Team Cymru Validates ShinyHunters-Linked Phishing Infrastructure on Mevspace

Summary
Team Cymru used passive network telemetry to identify two Mevspace IPs and more than 40 victim-themed domains consistent with Push Security’s Cluster A phishing infrastructure reporting, while noting the findings do not independently attribute the activity.
Key points
- Two IPs on Mevspace AS201814, 149.50.97.174 and 149.50.127.228, showed infrastructure patterns consistent with Push Security’s Cluster A reporting.
- More than 40 victim-themed domains were linked to the IPs using registrar, nameserver, recency, and hosting criteria.
- The domains targeted organizations and services across education, finance, retail, cryptocurrency, identity, and taxation themes.
- The analysis identified numeric-token brand domains and Binance typosquats designed to resemble legitimate URLs.
- A BT-Panel certificate and Doko-branded dokopanel.com were observed, but the article cautions these artifacts do not prove operator identity or control.
- The activity uses phishing pages to capture credentials and MFA, potentially enabling access to enterprise identity providers and connected SaaS services.
- Team Cymru published repeatable queries and indicators for defenders to hunt related infrastructure as domains rotate.
Article Details
- Attack Vectors
- Voice phishing combined with adversary-in-the-middle credential capture against enterprise identity providers and cryptocurrency platforms.
- Victims are directed to brand-themed internal identity, support, passkey, SSO, or credential-verification pages that capture credentials and MFA.
- Some Binance-themed domains use nested hostnames designed to make the URL bar appear to show binance.com or binance.us.
- Captured credentials and MFA may be used in attempts to access identity providers and connected SaaS environments; the article does not confirm successful access.
- Defensive Notes
- Hunt Mevspace AS201814 infrastructure using the reported domain patterns together with the NICENIC/CNOBIN registrar and 1984.is/1984hosting.com nameserver fingerprint.
- Use the reported IPs, domains, client.js hashes, and JA3 fingerprints as pivot points; the article notes that domains should be assessed against the full fingerprint because passive DNS can contain unrelated tenants and noise.
- Monitor for newly deployed domains and infrastructure through scheduled searches, since Cluster A operators rotate domains quickly.
- Treat BT-Panel, dokopanel.com, and infrastructure overlap as context rather than proof of attribution or control by a specific individual.
- The reported peer traffic includes CDN and scanner activity; the article cautions against treating those observations alone as evidence of operator activity.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | 118507coinbase[.]com | Cluster A-aligned numeric-token Coinbase-themed phishing domain associated with 149.50.127.228. |
| DOMAIN | 412721coinbase[.]com | Cluster A-aligned numeric-token Coinbase-themed phishing domain associated with 149.50.127.228. |
| DOMAIN | 419256crypto[.]com | Cluster A-aligned numeric-token cryptocurrency-themed phishing domain associated with 149.50.127.228. |
| DOMAIN | 501938binance[.]com | Cluster A-aligned numeric-token Binance-themed phishing domain associated with 149.50.127.228. |
| DOMAIN | 53253binance[.]com | Cluster A-aligned numeric-token Binance-themed phishing domain associated with 149.50.127.228. |
| DOMAIN | 852319-ndax[.]com | Cluster A-aligned numeric-token NDAX-themed phishing domain associated with 149.50.127.228. |
| DOMAIN | 953536-cb[.]com | Cluster A-aligned numeric-token domain associated with 149.50.127.228. |
| DOMAIN | account-ndax[.]com | Cluster A-aligned victim-themed phishing domain associated with 149.50.97.174 and 149.50.127.228. |
| DOMAIN | account-ndax[.]io | Cluster A-aligned NDAX-themed phishing domain associated with 149.50.127.228. |
| DOMAIN | accounts-bitpanda[.]com | Cluster A-aligned victim-themed domain associated with 149.50.127.228. |
| DOMAIN | accounts-nexo[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | amazoninternal[.]com | Cluster A-aligned victim-themed phishing domain associated with 149.50.97.174. |
| DOMAIN | atocalculation[.]com | Australian Taxation Office-themed domain associated with Cluster A infrastructure. |
| DOMAIN | binanapi-912512[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | brixmorssoo[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | crypto-ato[.]com | Australian tax-filing and cryptocurrency-themed domain associated with 149.50.127.228; the article says its specific panel variant is unconfirmed. |
| DOMAIN | device-verizon[.]com | Cluster A-aligned Verizon-themed domain associated with 149.50.127.228. |
| DOMAIN | dokopanel[.]com | Doko-branded hosting-layer artifact colocated with Cluster A-aligned infrastructure; the article says this does not prove control by a specific individual. |
| DOMAIN | help-cointracker[.]com | Cluster A-aligned victim-themed domain associated with 149.50.127.228. |
| DOMAIN | koinlylegal[.]io | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | legal-koinly[.]io | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | lvmhinternal[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | meridian-saving[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | mydicksmanager[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | mydisneyconnect[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | mydisneymanager[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | mydisneysso[.]com | Cluster A-aligned victim-themed phishing domain resolving to 149.50.97.174. |
| DOMAIN | mydropboxinternal[.]com | Domain included in the article's named-domain validation query for phishing infrastructure. |
| DOMAIN | myiqeq[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | myjbhifi[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | mykkrconnect[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | mynavmanadbsnsger[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | mynavmanagbsnsjser[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | mynikemanager[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | mypetcomanager[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | mypublixmanager[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | mypurpleconnect[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | mypurpledirect[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | mypurpleidsso[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | mypurplemanager[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | myupennmanager[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | myvaneckmanager[.]com | Cluster A-aligned victim-themed domain associated with 149.50.127.228. |
| DOMAIN | myvanecksso[.]com | Cluster A-aligned victim-themed domain associated with 149.50.127.228. |
| DOMAIN | myxerointernal[.]com | Domain included in the article's named-domain validation query for phishing infrastructure. |
| DOMAIN | myyalemanager[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | overview-gmail[.]com | Cluster A-aligned domain associated with 149.50.127.228. |
| DOMAIN | purpleidconnect[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | restriction-nexo[.]com | Cluster A-aligned victim-themed domain associated with 149.50.127.228. |
| DOMAIN | safety-river[.]com | Cluster A-aligned domain associated with 149.50.127.228. |
| DOMAIN | shift4internal[.]com | Cluster A-aligned victim-themed phishing domain associated with 149.50.97.174. |
| DOMAIN | vault-blofin[.]com | Cluster A-aligned victim-themed domain associated with 149.50.97.174. |
| DOMAIN | verification12589[.]com | Generic credential-verification phishing domain associated with 149.50.97.174. |
| DOMAIN | verify91358[.]com | Generic credential-verification phishing domain associated with 149.50.97.174. |
| HOSTNAME | admin[.]118507coinbase[.]com | Admin subdomain of a Cluster A-aligned Coinbase-themed phishing domain. |
| HOSTNAME | admin[.]412721coinbase[.]com | Admin subdomain of a Cluster A-aligned Coinbase-themed phishing domain. |
| HOSTNAME | admin[.]419256crypto[.]com | Admin subdomain of a Cluster A-aligned cryptocurrency-themed phishing domain. |
| HOSTNAME | admin[.]501938binance[.]com | Admin subdomain of a Cluster A-aligned Binance-themed phishing domain. |
| HOSTNAME | admin[.]852319-ndax[.]com | Admin subdomain of a Cluster A-aligned numeric-token NDAX-themed phishing domain. |
| HOSTNAME | admin[.]account-ndax[.]com | Admin subdomain of a Cluster A-aligned NDAX-themed phishing domain. |
| HOSTNAME | admin[.]account-ndax[.]io | Admin subdomain of a Cluster A-aligned NDAX-themed phishing domain. |
| HOSTNAME | admin[.]device-verizon[.]com | Admin subdomain of a Cluster A-aligned Verizon-themed domain. |
| HOSTNAME | admin[.]dokopanel[.]com | Admin subdomain of the Doko-branded hosting-layer artifact colocated with Cluster A-aligned infrastructure. |
| HOSTNAME | admin[.]help-cointracker[.]com | Admin subdomain of a Cluster A-aligned CoinTracker-themed domain. |
| HOSTNAME | cp[.]myyalemanager[.]com | Control-panel or admin-endpoint pattern on the Yale-themed phishing domain associated with 149.50.97.174. |
| HOSTNAME | l6[.]restriction-nexo[.]com | Subdomain of a Cluster A-aligned Nexo-themed domain associated with 149.50.127.228. |
| HOSTNAME | www[.]binance[.]com[.]53253binance[.]com | Cluster A-aligned Binance-themed hostname designed to appear like binance.com in a truncated URL bar. |
| HOSTNAME | www[.]binance[.]us[.]53253binance[.]com | Cluster A-aligned Binance-themed hostname designed to appear like binance.us in a truncated URL bar. |
| IPV4 | 149[.]50[.]127[.]228 | Cluster A-aligned phishing infrastructure hosted on Mevspace AS201814. |
| IPV4 | 149[.]50[.]97[.]174 | Cluster A-aligned phishing infrastructure hosted on Mevspace AS201814. |
| MD5 | 15af977ce25de452b96affa2addb1036 | JA3S TLS fingerprint provided for hunting related phishing infrastructure. |
| MD5 | 7291ea5e449f2c7b17582541703e549d | JA3 TLS fingerprint provided for hunting related phishing infrastructure. |
| SHA256 | 8a01bcb70ec1c101a163c9cb8e074781c1322096f7ae01789f02252854def44c | Push Security-published SHA-256 for the Cluster A Doko's Panel client.js artifact. |
| SHA256 | 9c0939960e49122196e44b6779fe55dd7a13ab437ce251c8cf35f8c6daf8be21 | Push Security-published SHA-256 for the Cluster B heartbeat-variant client.js artifact. |
| SHA256 | 9d65dd34384b441505e6b67647153c02d5c367bb53da36ce36a392e70b37940a | Push Security-published SHA-256 for the Cluster D minified client.js artifact. |
| SHA256 | c0df36ccf88d5c8434b13b58f7a55a9715643a126148b9d078a93075d09cad26 | Push Security-published SHA-256 for the Cluster B heartbeat-variant client.js artifact. |
| SHA256 | cb1d409278b2247af23e7b00ac779b232baaf4ce5f63fdf5ebc3920a38cc6102 | Push Security-published SHA-256 for the Cluster C heartbeat and Cloudflare Turnstile client.js artifact. |
| SHA256 | d178dc7108fa9344dae28e350e810352e9e874563496dc7876ee628b11b0eabb | Push Security-published SHA-256 for the Cluster B heartbeat-variant client.js artifact. |
| SHA256 | e8128b33259f7ea4313c942689ba0ba557f17b1474f2e621c62a5b77674fab86 | Push Security-published SHA-256 for the Cluster B heartbeat-variant client.js artifact. |
| SHA256 | f574b6e6b3a968cda5f51bec2c090d8eb095fbcfc383314f94bc15676a0d6692 | Push Security-published SHA-256 for the Cluster A Doko's Panel client.js artifact. |
MITRE ATT&CK
T1056.003 · Web Portal CapturePhishing-panel login pages capture credentials through web portals themed as victim identity, support, passkey, or SSO pages.T1111 · Multi-Factor Authentication InterceptionThe described adversary-in-the-middle credential-capture activity captures MFA as well as credentials.T1566.004 · Spearphishing VoiceThe article describes campaigns combining voice phishing with credential capture.
Threat Actors
BlackFileThe article says the phishing-panel campaigns are linked to BlackFile and notes that panel operators appear to be separate groups.ShinyHuntersCampaigns are linked to ShinyHunters; Mandiant attributes related extortion activity following UNC6661 intrusions to UNC6240, also known as ShinyHunters.UNC6240Mandiant attributes related extortion activity following UNC6661 intrusions to UNC6240; the article identifies UNC6240 as also known as ShinyHunters.UNC6661Push Security's Cluster A reporting overlaps with Mandiant reporting on UNC6661.UNC6671Named in the article's acknowledgment of Mandiant/GTIG reporting that established the actor framework.
Vendors
CloudflareCymru’s communications telemetry shows a peer profile consistent with two dominant traffic shapes. Cloudflare CDN peers (172.69.219.144, 172.69.219.145) on ports 80 and 443 are consistent with traffic reachingMevspaceOur analysis focused on Cluster A, the Doko’s Panel infrastructure hosted on Mevspace AS201814. Push noted that Cluster A overlaps with Mandiant reporting on UNC6661, and that Mandiant attributes related extortion
Products
Binance501938binance.com, 53253binance.com, admin.501938binance.com, www.binance.us.53253binance.com, www.binance.com.53253binance.comBitpandaaccounts-bitpanda.comBlofinvault-blofin.comBT-Panel Issuer: C=CN, ST=Guangdong, L=Dongguan, O=BT-PANEL, OU=BT,CoinbaseThe targeting set on this node is more concentrated on cryptocurrency platforms and tax-filing themes: Coinbase, Binance, NDAX, Bitpanda, Nexo, CoinTracker, Koinly, and the Australian Taxation Office. VanEck (assetCoinTrackerhelp-cointracker.com, admin.help-cointracker.comDocuSignidentity providers and pivot into connected SaaS environments such as Salesforce, SharePoint, Slack, DocuSign, or other high-value applications.Google WorkspaceIdentity providers: Okta, Microsoft Entra, Google WorkspaceKoinlykoinlylegal.io, legal-koinly.ioMicrosoft EntraIdentity providers: Okta, Microsoft Entra, Google WorkspaceMicrosoft SharePointcan attempt to access identity providers and pivot into connected SaaS environments such as Salesforce, SharePoint, Slack, DocuSign, or other high-value applications.NDAXaccount-ndax.comNexoaccounts-nexo.comOktaIdentity providers: Okta, Microsoft Entra, Google WorkspaceSalesforceoperator can attempt to access identity providers and pivot into connected SaaS environments such as Salesforce, SharePoint, Slack, DocuSign, or other high-value applications.Slackto access identity providers and pivot into connected SaaS environments such as Salesforce, SharePoint, Slack, DocuSign, or other high-value applications.
Tools
Doko's PanelPure Signal ReconThe Team Cymru threat research team monitors actor infrastructure across the global internet using Pure Signal Recon and Pure Signal Scout. To learn more about how Cymru helps defenders track adversary infrastructurePure Signal Scoutbecause it shows how the attack works from inside the panel. Team Cymru’s view is different. Using Pure Signal Scout, we looked at the infrastructure layer to validate and expand part of the picture Push identified.
Countries
Industries
Asset managementset spans higher education (Yale, UPenn), financial services (KKR, Shift4, Meridian Savings, IQ-EQ), asset management (VanEck), real estate (Brixmor), luxury goods (LVMH), media (Disney), retail (Nike, JB Hi-Fi,Cryptocurrencyphishing with adversary-in-the-middle credential capture against enterprise identity providers and cryptocurrency platforms. The victim is typically directed to a domain that looks like an internal identity,Enterprise SaaScompromised identity access could quickly create operational or financial leverage. That includes enterprise SaaS environments, financial services, payment processors, higher education, retail, and cryptocurrencyFinancial ServicesDNS associations for 149.50.97.174 showing victim-templated domains targeting higher education, financial services, payments, retail, media, and cryptocurrency platforms.Domains observed on 149.50.97.174:Higher EducationFigure 2: Passive DNS associations for 149.50.97.174 showing victim-templated domains targeting higher education, financial services, payments, retail, media, and cryptocurrency platforms.Domains observed onLuxury goodsservices (KKR, Shift4, Meridian Savings, IQ-EQ), asset management (VanEck), real estate (Brixmor), luxury goods (LVMH), media (Disney), retail (Nike, JB Hi-Fi, Dick’s, Publix, Petco, Purple Mattress),Mediashowing victim-templated domains targeting higher education, financial services, payments, retail, media, and cryptocurrency platforms.Domains observed on 149.50.97.174:Paymentsfor 149.50.97.174 showing victim-templated domains targeting higher education, financial services, payments, retail, media, and cryptocurrency platforms.Domains observed on 149.50.97.174:real estate(Yale, UPenn), financial services (KKR, Shift4, Meridian Savings, IQ-EQ), asset management (VanEck), real estate (Brixmor), luxury goods (LVMH), media (Disney), retail (Nike, JB Hi-Fi, Dick’s, Publix, Petco, PurpleRetail149.50.97.174 showing victim-templated domains targeting higher education, financial services, payments, retail, media, and cryptocurrency platforms.Domains observed on 149.50.97.174:TelecommunicationsTelecommunications and device attestation: Verizon