order No.: [order number])
has been officially added to the Amazon Product Safety Recall List.
For your safety, we kindly ask that you stop using this product immediately.
To learn more about the recall details and request your full refund, please
review the official recall information at the link below:
Review Recall Details & Refund Options:
http[:]//82ghi[.]top/vkF4N1Ow?NTAA=cpacGq
SMS, April 2026. Compressed variant, lander hidden behind a public shortener.
A product from your April 2026 order is subject to a safety recall.
Contact us for a full refund.
http[:]//shorturl[.]at/E9dufL
The second sample is the more interesting of the two. It is shorter, drops the corporate-letter register of the first, and puts a generic shortener in front of the lander. When we went back to resolve that shortlink, the token had already expired at the shortener. The mapping from short link to landing page exists only in the shortener's records, and once purged, the destination for that send is unrecoverable by anyone. Fronting a lander with a shortener buys evasion at send time and quietly destroys the forensic record later.
Technical Analysis
Lander Grammar
Every observed CTA follows the same shape: an eight-character mixed-case random path segment, optionally followed by a junk query parameter whose name and value are also random.
/vkF4N1Ow?NTAA=cpacGq
/XsCYMofR?qr=hofroz
/AaWBfX4K
The parameter carries no apparent function. It does not appear to be a per-recipient token, and the third send omits it entirely. Its likeliest purpose is to give otherwise-identical URLs surface variation. The path segment itself is the more durable artifact, because it is generated by the kit rather than chosen per campaign, and it survives complete domain rotation. Of everything in this estate, the path grammar and the pretext are the two things the operator would have to rebuild rather than re-register.
One lander sat on a random four-character subdomain (rukg.) rather than on the apex. The other two used the apex directly. A per-send subdomain layer on a domain that is itself per-send is redundant, which suggests the kit supports it as an option rather than requiring it.
Pivot One: The Registration Batch
The hypothesis was straightforward. If an operator registers a domain one to two days before each send, they are probably buying in batches, and the rest of the batch is future infrastructure worth pre-emptively flagging.
The batches exist. Around each lander's registration date, the same registrar produced a cohort of similarly-shaped .top domains: six on 2026-03-11, four on 2026-03-16, and fifty-three on 2026-04-29. That looks like exactly the finding we wanted.
None of those cohort members has ever appeared in our data, on any channel, at any time. Not as a scam, not as anything. The cohorts are the registrar's ordinary daily output, and the day gname.com produced six random .top domains it produced 293 domains overall across all TLDs. Our three landers were not a sample of an operator's stockpile. They were three purchases inside a commodity sales channel that moves hundreds of domains a day, and the same-day cohort is a coincidence of timing at a busy shop.
Pivot Two: The Registrant Organization
Two of the three landers had privacy-redacted WHOIS organization fields, which is unremarkable. The third did not. It carried a plain, specific-looking company name, and a non-redacted registrant organization on a burner domain is the kind of operational slip that occasionally cracks an investigation open.
Pulling every domain sharing that string returned 123 registrations spanning May 2025 to August 2026. Exactly one, our lander, is flagged malicious. The other 122 are a menagerie with nothing in common: crypto-brand impersonations, Telegram typosquats, webmail-phishing shapes, a Disney impersonation, adult and gambling sites, and a quantity of apparently ordinary business domains.
The explanation is mundane once seen. Privacy and proxy services, and resellers acting as registrant of record, substitute their own organization name into the WHOIS record on behalf of every customer that passes through them. The field is not the domain holder's identity. It is the name of the intermediary standing between the holder and the public record, and it is shared by everyone who bought through the same discount channel. Pivoting on it clusters a reseller's customer list.
Had we published that string as an operator fingerprint, we would have asserted a relationship between this campaign and 122 unrelated parties, some of whom are running legitimate businesses. This is why we describe the string here rather than print it.
Pivot Three: The Domain Shape
The most tempting pivot, and the one most likely to end up in someone's detection rule, is the shape itself: a short random label on a cheap TLD, freshly registered. It looks like nothing a legitimate business would choose.
Measured against our URL reputation corpus, short random-label .top domains carry a malicious rate of roughly 0.6%. Filtering additionally on registrar and on a registration-to-first-use gap under three days does not rescue it; both filters select for cheap bulk registration, which is the dominant benign use of the TLD, so the surviving population stays overwhelmingly clean.
This is the base-rate problem that Axelsson formalized for intrusion detection, and it is worth being concrete about the arithmetic. At a base rate near 0.6%, an indicator that fires on the shape alone returns on the order of 160 benign domains for every malicious one. The shape can feel highly specific to an analyst reading a single record while having almost no positive predictive value across the population it actually matches. An indicator's plausibility to a human and its precision in production are different quantities, and only one of them is measurable in advance.
What Actually Survived
| Pivot | Hypothesis | What measurement showed | Verdict |
|---|---|---|---|
| Registration cohort | Same-day, same-registrar siblings are future operator infrastructure | No cohort member ever appeared in use, anywhere | Registrar throughput |
| Registrant organization | A non-redacted org string identifies the registrant | Shared by 123 unrelated domains via a reseller channel | Intermediary artifact |
| Domain shape | Short random label on a cheap TLD is inherently suspicious | Roughly 0.6% malicious base rate | Ambient background |
| Lander path grammar | Eight-character path plus junk parameter is kit-generated | Consistent across every send, survives domain rotation | Durable |
| Pretext and channel | Recall-and-refund framing on SMS is narrow and specific | Narrow enough to scope a query usefully | Durable |
The two rows at the bottom are the campaign's actual signature. Both describe what the operator built or wrote, rather than what they bought. That distinction turns out to be the general rule: infrastructure purchased through commodity channels inherits the statistical properties of those channels and tells you about the channel, while infrastructure the operator constructs carries their choices and tells you about them.
Detection Observations
The signals below are behavioral, and they are useful in combination rather than individually.
- The composite that scopes usefully here is narrow: an SMS-delivered message carrying a recall or refund framing against a major retail brand, resolving to a recently-registered short random-label domain on a discount TLD, with an eight-character random lander path. Each element on its own matches far too much.
- The eight-character mixed-case path with an optional random query parameter is the most rotation-resistant artifact in the estate. Domains change every send; the path grammar did not.
- Registration age is a modifier, not a signal. A domain used within days of registration is meaningfully more interesting when something else already flagged it, and meaningless as a first-pass filter given how much legitimate bulk registration behaves identically.
- Screenshot-forwarded messages carry no text body, so content matching cannot reach them. Where a campaign arrives predominantly as forwarded images, the extracted link is the only pivot available, which raises the value of URL-level signals relative to content-level ones.
- Brand tagging on inbound messages is noisier than it looks. Traffic with no plausible connection to a retail brand can end up tagged with one, so a brand tag used as a standalone query predicate will pull in unrelated material. Pair it with a content guard.
Indicators of Compromise
All indicators below are defanged. Recipient data has been removed. This is the verified subset associated with this campaign.
Senders
| Value | Role | Notes |
|---|---|---|
robertcollinsna@outlook[.]co[.]id |
Sender | Throwaway address used for one email-to-SMS delivered send. The indicator is the address, not the mail domain, which is a general-purpose provider and must not be blocked. |
The alphanumeric sender ID used on the first send read as the Amazon brand name. It is a spoofed brand identifier rather than an operator asset, and it is not published as an indicator because acting on it would affect legitimate brand messaging.
Domains
| Value | Role | Notes |
|---|---|---|
82ghi[.]top |
Lander | Registered 2026-03-11, used 2026-03-13, credential harvest |
b1m8v[.]top |
Lander | Registered 2026-03-16, used 2026-03-17, payment link |
ezfez[.]top |
Lander apex | Registered 2026-04-29, used 2026-04-30 |
Hosts
| Value | Role | Notes |
|---|---|---|
rukg.ezfez[.]top |
Lander | Random subdomain on the above apex |
URLs
| Value | Role | Notes |
|---|---|---|
http[:]//82ghi[.]top/vkF4N1Ow?NTAA=cpacGq |
Lander | Recall and refund credential harvest |
http[:]//b1m8v[.]top/XsCYMofR?qr=hofroz |
Lander | Recall and refund payment link |
http[:]//rukg.ezfez[.]top/AaWBfX4K |
Lander | Image-delivered send |
http[:]//shorturl[.]at/E9dufL |
Redirect | Shortlink only. shorturl[.]at is a legitimate public shortener and its apex must never be blocked. The token has since expired and the destination is unrecoverable. |
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE Fight Fraud Framework (F3) v1.1, https://ctid.mitre.org/fraud. F3 is scoped to post-access fraud behavior, so a pre-access lure of this kind maps only partially; unmapped stages are noted rather than forced.
| F3 Tactic | Technique | ID |
|---|---|---|
| Reconnaissance | Gather Customer Information | F1029 |
| Resource Development | Create Fake Materials: Fake Website | F1020.002 |
| Initial Access | Impersonate Official | F1032 |
| Monetization | Harvesting of credentials and card details entered on the lander. No discrete F3 technique applies; the framework's Monetization techniques model movement of funds or account access already obtained. |
Conclusion
The operator here did very little that was clever. They bought cheap domains, wrote a good lure, and threw the domains away. What is instructive is how much apparent structure that behavior generates, and how little of it holds. Registration cohorts, registrant strings and domain shapes all looked like fingerprints and all turned out to be properties of the commodity market the operator shopped in. The parts that identified them were the parts they wrote themselves: the pretext and the path their kit generates. When infrastructure is disposable by design, the durable indicators are upstream of the infrastructure.
References
- FTC consumer alert on scam texts offering Amazon refunds: https://www.consumer.ftc.gov/consumer-alerts/2025/07/scammy-texts-offering-refunds-amazon-purchases
- Amazon guidance on identifying and reporting scam communications: https://www.amazon.com/gp/help/customer/display.html?nodeId=GRGRY7AQ3LMPXVCV
- Trend Micro on fake Amazon product-recall texts: https://news.trendmicro.com/2026/05/05/fake-amazon-product-recall-texts/
- Bitdefender on Amazon recall scams: https://www.bitdefender.com/en-us/blog/hotforsecurity/amazon-recall-scams
- Spamhaus on TLD abuse trends: https://www.spamhaus.com/resource-center/understanding-top-level-domain-tld-abuse-helps-illuminate-and-predict-domain-threat-trends/
- Krebs on Security, "Why Phishers Love New TLDs Like .shop, .top and .xyz": https://krebsonsecurity.com/2024/12/why-phishers-love-new-tlds-like-shop-top-and-xyz/
- Axelsson, "The Base-Rate Fallacy and the Difficulty of Intrusion Detection": https://www.researchgate.net/publication/313151040_The_base-rate_fallacy_and_the_difficulty_of_intrusion_detection
- ICANN on privacy and proxy service providers: https://www.icann.org/en/contracted-parties/accredited-registrars/privacy-and-proxy-service-providers
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.