A sophisticated and expansive fraud network, codenamed "DoppelCart," has been uncovered, operating an astonishing network of over 119,000 fake e-commerce websites designed to harvest sensitive payment card information from unsuspecting consumers. Cybersecurity startup Nebty, based in Germany, brought this massive operation to light, detailing its extensive reach and insidious methods. The sheer scale of DoppelCart positions it as the largest publicly documented cluster of fake shops by domain count, significantly dwarfing previous records.
The majority of these fraudulent domains are registered under the .SHOP top-level domain (TLD), representing a substantial 2.72% of all registered sites within this specific TLD. This disproportionate usage highlights how threat actors are leveraging newer or less scrutinized TLDs to establish their illicit operations. Nebty’s latest analysis indicates that a significant portion of these DoppelCart-affiliated shops, over 105,000, remain actively engaged in their deceptive practices.
This discovery far surpasses the previous benchmark for such operations. The second-largest identified fake-shop cluster, known as "BogusBazaar," operated a network of 75,000 sites. While substantial in its own right, BogusBazaar’s reach pales in comparison to DoppelCart’s sprawling infrastructure. BogusBazaar was estimated to have facilitated approximately 850,000 fraudulent transactions, a number that DoppelCart could potentially exceed given its larger footprint.
The Anatomy of the DoppelCart Operation
Benedikt Scheungraber, CEO of Nebty, provided critical insights into the operational mechanics of DoppelCart. He revealed that an overwhelming 96% of the shops confirmed to be part of the DoppelCart network share identical build files. This uniformity suggests a highly organized and templated approach to setting up these fraudulent websites, indicating a centralized command and control or a shared development effort among the perpetrators. These sites resolve to 27 distinct commerce backends, suggesting a multi-pronged infrastructure designed for resilience and evasion.
The deceptive strategy employed by DoppelCart is multifaceted and highly effective in misleading consumers. The fake shops meticulously impersonate legitimate businesses by replicating crucial elements of their online presence. This includes wholesale copying of product catalogs, detailed descriptions, brand logos, and product imagery. In many instances, these fake sites go as far as to directly load assets, such as images and product data, from the servers of the authentic companies they are impersonating. This technique not only lends an air of legitimacy but also reduces the effort required for the fraudsters to populate their sites with content.
Scheungraber further elaborated that DoppelCart shops mimic a staggering 44,182 different brands. While this broad impersonation strategy is employed, there is a median of two cloned sites for each brand. However, certain popular brands have been targeted with a significantly higher intensity. Companies such as SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS have each been impersonated by over 30 individual fake shops. This concentrated effort on specific brands suggests a strategic targeting, possibly based on their popularity, product type, or perceived vulnerability of their customer base.

To further entice potential victims, these fraudulent websites frequently advertise substantial discounts, with many offering price reductions of up to 65%. This aggressive discounting strategy is a classic lure for bargain-hunting shoppers, who may overlook subtle red flags in their eagerness to secure a seemingly exceptional deal. The combination of visually authentic storefronts and deeply discounted prices creates a powerful illusion that can easily deceive even vigilant consumers.
The Technical Details of Data Theft
Nebty’s investigation delved into the technical underpinnings of the DoppelCart operation, particularly focusing on the checkout process. During their analysis of several checkout pages within the DoppelCart cluster, researchers identified malicious code specifically designed to capture sensitive payment card and cardholder information. This code is embedded within the checkout forms, meticulously waiting to intercept data as it is entered by unsuspecting customers.
The captured data includes all the standard fields required for an online transaction: the full card number, the expiration date, the Card Verification Value (CVV) or Card Security Code (CSC), and the cardholder’s name. This comprehensive data collection is crucial for the attackers, as it provides them with all the necessary information to make fraudulent purchases or to sell the stolen data on the dark web.
A particularly concerning aspect of DoppelCart’s operation is the real-time transmission of this stolen data. Nebty reports that each piece of captured data is immediately sent over WebSockets to a command-and-control (C2) server. This instantaneous exfiltration minimizes the window of opportunity for detection and maximizes the speed at which the stolen information can be utilized by the perpetrators. The use of WebSockets allows for a persistent, bidirectional communication channel, enabling rapid data transfer and potentially more sophisticated real-time manipulation of the checkout process.
Furthermore, the malicious code employed by DoppelCart has the capability to relay one-time confirmation codes issued by a victim’s bank. These codes, often used for two-factor authentication or to verify transactions, are a critical security layer. By intercepting and forwarding these codes, the attackers can bypass these vital security protections, making it significantly easier to complete fraudulent transactions without triggering alerts. This capability represents a significant escalation in the sophistication of the attack.
The Broader Impact and Deceptive Practices
The ramifications of DoppelCart’s widespread operation extend beyond direct financial loss for consumers. Nebty’s report highlights a disturbing tactic where some of the fake stores display the legitimate support contact information of the brands they are impersonating. This can lead to a secondary layer of deception. Customers who fall victim to these scams, purchase products that are never delivered, and subsequently try to seek assistance, may inadvertently contact the actual company. This can result in frustration for both the victim and the legitimate business, as the real company is forced to deal with the fallout of crimes committed by imposters.
Nebty’s efforts to address the issue have met with limited success. Scheungraber indicated that the company attempted to contact the primary hosting provider for the DoppelCart sites. However, these outreach efforts reportedly received no response, underscoring the challenges in dismantling such large-scale, decentralized criminal enterprises. The lack of cooperation from hosting providers can significantly hinder the takedown process, allowing these operations to persist.

In response to the threat, Nebty has taken a proactive step by creating a searchable database. This resource is designed to empower businesses to identify instances of DoppelCart impersonation and brand abuse. By providing companies with the tools to detect these fraudulent activities, Nebty aims to facilitate swift action to protect their brands and their customers. The database allows companies to investigate potential compromises and implement appropriate countermeasures.
Historical Context and Future Implications
The emergence of DoppelCart is not an isolated incident but rather an evolution in the tactics employed by cybercriminals in the e-commerce space. For years, various forms of e-skimming and fake shop operations have plagued online retail. Early iterations often involved simpler scripts deployed on compromised legitimate websites. However, the sophistication has grown, with dedicated fake shop networks becoming increasingly prevalent.
The scale of DoppelCart suggests a well-funded and organized criminal syndicate. The investment in developing and maintaining such a vast network of domains, coupled with the technical expertise to implement advanced data theft techniques, points towards a professional criminal operation. This level of organization often implies a long-term strategy, making them harder to disrupt than smaller, opportunistic groups.
The implications of DoppelCart’s activities are far-reaching. For consumers, it means increased vigilance is paramount when shopping online. The proliferation of fake shops erodes trust in online retail and can lead to significant financial and personal data compromises. For legitimate businesses, it represents a direct threat to their brand reputation, customer loyalty, and revenue. The cost of dealing with brand impersonation, including customer support overhead and brand protection measures, can be substantial.
The reliance on newer TLDs like .SHOP also presents a challenge for domain registrars and cybersecurity firms. These TLDs may have less established monitoring and enforcement mechanisms compared to legacy TLDs, providing a fertile ground for illicit activities. The ability of DoppelCart to leverage such a large percentage of a specific TLD also raises questions about the adequacy of current registration and vetting processes.
The ongoing battle against these sophisticated fraud networks requires a multi-faceted approach. This includes enhanced collaboration between cybersecurity firms, law enforcement agencies, domain registrars, and e-commerce platforms. Technological solutions, such as advanced AI-driven threat detection and real-time monitoring, are crucial. Equally important are public awareness campaigns to educate consumers about the risks of online shopping and how to identify fraudulent websites. The DoppelCart operation serves as a stark reminder of the persistent and evolving threats within the digital economy and the continuous need for robust security measures.






