A sophisticated cyber-fraud operation known as 'DoppelCart' is utilizing over 119,000 fraudulent domains to impersonate global brands and steal sensitive payment information from unsuspecting shoppers.
- Over 119,000 fraudulent domains created to steal credit card details.
- Discovered by German startup Nebty; 105,000+ sites remain active.
- Impersonation of 44,182 brands, including SodaStream and Daniel Wellington.
- Real-time data theft via WebSockets, including bank OTP bypass capabilities.
In a staggering revelation of cyber-criminal scale, a massive operation dubbed 'DoppelCart' has been uncovered. This network leverages more than 119,000 domains to operate a sprawling web of fake e-commerce shops designed to harvest payment card details. According to findings by the German cybersecurity startup Nebty, this is the largest publicly documented fake-shop cluster by domain count, dwarfing previous operations like 'BogusBazaar'.
The infrastructure of DoppelCart is highly optimized for deception. A significant portion of these sites reside within the .SHOP top-level domain, accounting for roughly 2.72% of all sites on that TLD. Nebty CEO Benedikt Scheungraber noted that 96% of the confirmed shops share identical build files and resolve to just 27 commerce backends, indicating a highly centralized management system.
Why This Matters
BozokMedia analysis shows that the DoppelCart operation represents a shift toward 'industrialized' phishing. By mirroring the exact product catalogs, branding, and images of 44,182 different brands, the attackers remove the visual cues that typically alert users to a scam. The use of aggressive discounting—often up to 65%—targets the psychological vulnerability of bargain hunters, making the trap nearly irresistible to the average consumer.
"The ability of DoppelCart to relay one-time confirmation codes in real-time allows attackers to bypass the final layer of banking security, making this a high-criticality threat."
The technical execution is particularly alarming. During checkout, the fraudulent code collects card numbers, expiration dates, CVVs, and personal contact details. This data is transmitted via WebSockets to a command-and-control (C2) server in real-time. Furthermore, the system can relay the one-time password (OTP) issued by a victim's bank, allowing the criminals to authorize fraudulent transactions instantly.
Historically, the landscape of fake-shop networks has grown exponentially. While BogusBazaar previously held the record with 75,000 sites and 850,000 fraudulent transactions, DoppelCart has surpassed it in sheer volume. This trend suggests that cybercriminals are finding it easier and cheaper to register mass domains to cast a wider net for victims.
| Metric | BogusBazaar (Previous) | DoppelCart (Current) |
|---|---|---|
| Domain Count | 75,000 | 119,000+ |
| Brand Mimicry | Moderate | 44,182+ Brands |
| Data Transmission | Standard Forms | Real-time WebSockets |
Frequently Asked Questions
1. How can I tell if a shopping site is a DoppelCart clone?
Check for unrealistic discounts (over 50%), verify the URL carefully for slight misspellings, and use a browser extension that flags malicious sites.
2. What should I do if I entered my details on one of these sites?
Immediately contact your bank to freeze your cards, change your email passwords, and monitor your credit report for unauthorized activity.