Eleven Buying Teams, One Shared Crypto Lander Pool
Eleven Buying Teams, One Shared Crypto Lander Pool
Between November 2025 and August 2026, eleven media-buying teams ran crypto brand-impersonation ads using a shared pool of burner domains. The ads promised free TradingView Premium, a Binance desktop bonus, a 50 KUB gift from Bitkub, or hourly Solana mining on a home PC. Most activity was in Thailand, with secondary arms across Latin America, the Arabic-speaking markets, Bulgaria, Serbia, Malaysia and Kazakhstan. The lure is well documented. The operators behind it were not. Three separate attempts to attribute this infrastructure by domain produced three different conclusions because the domain is the wrong unit of analysis. The operators supplied the right one through a query-string parameter used for their own bookkeeping.
Key Takeaways
- The first token in each ad's
utm_campaignparameter identifies a media-buying team, and eleven of these teams use one shared pool of burner apex domains. One apex is used by eight of the eleven. - Attribution by apex fails for this population. A domain used by eight independent buyers cannot be attributed to one operator, explaining why apex-level clustering produced conflicting answers across three prior analyses.
- Serial or counter reuse across domain boundaries does not, by itself, establish control by a single operator. A shared traffic platform produces the same artifact, as this pool demonstrates.
- The registrable domain never contains the impersonated brand. Brand tokens appear in the subdomain label, beyond the scope of matching logic limited to the registrable domain. Nineteen apexes carry a
bitkublabel, and fourteen carrytradingview. - Two same-day bulk registrations at one Vietnamese registrar account for 21 of the pool's apexes. The same batch combines invented finance pseudo-brands with generic device names.
- Ad copy in one arm places a zero-width space between every letter. The text renders identically, but exact-string matching breaks.
- An invented real-estate creative appears across seven independently-registered apexes and three registrars over eight months. It gives us a stronger cross-apex link than the kit path or the shared tracking pixel we tested against it.
Background
Fake desktop-application ads for cryptocurrency platforms are among the best-documented malvertising patterns of the last two years. Bitdefender mapped Facebook ads impersonating Binance, TradingView, ByBit, MetaMask and others in May 2025, then followed the TradingView Premium lure through Android and macOS arms before publishing an APAC survey in June 2026. That survey covered Thailand and Malaysia, listed Binance, TradingView and Wise among the impersonated brands, and named desktop app downloads among the lures. Check Point's JSCEAL research counted roughly 35,000 Facebook ads in the first half of 2025 for a single fake-trading-app operation. TradingView also published its own warning, explicitly naming Facebook.
This post does not revisit those findings. For this pool, the unresolved question was organizational. The same apexes repeatedly appeared in separate analyses that assigned them incompatible owners, and the usual clustering features could not resolve the conflict.
Three characteristics of Meta ad traffic make attribution especially difficult. Meta rewrites every outbound link into a shim on l.facebook[.]com. Since roughly May 2026, the encoded target has been opaque to everyone outside the viewer's own session, so outside observers often cannot recover an ad's true destination. Advertiser pages are disposable: every page in this population is a numeric-ID page without a vanity slug, and the same generic username appears across many distinct IDs. Landing infrastructure is cheap as well, so registrar, WHOIS date, page name and lure copy all change faster than analysts can cluster them.
What remains is evidence from parameters written by the buyers themselves.
Discovery and Infrastructure
UTM parameters are query-string tags appended to a destination URL solely for the advertiser's analytics. The receiving server does not require them, no platform validates their contents, and Meta can populate them automatically from the ad's object names through dynamic parameters entered once in the ad-level URL field. They are diagnostic bookkeeping. They record the operator's internal structure instead of presenting a defender-facing surface, and nobody thought to randomize them.
Every ad in this pool carries a tracking string with this structure:
utm_campaign=<TEAM>+<NNNN>+<GEO>+<BRAND>+<offer>+<DD.MM>+<serial>
Sibling landers carry a parallel cid=<geo>+<brand>+<DD.MM>+<serial>, which omits the team token but retains the geo, brand and date fields in the same order. That second grammar matters for two reasons. It outlived the team-token form on this pool and still appeared in August 2026, after the last plus-delimited team string. Its field order also separates this population from a neighbouring pool whose cid= values encode age-range targeting instead. Two apexes can look identical in WHOIS and kit shape while having entirely different cid= grammars.
The first token in the utm_campaign form is a team label. Eleven appear, with activity windows that overlap heavily on the same domains. Tens of thousands of ad observations sit behind them, distributed across 298 disposable advertiser pages.
| Team token | Apexes used | Advertiser pages | Active window |
|---|---|---|---|
mirak* (spelled miraki, meraki, merake, mirake) |
17 | 67 | 2025-11-27 to 2026-02-02 |
fast |
17 | 49 | 2025-12-02 to 2026-07-19 |
shd |
19 | 36 | 2025-11-22 to 2025-12-19 |
traff |
16 | 48 | 2025-11-19 to 2026-01-27 |
dragon |
6 | 46 | 2025-12-15 to 2026-02-02 |
moon |
6 | 17 | 2026-02-13 to 2026-03-06 |
mircado |
4 | 6 | 2025-11-22 to 2025-11-25 |
agc |
3 | 10 | 2026-01-09 to 2026-02-02 |
seven |
3 | 5 | 2025-12-16 to 2025-12-20 |
t2t |
2 | 5 | 2026-02-20 to 2026-04-09 |
t121 |
2 | 3 | 2025-12-05 to 2026-01-07 |
The four mirak* spellings belong to one team. Manual entry in the Ads Manager campaign-name field explains the spelling drift. Counting the variants separately would imply four buyers where only one exists.
The first column contains the central finding. These teams do not operate separate estates. They draw from a shared pool of 48 burner apexes, and investlearner[.]com alone is used by eight of the eleven. An apex shared by eight independent buyers is not the property of one operator, regardless of what WHOIS research suggests.
The earlier errors resulted from aggregation in the opposite direction. Grouping by team produces eleven plausible operators, each with a domain list resembling a self-contained actor. Grouping by apex and collecting the attached team tokens exposes the sharing in a single pass.
Eleven is a floor rather than a census. The extraction pattern that surfaced these tokens caps the length of the first token, and that cap alone excluded at least one further team. The pattern does not cover a second, underscore-delimited dialect of the same scheme. That dialect carries mostly ordinary corporate marketing tokens, so a match in the underscore form is worth enumerating and worth nothing as attribution.
How It Works
A Facebook user in Thailand sees a sponsored post from a page with a name such as "TRD desk", "Kub Exchange" or "Sol Mine". The creative depends mostly on imagery, with a one-line hook introduced by an emoji and little additional text. The button reads ดาวน์โหลด or เรียนรู้เพิ่มเติม. Three lures rotate: a free premium subscription or anniversary giveaway, an official desktop app with a signup reward, and local cryptocurrency mining that supposedly runs on the victim's computer.
The click resolves to a brand-token subdomain on a burner apex, followed by a five-character lowercase path and the tracking string. The lander offers a desktop installer. Users who enter the "trading bot" flow encounter advance-fee fraud, with a deposit requested against a promised return.
We did not obtain an installer from this pool, and we make no claim about a sample, hash or family. The Bitdefender and Check Point research cited above documents the malware outcome for this lure family, and the delivery pattern observed here matches it.
Direct visits to these domains return nothing. Both the apex root and host root answer 404, consistent with the kit serving content only on the exact ad-referred path when the expected query parameters are present. We did not retrieve a lander through a captured parameterized URL, so that serving behavior is inferred rather than observed. The operational consequence is the same either way: a crawler without the referred path has nothing to classify, and an empty root looks parked to root-fetch reputation checks instead of hostile. Testing only the bare root therefore produces a false negative and can easily waste an hour.
Sample Lures
Advertiser-side content only. All destinations defanged.
TradingView anniversary and free-premium lure, Thai, on the flagship apex:
🔥 รับฟรี! 12 เดือน TradingView PREMIUM
มูลค่า $0 สำหรับผู้ใช้ใหม่ในไทย
ไม่มีค่าธรรมเนียม / ไม่มีผูกมัด / แค่ดาวน์โหลดและใช้งานได้ทันที
[Get 12 months of TradingView PREMIUM free, $0 for new users in Thailand.
No fees. No commitments. Just download and use immediately.]
Button: เรียนรู้เพิ่มเติม
Destination: hxxps[:]//investlearner[.]com/<5-char>?utm_campaign=TRAFF+1492+POOL+EUROPE+BINANCE+...
Bitkub bonus lure, Thai, on a purpose-registered apex:
ดาวน์โหลดแอป Bitkub อย่างเป็นทางการ
รับโบนัสฟรี 50 KUB ทันที
พร้อมใช้งานแล้วบน Windows! 💚
[Download the official Bitkub app. Get a free 50 KUB bonus immediately.
Available now on Windows!]
Destination: hxxps[:]//bitkub[.]itinvestdesktop[.]com/<5-char>?utm_campaign=SHD+1159+TH+BITKUB+CBO+boxer2+27.1
Fake local Solana mining, Thai, presented as passive income from an idle machine:
รับ 0.05 SOL/ชั่วโมง!
ขุด SOL ได้โดยตรงจากคอมพิวเตอร์ของคุณ 💻✨
ติดตั้งแอปฟรี เปิดตัวขุด และรับรางวัลรายชั่วโมงอย่างต่อเนื่อง ⚡💰
[Earn 0.05 SOL/hour. Mine SOL directly from your computer. Install the free
app, start mining, and receive continuous hourly rewards.]
Destination: hxxps[:]//solana[.]desktops-laptops[.]com/<5-char>
Binance desktop bonus, with Serbian body copy and a Cyrillic button, demonstrates the campaign's geographic reach:
💻 Instaliraj Binance Desktop
🪙 Ostvari 0.33 BNB
⚡ Brzo i jednostavno, preuzmi bonus sada!
Button: Преузми
Destination: hxxps[:]//investlearner[.]com/<5-char>?utm_campaign=...
One creative is unusually brazen. It gives anti-scam protection as the reason to install:
Install the updated Binance Desktop, the built-in anti-scam protection
system provides additional security.
The same flagship apex also carried an invented San Francisco property development with no crypto content, delivered through the same brand-token hosts as the other lures:
Discover Umbra Residences, a contemporary residential complex in San Francisco
offering architect-designed condos, immersive building renderings, detailed
floorplans, flexible mortgage options, and an easy "Book a Viewing" experience
for serious homebuyers.
Technical Analysis
Brand Tokens Live in the Subdomain
None of the registrable domains in this pool contains an impersonated brand string. The brand always appears in the subdomain label, where users see it but matching logic restricted to the registrable domain does not.
| Subdomain token | Distinct apexes carrying it | Impersonated brand |
|---|---|---|
bitkub |
19 | Bitkub |
tradingview |
14 | TradingView |
binance |
6 | Binance |
solana |
4 | Solana |
The economics explain this choice. Registering a lookalike apex requires a separate domain for each brand and exposes it to registrar-side brand monitoring. Subdomains are free and unlimited on an apex the platform already controls. One apex can serve a dozen brands without incurring a registration cost for each additional brand. Abbreviations and misspellings broaden the vocabulary: trd, tr, view, bin, binan, true, new, along with deliberate typosquats intended to evade exact-token matching. The observed set includes tradlngview, blnance, trade-vlew, 8inance, tradingvieww, deepsick and truebin.
On one live-tail apex, trade-vlew appears as a typosquat of trade-view, itself already a squat of the impersonated brand and located on the same apex. Whoever provisions these hosts is typosquatting their own lander, presumably to distribute one build across more distinct host strings.
Registration Cohorts
The pool spans six registrars, and teams move freely between registrar lanes. Registrar identity therefore does not distinguish one team from another. Registrar is an appealing pivot, but a misleading one. Registrar plus privacy service describes most disposable scam infrastructure and does not support a same-operator claim.
All six registrars named below are legitimate accredited businesses that compete on price and self-service signup. Their appearance in this WHOIS is arithmetic, not awareness.
Registration timing tells a different story. The dates fall into tight bulk batches.
| Registered | Registrar | Apexes | Naming family in the batch |
|---|---|---|---|
| 2022-09-26 / 09-28 | Dynadot | 2 | Aged short-label numerics, held roughly three years before use |
| 2025-06-17 | Dynadot | 3 | Five-letter opaque labels, registered same day |
| 2025-10-01 | WebCC | 3 | Finance pseudo-brand journals |
| 2025-10-06 | WebCC | 2 | Flagship apex plus an analytics pseudo-brand |
| 2025-11-17 | Mat Bao | 9 | Invented finance and invest* pseudo-brands |
| 2025-11-24 | Mat Bao | 12 | More invest*, plus the generic device-name family |
| 2026-01-07 | Hello Internet | 2 | Doubled-consonant misspelling pair |
| 2026-01-23 | WebCC and Webnic | 2 | Two apexes, same day, two registrars |
These batches account for 35 of the 48 apexes; the remainder were registered individually. Two same-day batches at one Vietnamese registrar account for 21 of them. The 2025-11-24 batch provides the clearest evidence because it combines two naming families that appear unrelated. Invented finance pseudo-brands and generic device-name domains in the desktops-laptops pattern were bought together, in one transaction, on one day. In isolation, a generic device-name domain resembles a plausible computer retailer. Its presence in the same batch as a dozen invented investment-education brands changes that assessment.
The 2022 pair shows the other side of the practice. Two short numeric-label domains were registered two days apart and remained dormant for roughly three years before appearing in this campaign. Holding them removes the registration-recency signal.
Two apexes carry named registrant strings instead of a privacy service, while the rest of the pool is entirely privacy-protected. Both strings use the given-name-plus-uncommon-surname form produced by the synthetic-name libraries commonly bundled with test-data and automation tooling. The same form appears in a minority of the advertiser page names alongside the generic finance titles. If those share a generator, page creation and domain registration draw from one identity source, providing a cross-layer link worth having. We have not confirmed the generator, and we have not published either string, because a name that merely looks synthetic is not established as belonging to no one.
The Kit
Landing paths use a fixed five-character lowercase alphanumeric slug: /f8lii, /bm0cf, /jrqsb, /ksqyr, /cetaq. The kit reuses a slug across multiple ad campaigns on the same host, so the slug identifies a build instead of an individual click.
The slug format helps enumerate hosts but supports no broader claim. This distinction matters because the pattern initially looks more diagnostic than it is. Across 216 distinct slugs observed, none recurs on two different apexes. Roughly five to six percent of unrelated Facebook ad traffic independently uses the same path format. The slug is a per-host enumeration pivot, never evidence of a cross-apex link.
Evasion in the Ad Copy
One campaign arm inserts U+200B, the zero-width space, between individual characters in the ad text. The ad looks identical to a human reader, but its byte sequence no longer matches the sequence expected by an exact-string rule:
🚀 I<ZWSP>n<ZWSP>s<ZWSP>t<ZWSP>a<ZWSP>l<ZWSP>l <ZWSP>t<ZWSP>h<ZWSP>e
<ZWSP>B<ZWSP>i<ZWSP>n<ZWSP>a<ZWSP>n<ZWSP>c<ZWSP>e <ZWSP>D<ZWSP>e<ZWSP>s...
This is part of the same family of techniques as Z-WASP email evasion. Here, only U+200B appears. No zero-width non-joiner, soft hyphen or byte-order mark is present, indicating one tool instead of a general obfuscation library. The technique appeared across four apexes during a two-month window beginning in late November 2025.
U+200B also has a legitimate typographic use as a line-break hint in scripts without spaces between words, including Thai. Its presence in Thai-language content alone proves nothing, so a rule based on presence will misfire. Insertion within words is the useful discriminator, especially in Latin-script words, where it has no typographic purpose.
Decoy Creatives Bridge the Pool
An invented San Francisco residential development, with architect-designed condos and a "Book a Viewing" call to action, is the strongest cross-apex link here. It is ad copy, not infrastructure. Within the documented pool, it ran on seven independently-registered apexes across three registrars, on 17 distinct hosts and 48 advertiser pages, from January 2026 through August 2026. It appeared on binance, tradingview and trade-view subdomains. A second decoy advertised natural skincare, and a third advertised an Atlanta property development.
The buying teams run creative unrelated to the destination to launder ads through review. The submitted ad looks unobjectionable, while the infrastructure behind it serves the crypto kit. The same invented development recurring across separately-registered domains for eight months identifies it as a platform asset, not a thematic coincidence.
Shared creative is usually weak attribution evidence because lure copy converges by base rate, and affiliate networks give identical assets to unrelated buyers. We tested this creative against that failure mode. An earlier candidate bridge in the same investigation, a tracking pixel shared across the pool, failed under measurement: it spanned 90 apexes, including clearly unrelated businesses, identifying it as a kit-template default rather than a fingerprint. When searched without the pool constraint, the decoy creative resolves to 15 apexes. Roughly two-thirds are already attributed to this campaign, and the rest use the pool's short-label-plus-digits naming grammar. No unrelated business appears in the set. That search also surfaces apexes outside the documented pool that were still serving in mid-August 2026.
What the Tracking Strings Reveal About the Operators
In addition to the team token, the parameters contain campaign-budget vocabulary (cbo, abo), numbered creative labels (creo1, creo2), ad-set structural notation such as 1-3-2, and literal budget amounts such as 16$ and 69.99$.
CBO is Meta's Campaign Budget Optimization, now branded Advantage campaign budget. Under CBO, one budget sits at campaign level, and the delivery system redistributes it across ad sets. ABO is the per-ad-set alternative, with isolated budgets. The standard working convention is to test with ABO and scale with CBO. Meta provides structured naming through Ads Manager name templates, while dynamic parameters carry those names into the destination URL. The numeric notations observed here are operator-specific idioms rather than a published standard, but the surrounding vocabulary comes from routine professional media buying.
The same fields contain Russian-language remnants, including Копия ("copy", the artifact of duplicating an ad set), пул ("pool") and создать ("create"). This reveals the working language of the people using the tooling. It does not support an attribution claim and should not be treated as one.
The offer tokens remain unresolved. Values such as 243.2 and 460.1 recur across structurally unrelated tracking grammars and independently registered apexes over eight months, including referral links outside Facebook. A dot-delimited value pairs an offer identifier with a sub-identifier. Affiliate trackers implement sub-ID attribution this way, which would place these buying teams as affiliates working a common offer. The network itself remains unidentified, and identifying it would close the question.
Detection Observations
The differences between this traffic and legitimate advertising are structural, not content-based.
- A brand token in the subdomain label, combined with a registrable domain unrelated to that brand, is close to definitive on its own. Legitimate brands do not advertise from another party's apex.
- Parse ad-tracking parameters instead of discarding them. A
utm_campaignvalue with a leading token followed by a numeric field, a country code and a brand name is a structured operator scheme. It persists through domain rotation, page bans and creative swaps that remove every surface feature. - Button locale often conflicts with body-copy language in this pool: Malay copy under a Thai button, Spanish copy under a Thai button, Serbian copy under a Cyrillic button on one ad and a Thai button on the next. A localized ad with an untranslated call to action indicates template reuse across geographies.
- Advertiser pages uniformly use numeric IDs without vanity slugs. They have generic finance names reused across many distinct IDs, and comments are disabled on the posts.
- Remove zero-width characters before comparing text. The operation is inexpensive, while a matcher that does not normalize them cannot detect copy that people can read without difficulty.
- Ad creative unrelated to its destination is a signal on its own. A specific invented creative repeated across separately-registered domains also supplies a usable clustering key.
- Root fetches do not confirm this activity. These hosts respond only on the referred path when expected parameters are present, so verification requires a captured parameterized URL.
Indicators of Compromise
All indicators are defanged. This is a representative subset, not the full set. The 48-apex figure above describes the documented team-token pool; the verified-malicious set below is larger because it also includes apexes reached through the decoy-creative pivot.
Domains
| Value | Role | Notes |
|---|---|---|
investlearner[.]com |
Shared flagship apex | Used by 8 of 11 teams; registered 2025-10-06 |
netflowtch[.]digital |
Shared apex | Brand-token hosts for several impersonated platforms |
dowpc[.]site |
Shared apex | Registered 2026-01-23, three teams |
itinvestdesktop[.]com |
Bitkub-lure apex | Registered 2025-09-24 |
cryptoinvestlearner[.]com |
Pseudo-brand apex | Naming sibling of the flagship |
desktops-laptops[.]com |
Device-name apex | Bulk batch of 2025-11-24 |
off-desktop-app[.]com |
Device-name apex | Bulk batch of 2025-11-24 |
netflowtech[.]org |
Device-name apex | Registered 2026-01-23 |
investlearnzone[.]com |
Pseudo-brand apex | Bulk batch of 2025-11-24 |
financegrowers[.]com |
Pseudo-brand apex | Bulk batch of 2025-11-17 |
bk92830[.]com |
Bitkub-squat burner | Numeric-label kit family |
ad760[.]com |
Aged burner apex | Registered 2022, dormant until use |
| ... (representative subset; 100+ verified-malicious apexes) |
Hosts
| Value | Role | Notes |
|---|---|---|
tradingview[.]investlearner[.]com |
Landing | Highest-volume host in the pool |
solana[.]investlearner[.]com |
Landing | Fake local mining lure |
binance[.]investlearner[.]com |
Landing | Desktop bonus lure |
wise[.]investlearner[.]com |
Landing | Money-transfer bonus lure |
deepsick[.]investlearner[.]com |
Landing | Typosquat of an AI brand token |
bitkub[.]itinvestdesktop[.]com |
Landing | 50 KUB bonus lure |
bitkub[.]cryptoinvestlearner[.]com |
Landing | 50 KUB bonus lure |
solana[.]desktops-laptops[.]com |
Landing | Fake local mining lure |
tradingview[.]dowpc[.]site |
Landing | Shared across three teams |
truebin[.]dowpc[.]site |
Landing | Blended brand-token typosquat |
tradlngview[.]ordelyxs[.]com |
Landing | Typosquat label, live tail |
trade-vlew[.]exactai[.]org |
Landing | Operator typosquat of its own lander host |
| ... (representative subset; 100+ verified-malicious brand-token hosts) |
Advertiser Profiles
Numeric-ID Facebook pages used by this operation. None carries a vanity slug.
| Value | Username | Notes |
|---|---|---|
profile.php?id=61551638908144 |
TRD desk | TradingView lures |
profile.php?id=61551018406476 |
TRD reward | TradingView lures |
profile.php?id=61576318230139 |
AsiaGrow | Solana mining lures |
profile.php?id=61579828379505 |
Sol Mine | Solana mining lures |
profile.php?id=100090898041489 |
Kub Exchange | Bitkub lures |
profile.php?id=61550218200194 |
Bin Tech | Multi-brand |
profile.php?id=100093997988650 |
TV Desktop | TradingView lures |
profile.php?id=61577953889594 |
Desktop 8inance | Typosquat page name |
profile.php?id=61586572377456 |
Special promotions news | Solana mining lures |
profile.php?id=100091571149725 |
Crypto Info | Multi-brand |
profile.php?id=61577811276393 |
TRD News | TradingView lures |
profile.php?id=61583546288993 |
View For | Multi-brand |
profile.php?id=100086281359850 |
World Finance | Reused generic finance name |
| ... (representative subset; 500+ verified-malicious advertiser profiles) |
MITRE Fight Fraud Framework Mapping
This mapping follows the MITRE Fight Fraud Framework (F3) v1.1, https://ctid.mitre.org/fraud. F3 covers post-access fraud behavior, while this operation uses pre-access lures and causes harm through installed malware and victim-initiated payments. The mapping is therefore partial and based on analogy. Unsupported stages remain unmapped instead of being forced into unsuitable techniques.
| F3 Tactic | Technique | ID |
|---|---|---|
| Resource Development | Acquire Infrastructure: Domains | T1583.001 |
| Resource Development | Acquire Infrastructure: Malvertising | T1583.008 |
| Resource Development | Create Fake Materials: Fake Website | F1020.002 |
| Resource Development | Establish Accounts | T1585 |
| Initial Access | Impersonate Official | F1032 |
| Stealth | Path-and-parameter cloaking; zero-width-character insertion in ad copy | |
| Execution | Fake desktop application installed by the victim | |
| Execution | Advance-fee bonus and reward fraud | |
| Monetization | Convert to Cryptocurrency | F1018 |
| Monetization | Transfer of funds | F1047 |
F3 has no technique for a fake application: F1020 Create Fake Materials covers only fake documents and fake websites. It also lacks techniques for advance-fee fraud, cloaking, or typosquatting. Its Stealth techniques concern actors spoofing their own device or location attributes, unlike filtering victims by referred path. Reconnaissance has no supported row because ad-platform audience targeting is not the same activity as gathering customer information. Finally, F1018 and F1047 describe actors moving proceeds, whereas the victim initiates the transfer in this campaign. As enterprise-ATT&CK cross-references rather than F3 techniques, T1036 Masquerading and T1204.002 User Execution: Malicious File both apply to the installer stage.
Conclusion
The durable result of this investigation is the corrected unit of analysis, since the domain list will rotate. An apex containing more than one internal tracking dialect is shared infrastructure. Attribution must move down to the parameter instead of up to the registrar. This changes how analysts should interpret counters as well. Sequential identifiers spanning several domains can resemble one operator's provisioning system, but they are equally consistent with several buyers using one platform. Distinguishing those cases requires a field the operators wrote for themselves. They keep writing those fields because the tracking string was never intended for defenders to read.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.