A fraud network operating more than 119,000 fake online shops has been harvesting payment-card details from shoppers, according to German cybersecurity company Nebty.
Dubbed DoppelCart, the operation is believed to be the largest publicly documented cluster of fraudulent retail websites by domain count. More than 105,000 of the sites remain active, Nebty said.
The network is heavily concentrated in the .SHOP domain, where its websites account for 2.72% of all registered sites. Nebty said DoppelCart is substantially larger than the previously identified BogusBazaar network, which operated about 75,000 fake shops and was linked to an estimated 850,000 fraudulent transactions.
Fake shops copied legitimate brands
The websites are designed to resemble genuine retailers, using copied product ranges, descriptions, logos and photographs. In some cases, images and other material are loaded directly from the legitimate company’s servers.
Nebty said the network has been used to imitate 44,182 brands, with a typical brand appearing on two cloned websites. Several companies, including SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA and SPARK PAWS, were targeted by more than 30 sites each.
The fake retailers commonly offered discounts of up to 65% in an apparent attempt to attract shoppers looking for bargains. Some also displayed the genuine company’s customer-support address, meaning people who paid for goods that never arrived could end up contacting the impersonated business.
Benedikt Scheungraber, Nebty’s chief executive, said 96% of the shops confirmed as part of DoppelCart used identical build files. The sites were connected to 27 commerce backends, suggesting that many apparently separate stores were being run through the same underlying infrastructure.
Checkout pages captured card and personal details
Tests of checkout pages found code that collected card numbers, expiry dates, security codes and cardholders’ names, alongside email addresses, telephone numbers and physical addresses.
Nebty said the information was sent in real time through WebSockets to servers controlled by the attackers. The checkout systems could also relay one-time confirmation codes issued by a victim’s bank, potentially allowing criminals to defeat additional verification measures.
Scheungraber said Nebty had attempted to contact the main hosting provider used by the websites but had received no response.
The cybersecurity company has since created a searchable database intended to help businesses identify DoppelCart sites using their names and branding, and take steps to address the impersonation.
