Cybersecurity researchers at Munich-based firm nebty have uncovered a massive cybercrime network comprising over 119,000 counterfeit online store domains. Operating largely under the .shop top-level domain suffix, this criminal operation impersonates popular tech manufacturers including robot vacuum maker Dreame, networking brand FRITZ!, EcoFlow, Roborock, Keychron, and Sennheiser to steal customer credit card credentials.
Unlike typical phishing pages that require users to hit a final submit button, these fake outlets deploy real-time WebSocket scripts that capture payment card numbers, security codes, and contact details the moment they are typed into a form field.
A Scale Unprecedented in E-Commerce Fraud
The newly documented cluster, tracked as Doppelcart, represents one of the largest fraudulent e-commerce networks ever recorded. With 119,012 confirmed domains, it far exceeds the 75,000 fake storefronts identified during the BogusBazaar campaign in 2024. Remarkably, 118,787 of these domains leverage the .shop suffix alone, representing roughly 2.72 percent of the 4.36 million .shop web addresses registered worldwide.
To construct an authentic facade, the attackers hotlink product photography and layout assets directly from the official content delivery servers of target brands. When prospective buyers search for deals on home routers or automated vacuums, they land on pages that look identical to official regional outlets. In some cases, domains masquerade as dedicated national hubs across Germany, Italy, France, Spain, and Belgium.
Real-Time Keylogging and Customer Support Spoofing
What makes this network particularly deceptive is its sophisticated manipulation of buyer trust. Many of the counterfeit sites display genuine customer support email addresses belonging to the victimized brands, such as embedding real manufacturer support channels directly on the fake checkout page. When orders inevitably fail to arrive, defrauded shoppers send complaints directly to the legitimate brand, forcing real customer support teams to manage complaints for purchases they never processed.
Underneath the polished design lies an aggressive payment capture mechanism. Technical analyses show that as soon as a victim enters their name, credit card number, expiration date, CVV, or shipping address, the site transmits each character individually over an open WebSocket connection back to attacker-controlled infrastructure. The transaction data is compromised long before the user clicks a purchase confirmation button. Furthermore, the underlying code is built to relay bank one-time authorization passcodes, tricking users into manually authorizing fraud directly with their financial provider.
Spotting Fake Outlets Before Making a Purchase
Despite the scale of the campaign, structural patterns make these malicious storefronts identifiable. Nebty Chief Executive Benedikt Scheungraber noted that 96 percent of the confirmed fraudulent pages utilize identical build files linked to just 27 shared commerce backends.
Shoppers should watch for distinct red flags when hunting for hardware deals online:
• Suspiciously uniform discounts ranging between 40 to 65 percent off retail pricing across entire product catalogs.
• Web addresses following rigid structural patterns, typically combining official brand names with filler words like store, direct, global, or hub under a .shop domain.
• Payment forms that lack standard third-party payment options such as PayPal, Apple Pay, or established banking processors.
With over 105,000 of these malicious domains remaining active as hosting providers ignore takedown requests, consumers are advised to navigate directly to manufacturer websites or verify sellers against official authorized dealer listings before checking out.