Inside a network of 20,000+ fake shops

Inside a network of 20,000+ fake shops

More than 20,000 fraudulent online stores—many running on Sellvia WordPress templates and concentrated on 36 IP addresses—were mapped as part of an industrialized scam ecosystem that harvests payment credentials and personal data under polished storefronts and aggressive sale tactics. Researchers linked large campaigns such as FraudWear and BogusBazaar to this activity and advise using browser protection, checking domains carefully, and preferring safer payment methods to avoid falling victim. #FraudWear #BogusBazaar

Keypoints

  • Researchers identified a cluster of over 20,000 fake e-commerce domains that share identical storefront templates and resolve to just 36 IP addresses, demonstrating centralized infrastructure.
  • Many sites use the .shop TLD and Sellvia WordPress templates, reusing product images and two base themes with cosmetic variations to impersonate legitimate retailers.
  • Fraud networks have scaled into franchise-style operations—examples include FraudWear (30,000 stores) and BogusBazaar (75,000 domains and 1M+ orders)—with core teams managing servers and decentralized operators launching shops.
  • Fake shops harvest payment details, billing addresses, and personal information for resale or direct identity fraud, relying on ad clicks, search results, countdown timers, and deep-discount psychology to drive victims.
  • Activity concentrates in IP ranges such as 207.244.x.x and 23.105.x.x, meaning takedowns of a small number of servers can disrupt thousands of fraudulent stores.
  • Defensive guidance includes using browser protection (e.g., Malwarebytes Browser Guard), scrutinizing unfamiliar TLDs (.shop, .top, .store, .xyz), checking independent reviews, and using credit or virtual cards for safer payments.

MITRE Techniques

Indicators of Compromise

  • [IP Address ] infrastructure backbone – 207[.]244[.]102[.]13, 23[.]105[.]8[.]15, and 34 more items
  • [TLD / Domain pattern ] domain choices used by scammers – .shop, .xyz
  • [Hosting IP ranges ] concentrated provider blocks – 207[.]244[.]x[.]x, 23[.]105[.]x[.]x
  • [Page title ] UI indicator used across storefronts – “Unrivaled selection only for you.”
  • [Platform / CMS ] storefront technology and templates – Sellvia, WordPress


Read more: https://www.malwarebytes.com/blog/scams/2026/03/inside-a-network-of-20000-fake-shops