Researchers reported large-scale automated account creation activity in which attackers attempted tens of thousands of registrations in under a week and relied on a bespoke email verification pipeline rather than public disposable-email services. Investigation of the registration traffic led to attacker-controlled email domains and an associated server that exposed a misconfigured administrative panel without authentication, providing rare real-time visibility into the operators’ verification workflow (e.g., verification request volumes, success rates, worker activity, and recently processed codes).
Separate reporting tied similar mass sign-up activity to a Vietnam-based cybercrime ecosystem (tracked as O-UNC-036) that uses bots, disposable email domains, and a broader cybercrime-as-a-service marketplace to sell fraud tooling (including proxies, anti-detect browsers, and access artifacts such as session tokens). The activity is linked to downstream monetization including spam/phishing enablement and SMS pumping/IRSF, where automated sign-ups trigger premium-rate SMS charges that service providers absorb. A third report on a Canada-focused phishing campaign hosted on infrastructure allegedly linked to Iranian state-aligned activity is a different threat set and does not materially overlap with the automated sign-up/email verification story.

TTPs, infrastructure, and targeting history in one profile.
7 events from the most recent confirmed update back to the earliest known activity.
By pivoting on the disposable email infrastructure, analysts discovered an exposed administrative dashboard and unauthenticated API that provided real-time visibility into the attackers' email verification operations and metrics. This revealed how the service supported automated account creation at scale.
Investigators identified unusual disposable email domains used to complete account verification and found they were part of a coordinated attacker-controlled email system. The infrastructure used centralized mail and DNS backends, polled inboxes via POP3, extracted verification codes, and exposed them through an API for bot-driven registrations.
The exposed ecosystem was found to support spam, phishing, and pig-butchering operations, while also directly monetizing through SMS pumping and International Revenue Sharing Fraud. This activity forces service providers to pay for large volumes of premium-rate SMS traffic generated through fraudulent accounts.
The report identified a Vietnam-based web design company operating CMSNT[.]co whose templates were used across many fraud storefronts. It also highlighted Via17[.]com as a marketplace selling compromised social media accounts, session tokens, and other access artifacts sourced from brute-force activity or infostealer logs.
Okta analysts and the University of Cyprus connected the activity to dozens of storefronts selling hijacked and synthetic accounts as part of a cybercrime-as-a-service marketplace. These shops also offered related fraud services such as phone farms, engagement inflation, and anti-detect tooling.
Researchers attributed the large-scale fraudulent account registration activity to a Vietnam-rooted cybercrime ecosystem tracked as O-UNC-036. The cluster was linked to infrastructure and services enabling mass production of fake identities for downstream abuse.
Analysts investigating an automated account creation attack observed more than 80,000 suspicious registration attempts in under a week, indicating a coordinated mass sign-up operation. Okta also reported waves of suspicious sign-ups tied to disposable email domains.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.