One Lure, Four Operators: Ad Tracking Strings as Fingerprints
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and only one query-string key distinguished them. From November 2025 to August 2026, we tracked thousands of sponsored ads offering a free desktop client, an anniversary giveaway, or an exchange bonus for a trusted financial brand. Every surface signal pointed to one campaign: the same page names, the same lure copy, the same Thai-heavy targeting, the same registrar, even the same registration days. Every one of those signals was wrong. The operators were separated by a two-letter value in a tracking parameter that has no effect on the ad or landing page and is invisible to the victim.
Key Takeaways
- Four operator families shared a brand, a lure, a page-name template and a registrar. Only the internal ad-tracking token vocabulary inside the click URL separated them. The discriminator is
bid=, a key whose value isCK,KT,IM, or absent entirely. - We tested eight plausible clustering signals against the corpus, and each failed: registrar, WHOIS creation date, URL path length, page name, homoglyph display names, the shared "15th anniversary" ad copy, the
fbid=parameter, and thetrading.hostname convention. Two of the four families register domains on the same days through the same registrar. - No backend correlate exists. Every lander sits behind Cloudflare proxy space with an individually auto-issued per-domain certificate and no multi-domain SAN bundling anywhere in the estate, so shared-address and Certificate Transparency pivots both return nothing.
- One family almost never registers its own infrastructure. It puts brand-token subdomains such as
solana.,binance.andkasikornbank.on aged third-party apexes it does not own. Any reputation verdict must therefore apply to the hostname, never the apex. - Two burnt landing domains now host a live Russian-language credential-harvesting panel whose password field sits in a form with no
actionattribute. We found them only by fetching dead campaign infrastructure because no ad traffic points to them any more. - The operators' campaign-naming habits expose their tooling. A localized "copy" suffix from Facebook Ads Manager survives in the click URL, showing that one family used a Russian-language advertising console and another used an English one.
Background
TradingView is a charting and market-data platform with a paid Premium tier and official desktop clients distributed only from its own site and approved app stores. That combination makes it an unusually effective lure. The product is real, the paid tier is real, and "install the desktop app to unlock Premium" justifies pushing a download without sounding like a scam. TradingView published its own advisory in August 2025 warning about a rising volume of fake Facebook ads offering free annual subscriptions, sometimes bundled with fake exchange giveaways, and identified lookalike domains as the tell.
The pretext has prior public reporting behind it. Bitdefender documented a Meta-ad cluster in August 2025 that used free-Premium TradingView creatives to deliver Android spyware through APK downloads presented as an app update. It then followed up in September, showing the same pretext moving to Google Ads and YouTube with English, Vietnamese and Thai localization. Infoblox had already described the wider mechanism in May 2025: investment-scam actors running Facebook ads whose displayed domain differs from the real redirect target, backed by registered-DGA domain fleets and third-party geolocation lookups used to filter visitors by country. Bitdefender's March 2026 survey of investment-scam networks on Meta describes the mature version of the same playbook, including deliberate Cyrillic homoglyph substitution to defeat keyword filters and rotating low-credibility pages to spread ad spend below enforcement thresholds.
Platform and regulatory pressure has grown alongside it. Meta announced legal action in February 2026 against four scam-advertiser operations, one specifically for cloaking to bypass ad review, and sent cease-and-desist letters to eight former business partners selling account-restoration and enforcement-evasion services. That last category is the supply side of the disposable advertiser accounts described below. Thailand, the geography this ecosystem targets hardest, is an active enforcement front rather than a quiet one.
The question here is not whether this pretext is being abused. It is how to count the operators abusing it. When several operators run identical creatives against identical brands during the same window, an analyst who clusters on what the ad shows will merge them, publish one inflated actor, and build monitoring that breaks as soon as any one of them rotates. Almost every available clustering signal here could be tested individually, and almost all of them failed.
Three pieces of infrastructure recur throughout.
The Facebook link wrapper. Every outbound link clicked from Facebook or Instagram is rewritten to l[.]facebook[.]com/l.php?u=<url-encoded destination>&h=<hash>, a redirector Meta uses to strip referrer data, log the click, and check the destination against its own blocklist before forwarding the browser. As a result, the ad creative, transparency-library entry and click telemetry all show a facebook[.]com URL. The real lander is URL-encoded inside the u= parameter and must be extracted before it can be scored. Everything in this post about tracking grammar appears inside that encoded payload.
Cloudflare free-tier proxying and Universal SSL. On a free plan, a domain's address records resolve to Cloudflare anycast edge addresses, and the origin server never appears in public DNS. Millions of unrelated legitimate sites share those ranges, so the classic "what else is hosted here" pivot returns noise. Cloudflare also issues a free edge certificate per zone, covering only that apex and its wildcard. Certificate Transparency pivoting usually works by finding one certificate whose SAN list names dozens of related attacker domains at once. When every lander has a solitary auto-issued certificate with no co-tenants, a CT record contains only a timestamp and a single name. None of this is a fault in the service. It is free-tier abuse of infrastructure that millions of legitimate sites use for exactly the same reasons.
Ad cloaking. A cloaker is a script in front of the real lander that decides, for each request, whether a visitor is a target or a reviewer. Targets receive the scam funnel. Reviewers receive benign decoy content. Cloakers generally combine source address and ASN, geolocation and Accept-Language, User-Agent and TLS fingerprint, the expected referrer and click parameters, first-visit-only cookies, and an inline JavaScript fingerprint that only a real browser can compute. We did not enumerate which of those this particular cloaker used. Ad platforms approve the decoy because both the crawler and human reviewer receive it. A researcher who fetches the apex directly from a datacenter address, without a Facebook referrer or click parameters, falls squarely into the reviewer bucket and receives a page that looks legitimate.
Discovery and Infrastructure
The investigation began with a page-name sweep for "Desktop App" and "Sponsored by TradingView" variants, which returned more advertiser pages than the query would render. Our working hypothesis was a single active wave distinguished by domains registered through one registrar in November and December 2025. Both parts of that hypothesis were wrong.
We rebuilt the clustering around the internal ad-tracking token vocabulary in the click URL rather than anything visible in the ad. That one change separated populations that page name, lure copy, registrar, WHOIS date and path length had merged. Two of the resulting families belong to campaigns adjudicated separately and are not discussed here. Four remain. We retain their internal cluster letters below, which is why the sequence skips.
| Family | Discriminating grammar | Path shape | Domain-name class | Hosting posture | Advertiser pages | Apexes / hosts | Window | Span |
|---|---|---|---|---|---|---|---|---|
| B | bid=CK plus cid=adv<GEO> |
8-char mixed-case | invented pseudo-word throughout | standalone throwaway apex | 20 | 17 | 2025-12-17 to 2026-07-23 | 218 days |
| C | bid=KT plus <GEO>_<BRAND>_<TIER>_<N>_<N> |
5-char lowercase | none, abuses third-party apexes | brand-token subdomain on an aged third-party apex | 34 | 14 | 2025-11-24 to 2026-07-19 | 237 days |
| E | bid=IM plus cid=add<N> |
8-char mixed-case, newest asset drifted to 6-char lowercase | 16 invented, 7 brand-plus-suffix | standalone throwaway apex | 29 | 22 | 2025-11-24 to 2026-08-21 | 270 days |
| F | no bid= key at all |
5-char lowercase, one fixed path per host | brand-plus-descriptor throughout | standalone throwaway apex | 32 | 3 | 2026-02-10 to 2026-03-18 | 36 days |
Every advertiser account across all four families is a numeric-ID Facebook profile in the profile.php?id= form. A brand-new account has that form before someone claims a username. Operators favor these accounts because they are cheap to mass-register or buy, have no history worth protecting, and can be discarded as soon as an ad account is disabled. A legitimate advertiser does the opposite. It invests in a named page with a claimed vanity URL, verified business assets and continuous ad history because that reputation is the asset.
Two hosting postures operate side by side. Families B, E and F register their own throwaway apexes, so the operator controls the entire domain and a verdict can safely apply at the apex. Family C almost never registers its own, apart from one bare-apex exception noted later. It places brand-token subdomains on aged apexes registered by somebody else months or a year before the first abuse. That delay is the point of the posture. A verdict on one of those apexes would affect whoever actually owns it, so Family C is scored at the hostname and never above it. Three apexes it used remain under an unresolved-ownership hold in our records. We excluded them, and the operator hosts beneath them, from this post entirely.
The brand-token subdomain vocabulary across the estate is small and easy to read.
| Subdomain token | Observed on | Family | Brand invoked |
|---|---|---|---|
tradingview. |
tradingview.lokateldn[.]com |
C | TradingView |
tradingviewbon. |
tradingviewbon.financialsupp[.]com |
C | TradingView, with a bonus suffix |
solana. |
solana.financialsupp[.]com, solana.roundlevel[.]com |
C | Solana |
binance. |
binance.roundlevel[.]com |
C | Binance |
ethereum. |
ethereum.lokateldn[.]com |
C | Ethereum |
wise. |
wise.financialsupp[.]com |
C | Wise |
kasikornbank. |
kasikornbank.cubicseg[.]com |
C | Kasikornbank, a Thai retail bank |
apphub. |
apphub.desktop-app-download[.]com |
C | none, a generic trust token |
desktop. |
desktop.tradingview-proo[.]com |
F | none, a product token |
Seven of the nine name a real financial brand. The final two name nothing; they imitate the shape of a product subdomain to appear organized. The desktop. row differs in another respect: it belongs to Family F, which registers its own apexes, so it copies the shape of Family C's posture without relying on a third party.
There is no backend to correlate. Every live domain in the estate resolves into Cloudflare proxy space and presents its own auto-issued certificate naming only that domain and its wildcard. There is no shared origin address, shared ASN, or bundled SAN list. That negative result gives the tracking grammar its weight. There is nothing else to fall back on.
How It Works
A victim scrolling Facebook sees a sponsored post from a page called something like "Desktop App" or "Trading View," or from a page impersonating a financial news outlet. The creative promises a free desktop client, a free year of Premium for the brand's anniversary, or an exchange bonus paid on install. The button reads "Download."
The click opens the Facebook link wrapper, which forwards the browser to a lander whose real address is encoded inside the wrapper's u= parameter. That lander is cloaked. A visitor who arrives with the right referrer and click parameters, a residential address in the targeted country, and a real browser receives the crypto funnel. Anyone else receives a complete decoy site for a business that does not exist.
The decoys have a consistent character. Every one we recorded is a small professional-services or creative business: a UK business consultancy, a Malay-language game studio, an Australian career-coaching practice. These are all verticals with plausibly thin web presences, no regulatory footprint, and no brand that a reviewer would recognize or think to check.
Direct fetch of hxxps://datalyticuzy[.]com/8GXfDDM1
-> "Prime Bridge Consulting", a UK business-advisory site
-> <base href="//datalyticuzy[.]com/landers/business1/">
Direct fetch of hxxps://exillonkozy[.]com/wYyn7nm8
-> "Nusantara GameDev", a Malay-language game studio
-> <base href="//exillonkozy[.]com/landers/nusantaragamedev/">
The /landers/<slug>/ directory convention is the kit's signature, but its evidentiary scope matters. No slug is reused across apexes. Every apex has its own slug and fabricated business, so the shared feature is the directory schema, not a replicated decoy library. The same schema also appears on infrastructure independently attributed to a separately adjudicated campaign. It identifies a common cloaking codebase that crosses operator boundaries and must never be used to merge operators.
Sample Lures
All samples below are advertiser-side ad creatives. No recipient or victim data is involved.
Fabricated anniversary, Thai, Family C. A celebration TradingView never held, offering a year of Premium for installing a desktop client that the copy attributes to the Microsoft Store.
Page: Desktop App
Text: 🎉 ฉลองครบรอบ 15 ปี TradingView
ดาวน์โหลด TradingView Desktop จาก Microsoft Store
และใช้งานกราฟระดับมืออาชีพได้สะดวกยิ่งขึ้นบน Windows
🎁 ในช่วงโปรโมชัน ผู้ใช้ที่มีสิทธิ์สามารถตรวจสอบสิทธิ์รับ Premium ฟรี 1 ปี หลังติดตั้งแอป
✅ กราฟขั้นสูง ✅ ข้อมูลตลาดแบบเรียลไทม์ ✅ ใช้งานบน Windows ได้สะดวก
("Celebrating TradingView's 15th anniversary. Download TradingView
Desktop from the Microsoft Store... eligible users can claim 1 year
of Premium free after installing the app.")
CTA: hxxps://apphub.desktop-app-download[.]com/fgh0e?utm_campaign=MIX_TV_BINT_111_1
&utm_content=tv1&bid=KT&utm_medium=paid&utm_source=fb
Exchange bonus, Spanish, Family C. A 200 USDT payout promised on install.
Page: LBank World
Text: ⚽ La oferta especial de LBank ya está disponible
Descarga la aplicación de escritorio de LBank para Windows y accede a
una experiencia más rápida y cómoda desde tu PC.
🎁 Los usuarios elegibles pueden recibir un bono de 200 USDT después de
descargar y activar la app de escritorio.
Exchange bonus, English, Family C. Note the page name. This family fronts its ads with invented three-given-name human personas rather than product names.
Page: [three-given-name persona]
Text: Download the Binance Desktop App for Windows and unlock your 0.25 BNB
reward instantly. ⚡ Install in just 60 seconds and start right away.
Limited-time offer for desktop users only - claim your bonus now! 🚀
Off-vertical money-transfer lure, Arabic, Family B. The same operator scaffolding with a different brand and market. The page name replaces Latin characters with Cyrillic ones.
Page: Wіsе Арр (Cyrillic і and е in "Wise", Cyrillic А and р in "App")
Text: 💰 مكافأة ترحيب 200 دولار للمستخدمين الجدد والحاليين
🖥 قم بإعداد Wise على جهازك
🎁 المكافأة متاحة بعد التثبيت
🌍 خدمة مالية عالمية • موثوقة حول العالم
("A $200 welcome bonus for new and existing users. Set up Wise on your
device. The bonus is available after installation.")
CTA: hxxps://gameonpixel[.]com/WGbnPNTZ?utm_campaign=WS_570_camp1_abo
&utm_content=wsgcc2&cid=gcc2&bid=CK&utm_medium=paid&utm_source=fb
Media-outlet impersonation, Chinese, Family F. This family does not pretend to be the brand. It pretends to be the financial press reporting on the brand.
Page: 日经中文网 (impersonating a Japanese financial-news outlet's Chinese edition)
Text: 🎉 TradingView 正在慶祝 15 週年!
TradingView 將贈送你 完整 1 年的 Premium 訂閱!
⚡ 別錯過 — 立刻領取這份特別禮物!
("TradingView is celebrating its 15th anniversary. TradingView will give
you a full 1 year Premium subscription. Don't miss out.")
Invented investment firm, English, Family B. The copy describes a UK investment-management business called BeaconLine Capital Group. We found no UK Companies House registration under that name, and the persona appears only in this operator's creatives. Several unrelated real firms use similar "Beacon Capital" names; none of them is this.
Page: TV Рremіum (Cyrillic Р, і and е)
Text: BeaconLine Capital Group is a UK-based investment firm dedicated to
helping individuals and businesses grow and protect their wealth
through disciplined, data-driven strategies. We combine
institutional-level research, meticulous risk management, and
personalised advisory services to deliver long-te...
Technical Analysis
The Two-Letter Key
Once decoded from the Facebook wrapper, every click URL in the estate has the same skeleton.
hxxps://<host>/<path>?utm_campaign=<...>&utm_content=<...>&cid=<...>
[&bid=<XX>]&fbid=<N>&utm_medium=paid&utm_source=fb&utm_id=<N>&utm_term=<N>
utm_medium=paid and utm_source=fb are constant across all four families and every observed row, so they carry no distinguishing value. utm_id and utm_term are platform-issued identifiers that change per ad. The useful keys are those typed by a person.
utm_source and utm_campaign are Urchin tracking parameters, an analytics convention appended by the advertiser rather than required by Meta. cid and bid are not platform standards. In affiliate and performance-marketing stacks, they are shorthand for a campaign identifier and a banner or buyer identifier. They are passed to a traffic-broker backend so that a conversion can be credited to the correct creative and traffic source. Their presence implies an affiliate or tracker layer between the ad and destination.
A person authored these values, and the convention is copied forward when creatives, domains and ad accounts rotate. It therefore persists across infrastructure with no shared address, certificate or registration data. In this estate, one key does all the work.
| Family | Canonical decoded click URL |
|---|---|
| B | hxxps://drintrag[.]com/R1YQHKgq?utm_campaign=TV_894_camp2_abo&utm_content=cat_tv3_set3&cid=advTH&fbid=<rotates>&bid=CK&... |
| C | hxxps://solana.financialsupp[.]com/47rkt?utm_campaign=MIX_TV_BINT_111_1&utm_content=tv1&bid=KT&fbid=<rotates>&cid=<rotating 15-digit>&... |
| E | hxxps://sol-macos[.]com/ccrqma?utm_campaign=TH||<ad-account-id>||dime_02_mac||ABO1&utm_content=dime_02_mac&cid=add2&fbid=<rotates>&bid=IM&... |
| F | hxxps://desktop.tradingview-proo[.]com/9txnu?utm_campaign=IG + | + 2.03 + a + 144 + | + CBO + [50$] + 1-5-1 + | + (TH) + #243 + | + NYO + TH + 1&utm_content=1&cid=(TH) + #243 + _ + ADS + 1&fbid=<rotates>&... |
Each family's campaign token has a distinct construction. Family B uses <BRAND>_<NNN>_camp<N>_<abo|cbo>, with brand slots for TradingView, two exchanges, Ethereum, a money-transfer service and one further vertical. Family C uses a structured <GEO>_<BRAND>_<TIER>_<N>_<N>, with geo slots for Thailand, Japan, Malaysia, Latin America and several mixed-market codes, and brand slots across seven financial brands. Family E uses double pipes as delimiters and embeds its own ad-account identifier. Family F uses no template. It pastes a hand-typed Ads Manager campaign name directly into the URL, including spaces, a currency amount in square brackets, a DD.MM date, a creative serial, and free text ranging from coindesk and forum to goblin and Thai script.
Without the campaign tokens, the pattern is simpler.
| Key | Family-constant | Family-unique | Usable as an identifier |
|---|---|---|---|
bid= |
yes, on every host in every family | yes: CK, KT, IM, or absent |
yes, and it is the only one |
cid= |
shape yes, value no | shape yes | as a shape regex only |
fbid= |
no, rotates in all four families | no | no |
utm_campaign= |
shape yes, value no | shape mostly | as a shape regex only |
utm_content= |
no | no | no |
utm_medium=, utm_source= |
yes | no, identical in all four | no |
Family F requires special attention because an absence, rather than a value, defines it. None of its 78 rows contains a bid= key, while every row contains cid= and fbid=. The family is not missing tracking. It is missing that single key, a negative signature that a positive-match monitoring query will never surface.
cid= almost works. Its shape is diagnostic in three of the four families, but Family C's cid is a rotating 15-digit number with no semantic content across dozens of distinct values. It resembles a stable identifier but is useless as one.
Eight Pivots That Failed
The bid= finding matters because we tested the signals a defender would try first, and none survived.
| Signal | Why it looks diagnostic | What falsified it |
|---|---|---|
| Registrar | Family B is entirely one registrar, Family E almost entirely | Both families share it. A same-day sweep of that registrar returns roughly a hundred unrelated domains |
| WHOIS creation date | Tight same-day bursts read like operator batches | Families B and E land on the identical calendar day three times, with 8 domains on one date, 6 on another and 4 on a third, all through the same registrar |
| URL path length | 5-character and 8-character paths read like two build systems | The two 5-character families are unrelated to each other. Within Family C, one apex uses 8-character paths while every other host uses 5 |
| Page name | "Desktop App," "Trading View" and "Ultimate Plan" recur across families | Only one exact string crosses a family boundary. What recurs is a template, and each family's private naming class does not cross at all |
| Homoglyph display names | Cyrillic and Greek substitutions in names like "TV Lіfеtіme" look like a signature | Across the same window's advertiser-page corpus, roughly 92% of Facebook pages carrying adjacent Latin and Cyrillic or Greek names are ordinary multi-script branding by legitimate Balkan, Greek and Ukrainian small businesses. Under 1% carried this campaign's grammar |
| The "15th anniversary" copy | A fabricated anniversary is oddly specific | The same copy appears under three mutually distinct tracking grammars and across two separately adjudicated campaigns. It is recycled ad copy circulating between unrelated operators |
fbid= |
It reads like a pixel identifier, and it held constant in a small sample | It rotates in all four families. A constant identifier in a small sample may simply be rotation you cannot see yet |
The trading. hostname convention |
Brand-adjacent and TradingView-proximate | Of every distinct trading. host in the corpus, not one carries any of this campaign's three bid= values |
Two of those rows have implications beyond this campaign.
The trading. row illustrates a general trap. An operator chooses a brand-token subdomain prefix because it looks plausible to the victim. Every operator impersonating that brand therefore converges independently on the same prefix. The prefix groups impersonators of one brand but says nothing about who built what. Fourteen hostnames were attributed to this campaign on that basis and had to be reassigned. They are all genuinely malicious; the error concerned attribution, not maliciousness.
The homoglyph row is more likely to cause harm if mishandled. Mixed-script page names are a real evasion technique here, and the codepoints are consistent: Cyrillic і, е, Р, А, О, С, У, Н, Т and Greek Ι, Ο, Μ, Α, Β substituted into otherwise-Latin strings. But real businesses that legitimately brand in two scripts dominate a sweep for mixed-script names without a grammar gate. This is a confirmatory detail after a candidate is already inside the grammar, never a discovery method on its own.
Domain Generation
The estate contains two visibly different naming classes.
The first consists of invented, pronounceable pseudo-words: drintrag, zigasist, volyzen, kostrelio, ulnyra, quelynx, melaqaro, lorqeta, morlinqo, ronavix, rigeraty, zavryton, flenirox, tallvoro, dynoreta, exillonkozy and about twenty more. Across 35 such apexes, the set has structure that neither a random generator nor a wordlist produces.
| Property | Measured | Natural-language baseline |
|---|---|---|
| Length | 6 to 15 characters, median 8 | — |
| Syllable count | 83% land at 3 or 4 syllables | — |
| Vowel share of letters | 36.8% | roughly 38% |
| Share of the letters z, q, x, j, v, k | 13.0% | roughly 1.6% |
| Vowel-final endings in -o, -a or -y | 43% | roughly 15 to 20% |
| Names containing a digit or hyphen | none | — |
Every string is phonotactically legal English. The onsets and codas are ordinary, and strict alternating consonant-vowel skeletons recur throughout. That rules out random character generation. None of the strings is a real word, and no dictionary supplies the invented tails, which rules out a plain wordlist.
Two properties suggest a model rather than a script. First, the eightfold over-weighting of exotic letters is an aesthetic choice that amounts to "make it look distinctive." A chain trained on real names would reproduce the corpus frequency rather than invert it. Second, a subclass of these names produces clean, correctly ordered English compounds with an invented tail attached, all within a tech-startup semantic field: zenbytejump, deskpointstudio, gameonpixel, taskloomuqiz, knowvancebezr, datalyticuzy, texilonjys. A character-level chain fragments compounds like these. A token-level model, or a two-stage template that pairs a real morpheme with a generated suffix, does not.
The second class combines a brand with a descriptive suffix from a small vocabulary: -15th, -deal, -discount, -bonus, -offer, -reward, -center, -portal, -app, -download, -macos, plus deliberate misspellings such as a doubled vowel or a dropped letter in a common word.
The split among families is itself a fingerprint. Family B never includes a brand token in a domain it registers; the brand appears only in the page name and creative. Family F does the opposite, putting a brand token in every domain it owns. Family E alone mixes both classes in its registrations.
Path shape also follows family lines. Families B and E use 8-character mixed-case alphanumeric paths, although E's newest apex changed to a 6-character lowercase path in August 2026. Families C and F use 5-character lowercase paths. Family F assigns exactly one fixed path to each host and never varies it. Path length conceals a smaller pivot: the path value is a per-lander build artifact that carries over when the apex rotates. Four path tokens each appear on two different apexes within the same family, linking domains that share nothing else.
Registration Cohorts
Every registration in the estate has a one-year term, and every row either names a registrar privacy service as the registrant organization or leaves it absent.
| Registrar | Family B | Apexes used by Family C | Family E | Family F |
|---|---|---|---|---|
| Spaceship | 17 of 17 | none | 21 of 22 | none |
| Namecheap | none | 5 of 6 | none | none |
| Global Domain Group | none | 1 of 6 | none | 2 of 2 |
| Dynadot | none | none | 1 of 22, plus a late-window burst | none |
Registrars appear here as public WHOIS facts. Concentration on any one of them reflects that registrar's price and popularity, not any involvement on its part.
The registration bursts look persuasive until the families within them are checked.
| Date | Domains registered | Registrar | Families in the burst |
|---|---|---|---|
| 2025-11-15 | 8 | Spaceship | B and E together |
| 2025-11-19 | 3 | Spaceship | E |
| 2025-12-05 | 6 | Spaceship | B and E together |
| 2025-12-11 | 4 | Spaceship | E and B together |
| 2026-02-20 | 3 | Spaceship | B |
| 2026-08-14 to 08-21 | 4 | Dynadot | late-window burst across B and E, brand-plus-suffix names |
Two separate operators registered domains on the same day through the same registrar three times. Same-day plus same-registrar reflects registrar popularity. This directly disproves a clustering method that analysts use constantly. The apexes abused by Family C occupy a different band, having been registered between January and November 2025, months to a year before the first abuse. That timing is required by the posture.
One registrar signal does carry information, but it separates rather than groups. Both Family F apexes use a registrar lane otherwise associated with campaigns adjudicated elsewhere. This separates F from the other three. It does not group B with E.
Locale Artifacts in the Tracking String
Facebook Ads Manager appends a localized "copy" suffix when an operator duplicates a campaign. Because these families paste campaign names into the click URL, the suffix remains in the destination.
| Artifact | B | C | E | F |
|---|---|---|---|---|
| Russian "— Копия" duplicate suffix | none | none | none | about a quarter of distinct URLs |
| English "– Copy" duplicate suffix | none | present | none | none |
| Cyrillic С substituted into the CBO budget token | none | none | present | present |
| Budget-mode token present at all | always | never | usually | usually |
Family F's operator uses a Russian-language advertising console. Family C's uses an English one. Family C never labels budget mode, a small workflow habit that remains perfectly consistent throughout its run.
The Cyrillic-C row is a caution, not a finding. It was originally proposed as Family F's discriminator, but it fails. The same token appears interchangeably in plain ASCII, with a Cyrillic C, and with a Cyrillic A. It is also not confined to F, appearing in Family E as well. The habit is real. It has no discriminating power.
Escalation and End State
Each family keeps its tracking grammar fixed while rotating the impersonated brand beneath it. Family C is the most aggressive, running TradingView, Solana, Binance, Ethereum, Wise, LBank and a Thai retail bank concurrently rather than sequentially, all on the same bid=KT scaffolding. Family E runs TradingView alongside a money-transfer and exchange-bonus sub-line. Family F ran only TradingView, through financial-media personas, during the shortest and most concentrated window in the estate.
Family B fits that model least well, and the exception is informative. Its scaffolding remains intact, including bid=CK, but one sub-line drops the cid=adv<GEO> convention entirely and changes its campaign prefix to a money-transfer vertical.
| Apex | Path | Campaign token | cid |
Fronting page | Observed |
|---|---|---|---|---|---|
gameonpixel[.]com |
/WGbnPNTZ |
WS_570_camp1_abo |
gcc2 |
"Wіsе Арр" | 2026-01-09 |
texilonjys[.]com |
/v7Nd6DLq |
WS_834_camp4_cbo |
wsmix1int5wm |
"Wіsе Glоbаl" | 2026-03-14 |
taskloomuqiz[.]com |
/cTJN7J17 |
CL_050_camp1_cbo |
testmix2 |
— | 2026-04-30 |
Both money-transfer apexes were unattributed before this analysis for a mechanical reason. Any monitoring query built around cid=adv is structurally blind to this sub-line, so it ran for months inside a family we were already watching. A grammar derived from the most common family variant will miss that family's own extensions.
The end state completes the picture. Every original lure lander now returns 522, 502 or 404. Four aged apexes abused by Family C have expired out of the registry entirely. Two Family E domains, zavryton[.]com and morlinqo[.]com, were registered on the same day through the same registrar. They are the only live assets left, and neither still runs the TradingView cloak. Both serve a Russian-language credential-harvesting login page titled "Панель клиента," or Client Panel. Apart from a Cloudflare analytics token, their HTML is byte-identical.
The login form warrants close examination. Its password field is inside a form with no action attribute and is paired with a client-side fake error message. A normal login form names the endpoint that receives the submission. Static scanners and kit classifiers use that endpoint to identify the exfiltration destination. When it is omitted, a JavaScript handler intercepts the submission, reads the field values and sends them itself, often to a path assembled at runtime or to a third-party messaging API. The destination never appears in the markup. A page whose only login form has no submit destination cannot accidentally be a functioning legitimate login.
Both domains retain their original registration records, so the same registrant is recycling burnt infrastructure rather than using a drop-catch or resale. Neither serves the /landers/<slug>/ cloaker signature, which means the tooling changed with the target: a Russian-language panel following a campaign that spent nine months targeting Thai, Spanish, Arabic, Chinese and English speakers. We found them only by fetching dead campaign infrastructure directly. No ad traffic points to them any more, so research that begins at the advertising surface will not find them.
Detection Observations
The signals below separate this ecosystem's traffic from legitimate advertising. They describe the adversary rather than any particular control.
- The destination is not the visible link. Anyone scoring the URL shown in an ad or transparency listing is scoring a Meta hostname. The lander must be extracted from the wrapper's
u=parameter before it can be evaluated. A decision made before that extraction is based on no information about the lander. - Score the hostname, not the apex, wherever the posture is a brand-token subdomain. Family C's entire estate sits on apexes it does not own, several of them ordinary aged registrations belonging to third parties. An apex-level verdict would affect whoever actually holds the domain. The subdomain label is the operator's contribution; the apex is not.
- A direct fetch of a cloaked lander is not a verification. Fetching the apex with no Facebook referrer or click parameters and from a datacenter address puts the fetcher in the reviewer bucket by design, returning a complete decoy business. Confirming a cloaked lander requires replaying the click path: the wrapper referrer, the campaign query string, a residential in-geo egress and a real browser.
- Hand-authored tracking parameters cluster where infrastructure cannot. These values persist through domain, creative and ad-account rotation because a person copies them forward. The caveat works both ways: a shared affiliate network or purchased tracker template can produce the same convention across genuinely unrelated operators. This is a clustering signal, not an attribution.
- Absence is also a signature. Family F is defined by a missing key, and a positive-match query never returns a missing key. Grammar rules written only as inclusion tests are blind to an operator that omits a field.
- A brand-named subdomain is chosen for the victim, not by the operator's build. Every operator impersonating the same brand converges on the same brand-token prefix. It can identify campaign traffic but cannot attribute it.
- Mixed-script display names need a second gate. The evasion is real and uses a narrow codepoint set, but the overwhelming majority of mixed-script advertiser names on the platform belong to legitimate businesses in regions where two scripts are normal. Intersect the name with a grammar or infrastructure signal before acting on it.
- Reuse of a path token across a rotation deserves attention. The random-looking path is a per-lander build artifact and survives domain rotation often enough to link a burnt apex to its replacement.
- A dead lure domain is not a closed case. We found the only live infrastructure in this estate by re-fetching domains after their advertising had stopped. Registration, DNS and certificates are already paid for and warm, so re-skinning a burnt apex into a panel costs less than starting over.
Indicators of Compromise
All indicators are defanged. This is a representative subset drawn from the verified-malicious tier of our indicator store, not a complete inventory.
Advertiser Profiles
Facebook numeric profile identifiers, all of the disposable profile.php?id= form.
| Value | Role | Notes |
|---|---|---|
100086410963593 |
Advertiser | Family B |
61577818468888 |
Advertiser | Family B, cycles across four lander apexes |
100086676272921 |
Advertiser | Family B, Cyrillic-homoglyph display name |
100089438567490 |
Advertiser | Family B, exchange-token lure |
100092678563347 |
Advertiser | Family B off-vertical, money-transfer lure |
100090666776005 |
Advertiser | Family B off-vertical, money-transfer lure |
61565362006682 |
Advertiser | Family C |
61584063100130 |
Advertiser | Family C |
61586649354864 |
Advertiser | Family C |
100089668579790 |
Advertiser | Family C, money-transfer lure |
100093843301514 |
Advertiser | Family E |
100086288091769 |
Advertiser | Family E |
61550256836721 |
Advertiser | Family E |
100089589390343 |
Advertiser | Family E, earliest observed activity |
100090010341351 |
Advertiser | Family E, exchange lure |
| ... | (representative subset; 100+ verified-malicious advertiser profiles) |
Domains
| Value | Role | Notes |
|---|---|---|
drintrag[.]com |
Lander | Family B, highest-volume apex |
zencodaenar[.]com |
Lander | Family B |
myredink[.]com |
Lander | Family B, latest observed B activity |
mystarvo[.]com |
Lander | Family B, earliest observed B activity |
gameonpixel[.]com |
Lander | Family B off-vertical, money-transfer lure |
texilonjys[.]com |
Lander | Family B off-vertical, money-transfer lure |
mostpdf[.]com |
Lander | Family C, the only C lander used bare with no subdomain |
datalyticuzy[.]com |
Lander | Family E, highest-volume apex, "Prime Bridge Consulting" decoy |
tradingview-15th[.]com |
Lander | Family E, fabricated anniversary pretext |
dynoreta[.]com |
Lander | Family E, earliest observed E activity |
wise-bonus[.]com |
Lander | Family E, money-transfer lure |
zavryton[.]com |
Lander | Family E, now serving a credential-harvest panel |
morlinqo[.]com |
Lander | Family E, now serving a credential-harvest panel |
tradingview-proo[.]com |
Lander | Family F |
tradingview-datapulse-download[.]site |
Lander | Family F |
| ... | (representative subset; 50+ verified-malicious lander domains) |
Hosts
Operator-controlled subdomains. Where the apex belongs to a third party, only the hostname is an indicator.
| Value | Role | Notes |
|---|---|---|
tradingview.lokateldn[.]com |
Lander | Family C; only the hostname is an indicator, the apex is not |
ethereum.lokateldn[.]com |
Lander | Family C; only the hostname is an indicator, the apex is not |
solana.roundlevel[.]com |
Lander | Family C; only the hostname is an indicator, the apex is not |
binance.roundlevel[.]com |
Lander | Family C; only the hostname is an indicator, the apex is not |
solana.financialsupp[.]com |
Lander | Family C, earliest observed C activity; hostname only |
tradingviewbon.financialsupp[.]com |
Lander | Family C; only the hostname is an indicator, the apex is not |
wise.financialsupp[.]com |
Lander | Family C; only the hostname is an indicator, the apex is not |
kasikornbank.cubicseg[.]com |
Lander | Family C, Thai bank impersonation; hostname only |
apphub.desktop-app-download[.]com |
Lander | Family C; hostname only |
desktop.tradingview-proo[.]com |
Lander | Family F |
URLs
| Value | Role | Notes |
|---|---|---|
hxxps://drintrag[.]com/R1YQHKgq |
Lander | Family B, 8-character mixed-case path |
hxxps://apphub.desktop-app-download[.]com/fgh0e |
Lander | Family C, 5-character lowercase path |
hxxps://datalyticuzy[.]com/8GXfDDM1 |
Lander | Family E, "Prime Bridge Consulting" decoy |
hxxps://exillonkozy[.]com/wYyn7nm8 |
Lander | Family E, "Nusantara GameDev" decoy |
hxxps://desktop.tradingview-proo[.]com/9txnu |
Lander | Family F, one fixed path per host |
Grammar Signatures
| Pattern | Family |
|---|---|
bid=CK with cid=adv<GEO> |
B |
bid=KT with a <GEO>_<BRAND>_<TIER>_<N>_<N> campaign token |
C |
bid=IM with cid=add<N> and a double-pipe campaign token |
E |
no bid= key, free-typed campaign token with a DD.MM date and a (GEO) slot |
F |
<base href="//<apex>/landers/<slug>/"> |
commodity cloaking kit, crosses operators |
MITRE Fight Fraud Framework Mapping
Mapping aligns to the MITRE Fight Fraud Framework (F3) v1.1, https://ctid.mitre.org/fraud. F3 is scoped to post-access fraud behavior, so this mapping is an alignment by analogy rather than a literal fit. A pre-access advertising lure maps only partially, and stages without a fit remain unmapped.
| F3 Tactic | Technique | ID |
|---|---|---|
| Resource Development | Create Fake Materials: Fake Website | F1020.002 |
| Resource Development | Establish Accounts | T1585 |
| Reconnaissance | Gather Customer Information | F1029 |
| Initial Access | Impersonate Official | F1032 |
| Initial Access | Phishing | T1660 |
| Stealth | Cloaked landing pages serving decoy content to inspection; no discrete F3 technique | |
| Monetization | Crypto-investment funnel entered after install; terminal step not observed, no discrete F3 technique claimed |
The Stealth and Monetization rows are deliberately unmapped. F3 focuses on financial-account fraud, and neither ad cloaking nor the downstream investment funnel has a v1.1 technique that fits without stretching it.
Conclusion
The distinguishing feature in this ecosystem was a two-letter value in a parameter that nobody looks at. It is invisible to the victim and irrelevant to ad delivery. Everything visible was shared, borrowed or recycled. Treating any of it as a fingerprint would have produced one inflated actor and monitoring that failed on the first rotation. Operator tooling artifacts persist because a person types them and copies them forward without thinking. That is also their limit: a shared tracker template can reproduce the same convention. The estate is burnt now, but two of its domains already host something else. Burnt advertising infrastructure retains its registration, DNS and certificate, which are the expensive parts.
Related research
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
Rented Storefronts: A Fake-Store Franchise on Facebook Ads
Across 2026 we mapped 100+ fraudulent storefronts fronted by disposable Facebook advertisers, increasingly hosted as tenants on legitimate builder platforms.
Eleven Buying Teams, One Shared Crypto Lander Pool
Between November 2025 and August 2026, eleven media-buying teams ran crypto brand-impersonation ads out of one shared pool of burner domains.