This cluster centers on 420 connected domains tagged as iso, malware, stealer. The domains include dl.dropboxusercontent.com, s3.us-east-2.amazonaws.com, cdn.discordapp.com, aol.com, n9gov.com, 419scam.org, boardreader.com, consultant.com, weareelectricals.wordpress.com, guardian.co.uk, weareelectricals.com, grahamworthingtonspammer.wordpress.com, grahamworthingtonscammer.xanga.com, darkoozeripple.xanga.com, johnrlindensmith.blogspot.com, createspace.com, topix.com, img828.imageshack.us, img33.imageshack.us, img191.imageshack.us and 400 more. 3 of these domains have been flagged by threat intelligence feeds including Google Safe Browsing and URLhaus.
Flagged domains in this cluster, dl.dropboxusercontent.com, s3.us-east-2.amazonaws.com, cdn.discordapp.com.
The connected infrastructure includes 342 phone numbers (9056283715, 8777058586, 5086371451) with 230 FTC complaints; 74 companies (EQUIFAX, INC., BANK OF AMERICA, NATIONAL ASSOCIATION, TRANSUNION INTERMEDIATE HOLDINGS, INC.) with 9690415 CFPB complaints; 63 email addresses (sensepin@jabber.at, amaneesam@yahoo.co.jp, elizabeth.hens1@consultant.com).
Across all linked entities, consumers have filed 9691075 complaints with federal agencies.
Geographically, consumer complaints associated with this campaign are concentrated in San Antonio, TX, Everett, WA, Seattle, WA, Austin, TX, Santa Fe, NM. This regional pattern may indicate targeted operations or reflect where the scam has been most actively reported.
This campaign was identified through automated analysis of FTC/FCC complaint databases, threat intelligence feeds, CFPB consumer complaints, email threat intelligence and entity relationship mapping.