One Server, Many Domains: Rotation a Domain List Cannot See
A family of unrelated-looking domains, retired and replaced on a schedule, all sitting on one server the whole time.
15 indicators · c2 · extensions · infrastructure · detection
We flag hostile hosts when they show up in our customers' browser telemetry. These are the write-ups behind that: how each campaign works, what infrastructure it runs on, and how to spot it in your own reports.
Every campaign documented here began the same way: an unexpected request, blocked by a customer's security policy and captured in real browser telemetry. On its own, a strange hostname might be nothing more than noise. But when the same host starts appearing across unrelated sites, it becomes a pattern worth investigating. We follow those signals, connect the dots, and document what we find here — with the latest campaigns first.
A family of unrelated-looking domains, retired and replaced on a schedule, all sitting on one server the whole time.
15 indicators · c2 · extensions · infrastructure · detection
Attacks that remove a hosted payment element and render a convincing copy in its place, so card details are typed into attacker-controlled markup on a page that still looks entirely correct.
2 indicators · magecart · skimmer · pci-dss · tag-manager
Skimmers that read their next-stage host out of a blockchain contract, so the operator can move infrastructure without ever going back into the sites they compromised.
5 indicators · magecart · skimmer · clickfix · web3 · c2
A Magecart cluster that pushes stolen card data down a WebRTC data channel instead of sending a request, so monitoring built to inspect requests sees a checkout behaving normally.
5 indicators · magecart · skimmer · webrtc · exfiltration
Attackers who generate a new subdomain for every victim, so blocking the host you saw yesterday achieves nothing today.
3 indicators · magecart · skimmer · dga · detection
Injected scam and scareware content that steals attention and trust rather than card numbers, which is exactly why it survives on a page longer than a skimmer would.
3 indicators · scareware · scam · injection · monetisation
An overlay that tells the visitor to fix a problem by pasting a command, turning the person into the delivery mechanism and leaving no malicious download to catch.
5 indicators · clickfix · social-engineering · websocket · c2
Skimmers served from domains registered one character away from a CDN you already trust, so the host survives the glance that a review gives it.
8 indicators · magecart · skimmer · typosquat · supply-chain
Extensions your visitors installed, running on your pages, reporting to a shared C2 cluster and taking session data with them.
16 indicators · extensions · c2 · session-theft · exfiltration
Packages you legitimately depend on, compromised upstream, arriving in your bundle through the same pipeline everything else uses.
7 indicators · supply-chain · npm · exfiltration · sri
We assess hosts continuously as they appear in browser telemetry, so classifications can change as new evidence emerges. We use two distinct tiers — Indicator of Compromise and Suspicious — to show how confident we are that a host represents a genuine threat. The telemetry behind that runs at thousands of data points a second, and you can watch it live on our public dashboard.
We have evidence the host is doing something hostile: serving skimmer code, collecting stolen card data, or staging a payload. If one shows up in your reports, it needs looking at.
Something about the host looks wrong but we can't confirm it's hostile yet. We flag it so you can see it, without calling it a confirmed finding. Some of these become Indicators of Compromise later and some turn out to be fine.
Both surface in the product: badges on your report rows, filters, and Watch alerts. Where a flagged host belongs to a campaign we have written up, its badge links straight through to the research — so the evidence behind a classification is one click from the report that raised it, and you can judge for yourself what it means for your site. See how threat intelligence works →
It starts with our own data. Hosts show up in the reports our customers already send us, the ones that look wrong get triaged and classified, and where somebody else has covered the same infrastructure we check our findings against theirs. Every write-up says which of those applies.
This runs all the time, so the feed is never finished. We add hosts as they appear, widen an entry when an attacker starts rotating subdomains, and pull a host back out when the evidence no longer holds up.
We describe what a host was seen doing: serving skimmer JavaScript, receiving card data. We don't make claims about who's running it or why.
An entry starting *. covers a domain and everything under it, so an attacker cycling through subdomains doesn't get away from it. We only do this when the attacker registered the domain themselves. If it's a real site that's been compromised, we stick to the exact host.
There are thousands of hosts in the feed and a few dozen write-ups here. That gap isn't a backlog we're working through.
Most of these domains don't last long. One gets registered, serves a skimmer for a week or two, then goes quiet. The attacker moves to a new subdomain, we widen our entry to cover the whole domain, and the original host stops mattering. If we wrote a page for every one of them, most would be about domains that were already dead.
The campaign is the part worth writing about. Attackers swap domains constantly, but they reuse the same techniques and delivery routes for months, sometimes years. That's what these pages cover, so they're still useful after every host in them has gone.
If a host named here is yours and we've got it wrong, email support@report-uri.com and tell us what it actually does.
If we're wrong, we take the host out of the feed and off this page. We don't just add a note saying it's disputed. The pages and the feed come from the same place, so the fix lands in both at once.
We check your reports against the feed as they arrive, so if one of these hosts turns up on your site you'll know about it straight away. It's one HTTP header, and nothing of ours runs on your pages.