Team Cymru Validates ShinyHunters-Linked Phishing Infrastructure on Mevspace

· Original article ↗

Summary

Team Cymru used passive network telemetry to identify two Mevspace IPs and more than 40 victim-themed domains consistent with Push Security’s Cluster A phishing infrastructure reporting, while noting the findings do not independently attribute the activity.

Key points

  • Two IPs on Mevspace AS201814, 149.50.97.174 and 149.50.127.228, showed infrastructure patterns consistent with Push Security’s Cluster A reporting.
  • More than 40 victim-themed domains were linked to the IPs using registrar, nameserver, recency, and hosting criteria.
  • The domains targeted organizations and services across education, finance, retail, cryptocurrency, identity, and taxation themes.
  • The analysis identified numeric-token brand domains and Binance typosquats designed to resemble legitimate URLs.
  • A BT-Panel certificate and Doko-branded dokopanel.com were observed, but the article cautions these artifacts do not prove operator identity or control.
  • The activity uses phishing pages to capture credentials and MFA, potentially enabling access to enterprise identity providers and connected SaaS services.
  • Team Cymru published repeatable queries and indicators for defenders to hunt related infrastructure as domains rotate.

Article Details

Attack Vectors
  • Voice phishing combined with adversary-in-the-middle credential capture against enterprise identity providers and cryptocurrency platforms.
  • Victims are directed to brand-themed internal identity, support, passkey, SSO, or credential-verification pages that capture credentials and MFA.
  • Some Binance-themed domains use nested hostnames designed to make the URL bar appear to show binance.com or binance.us.
  • Captured credentials and MFA may be used in attempts to access identity providers and connected SaaS environments; the article does not confirm successful access.
Defensive Notes
  • Hunt Mevspace AS201814 infrastructure using the reported domain patterns together with the NICENIC/CNOBIN registrar and 1984.is/1984hosting.com nameserver fingerprint.
  • Use the reported IPs, domains, client.js hashes, and JA3 fingerprints as pivot points; the article notes that domains should be assessed against the full fingerprint because passive DNS can contain unrelated tenants and noise.
  • Monitor for newly deployed domains and infrastructure through scheduled searches, since Cluster A operators rotate domains quickly.
  • Treat BT-Panel, dokopanel.com, and infrastructure overlap as context rather than proof of attribution or control by a specific individual.
  • The reported peer traffic includes CDN and scanner activity; the article cautions against treating those observations alone as evidence of operator activity.

Indicators of compromise

TypeIndicatorContext
DOMAIN118507coinbase[.]comCluster A-aligned numeric-token Coinbase-themed phishing domain associated with 149.50.127.228.
DOMAIN412721coinbase[.]comCluster A-aligned numeric-token Coinbase-themed phishing domain associated with 149.50.127.228.
DOMAIN419256crypto[.]comCluster A-aligned numeric-token cryptocurrency-themed phishing domain associated with 149.50.127.228.
DOMAIN501938binance[.]comCluster A-aligned numeric-token Binance-themed phishing domain associated with 149.50.127.228.
DOMAIN53253binance[.]comCluster A-aligned numeric-token Binance-themed phishing domain associated with 149.50.127.228.
DOMAIN852319-ndax[.]comCluster A-aligned numeric-token NDAX-themed phishing domain associated with 149.50.127.228.
DOMAIN953536-cb[.]comCluster A-aligned numeric-token domain associated with 149.50.127.228.
DOMAINaccount-ndax[.]comCluster A-aligned victim-themed phishing domain associated with 149.50.97.174 and 149.50.127.228.
DOMAINaccount-ndax[.]ioCluster A-aligned NDAX-themed phishing domain associated with 149.50.127.228.
DOMAINaccounts-bitpanda[.]comCluster A-aligned victim-themed domain associated with 149.50.127.228.
DOMAINaccounts-nexo[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINamazoninternal[.]comCluster A-aligned victim-themed phishing domain associated with 149.50.97.174.
DOMAINatocalculation[.]comAustralian Taxation Office-themed domain associated with Cluster A infrastructure.
DOMAINbinanapi-912512[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINbrixmorssoo[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINcrypto-ato[.]comAustralian tax-filing and cryptocurrency-themed domain associated with 149.50.127.228; the article says its specific panel variant is unconfirmed.
DOMAINdevice-verizon[.]comCluster A-aligned Verizon-themed domain associated with 149.50.127.228.
DOMAINdokopanel[.]comDoko-branded hosting-layer artifact colocated with Cluster A-aligned infrastructure; the article says this does not prove control by a specific individual.
DOMAINhelp-cointracker[.]comCluster A-aligned victim-themed domain associated with 149.50.127.228.
DOMAINkoinlylegal[.]ioCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINlegal-koinly[.]ioCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINlvmhinternal[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmeridian-saving[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmydicksmanager[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmydisneyconnect[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmydisneymanager[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmydisneysso[.]comCluster A-aligned victim-themed phishing domain resolving to 149.50.97.174.
DOMAINmydropboxinternal[.]comDomain included in the article's named-domain validation query for phishing infrastructure.
DOMAINmyiqeq[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmyjbhifi[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmykkrconnect[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmynavmanadbsnsger[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmynavmanagbsnsjser[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmynikemanager[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmypetcomanager[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmypublixmanager[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmypurpleconnect[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmypurpledirect[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmypurpleidsso[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmypurplemanager[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmyupennmanager[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINmyvaneckmanager[.]comCluster A-aligned victim-themed domain associated with 149.50.127.228.
DOMAINmyvanecksso[.]comCluster A-aligned victim-themed domain associated with 149.50.127.228.
DOMAINmyxerointernal[.]comDomain included in the article's named-domain validation query for phishing infrastructure.
DOMAINmyyalemanager[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINoverview-gmail[.]comCluster A-aligned domain associated with 149.50.127.228.
DOMAINpurpleidconnect[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINrestriction-nexo[.]comCluster A-aligned victim-themed domain associated with 149.50.127.228.
DOMAINsafety-river[.]comCluster A-aligned domain associated with 149.50.127.228.
DOMAINshift4internal[.]comCluster A-aligned victim-themed phishing domain associated with 149.50.97.174.
DOMAINvault-blofin[.]comCluster A-aligned victim-themed domain associated with 149.50.97.174.
DOMAINverification12589[.]comGeneric credential-verification phishing domain associated with 149.50.97.174.
DOMAINverify91358[.]comGeneric credential-verification phishing domain associated with 149.50.97.174.
HOSTNAMEadmin[.]118507coinbase[.]comAdmin subdomain of a Cluster A-aligned Coinbase-themed phishing domain.
HOSTNAMEadmin[.]412721coinbase[.]comAdmin subdomain of a Cluster A-aligned Coinbase-themed phishing domain.
HOSTNAMEadmin[.]419256crypto[.]comAdmin subdomain of a Cluster A-aligned cryptocurrency-themed phishing domain.
HOSTNAMEadmin[.]501938binance[.]comAdmin subdomain of a Cluster A-aligned Binance-themed phishing domain.
HOSTNAMEadmin[.]852319-ndax[.]comAdmin subdomain of a Cluster A-aligned numeric-token NDAX-themed phishing domain.
HOSTNAMEadmin[.]account-ndax[.]comAdmin subdomain of a Cluster A-aligned NDAX-themed phishing domain.
HOSTNAMEadmin[.]account-ndax[.]ioAdmin subdomain of a Cluster A-aligned NDAX-themed phishing domain.
HOSTNAMEadmin[.]device-verizon[.]comAdmin subdomain of a Cluster A-aligned Verizon-themed domain.
HOSTNAMEadmin[.]dokopanel[.]comAdmin subdomain of the Doko-branded hosting-layer artifact colocated with Cluster A-aligned infrastructure.
HOSTNAMEadmin[.]help-cointracker[.]comAdmin subdomain of a Cluster A-aligned CoinTracker-themed domain.
HOSTNAMEcp[.]myyalemanager[.]comControl-panel or admin-endpoint pattern on the Yale-themed phishing domain associated with 149.50.97.174.
HOSTNAMEl6[.]restriction-nexo[.]comSubdomain of a Cluster A-aligned Nexo-themed domain associated with 149.50.127.228.
HOSTNAMEwww[.]binance[.]com[.]53253binance[.]comCluster A-aligned Binance-themed hostname designed to appear like binance.com in a truncated URL bar.
HOSTNAMEwww[.]binance[.]us[.]53253binance[.]comCluster A-aligned Binance-themed hostname designed to appear like binance.us in a truncated URL bar.
IPV4149[.]50[.]127[.]228Cluster A-aligned phishing infrastructure hosted on Mevspace AS201814.
IPV4149[.]50[.]97[.]174Cluster A-aligned phishing infrastructure hosted on Mevspace AS201814.
MD515af977ce25de452b96affa2addb1036JA3S TLS fingerprint provided for hunting related phishing infrastructure.
MD57291ea5e449f2c7b17582541703e549dJA3 TLS fingerprint provided for hunting related phishing infrastructure.
SHA2568a01bcb70ec1c101a163c9cb8e074781c1322096f7ae01789f02252854def44cPush Security-published SHA-256 for the Cluster A Doko's Panel client.js artifact.
SHA2569c0939960e49122196e44b6779fe55dd7a13ab437ce251c8cf35f8c6daf8be21Push Security-published SHA-256 for the Cluster B heartbeat-variant client.js artifact.
SHA2569d65dd34384b441505e6b67647153c02d5c367bb53da36ce36a392e70b37940aPush Security-published SHA-256 for the Cluster D minified client.js artifact.
SHA256c0df36ccf88d5c8434b13b58f7a55a9715643a126148b9d078a93075d09cad26Push Security-published SHA-256 for the Cluster B heartbeat-variant client.js artifact.
SHA256cb1d409278b2247af23e7b00ac779b232baaf4ce5f63fdf5ebc3920a38cc6102Push Security-published SHA-256 for the Cluster C heartbeat and Cloudflare Turnstile client.js artifact.
SHA256d178dc7108fa9344dae28e350e810352e9e874563496dc7876ee628b11b0eabbPush Security-published SHA-256 for the Cluster B heartbeat-variant client.js artifact.
SHA256e8128b33259f7ea4313c942689ba0ba557f17b1474f2e621c62a5b77674fab86Push Security-published SHA-256 for the Cluster B heartbeat-variant client.js artifact.
SHA256f574b6e6b3a968cda5f51bec2c090d8eb095fbcfc383314f94bc15676a0d6692Push Security-published SHA-256 for the Cluster A Doko's Panel client.js artifact.

MITRE ATT&CK

Threat Actors

Vendors

Products

Binance501938binance.com, 53253binance.com, admin.501938binance.com, www.binance.us.53253binance.com, www.binance.com.53253binance.comBitpandaaccounts-bitpanda.comBlofinvault-blofin.comBT-Panel        Issuer:  C=CN, ST=Guangdong, L=Dongguan, O=BT-PANEL, OU=BT,CoinbaseThe targeting set on this node is more concentrated on cryptocurrency platforms and tax-filing themes: Coinbase, Binance, NDAX, Bitpanda, Nexo, CoinTracker, Koinly, and the Australian Taxation Office. VanEck (assetCoinTrackerhelp-cointracker.com, admin.help-cointracker.comDocuSignidentity providers and pivot into connected SaaS environments such as Salesforce, SharePoint, Slack, DocuSign, or other high-value applications.Google WorkspaceIdentity providers: Okta, Microsoft Entra, Google WorkspaceKoinlykoinlylegal.io, legal-koinly.ioMicrosoft EntraIdentity providers: Okta, Microsoft Entra, Google WorkspaceMicrosoft SharePointcan attempt to access identity providers and pivot into connected SaaS environments such as Salesforce, SharePoint, Slack, DocuSign, or other high-value applications.NDAXaccount-ndax.comNexoaccounts-nexo.comOktaIdentity providers: Okta, Microsoft Entra, Google WorkspaceSalesforceoperator can attempt to access identity providers and pivot into connected SaaS environments such as Salesforce, SharePoint, Slack, DocuSign, or other high-value applications.Slackto access identity providers and pivot into connected SaaS environments such as Salesforce, SharePoint, Slack, DocuSign, or other high-value applications.

Tools

Countries

Industries

Asset managementset spans higher education (Yale, UPenn), financial services (KKR, Shift4, Meridian Savings, IQ-EQ), asset management (VanEck), real estate (Brixmor), luxury goods (LVMH), media (Disney), retail (Nike, JB Hi-Fi,Cryptocurrencyphishing with adversary-in-the-middle credential capture against enterprise identity providers and cryptocurrency platforms. The victim is typically directed to a domain that looks like an internal identity,Enterprise SaaScompromised identity access could quickly create operational or financial leverage. That includes enterprise SaaS environments, financial services, payment processors, higher education, retail, and cryptocurrencyFinancial ServicesDNS associations for 149.50.97.174 showing victim-templated domains targeting higher education, financial services, payments, retail, media, and cryptocurrency platforms.Domains observed on 149.50.97.174:Higher EducationFigure 2: Passive DNS associations for 149.50.97.174 showing victim-templated domains targeting higher education, financial services, payments, retail, media, and cryptocurrency platforms.Domains observed onLuxury goodsservices (KKR, Shift4, Meridian Savings, IQ-EQ), asset management (VanEck), real estate (Brixmor), luxury goods (LVMH), media (Disney), retail (Nike, JB Hi-Fi, Dick’s, Publix, Petco, Purple Mattress),Mediashowing victim-templated domains targeting higher education, financial services, payments, retail, media, and cryptocurrency platforms.Domains observed on 149.50.97.174:Paymentsfor 149.50.97.174 showing victim-templated domains targeting higher education, financial services, payments, retail, media, and cryptocurrency platforms.Domains observed on 149.50.97.174:real estate(Yale, UPenn), financial services (KKR, Shift4, Meridian Savings, IQ-EQ), asset management (VanEck), real estate (Brixmor), luxury goods (LVMH), media (Disney), retail (Nike, JB Hi-Fi, Dick’s, Publix, Petco, PurpleRetail149.50.97.174 showing victim-templated domains targeting higher education, financial services, payments, retail, media, and cryptocurrency platforms.Domains observed on 149.50.97.174:TelecommunicationsTelecommunications and device attestation: Verizon

Related Articles