Full Report
Group-IB uncovers largest networks of fake shops – phishing websites disguised as card shops
Analysis Summary
# Threat Actor: Bogus Cartel (Large-Scale Fake Shop Networks)
## Attribution & Identity
* **Actor Identification:** The activity is attributed to a sophisticated class of cybercriminals operating as "fake shop" network administrators within the carding ecosystem.
* **Aliases:** Referred to collectively by Group-IB as "Fake Carding Shop Networks."
* **Known Associations:** These actors are deeply integrated into the underground "carding" industry, acting as intermediaries or parasites that prey on both novice carders and legitimate cardholders.
## Activity Summary
* **Campaign Overview:** The discovery of the largest known networks of fake phishing websites disguised as legitimate "card shops" (marketplaces for stolen credit card data).
* **Scale:** The networks consist of thousands of domains designed to mimic reputable underground shops like Brian's Club or Vclub.
* **Operations:** The actors create "mirrors" or clones of well-known carding platforms to lure users into depositing funds (Bitcoin/cryptocurrency) into accounts they will never be able to use, or to harvest credentials of other cybercriminals.
## Tactics, Techniques & Procedures
* **Search Engine Optimization (SEO) Poisoning:** Using SEO techniques to ensure fake shop links appear at the top of search results when users search for carding forums or shops.
* **Brand Impersonation:** Precisely copying the UI/UX, logos, and layouts of established underground marketplaces to gain trust.
* **Deposit Fraud:** Requiring a "minimum deposit" (usually in cryptocurrency) to activate a new account, which is then immediately stolen by the admin.
* **Data Scrapping:** Scraping data from legitimate carding shops to display "live" inventory, making the fake site appear authentic.
* **Credential Harvesting:** Capturing the login details of carders to hijack their accounts on real marketplaces.
**MITRE ATT&CK Mapping:**
* **T1583.001:** Acquire Infrastructure: Domains
* **T1566:** Phishing
* **T1204.001:** User Execution: Malicious Link
* **T1589:** Gather Victim Identity Information
## Targeting
* **Sectors:** The underground "Carding" economy and financial services.
* **Geography:** Global; however, the UI of these shops often targets English and Russian-speaking cybercriminals.
* **Victims:**
* **Direct:** Novice cybercriminals and "script kiddies" looking to buy stolen data.
* **Indirect:** Legitimate cardholders whose data is supposedly being sold (though the shops are fake, they often use real leaked data to prove "validity").
* **Researchers:** Threat intelligence analysts who may misattribute these sites as legitimate C2s or primary sources of leaks.
## Tools & Infrastructure
* **Infrastructure:** Extensive networks of domain names often registered via bulletproof hosters.
* **Domains:** Thousands of rotating domains (e.g., `briansclub[.]cm` - *defanged*, `vclub[.]tel` - *defanged*).
* **Payment Gateways:** Custom-built cryptocurrency payment templates for BTC, LTC, and ETH.
## Implications
* **Misattribution:** One of the greatest risks identified is the potential for researchers to issue false positives or inaccurate threat intelligence by treating these fake shops as legitimate sources of breached data.
* **Market Consolidation:** The report suggests the fake-shop market is currently monopolized by a few large-scale administrators, making it difficult for new actors to enter but ensuring a high level of professionalized fraud.
## Mitigations
* **For Researchers:** Verify the authenticity of carding shops through multiple underground community sources before attributing leaks or activity.
* **For Financial Institutions:** Monitor for "brand abuse" involving the bank's name on these platforms, even if the shop is fake, as the data advertised may still be sourced from real, older breaches.
* **For Users:** Avoid interacting with underground marketplaces; utilize official search engine warnings and "Safe Browsing" tools that flag known phishing and fraudulent domains.