This cluster centers on 2957 connected domains tagged as GuLoader, NorthKorea, censys. The domains include salelegalsteroids.com, 192.210.186.208, gharnt.com, cloflart.com, id3702579photo-image-docs.com, www.almacensantangel.com, 64.95.12.162, blue-oceans.net, sixmexicos.com, baritonclick.online, 185.252.24.15, un1rw11q4u.com, ameyiando.com, niril.sbs, bursaelektriktamir.com, blankeyeo.com, umxtxhub.za.com, sunchernical.com, 18.194.67.137, servecdn.my and 2937 more. 606 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus.
Flagged domains in this cluster, salelegalsteroids.com, 192.210.186.208, gharnt.com, cloflart.com, id3702579photo-image-docs.com, www.almacensantangel.com, 64.95.12.162, blue-oceans.net, sixmexicos.com, baritonclick.online, 185.252.24.15, un1rw11q4u.com, ameyiando.com, niril.sbs, bursaelektriktamir.com, blankeyeo.com, umxtxhub.za.com, sunchernical.com, 18.194.67.137, servecdn.my and 586 more.
The connected infrastructure includes 1368 phone numbers (8334984700, 8446079115, 2395167035) with 9345 FTC complaints; 143 companies (Collections Inc, Direct, Inc, Credit Corp Solutions Inc.) with 8939528 CFPB complaints; 281 email addresses (lawnstone01@mobile.pinger.com, onlinebanking@alerts-bankofamerica.wmi3.com, candy05@sbcglobal.net).
Across all linked entities, consumers have filed 8952060 complaints with federal agencies.
Geographically, consumer complaints associated with this campaign are concentrated in Chicago, Illinois, Orlando, Florida, Las Vegas, Nevada, West Palm Beach, Florida, Houston, Texas. This regional pattern may indicate targeted operations or reflect where the scam has been most actively reported.
If you receive a call or text from any of these numbers, do not engage. Hang up immediately and do not call back. Never provide personal information or make payments to unknown callers. Do not click links to any of the flagged domains. If you have visited one, check your accounts for unauthorized activity and consider changing your passwords. If you were contacted by any of these companies, verify their legitimacy by looking up their official contact information independently — do not use phone numbers or links provided in the suspicious communication. Do not reply to suspicious emails or click any links or attachments they contain. Check the sender's domain carefully for misspellings or unusual variations. You can report suspicious contacts to the FTC at reportfraud.ftc.gov or to the FCC at consumercomplaints.fcc.gov.
This campaign was identified through automated analysis of FTC/FCC complaint databases, threat intelligence feeds, CFPB consumer complaints, email threat intelligence and entity relationship mapping.