Aged-Domain Rotation Behind Two Adult-Dating Credit Drains
Aged-Domain Rotation Behind Two Adult-Dating Credit Drains
Two adult-dating operators spent 2026 monetizing fabricated romantic interest across 37 domains, some of them bought and parked as far back as 2017. Neither one phishes. There is no credential form, no brand impersonation, no malware. The entire operation rests on a single lie repeated at volume: somebody liked your profile. One operator bills the victim USD 0.60 to 2.50 for every message they send to a profile that does not exist. The other funnels them into a recurring subscription paywall. We tracked tens of thousands of messages across both clusters between January and late July 2026, and the more interesting half of the story turned out to be the registrar records rather than the mail.
Key Takeaways
- The larger operator runs 31 self-branded dating domains where each apex is simultaneously its own sending domain, its own bounce domain, and its own click-tracking host, with SPF, DKIM and DMARC all aligned.
- Domain age is not a usable signal against this operator. The 31 apexes carry WHOIS creation dates spread across 2017 to 2026, and several were parked for six or seven years before their first message.
- Registration shows a hard temporal boundary: every apex created between 2017 and 2024 sits at one registrar, and every apex created from 2025 onward sits at a different one, with zero overlap. That boundary is a durable operator-continuity marker.
- The second operator is bounded where the first is not. Its six brands are tenants of a white-label adult-dating platform, so the platform caps the brand count and repeated fingerprint sweeps find no siblings.
- Both clusters generate fabricated member names programmatically, and the Spanish-language brand pushes character substitutions into those names (
JUL1A,CIAUDIA,ROMLNA) so that no two subject lines match. - One sender exists only to spoof another brand's support display name while pointing every link at that brand's own site, keeping the monetization domain off the envelope.
Background
Fabricated-engagement dating spam is an old category that gets dismissed as low-grade nuisance mail, and that dismissal is roughly why it works. The messages carry no payload and impersonate no bank. A URL-reputation system sees a dating site. A content classifier sees mildly explicit marketing. Nothing about an individual message looks like fraud, because the fraud is not in the message. It is in what happens after the victim arrives, creates an account, and starts paying to talk to software.
Two monetization models show up in this campaign. Per-message credit billing charges the victim each time they send a chat message, at USD 0.60 to 2.50 a message, against profiles that reply on a schedule rather than out of interest. Subscription paywalling puts the fabricated inbound message behind a recurring upgrade: the victim can see that someone wrote to them, and can pay monthly to read it. Neither model requires the operator to steal anything. The victim hands money over voluntarily, for a service that is real in the sense that the charges are real.
The second cluster's brands sit on a white-label adult-dating platform, a legitimate multi-tenant service that lets an operator launch a branded dating site with the member database, billing, and templated notification mail supplied by the platform. This matters for analysis in two directions. It explains why those brands share templated behavior down to identical subject strings, and it puts a hard ceiling on how many of them can exist, because the tenant is buying a configuration rather than building a stack. The platform itself is a real business with legitimate customers and is not the operator here. The same holds for a shared administration-panel service that appears as an asset host in the second cluster's mail: it is a generic multi-tenant product, referenced by this operation rather than built for it.
Both footer identities in this campaign name corporate entities. We verified one against a national business registry and found a live, active company matching the footer exactly, including street address and registration number. We are not naming either identity in this post. A matching registry entry establishes that the entity exists, not that it authored the traffic, and the gap between those two claims is not one a public post should paper over.
Discovery and Infrastructure
The two clusters separate cleanly on four axes at once: sender local part, click-tracker path, bounce path, and sending stack. That much co-variation is unusual and made the split easy.
| Signal | Cluster A (per-message billing) | Cluster B (subscription paywall) |
|---|---|---|
| Sender local part | mail@<brand> |
noreply@<brand> |
| Click tracker | <brand>/l/link/<uuid> |
www.<brand>/mail/log/click?mailid= |
| Bounce domain | delivery.<brand> |
eu-west-1.amazonses.com |
| Sending stack | Self-hosted, per-brand | Amazon SES, EU West |
| Display name | Brand name in camel case | <apex> Customer service |
| Brand count | 31 | 6 |
| Monetization path | Autologin, then per-message billing | Autologin, then /payment/ upgrade |
| Languages | English, Polish, German, Hungarian | English, Spanish |
Cluster A's giveaway is that everything lives on one registrable domain. The From address, the Return-Path parent, and the CTA host are all the same apex. A brand called usfling[.]com sends as mail@usfling[.]com, bounces to delivery.usfling[.]com, and links to usfling[.]com/l/link/<uuid>. Legitimate dating platforms at any scale do not look like this. They send through an ESP, or they at least split the tracking domain from the primary web property, because deliverability and web hosting are different problems solved by different vendors. Full self-containment across all three roles, repeated identically across 31 brands, is the operator telling you it built one mailer and stamped out brands on top of it.
Cluster B inverts the pattern. It sends through Amazon SES out of EU West, which is a legitimate service used by an enormous number of legitimate senders and carries no signal on its own. The tenant identity leaks instead through the click path and the display-name convention, both inherited from the white-label platform. Every brand uses www.<apex>/mail/log/click?mailid= with al_prof, al_token and autoreg_prof parameters that log the recipient straight into an account, and every brand's display name is the bare apex followed by a support-desk label in the target language.
Cross-linking sealed the second cluster. Two of its brands send mail whose click paths resolve into a third brand's site with an autoreg_prof autologin attached. A tenant does not push its own traffic into a competitor's funnel. Separately, three brands ship byte-identical subject lines, which a shared template explains and coincidence does not.
How It Works
The chain is short because it has to be. Every extra step is a chance for the recipient to reconsider.
A message arrives claiming a named member has written to the recipient, viewed their profile, or matched with them. The name is fabricated and generated per message. The body carries one link and nothing else worth clicking. That link is an autologin: it does not land on a sign-in page, it lands the recipient inside an account that the operator created for them, already authenticated, with the fabricated conversation waiting.
That autologin is the whole trick. It removes the moment where a person would normally stop and ask whether they have an account here. They are already in, the message is already there, and the only remaining friction is payment. In Cluster A the payment gate is per message: composing a reply bills the card. In Cluster B it is a subscription upgrade at a /payment/ path, with the unread message as the hostage.
Cluster A also runs a reactivation lure alongside the engagement bait. Subjects like "We missed your activation on <brand>" and "Please confirm your account" borrow the shape of a legitimate onboarding reminder for an account the recipient never opened.
Sample Lures
All samples below are redacted. Recipient usernames, per-recipient tracking identifiers, and click tokens have been replaced with placeholders. Domains and URLs are defanged. Emoji and misspellings are reproduced as sent, because both are part of the fingerprint.
Cluster A, English, per-message billing. The fabricated persona name changes on every message.
From: "MatureInMyArea" <mail@matureinmyarea[.]com>
Return-Path: <bounce@delivery.matureinmyarea[.]com>
Subject: MuseTwilight just sent you a personal message!
She's interested in your profile :)
[CTA] http[:]//matureinmyarea[.]com/l/link/[uuid]
Cluster A, Polish, same body constants translated. "Jest zainteresowana Twoim profilem" is the direct rendering of the English line above.
From: "GoraceFantazje" <mail@goracefantazje[.]com>
Return-Path: <bounce@delivery.goracefantazje[.]com>
Subject: Psst, Ci uzytkownicy sa Toba zainteresowani! ๐
Zobacz profile, ktore maja Cie na oku.
[CTA] http[:]//goracefantazje[.]com/l/link/[uuid]
Cluster B, English, subscription paywall. This subject line is byte-identical across three separate brand domains.
From: "maturedate[.]xxx Customer service" <noreply@maturedate[.]xxx>
Return-Path: <bounce@eu-west-1[.]amazonses[.]com>
Subject: Somebody liked your profile ๐
Someone liked your profile. Find out who.
[CTA] http[:]//www[.]maturedate[.]xxx/mail/log/click?mailid=[token]&autoreg_prof=[id]
Cluster B, Spanish, sent from a throwaway domain that impersonates another brand's support desk in the display name while linking only to that brand. Note "perfl" for "perfil" in one variant, and the substituted character in the persona name.
From: "buscoamor[.]mx Atencion al cliente" <noreply@event-service[.]info>
Return-Path: <bounce@eu-west-1[.]amazonses[.]com>
Subject: Nuevo mensaje de JUL1A โ๏ธ
Tienes un nuevo mensaje!
[CTA] http[:]//www[.]buscoamor[.]mx/mail/log/click?mailid=[token]
Technical Analysis
Registration Cohorts and the Registrar Boundary
The registration record is the most useful artifact this campaign produced, and it says something that runs against a common assumption. Cluster A's 31 apexes were not bought in a burst before a campaign. They were accumulated over eight years.
| Registrar | Creation years | Apexes |
|---|---|---|
Registrar 1 (1api) |
2017 | 1 |
| Openprovider | 2018 | 1 |
Registrar 1 (1api) |
2019 | 4 |
Registrar 1 (1api) |
2020 | 2 |
Registrar 1 (1api) |
2021 | 3 |
Registrar 1 (1api) |
2022 | 4 |
Registrar 1 (1api) |
2023 | 3 |
Registrar 1 (1api) |
2024 | 6 |
| Registrar 2 (Key-Systems) | 2025 | 6 |
| Registrar 2 (Key-Systems) | 2026 | 1 |
Two things fall out of that table. The first is a clean temporal boundary at the end of 2024. Every apex created from 2017 through 2024 sits at one registrar. Every apex created in 2025 or later sits at a second registrar. There is no overlap in either direction, which is what a deliberate account migration looks like rather than opportunistic shopping. For anyone tracking this operator, that boundary is predictive: the next brand will almost certainly be registered at the second registrar, and it narrows where to watch.
The second is that activation lags registration badly, and often by years:
| Apex | Registered | First message observed |
|---|---|---|
localflirtalert[.]com |
2017-12-22 | 2026-02-24 |
flirtingmatch[.]com |
2018-02-13 | 2026-06-04 |
usfling[.]com |
2019-11-25 | 2026-04-20 |
temptinglocals[.]com |
2019-12-17 | 2026-02-04 |
planetamilosci[.]com |
2021-07-05 | 2026-01-17 |
partnerschat[.]com |
2026-01-21 | 2026-07-20 |
A brand that started sending in June 2026 can present a WHOIS record from February 2018. Any heuristic that treats domain age as evidence of legitimacy will pass this operator's mail, and it will do so most reliably on the brands the operator has held longest. Only one cohort in the whole set looks purpose-registered for immediate use: three apexes created on the same day in July 2025 at the second registrar, which behave like conventional burn stock.
Registrant privacy is uniform across all 31 apexes, either a privacy-proxy organization or a literal "Registrant of <domain>" placeholder. WHOIS organization therefore carries no discriminating value here, and the registrar plus privacy-provider tuple is the only part of the record worth pivoting on.
Naming Grammar of the Brand Stable
The brand names are assembled from a small semantic vocabulary rather than invented individually. Sorting them makes the generator visible: a proximity or availability token (local, nearby, inmyarea, neighbor, hometown, american), an age or demographic token (mature, after50, milf), and an activity token (flirt, fling, crush, match, passion, secret, date, chat). Compositions include localflirtalert, matureflirtsnearby, crushwithaneighbor, americanmatureflirt, flirtingwithmatures and matchafter50.
The demographic token is the part worth dwelling on. A large share of the stable explicitly encodes age targeting, and the localized brands do it too. The Polish mamuskizokolicy composes a familiar term for older women with "from the neighborhood", which is the same proximity-plus-age formula as the English brands. The operator is not incidentally reaching older recipients. It is naming its brands for them.
Localization runs through the same generator into four languages beyond English. goracefantazje and planetamilosci are Polish, kalandosvagyak Hungarian, flirtsmitnachbarn German. In every case the body constants are direct translations of the English strings, not independently written copy, which is another indication of one codebase behind the whole stable.
Fabricated Persona Generation
Both clusters generate member names per message, and the two generators are distinguishable.
Cluster A composes adjective-plus-noun pairs from an evocative English vocabulary, sometimes with a numeric suffix or an underscore separator: MuseTwilight, PhantomGlimmer, SilkenAdmire, BelieveDesires, ArtistryTrendy, Glisten_Luck, AverageWisher, Weirdtingles. The Polish brands run the identical grammar on Polish stems, including inflected verb forms as tokens, which produces names like CzarnaLucja9304 and ZmyslowaEwa53. Same generator, swapped dictionary.
Cluster B uses real given names in uppercase, and the Spanish brand adds a substitution layer on top. Across a single sender we recorded JUL1A and STEFAN1A with a digit standing in for the letter I, CIAUDIA with a capital I for the L in Claudia, ROMLNA with an L for the I in Romina, CLOHE as a transposition of Chloe, and VERoNIC truncated mid-word. The subject-line typo "perfl" for "perfil" sits in the same family of deliberate near-misses.
Substitutions of this kind are cheap and do specific work. They guarantee subject-line uniqueness across a send, which frustrates naive deduplication, and they defeat exact-string matching on a persona list without changing what a human reader perceives. A defender building signatures against these subjects should assume the name token is adversarial and match the invariant frame around it instead.
The Reputation-Laundering Sender
One sender in Cluster B is worth isolating because it inverts the usual relationship between envelope and destination. It sends from its own throwaway domain, correctly authenticated, carrying a display name that impersonates a different brand's Spanish-language support desk, and every link in the body points at that other brand's site rather than its own.
The domain on the envelope is therefore disposable and the domain that takes the money never appears in the From header. Burning the sending domain costs the operator a registration fee. It does not cost the funnel anything, because the funnel was never named. Any control keyed to the relationship between sending domain and destination domain will find them mismatched, but any control that only scores the sending domain will burn effort on an asset the operator has already written off.
Escalation and Continuity
Both clusters authenticate correctly on every domain they own. SPF, DKIM and DMARC align across the whole stable, which means authentication carries no signal in this campaign. Self-hosting is the reason: an operator running its own mail on its own apexes has no reason to fail alignment, and the effort involved is one-time configuration rather than ongoing work.
Continuity across the whole period rests on the body constants. The English strings "She's interested in your profile :)", "Just for you." and "See the profiles who have been eyeing you." appear unchanged from January through late July 2026, across all 31 brands and all four localizations. The operator has rotated registrars, domains, brand names and languages. It has not rewritten its templates.
Detection Observations
The signals below describe what separates this traffic from legitimate dating mail. They are observations about how the operator built the campaign, not an assessment of any detection stack.
Cluster A's strongest structural signal is total self-containment on one registrable domain. When the From domain, the Return-Path parent, and the CTA host all reduce to the same apex, and that apex is a coined consumer-brand name, the sender is running its own mailer on its own property. Legitimate consumer platforms at comparable volume separate these roles across vendors. The delivery.<brand> bounce subdomain paired with a <brand>/l/link/<uuid> click path on the same apex is a tight two-part signature.
Body constants outperform every other content feature here, and by a wide margin. A fixed short string reproduced verbatim across 31 unrelated registrable domains and four languages is not something legitimate senders produce, because legitimate brands write their own copy. The subject line is the wrong place to look: it is deliberately unique per message. The body constant sitting underneath it does not move at all.
Persona-name tokens should be treated as adversarial input rather than matched directly. Character-substituted given names, digit-for-letter swaps, and mid-word truncation all appear inside these tokens. The invariant is the frame around the name, not the name.
Cluster B is recognizable through path grammar rather than domain reputation, because its sending path is a mainstream cloud provider shared with a very large legitimate population. An autologin parameter such as autoreg_prof on a click-tracking path, resolving to a payment or upgrade route, describes a funnel that logs a recipient into an account they never created. A display name consisting of a bare apex followed by a support-desk label is a related convention worth noting, and it is what the laundering sender copies.
For cross-brand clustering, the registrar plus privacy-provider tuple is the highest-value pivot in the registration record. WHOIS organization is uniformly redacted and carries nothing. Creation date is actively misleading, because the inventory spans eight years and is activated out of order.
Indicators of Compromise
All indicators are defanged. Recipient data has been removed.
Sender Addresses
| Value | Role | Notes |
|---|---|---|
mail@matureinmyarea[.]com |
Sender | Cluster A, highest-volume brand, active late July 2026 |
mail@usfling[.]com |
Sender | Cluster A, fastest-growing brand |
mail@localmaturematch[.]com |
Sender | Cluster A, 2025 registrar-2 cohort |
mail@localflirtalert[.]com |
Sender | Cluster A, oldest apex in the stable |
mail@matureflirting[.]com |
Sender | Cluster A |
mail@secretflirtsnearby[.]com |
Sender | Cluster A |
mail@hometownflirt[.]com |
Sender | Cluster A, July 2025 same-day cohort |
mail@planetamilosci[.]com |
Sender | Cluster A, Polish, earliest activity in the corpus |
mail@goracefantazje[.]com |
Sender | Cluster A, Polish |
mail@partnerschat[.]com |
Sender | Cluster A, newest brand, first seen 2026-07-20 |
noreply@tsseeker[.]com |
Sender | Cluster B, cross-link destination for the .xxx pair |
noreply@maturedate[.]xxx |
Sender | Cluster B, shares subject template with two siblings |
noreply@fetishdate[.]xxx |
Sender | Cluster B |
noreply@buscoamor[.]mx |
Sender | Cluster B, Spanish |
noreply@event-service[.]info |
Sender | Cluster B, display-name impersonation of a sibling brand |
Representative subset of 36 verified-malicious sender addresses across both clusters.
Domains
Creation dates are public WHOIS data. Registrar 1 covers the 2017 to 2024 cohort, registrar 2 the 2025 to 2026 cohort.
| Value | Role | Notes |
|---|---|---|
localflirtalert[.]com |
Sender and CTA | Created 2017-12-22, activated 2026-02 |
flirtingmatch[.]com |
Sender and CTA | Created 2018-02-13, activated 2026-06 |
usfling[.]com |
Sender and CTA | Created 2019-11-25, activated 2026-04 |
temptinglocals[.]com |
Sender and CTA | Created 2019-12-17, activated 2026-02 |
matureflirting[.]com |
Sender and CTA | Created 2020-06-28 |
planetamilosci[.]com |
Sender and CTA | Created 2021-07-05, Polish brand |
goracefantazje[.]com |
Sender and CTA | Created 2022-08-02, Polish brand |
pickyourcrush[.]com |
Sender and CTA | Created 2023-06-27 |
crushwithaneighbor[.]com |
Sender and CTA | Created 2024-02-20 |
americanmatureflirt[.]com |
Sender and CTA | Created 2024-08-13 |
matureinmyarea[.]com |
Sender and CTA | Created 2025-07-18, same-day cohort of three |
localmaturematch[.]com |
Sender and CTA | Created 2025-07-18, same-day cohort of three |
mymaturepassion[.]com |
Sender and CTA | Created 2025-11-26 |
partnerschat[.]com |
Sender and CTA | Created 2026-01-21, newest apex |
tsseeker[.]com |
Sender and CTA | Cluster B, created 2025-07-28 |
Representative subset of 37 verified-malicious domains: 31 in Cluster A, 6 in Cluster B.
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE Fight Fraud Framework (F3) v1.1, https://ctid.mitre.org/fraud. F3 is scoped to post-access fraud behavior, so this mapping is an alignment by analogy rather than a literal fit. The monetization stage in particular has no discrete F3 technique, because the victim pays the operator directly for a service rather than having funds moved out from under them.
| F3 Tactic | Technique | ID |
|---|---|---|
| Resource Development | Acquire Infrastructure: Domains | T1583.001 |
| Resource Development | Create Fake Materials: Fake Website | F1020.002 |
| Resource Development | Establish Accounts | T1585 |
| Initial Access | Impersonate Official | F1032 |
| Stealth | Email Spoofing | T1672 |
| Monetization | Direct billing for fabricated engagement; no discrete F3 technique |
T1583.001, T1585 and T1672 are ATT&CK-inherited techniques carried in the F3 v1.1 export. The Impersonate Official mapping covers the support-desk display names rather than any impersonation of a bank or government body, and the Email Spoofing mapping covers display-name spoofing on an otherwise correctly authenticated domain.
Conclusion
The registration record is the part of this campaign worth carrying forward. An operator that buys domains years before it uses them has quietly removed one of the cheapest signals defenders rely on, and it did so without any technical sophistication: it just waited. What it did not change is its copy. The same six-word English sentence has anchored every brand in this stable since January, through two registrars, four languages and 31 domains. When an operator rotates everything it can rent and nothing it has written, the writing is where to look.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.