Brand Impersonation at Scale: How One IP Address Ran a Multi-Brand Foreclosure Fraud Factory
By Scrutex Published
A distressed borrower searches for their lender's foreclosure helpline, clicks the top result, and calls the number on a page that looks exactly like their bank. The page is fake. The number is a fraudster's. And the same operator running that page is running forty more, each cloning a different financial brand, all from one server.
Brand impersonation is the abuse of a company's name, domain, logo, or design to deceive its customers, usually to steal money or data. In its industrialised form, one actor spins up dozens of lookalike sites across many brands, ranks them in search, and harvests victims at scale. That is exactly what Scrutex found behind a single IP address in March 2026.
This report walks through the investigation: how one flagged domain led to a fraud operation spanning more than 70 lookalike domains and three hosting clusters, which brands it cloned, how the foreclosure scam converts a search into a financial loss, the Android malware running on the same infrastructure, and why single-brand monitoring missed all of it. Scrutex assesses with high confidence that this is a serial, organised, multi-brand fraud operation targeting India's financial sector, with a staged inventory of mail-ready domains ready for the next wave.
Every finding, statistic, and indicator below comes from Scrutex's own investigation. The impersonated brands are named as victims of the abuse, not as sources.
In This Post
- What did Scrutex uncover?
- How did one domain lead to a fraud factory?
- Which brands were impersonated?
- How does the foreclosure scam actually work?
- What does the victim journey look like?
- Beyond brand fraud: the CraxsRAT connection
- The infrastructure: three clusters and a mail-ready arsenal
- What is at stake for customers and the brand?
- Why did single-brand monitoring miss this?
- Indicators of compromise
- What Scrutex has done
- What financial-sector defenders should do now
- How Scrutex detects and dismantles these campaigns
- Key takeaways
- FAQ
What did Scrutex uncover?
Scrutex traced a single threat actor operating industrialised brand impersonation across India's financial sector. Starting from one fraudulent foreclosure domain, the investigation pivoted on the hosting IP and surfaced an entire operation.
The numbers describe the scale.
| Metric | Finding |
|---|---|
| Lookalike domains | More than 70 |
| Financial brands cloned | At least six major Indian lenders |
| Hosting clusters | Three, across SpectraIP and AWS |
| Major-vendor detections | None at the time of discovery |
| Mail-enabled staging domains | 11 or more, configured for phishing |
| Takedown | Initiated across the active cluster |
The most striking part was the stealth. At the time of the investigation, not one major security vendor had flagged these domains or the malware payloads on the same infrastructure. They had bypassed standard threat feeds entirely. Scrutex was first to map the cluster and moved to take it down.
The operation was not limited to fake support pages. The same infrastructure ran lottery scams, fake franchise schemes, crypto account sales, and Android remote access trojan delivery. Each domain was a revenue stream. The infrastructure was the business.
How did one domain lead to a fraud factory?
The entry point was a fraudulent domain impersonating a lender's customer care and foreclosure services. It had been registered on March 6 and first posed as a support page for one lender, then was repurposed overnight to target a different financial brand. That rotation was the first clue: this was not a one-off page, it was a reusable asset.
Scrutex pivoted on the hosting IP, 5.182.209.28, at SpectraIP B.V. in Amsterdam. That pivot did not return one or two related sites. It returned more than 20 active scam domains on that single address, impersonating multiple Indian lenders and running side operations in parallel.
Three signals tied the domains to one operator. They shared nameservers (NS.PWXS.ME and NS.PWXS.NL). They used WHOIS privacy across the board to hide registration details. And they reused page templates and contact details from site to site. The domains were young, most registered within the previous 30 days, while the IP itself had been active far longer. That pattern, fresh domains on a long-lived host, points to persistent infrastructure that simply rotates new domains onto it.
Which brands were impersonated?
The operator cloned established lenders, then extended into franchise and gaming brands to widen the victim pool. The table below lists the financial-sector impersonations and the contact indicators the actor exposed to victims.
| Brand cloned | Fraudulent domain(s) | Fraud type | Contact indicators |
|---|---|---|---|
| Tata Capital | tatacapitalforclosure.com, tatacapitalloan.in, tatacapitalclosure.com, capitalloanforeclosure.com | Foreclosure fraud | +91 9341065312, customercare@tatacapital.online |
| Lendingkart | lendingkartloan.in, lendingkarts.in, lendingkartforclosure.com | Foreclosure fraud | +91 9341048522, care@lendingkart.org |
| IIFL Finance | iiflforeclosure.com | Foreclosure fraud | +91 9341048522, customercare@iifl.online |
| Dhani Finance | dhanifinancel.com, dhanifinancelimited.co.in | Loan fraud | +91 7814948875, info@dhanifinanceltd.online |
| Piramal Finance | piramalforeclosure.com | Foreclosure fraud | 403, held in reserve |
| Al Khair Bank | alkhairbankloans.com | Loan fraud | Under investigation |
Beyond lending, the same actor ran franchise scams cloning Tata 1mg (tata1mgfranchise.com) and Blinkit (blinkit-franchisee.com, with a payment gateway embedded), plus a gaming account-takeover page targeting Brawl Stars players (brawlstarsfreegems.us).
Two shared phone numbers removed any doubt about attribution. The number +91 9341048522 appears on both the IIFL and Lendingkart impersonation domains. The number +91 9341065312 is shared across the Tata Capital domains. Same hosting, same nameservers, same templates, shared contact details: one operator.
The quality set these sites apart. These were not crude pages with broken layouts. They carried proper meta descriptions, keyword-stuffed metadata aimed at real loan-related queries, brand-consistent design, and believable menu structure. Some hotlinked the genuine brand's own logos, CSS, and JavaScript to build a near-pixel-perfect replica. To a customer under financial stress, they were hard to tell apart from the real thing. One domain, piramalforeclosure.com, returned a 403, which suggests it was staged and held in reserve for later activation.
How does the foreclosure scam actually work?
The method is repeatable and tuned for conversion. It exploits one gap: the delay between a customer needing help and the real institution responding.
- Bulk domain registration. Register brand-adjacent lookalikes in volume, using words like foreclosure, finance, loan, and customercare, with WHOIS privacy enabled, and separate lander domains on other IPs to act as mail servers.
- SEO weaponisation. Stuff pages with high-intent keywords such as "foreclosure", "customer care number", "loan closure", and "EMI payment" so they rank alongside or above the official properties.
- Content deployment and rotation. Publish support pages that mirror the target brand, then rotate the brand every few weeks, one lender this week, another the next, to slip under single-brand monitoring.
- Contact channel exposure. Surface fraudulent phone numbers, customer care emails, and WhatsApp links as the first thing a worried customer sees.
- Off-platform engagement. Once the victim calls or emails, the operator builds trust with professional-sounding replies and issues fabricated documents such as foreclosure letters and settlement notices.
- Financial extraction. Direct the victim to pay a fake foreclosure amount into a fraudulent account by UPI, transfer, or payment link, and harvest KYC documents, PAN and Aadhaar details, and loan data for later abuse.
The reason it converts is simple. The customer is already expecting a foreclosure process, is under time pressure, and has no reason to distrust a professional-looking site that ranks in Google for exactly what they searched.
What does the victim journey look like?
This is the path Scrutex observed from search to loss.
- The customer submits a foreclosure request through their branch.
- The official response is delayed, which opens the gap the actor exploits.
- The customer searches online for "foreclosure support" or a "customer care number".
- A fraudulent site appears in the results and presents itself as an official channel.
- The customer contacts the phone number or email listed on the site.
- The impersonator responds with professional communication and builds trust.
- The customer receives a fabricated foreclosure letter and a payment link, and the fraud completes.
The data-capture step is deliberate. The fraudulent forms ask for the outstanding loan amount and current EMI alongside name, phone, and email. That is not a generic contact form. It qualifies the victim and extracts financial intelligence before the operator even makes contact.
Beyond brand fraud: the CraxsRAT connection
Mapping the IP surfaced something that extends this actor's profile past financial fraud. Two domains on the same host, craxsrat-craxrat-craxsrats-craxs-rat-official.net and craxs-rat-selller.com, were advertising and distributing CraxsRAT, an Android remote access trojan. The metadata referenced "CraxsRAT 7.9" and linked to a Telegram channel with more than 210 subscribers marketing it as an Android remote access tool.
This matters because the same infrastructure hosting brand impersonation is also distributing malware built for device takeover, surveillance, and credential theft. It raises the actor's profile from financial fraudster to a more capable operator with both social engineering and technical tooling. There is a realistic possibility that victims who engage the foreclosure pages could also be pushed malware through the same pipeline. The presence of a crypto-account resale domain (trustedaccountsseller.com) and several lottery scams confirms an operator monetising across many vectors at once.
The CraxsRAT sales channel also points to a wider pattern. Malware, stolen data, and fraud kits increasingly change hands on Telegram, which is why continuous Telegram channel monitoring now sits alongside domain and dark web coverage in any serious external-risk programme.
The infrastructure: three clusters and a mail-ready arsenal
The investigation did not stop at the first IP. By extracting the domains behind the fraudulent contact emails and pivoting on secondary addresses, Scrutex mapped three distinct clusters across two providers.
| Cluster | IP(s) | Provider | Role | Status |
|---|---|---|---|---|
| 1 | 5.182.209.28 | SpectraIP B.V. (Amsterdam) | 20+ active scam sites, CraxsRAT and scam distribution | Takedown initiated |
| 2 | 15.197.148.33, 3.33.130.190 | Amazon AWS Global Accelerator | 50+ staging and lander domains, email infrastructure | Monitoring |
| 3 | 76.223.67.189 | Amazon AWS | Additional phishing infrastructure and pivots | Pivoting |
Cluster 2 is the part that should worry defenders most. The email domains behind the fraudulent contact points resolve to a pair of AWS Global Accelerator addresses, and behind them sits a large inventory of pre-registered domains. They currently redirect to lander pages, but many carry active MX records configured on GoDaddy. That means the operator can send and receive email from them: fake customer care replies, fabricated foreclosure letters, and payment instructions.
These staging domains follow the same brand patterns, with variants such as dhanifinanceltd.online, lendingkartfinanceslimited.online, tatacapitalltd.com, tatacapital.online, and iifl.online, plus a run of "cantatacapital" variations across many TLDs. They are not active scam pages yet. They are the next wave, mail-ready and waiting for content.
That changes the assessment. This is not only an active campaign. It is a premeditated pipeline: register in bulk, configure mail, stage landers, and activate on demand. Every domain with an MX record is a future phishing vector, and the spread across SpectraIP and AWS gives the operator resilience and failover.
What is at stake for customers and the brand?
This abuse sits directly on top of customer servicing and payments, which is why it should be treated as fraud infrastructure, not a brand dispute. Four kinds of harm follow.
- Customer financial loss. Victims are induced to pay fake foreclosure amounts into fraudulent accounts by UPI, bank transfer, or embedded payment links. Once the money moves, it is effectively unrecoverable.
- Identity and KYC exposure. PAN, Aadhaar, loan numbers, mobile numbers, and repayment details are harvested through fake verification flows, which feeds downstream identity fraud long after the first contact.
- Fake document fraud. Fabricated foreclosure letters, settlement notices, and no-objection certificates create false assurance. The victim believes the loan is resolved when it is not, which delays real resolution and deepens the loss.
- Brand and reputational damage. Even where no money is lost, customers attribute the experience to the real institution. That triggers complaints, trust erosion, regulatory scrutiny, and escalation on social media.
The through-line is timing. Every hour a fraudulent domain stays live is a window for a real customer to lose money and for the brand to absorb the blame.
Why did single-brand monitoring miss this?
Because the operator was built to defeat it. Most brand and phishing alerting keys on a single brand name and a few domains. This actor rotated the target brand every few weeks and shared one set of infrastructure across many brands at once. The page that triggered the first alert had, days earlier, been cloning a different lender.
Two facts make the point. First, at discovery, none of the major security vendors had flagged the domains, so anyone relying on standard feeds saw nothing. Second, the strongest evidence was never a brand name at all. It was the shared IP, the shared nameservers, and the two reused phone numbers. Single-brand keyword monitoring catches the attack after the rotation, once customers have already been exposed.
Effective defence needs multi-signal detection: shared hosting and IP correlation, phone numbers reused across campaigns, hosting and template fingerprints, bulk-registration patterns, and content and form similarity. Scrutex found the wider operation from a single flagged page precisely because it was already tracking the actor's infrastructure, not waiting for a brand name to surface.
Indicators of compromise
Block and monitor everything below. This is the consolidated registry across all three clusters: active scam domains, staging and lander domains, mail-ready domains, IPs, phone numbers, and email addresses. It is a working document, and the list is expected to grow as pivoting continues.
Active scam domains (Cluster 1, SpectraIP)
tatacapitalforclosure[.]com, tatacapitalloan[.]in, tatacapitalclosure[.]com, capitalloanforeclosure[.]com, lendingkartloan[.]in, lendingkarts[.]in, lendingkartforclosure[.]com, iiflforeclosure[.]com, piramalforeclosure[.]com, dhanifinancel[.]com, dhanifinancelimited[.]co[.]in, alkhairbankloans[.]com
Scam and malware domains (Cluster 1)
tata1mgfranchise[.]com, blinkit-franchisee[.]com, brawlstarsfreegems[.]us, trustedaccountsseller[.]com, punjablotteriesticket[.]com, klonlinebooking[.]com, keralamlotteryticket[.]com, craxsrat-...-official[.]net, craxs-rat-selller[.]com, suiclaimtrade[.]com
Staging and lander domains (Cluster 2, AWS), Dhani Finance
dhanifinanceltd[.]online, dhanifiananceltd[.]online, dhanifinancecompany[.]com, dhanifinancesindiaonline[.]com, dhanifince[.]online, dhanifinancing[.]com, dhanifinanance[.]com, dhanifinance[.]live
Staging and lander domains (Cluster 2), Lendingkart
lendingkartfinancelimited[.]co, lendingkartskartforeclosures[.]online, lendingkartfinanceslimited[.]online, lendingkart[.]co, lendingkart[.]org, lendingkartforeclosures[.]in, lendingkartcustomersupport[.]com, lendingkart[.]co[.]in, carelendingkart[.]com
Staging and lander domains (Cluster 2), Tata Capital and cantata variants
tatacapital[.]online, tatacapitalltd[.]com, tatacapitaluae[.]com, tatacapitalco[.]com, tatacapital[.]co, tatacapital[.]org[.]in, tatacapitallimited[.]in, tatacapital[.]net[.]in, cantatacapital[.]info, cantatacapital[.]org, cantatacapital[.]us, cantatacapital[.]store, cantatacapital[.]xyz, cantatacapital[.]net, cantatacapital[.]co, aristatacapital[.]co[.]uk
Staging and lander domains (Cluster 2), IIFL and other
iifl[.]online, iifl[.]net, iiflcapitals[.]com, iiflbuissness[.]info, punjablotteryticket[.]online, keralamlotteryticket[.]com
Mail-ready domains (active MX on GoDaddy)
dhanifinanceltd[.]online, lendingkartfinanceslimited[.]online, lendingkartfinancelimited[.]co, lendingkart[.]org, tatacapitalltd[.]com, tatacapitaluae[.]com, tatacapitalco[.]com, tatacapital[.]co, tatacapital[.]org[.]in, tatacapital[.]online, iifl[.]online
IP addresses
5.182.209.28 (SpectraIP B.V., NL), 15.197.148.33 (AWS Global Accelerator), 3.33.130.190 (AWS Global Accelerator), 76.223.67.189 (AWS phishing pivot)
Phone indicators
+91 93410 48522 (IIFL and Lendingkart), +91 93410 65312 (Tata Capital), +91 78149 48875 (Dhani), +91 98218 48801 (OSINT pivot), +91 89177 43062 (Punjab lottery), 62074 98540 (additional)
Email indicators
customercare@iifl[.]online, customercare@tatacapital[.]online, care@lendingkart[.]org, info@dhanifinanceltd[.]online, info@tatacapitalforclosure[.]com
What Scrutex has done
Takedown is already underway across the active cluster, with tracking on the rest.
| Action | Detail | Status |
|---|---|---|
| Domain identification | 22 or more domains documented and assessed | Complete |
| Registrar takedown | Abuse request raised with the domain registrar (Hosting Concepts B.V., registrar.eu; abuse@registrar.eu) | Raised |
| Hosting escalation | Escalation to SpectraIP B.V. for IP-level disruption, given the single-IP convergence of the active cluster | In progress |
| Blacklisting | Domains submitted to Google Safe Browsing, abuse databases, and blocklist feeds to trigger browser warnings | In progress |
| Campaign tracking | Continuous monitoring for new registrations, content rotations, and activation of reserve domains such as piramalforeclosure.com | Ongoing |
The single-IP convergence of the active cluster is useful here: it is both the investigative pivot and a single point from which to disrupt the whole active cluster. The AWS staging cluster is under monitoring so that a domain moving from dormant to active, or a mail-ready domain beginning to send, is caught at activation rather than after the next round of victims.
What financial-sector defenders should do now
Treat this as fraud infrastructure, not a domain dispute. The abuse touches customer servicing and payments directly, and every hour a domain stays live is a window for customer loss. The priorities:
- Issue a customer advisory. Warn customers about the fraudulent domains, emails, and phone numbers, and tell them to use only the contact channels published on your official site.
- Brief internal teams. Circulate the intelligence to branch operations, collections, call centres, fraud and risk, legal, and digital teams so related complaints are recognised and escalated fast.
- Defend the search results. Suppress the fraudulent domains and strengthen the ranking of your official support and foreclosure pages. Publish verified customer care and foreclosure contact details prominently.
- Investigate the payment trail. Trace the UPI IDs, beneficiary accounts, and payment links tied to the actor, and check for mule or collection accounts.
- Monitor for clones and MX activation. Watch for domains that mirror your site by visual assets, CSS and JavaScript fingerprints, page structure, and form replication, and alert the moment a staged domain becomes mail-ready.
How Scrutex detects and dismantles these campaigns
An operation built as a pipeline needs more than manual monitoring, and this is where Scrutex Brand Insights fits. It discovers lookalike and brand-adjacent registrations across many TLDs using fuzzy matching and DNS-level pivoting, so dormant domains, like the mail-ready AWS inventory in this campaign, surface before they are weaponised. It detects near-pixel-perfect clones by tracking your brand's own visual assets, CSS and JavaScript fingerprints, page structure, and form patterns, and it flags MX activation the moment a staged domain becomes capable of sending mail.
Because fraud moves off the web into chat and social, Brand Insights extends to messaging and social platforms, including impersonating profiles, fraudulent customer care ads, and channels distributing Android malware such as CraxsRAT. Threat Insights correlates the shared infrastructure, IPs, nameservers, and reused phone numbers that connect one page to a whole operation, and Data Exposure Insights watches for the harvested KYC and credentials that fuel the next stage. Confirmed findings feed takedown coordination with registrars and hosting providers.
The result that matters is time. Scrutex turned a single flagged page into the discovery of a 70-plus-domain operation because it correlated signals rather than chasing one brand name. If your organisation runs in lending, insurance, or any customer-facing sector, you can start a free external scan of your own brand exposure at scrutex.ai and see what is already out there.
Key takeaways
- Brand impersonation is industrialised. One actor ran more than 70 lookalike domains across three hosting clusters, cloning at least six Indian lenders plus franchise and gaming brands, all from shared infrastructure.
- The sites are convincing. Keyword-stuffed SEO, brand-consistent design, and hotlinked logos and code make the clones hard to tell from the real support pages, especially for a customer under stress.
- Foreclosure fraud weaponises the response gap. The scam works in the delay between a customer needing help and the lender replying, converting a search into a payment into a fraudulent account.
- The same infrastructure spreads malware. CraxsRAT, an Android remote access trojan, was sold from the same IP and marketed through a Telegram channel, widening the threat beyond financial fraud.
- A mail-ready arsenal is staged. More than 11 AWS-hosted domains carry active MX records, ready to run phishing as the next wave.
- Single-brand monitoring is not enough. The strongest evidence was shared IPs, nameservers, and reused phone numbers, not a brand name. Multi-signal detection catches the operation before the rotation.
Frequently Asked Questions
Q: What is brand impersonation?
A: Brand impersonation is the abuse of a company's name, domain, logo, or design to deceive its customers, usually to steal money or data. It ranges from a single fake page to industrialised operations that clone many brands across dozens of lookalike domains and rank them in search.
Q: What is a foreclosure scam?
A: A foreclosure scam impersonates a lender's loan-closure or customer care service to trick borrowers into paying a fake foreclosure amount into a fraudulent account. Fraudsters publish lookalike websites, list fake helpline numbers, and send fabricated foreclosure letters and payment links.
Q: How did Scrutex link so many domains to one threat actor?
A: By pivoting on shared infrastructure rather than brand names. The domains resolved to the same IP, used the same nameservers, reused page templates, and shared two phone numbers across different brands, which together attribute the campaign to a single operator with high confidence.
Q: Why did no antivirus or security vendor flag these sites?
A: The domains were young, used WHOIS privacy, and rotated brands, so they had not yet appeared in standard threat feeds. At discovery, none of the major vendors had flagged them. Infrastructure-level correlation found them where signature-based feeds did not.
Q: What is CraxsRAT and why does it matter here?
A: CraxsRAT is an Android remote access trojan used for device takeover, surveillance, and credential theft. It was being sold from the same IP as the fraud sites and marketed on Telegram, which shows the operator had both social engineering and technical malware capabilities.
Q: What are MX records and why are staged domains with MX dangerous?
A: MX records tell the internet where a domain receives email. A staged lookalike domain with active MX records can send and receive mail, so it is ready to run phishing, deliver fake customer care replies, and issue fraudulent payment instructions the moment it is activated.
Q: How can a business detect brand impersonation early?
A: Combine lookalike domain discovery across many TLDs, clone detection based on visual assets and CSS and JavaScript fingerprints, monitoring of reused phone numbers and shared hosting, and alerts on MX activation. Digital risk protection platforms automate this and coordinate takedowns.
Q: Is it legal to publish the impersonated brand names and indicators?
A: This report is classified TLP:CLEAR and names brands only as victims of impersonation, alongside the domains and indicators abusing them, which is standard practice for a public fraud advisory. Organisations should still act on the indicators through their own legal and security channels.
Q: What should customers do if they suspect a fake lender site?
A: Do not call numbers or pay amounts listed on a site reached through search. Use only the contact details on the lender's official website or app, verify any foreclosure letter through an official channel, and never share PAN, Aadhaar, or payment details with an unverified caller.
The domains in this campaign are active, the customers are real, and the financial risk is immediate. The organisations that get hurt are rarely the ones without a lookalike out there. They are the ones who hear about it from a defrauded customer first.
Scrutex found this operation by correlating one flagged page against the actor's wider infrastructure, then moved to take it down. If your brand operates in financial services or any customer-facing sector, continuous external monitoring and takedown means you learn about the next fraud factory before your customers do. Start with a free scan of your brand exposure at scrutex.ai.