DoppelCart: Massive Fake Shop Network Steals Credit Card Data from 119,000 Domains
A colossal fraudulent operation, dubbed **DoppelCart**, has been uncovered, utilizing a network of over 119,000 fake e-shops to illicitly harvest payment card details. This sophisticated scheme impersonates thousands of legitimate brands, luring unsuspecting shoppers with deep discounts.
German cybersecurity startup **Nebty** has unveiled **DoppelCart**, an unprecedented fake-shop cluster that dwarfs previous operations in scale. With more than 119,000 domains, predominantly in the .SHOP TLD, this network represents a significant threat to online consumers and brand integrity.
**DoppelCart** surpasses the previously documented **BogusBazaar** operation, which involved 75,000 sites and an estimated 850,000 fraudulent transactions. **Nebty**'s latest scans indicate that over 105,000 **DoppelCart** shops remain active.
### How DoppelCart Operates
**Nebty** CEO **Benedikt Scheungraber** revealed that 96% of confirmed **DoppelCart** shops share identical build files and resolve to 27 distinct commerce backends. These sites meticulously mimic legitimate businesses, copying product catalogs, descriptions, branding, and even images, sometimes loading assets directly from the real companies' servers.
The network impersonates an astonishing 44,182 different brands, with an average of two clones per brand. High-profile brands such as **SodaStream**, **Velasca**, **CurrentBody**, **Daniel Wellington**, **Dreame**, **Horze**, **MOVA**, and **SPARK PAWS** have been particularly targeted, with some experiencing over 30 imposter shops each.

To entice bargain hunters, the fake sites frequently advertise substantial discounts, often up to 65% off genuine product prices.
### Data Exfiltration Tactics
**Nebty**'s analysis of several **DoppelCart** checkout pages uncovered code designed to collect a comprehensive range of sensitive payment card and cardholder information, including:
* Card numbers
* Expiration dates
* Security codes
* Cardholder names
* Email addresses
* Phone numbers
* Physical addresses
This data is immediately transmitted in real-time over WebSockets to command-and-control (C2) servers. Furthermore, the sophisticated checkout code can even relay one-time confirmation codes issued by victims' banks, potentially enabling attackers to bypass crucial security measures.
Adding to the deception, some fake stores display the legitimate support addresses of the impersonated brands. This tactic leads victims, who never receive their purchases, to contact the real companies, further complicating incident response and customer service for affected businesses.
### Response and Mitigation
**Scheungraber** noted that attempts to contact the main hosting provider for **DoppelCart** sites have gone unanswered. In response to the widespread threat, **Nebty** has developed a [searchable database](https://investigations.nebty-id.com/doppelcart?verdict=fleet_confirmed) to assist companies in identifying **DoppelCart** impersonations and brand abuse. This resource empowers businesses to take proactive steps to protect their brand reputation and customers.
This large-scale operation underscores the persistent and evolving threat of online fraud. IT security professionals and privacy-conscious users must remain vigilant, scrutinizing URLs, checking for secure connections, and exercising caution with unsolicited offers and overly attractive discounts.