Researchers identified DoppelCart, a network of roughly 118,787–119,000 fraudulent online-shop domains, predominantly under the .shop top-level domain, impersonating more than 44,000 brands. The storefronts copy legitimate product catalogs, images, descriptions, and branding—at times publishing a victim company’s real support address—causing reputational damage and redirecting customer-service complaints to the impersonated business. The shops lure buyers with discounts of up to 65%, and most of the identified network remains online despite some takedowns.
DoppelCart checkout pages capture billing and payment-card details, including CVVs and potentially bank one-time authentication codes, then exfiltrate them to attacker-controlled infrastructure over WebSockets in real time. Investigators linked the sites through recurring infrastructure and site-building traits: 96% of confirmed shops shared identical build files and the cluster used 27 e-commerce backends. The attribution reflects shared technical characteristics rather than proof that a single identified actor operates every domain; researchers have published a searchable database to help organizations find impersonating stores.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Nebty published an investigation identifying DoppelCart, a cluster of approximately 119,000 .shop domains impersonating more than 44,000 brands, described as the largest publicly documented fake-shop network by associated-domain count. The cloned stores reused legitimate retail content and captured payment-card, billing, and potentially bank authentication-code data through checkout pages that transmitted data to attacker-controlled servers; Nebty also published a searchable database for affected businesses.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
9 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecyberveille.ch
Open sourcecysecurity.news
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourcenebty-id.com
Open sourcenebty-id.com
Open sourcenetcraft.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.