Massive fake e-commerce network uncovered with over 119,000 domains

Researchers at Nebty discovered a fraud operation called DoppelCart that operates more than 119,000 fake online stores to steal payment card data. The sites impersonate over 44,000 brands and use WebSockets to transmit card details and one-time codes to attackers. Most of the shops are still active, and the network is the largest documented fake-shop cluster by domain count.
The network's scale is notable, with over 105,000 shops still operational out of the 119,000+ domains. The operation's technical consistency is striking, as 96% of the confirmed sites share identical build files and route to just 27 backend servers. This uniformity likely aids the attackers in managing such a vast infrastructure.
The fraudsters employ sophisticated tactics, including copying product catalogs and offering discounts up to 65% to lure shoppers. Crucially, they can intercept one-time bank confirmation codes via WebSockets, potentially bypassing two-factor authentication. Nebty's response includes a searchable database for brands, while their outreach to the primary hosting provider went unanswered.
This operation could significantly erode consumer trust in online marketplaces, particularly for bargain hunters who may unknowingly enter sensitive data into fraudulent checkout pages. Legitimate brands impersonated by these sites may face reputational harm and increased customer service costs as victims contact them. The ability to intercept one-time bank codes could bypass common security measures, potentially leading to substantial financial losses for individuals. The persistence of over 105,000 active shops suggests this threat may remain pervasive, prompting consumers to exercise greater caution when encountering steep discounts.