DoppelCart Network Runs 119,000 Fake Shops to Steal Credit Cards

A massive criminal network of 119,000 fake shops uses automated infrastructure to steal credit card data from unsuspecting shoppers.

By Central
Highlights
  • The DoppelCart network operates over 119,000 fraudulent e-commerce domains, dwarfing any previously documented fraud network.
  • Nearly all fake shops are hosted under the .SHOP top-level domain, accounting for 2.72 percent of all registered .SHOP domains.
  • The fake shops mimic 44,182 distinct brands, with some brands like SodaStream having over 30 fraudulent storefronts.

A sprawling criminal operation known as “DoppelCart” has built a network of more than 119,000 fraudulent e-commerce domains designed to steal payment card details from unsuspecting shoppers. The scale of this fake-shop cluster dwarfs any previously documented fraud network, with nearly all sites hosted under the .SHOP top-level domain — accounting for 2.72 percent of all registered .SHOP domains. Cybersecurity startup Nebty discovered the operation and describes it as the largest publicly documented fake-shop cluster by domain count, surpassing the second-largest network, BogusBazaar, which operated 75,000 sites and recorded an estimated 850,000 fraudulent transactions.

Anatomy of a Fraud Machine: 119,000 Domains, 27 Backends, and 44,182 Impersonated Brands

The DoppelCart operation relies on a highly automated infrastructure. Nebty’s scans revealed that more than 105,000 of these fraudulent shops remain active. CEO Benedikt Scheungraber reported that 96 percent of the confirmed shops share identical build files and resolve to just 27 commerce backends. This centralized architecture allows the operators to rapidly spin up thousands of nearly identical storefronts, each impersonating a legitimate business by copying product catalogs, descriptions, branding, and images — sometimes loading assets directly from the real company’s servers.

The scale of brand abuse is staggering. Across the network, the fake shops mimic 44,182 distinct brands, with a median of two clone sites per brand. Certain high-profile brands received far more attention: SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS all had more than 30 fraudulent shops impersonating them. The attackers lure bargain-hunting shoppers by advertising steep discounts — often up to 65 percent off retail prices — making the offers appear too good to pass up.

Shared Infrastructure and Rapid Domain Rotation

The homogeneity of the DoppelCart network is key to its resilience. With identical build files and a small number of backend servers, the operators can quickly replace any domain that gets flagged or taken down. The heavy concentration in the .SHOP TLD — over 2.7 percent of all .SHOP domains are part of this network — suggests the fraudsters either registered domains in bulk or compromised existing registrations. The use of a single top-level domain also simplifies monitoring for defenders, but the sheer number of domains makes manual takedown efforts impractical.

How DoppelCart Harvests Payment Card Data in Real Time

When a victim reaches the checkout page on one of these fake shops, the site executes code that captures every piece of sensitive information required to complete a fraudulent transaction. Nebty identified that the checkout pages collect card numbers, expiration dates, security codes, cardholder names, email addresses, phone numbers, and physical addresses. Each data field is transmitted over WebSockets to a command-and-control (C2) server in real time, allowing the attackers to collect credentials the moment a victim submits the form.

What is the DoppelCart Network? It is a massive cluster of over 119,000 fraudulent e-commerce domains that impersonate legitimate brands to steal credit card details. The sites share identical build files and rely on 27 centralized backends, transmitting stolen payment information via WebSockets to attackers in real time. Discovered by cybersecurity firm Nebty, it is the largest fake-shop network ever documented, surpassing the BogusBazaar operation by tens of thousands of domains.

The checkout code can also intercept the one-time confirmation code issued by a victim’s bank. If the attacker has already initiated a transaction using the stolen card data, they can use that code to bypass two-factor authentication or other security protections. This technique turns the victim’s own payment verification step into an enabler of fraud.

Collateral Damage: Victims Contact Real Companies for Fake Orders

The DoppelCart operation does not only harm consumers. Nebty observed that many fake stores display the impersonated brand’s legitimate customer support address. Victims who never receive their purchased items — because no real product exists — often reach out to the genuine company for help. This floods legitimate businesses with complaints, damages brand reputation, and forces support teams to field inquiries about fraudulent transactions they have no control over.

Furthermore, Nebty tried to contact the main hosting provider hosting the DoppelCart domains but received no response. Without cooperation from the hosting infrastructure, dismantling the network becomes significantly harder. The operators can continue adding new domains and rotating backends, while the stolen data flows to the C2 servers unimpeded.

A Searchable Database for Brand Protection

To help companies identify whether they have been impersonated by the DoppelCart network, Nebty created a publicly searchable database. The database allows brands to check if their domains or product listings appear among the confirmed fraudulent shops. Although the database does not directly prevent fraud, it enables companies to take targeted action — such as issuing takedown requests, notifying payment processors, or alerting customers through official channels. For brands with dozens of clones in the network, this awareness is a critical first step in damage control.

Broader Implications for E-Commerce Security and TLD Governance

The DoppelCart network highlights a fundamental vulnerability in the domain registration ecosystem. The heavy concentration in the .SHOP TLD raises questions about the oversight exercised by the registry operator. While .SHOP is marketed as a top-level domain for online stores, it has become a fertile ground for fraud. The fact that 2.72 percent of all .SHOP domains are part of this single criminal operation suggests that registration controls — such as identity verification, rate limiting, or abuse monitoring — are insufficient.

The network also demonstrates how fraudsters can scale brand impersonation to levels that overwhelm traditional detection methods. With 119,000 domains, even advanced automated takedown systems struggle to keep pace. The identical build files and small number of backends make the operation efficient from the attacker’s perspective, but also create a single point of failure: if the 27 commerce backends could be identified and disrupted, the entire network would collapse. However, finding and taking down those backends requires cooperation from hosting providers, domain registrars, and law enforcement across multiple jurisdictions.

For consumers, the lesson is clear: an online store offering extreme discounts on a popular brand should be scrutinized carefully. Checking for typos in the domain name, verifying the company’s official website, and looking for secure payment options can reduce the risk. But the sophistication of DoppelCart — complete with copied product images and legitimate support addresses — means that even careful shoppers can be deceived.

The DoppelCart operation is not an isolated incident. It follows the pattern set by BogusBazaar and other fake-shop networks, but on a much larger scale. As fraudsters continue to refine their automation and expand their domain portfolios, the gap between the number of fraudulent shops and the capacity to take them down is likely to widen. The response will require not just technical defenses but also structural changes in how domain registries and hosting providers police their own ecosystems. Until then, the DoppelCart network — and the next generation of clones — will keep running.

Share This Article