INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
DoppelCart fraud network uses 119,000 fake shops to steal
| 2026-09-08 20:35 CRITICAL HIGH PHISHING & SOCIAL ENGINEERING FRAUD & CRYPTO THEFT
Executive Summary
AI-generated
A cyber operation using the tactic of "DoppelCart" impersonation and brand abuse was detected on 2026-09-08, targeting countries in TARGET_REGION. The attackers created approximately 119,000 fake shops to steal credit card information. This attack works by copying product catalogs, descriptions, branding, and images from legitimate businesses' servers, sometimes loading assets directly from the real company's servers. As of now, a searchable database has been created to help companies identify DoppelCart impersonation and brand abuse, allowing them to take action against these fake shops.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Impersonation): Train users to be aware of impersonation tricks and how to counter them, for example confirming incoming requests through an independent platform like a phone call or in-
• Threat Intelligence Program (ATT&CK mitigation for Impersonation): Threat intelligence helps defenders and users be aware of and defend against common lures and active campaigns that have been used for impersonation.
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
bi•••@bl•••.•••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
bi•••••.toulas
ad•••••.com
ne•••••.com
ww•••••.com
10•••••.jpg
10•••••.jpg
10•••••.jpg
10•••••.png
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA
NORTH_AMERICA
financefinance
Incident Timeline
2016 August
Threat actors exploited vulnerabilities in Windows Server 2016 to trigger the 0xc0000409 error, which was later linked to a DoppelCart fraud network using fake shops to steal credit cards.
Click on any entity below to view its context and source!
infrastructure
Windows
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
tactic
T1584.004 - Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
infrastructure
2016 Windows Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
September 2026
Microsoft released a September 2026 Patch Tuesday that addressed 966 flaws, including two zero-days, which may have indirectly mitigated the DoppelCart fraud network's operations.
Click on any entity below to view its context and source!
organisation
Microsoft
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
general_metric
966 flaws
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
general_metric
2 days
[Image 2: Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days](
* !
September 8, 2026
Threat actors utilizing DoppelCart's 119,000 fake shops impersonated legitimate brands to steal credit card information through tactics such as offering deep discounts.
Click on any entity below to view its context and source!
general_metric
119,000 fake shops
[Image 34: ThreatLocker](
* Home
* News
* Security
* DoppelCart fraud network uses 119,000 fake shops to steal credit cards
# DoppelCart fraud network uses 119,000 fake shops to steal credit cards
By
###### Bill Toulas
* September 8, 2026
* 04:35 PM
* 0
!
organisation
ThreatLocker
[Image 34: ThreatLocker](
* Home
* News
* Security
* DoppelCart fraud network uses 119,000 fake shops to steal credit cards
# DoppelCart fraud network uses 119,000 fake shops to steal credit cards
By
###### Bill Toulas
* September 8, 2026
* 04:35 PM
* 0
!
general_metric
0 PM
[Image 34: ThreatLocker](
* Home
* News
* Security
* DoppelCart fraud network uses 119,000 fake shops to steal credit cards
# DoppelCart fraud network uses 119,000 fake shops to steal credit cards
By
###### Bill Toulas
* September 8, 2026
* 04:35 PM
* 0
!
organisation
TLD
Most of the domains are in the .SHOP top-level domain, accounting for 2.72% of all sites on the TLD.
organisation
BleepingComputer
Nebty CEO Benedikt Scheungraber told BleepingComputer that 96% of the shops confirmed to be part of DoppelCart share identical build files and resolve to 27 commerce backends.
organisation
CurrentBody
However, some brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS received more attention, with over 30 shops each.
organisation
MOVA
However, some brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS received more attention, with over 30 shops each.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
organisation
EU CRA
Check your EU CRA readiness in 5 questions.
2003 - 2026
Threat actors behind the DoppelCart fraud network used fake online shops to steal credit card information from approximately 119,000 victims over nearly two decades.
Click on any entity below to view its context and source!
organisation
Social & Feeds
* Advertising
* Write for BleepingComputer
* Social & Feeds
* Changelog
Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure
Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved
[]( "Back to Top")
2026/09/08
Threat actors used DoppelCart to impersonate legitimate e-commerce sites and steal credit card details through a network of over 119,000 fake shops.
Click on any entity below to view its context and source!
infrastructure
Linux
[](
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
Get the report
### Related Articles:
Android malware combo takes out loans and relays victims' credit cards
Inside the Search for "Clean" Residential Proxies for Carding
Adobe fixes critical Magento zero-day exploited to backdoor servers
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Why Even the Best Edge Security Still Misses High-Risk Sessions
* Credit Card
* DoppelCart
* E-Commerce
* Fraud
*
organisation
infosec news
[](
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
organisation
APM
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
organisation
Hackers
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
infrastructure
Android
Get the report
### Related Articles:
Android malware combo takes out loans and relays victims' credit cards
Inside the Search for "Clean" Residential Proxies for Carding
Adobe fixes critical Magento zero-day exploited to backdoor servers
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Why Even the Best Edge Security Still Misses High-Risk Sessions
* Credit Card
* DoppelCart
* E-Commerce
* Fraud
*
organisation
the Best Edge Security
Get the report
### Related Articles:
Android malware combo takes out loans and relays victims' credit cards
Inside the Search for "Clean" Residential Proxies for Carding
Adobe fixes critical Magento zero-day exploited to backdoor servers
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Why Even the Best Edge Security Still Misses High-Risk Sessions
* Credit Card
* DoppelCart
* E-Commerce
* Fraud
*
organisation
Credit Card
Get the report
### Related Articles:
Android malware combo takes out loans and relays victims' credit cards
Inside the Search for "Clean" Residential Proxies for Carding
Adobe fixes critical Magento zero-day exploited to backdoor servers
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Why Even the Best Edge Security Still Misses High-Risk Sessions
* Credit Card
* DoppelCart
* E-Commerce
* Fraud
*
infrastructure
Microsoft 365
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
organisation
BigBear Microsoft 365
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
organisation
MFA
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
victims
258 organizations
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
organisation
Unicode
[Image 43: Phishing Attackers conceal phishing lures using invisible Unicode characters](
S ponsor Posts
* !
infrastructure
Windows
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
[Image 14: How to start Windows in Safe Mode How to start Windows in Safe Mode](
* !
[Image 16: How to show hidden files in Windows 7 How to show hidden files in Windows 7](
* !
[Image 17: How to see hidden files in Windows How to see hidden files in Windows](
* Webinars
* Downloads
* Latest
* Most Downloaded
* !
organisation
Stack Protection
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
organisation
Windows Registry
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
organisation
the Windows Registry
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
organisation
DoppelCart
DoppelCart fraud network uses 119,000 fake shops to steal credit cards.
infrastructure
119,000 domains
Image 35: DoppelCart fraud network uses 119,000 fake shops to steal credit cards
A massive operation dubbed “DoppelCart” uses more than 119,000 domains to run a network of fake e-shops that steal payment card details.
organisation
Magento
[Image 3: Adobe fixes critical Magento zero-day exploited to backdoor servers Adobe fixes critical Magento zero-day exploited to backdoor servers](
* !
organisation
Adobe
[Image 3: Adobe fixes critical Magento zero-day exploited to backdoor servers Adobe fixes critical Magento zero-day exploited to backdoor servers](
* !
threat_actor
ShinyHunters
[Image 4: ShinyHunters hackers claim breach of Florida ShinyHunters hackers claim breach of Florida "DAVID" DMV database](
* !
organisation
DMV
[Image 4: ShinyHunters hackers claim breach of Florida ShinyHunters hackers claim breach of Florida "DAVID" DMV database](
* !
organisation
IP
[Image 31: How to change IP address.jpg) How to change IP address](
* !
organisation
safely.jpg
Access the dark web safely.jpg)
organisation
BogusBazaar
German cybersecurity startup Nebty discovered DoppelCart and describes it as the largest publicly documented fake-shop cluster by domain count, far surpassing the second-largest, “BogusBazaar,” which operated a network of 75,000 sites that recorded an estimated 850,000 fraudulent transactions.
organisation
WebSockets
Email addresses
* Phone numbers
* Physical addresses
Each data field is transmitted over WebSockets to the command-and-control (C2) in real time, Netby says in a report shared with BleepingComputer.
organisation
CTI
[Image 46: CTI Starter Kit + 2026 SANS CTI Survey CTI Starter Kit + 2026 SANS CTI Survey](
* !
organisation
Upcoming Webinar
[Image 39: ThreatLocker](
Upcoming Webinar
!
organisation
Astra
[Image 42: ChatGPT ChatGPT Astra is now rolling out to $20 Plus subscription](
* !
financial
$20 $ subscription
[Image 42: ChatGPT ChatGPT Astra is now rolling out to $20 Plus subscription](
* !
organisation
Freestar.com
Image 50!Image 51!Image 52!Image 53!Image 54!Image 55!Image 56!Image 57!Image 58!Image 59!Image 60
Freestar.com
!
Tactical Metrics
Metrics
infrastructure
Linux
Affected Product
Click for context!
[](
Bill Toulas is a tech writer and infosec news reporter with over a decade of experience working on various online publications, covering open-source, Linux, malware, data breach incidents, and hacks.
[Image 9: Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit](
* Tutorials
*
Get the report
### Related Articles:
Android malware combo takes out loans and relays victims' credit cards
Inside the Search for "Clean" Residential Proxies for Carding
Adobe fixes critical Magento zero-day exploited to backdoor servers
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Why Even the Best Edge Security Still Misses High-Risk Sessions
* Credit Card
* DoppelCart
* E-Commerce
* Fraud
*
Metrics
infrastructure
Microsoft 365
Affected Product
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
Metrics
victims
258
Organizations
Microsoft 365 phishing BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations](
* !
Metrics
infrastructure
Windows
Affected Product
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
[Image 11: How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11 How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11](
* !
[Image 12: How to use the Windows Registry Editor How to use the Windows Registry Editor](
* !
[Image 13: How to backup and restore the Windows Registry How to backup and restore the Windows Registry](
* !
[Image 14: How to start Windows in Safe Mode How to start Windows in Safe Mode](
* !
[Image 16: How to show hidden files in Windows 7 How to show hidden files in Windows 7](
* !
[Image 17: How to see hidden files in Windows How to see hidden files in Windows](
* Webinars
* Downloads
* Latest
* Most Downloaded
* !
Metrics
infrastructure
2,016
Windows Server
[Image 5: August updates trigger 0xc0000409 errors on Windows Server 2016 August updates trigger 0xc0000409 errors on Windows Server 2016](
* !
Metrics
infrastructure
Android
Affected Product
Get the report
### Related Articles:
Android malware combo takes out loans and relays victims' credit cards
Inside the Search for "Clean" Residential Proxies for Carding
Adobe fixes critical Magento zero-day exploited to backdoor servers
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
Why Even the Best Edge Security Still Misses High-Risk Sessions
* Credit Card
* DoppelCart
* E-Commerce
* Fraud
*
Metrics
financial
20
$ Subscription
[Image 42: ChatGPT ChatGPT Astra is now rolling out to $20 Plus subscription](
* !
Metrics
infrastructure
119,000
Domains
Image 35: DoppelCart fraud network uses 119,000 fake shops to steal credit cards
A massive operation dubbed “DoppelCart” uses more than 119,000 domains to run a network of fake e-shops that steal payment card details.
Intelligence Sources
BleepingComputer
2026-09-08
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
32x
organisation
Identified Entity
infosec news
entity
6x
tactic
MITRE ATT&CK Technique
T1566 - Phishing
technique
5x
tactic
Cyber Operation Type
Impersonate
tactic
4x
infrastructure
Affected Product
Linux
software
4x
timeline
Temporal Reference
September 8, 2026
date
4x
general metric
%
3
%
4x
general metric
Video
1
video
2x
general metric
Windows
11
windows
Contextual Telemetry
Context Block
22 METRICS
target region
Target Country
United States
country
general metric
Microsoft
365
microsoft
victims
Organizations
258
organizations
infrastructure
Windows Server
2,016
windows server
general metric
Fake Shops
119,000
fake shops
general metric
Flaws
966
flaws
general metric
Days
2
days
threat actor
APT Group
ShinyHunters
actor
general metric
Pm
0
pm
source region
Origin Country
Germany
country
general metric
Sites
75,000
sites
general metric
Estimated Fraudulent Transactions
850,000
estimated fraudulent transactions
general metric
Commerce Backends
27
commerce backends
general metric
Shops
30
shops
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
financial
$ Subscription
20
$ subscription
general metric
Questions
5
questions
general metric
Freestar.Com
60
freestar.com
infrastructure
Domains
119,000
domains
general metric
Doppelcart Shops
105,000
doppelcart shops
general metric
Different Brands
44,182
different brands
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.