Back www.bleepingcomputer.com According to BleepingComputer
A massive operation dubbed “DoppelCart” uses more than 119,000 domains to run a network of fake e-shops that steal payment card details.
Most of the domains are in the .SHOP top-level domain, accounting for 2.72% of all sites on the TLD.
German cybersecurity startup Nebty discovered DoppelCart and describes it as the largest publicly documented fake-shop cluster by domain count, far surpassing the second-largest, “ BogusBazaar ,” which operated a network of 75,000 sites that recorded an estimated 850,000 fraudulent transactions.
The company's latest scans show that more than 105,000 DoppelCart shops are still active.
Nebty CEO Benedikt Scheungraber told BleepingComputer that 96% of the shops confirmed to be part of DoppelCart identical build files and resolve to 27 commerce backends.
The sites impersonate legitimate businesses by copying product catalogs, descriptions, branding, and images, sometimes loading assets directly from the real company’s servers.
Scheungraber says that the shops mimic 44,182 different brands, with a median of two clones for each.
However, some brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS received more attention, with over 30 shops each.
The fake sites advertise big discounts of up to 65% in many cases to lure bargain-hunting shoppers.
When testing several checkout pages in the DoppelCart cluster, Nebty found code that collected sensitive information related to payment cards and their holders:
Each data field is transmitted over WebSockets to the command-and-control (C2) in real time, Netby says in a report shared with BleepingComputer.
The checkout code can also relay the one-time confirmation code issued by a victim’s bank, which the attackers may use to bypass security protections.
Nebty says some of the fake stores show the impersonated brand’s legitimate support address, leading victims who didn’t receive their purchases to the real company.
Scheungraber says that the company tried to the main hosting provider for DoppelCart sites but received no response.
Separately, Nebty created a searchable database to help companies identify DoppelCart impersonation and brand abuse and take appropriate action to protect themselves.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
