Executive Summary
This investigation identified a long-running fraudulent online service ecosystem masquerading as legitimate trademark registration and patent filing consulting businesses.
Analysis of infrastructure, communication channels, payment mechanisms, and website technologies indicates that these websites are not isolated entities, but rather components of a coordinated operation that reuses infrastructure, personnel, and operational procedures across multiple fraudulent brands.
The operation relies primarily on:
- Spam-based lead generation
- Social engineering via professional-looking email domains
- Urgency in the email ex: Mentioning that a competing party has reached out to them to register the victim’s trademark for their use and hinder the victims’ utilization of their own trademark.
- International call center operations
- Legitimate payment processing platforms
- Continuous domain rotation
- Reusable website templates
Infrastructure analysis identified 16+ linked domains, multiple international telephone numbers, shared payment infrastructure, and common website technologies, indicating centralized management despite branding the services as independent companies.
1. Threat Actor Profile
1.1 Actor Assessment
The observed activity is assessed as the work of organized groups operating from Karachi, Sindh, Pakistan.
1.2 Motivation
Financial gain through the collection of fees for purported trademark and patent services.
1.3 Victimology
The campaign primarily targets small-to-medium organizations worldwide, with a particular focus on those based in the following countries and regions:
- Saudi Arabia
- United Arab Emirates
- Qatar
- Kuwait
- Bahrain
- United States
- Canada
- Australia
- United Kingdom
1.4 Observed victim categories include:
- Businesses and brand owners (targeted with claims of trademark conflicts, infringement risks, or the need for registration/monitoring services)
- Authors and independent publishers (targeted with publishing, book marketing, and related service offers)
- Amazon/KDP sellers and e-commerce operators (targeted with offers related to brand registry, publishing, or store optimization services)
2. Technical & Operational Infrastructure
2.1 Domain Layer
- Registration Pattern:
Heavily relying on NameCheap but other registrars were observed as well such as: Name.com, Hostinger, Dynadot, Spaceship, Internet Domain Service BS Corp. WHOIS data is typically redacted.
- Rotation Strategy:
New domains are introduced as older ones attract complaints.
- Creation Date:
March 2024 – July 2026 (ongoing operation)
- Active Registration Period:
Over 2 years (Mar 2024 – July 2026).
2.2 Email Infrastructure (Obfuscation Layer)
- Tactic Observed:
Use of clean, law-firm-sounding recent domains with no active websites (Mostly parked or completely empty).
- Hosting:
Utilizing Contabo for the email client, which is connected to the SMTP server on Hostinger.
KEY OBSERVATION:
usptopatentoffice.com impersonates the official USPTO, marking an escalation from private law firms to government entities.
2.3 Telephony Layer
- The threat actor utilized a combination of VoIP numbers associated with Pakistani-based call center infrastructure and registered local telephone numbers across multiple countries.
- The VoIP numbers were primarily used to route victims responding to phishing emails to call center operators,
- While the registered local numbers were subsequently used for direct communication with victims throughout the social engineering process.
2.4 Payment Layer
- Analysis of the payment stage identified the use of a payment page hosted on invoice-nest.com.
- https://invoice-nest.com/nuvei/pay/019fa86b-8a25-7218-86a7-74bbc190****
- The payment page presented a Nuvei-branded payment interface, giving the appearance of a legitimate payment workflow.
- The use of a legitimate-looking payment interface likely serves to increase victim trust and encourage completion of the requested payment.
- This approach helps obscure the fraudulent nature of the campaign by embedding the payment stage within an interface that appears familiar and credible.
2.5 Website Technology Stack
Analysis of representative campaign websites identified consistent technology choices and web development patterns across multiple domains, indicating the likely use of reusable website templates and common development practices.
Hosting Infrastructure: Primarily Hostinger. Inaddition to Amazon Web Services (AWS)
Development Languages: PHP, jQuery, Bootstrap
Hosting Technology: LiteSpeed or Apache HTTP Server, with Nginx observed on a limited number of sites
Protection: Usually, Cloudflare
Features: Interactive customer engagement features such as live chat, contact forms, and consultation request forms were consistently implemented across campaign websites, supporting the social engineering workflow.
Additional: Multiple sites integrated third-party marketing and tracking services, including Google Tag Manager, Google Analytics (GA4), Facebook Pixel, Microsoft Clarity, and Google Ads Conversion Tracking.
Note: Technology overlap across multiple campaign domains including identical front-end frameworks, JavaScript libraries, analytics services, and UI components suggests centralized management or reuse of common website templates by the threat actor.
2.6 False Location Claims
- Multiple campaign websites claim to operate from specific physical addresses in various countries. Analysis indicates these addresses are virtual or fabricated, with no corresponding real-world presence or verifiable office locations. This tactic is used to create an appearance of legitimacy and geographic credibility while concealing the actual operational base.
3. Attack Pattern & Victim Flow
1. Reconnaissance – Automated scraping of business names, domains, and contact data.
2. Delivery – Unsolicited emails from professional-looking email domains
(e.g., diwanlegal.com, usptopatentoffice.com ).
3. Social Engineering – Urgency created with claims of trademark conflicts.

4. Conversion – Direct victim to payment pages or shared call centers.

5. Monetization – Collection of fees for trademark filing / monitoring / publishing services.

6. Evasion – Limited or no delivery of the promised services, combined with rapid domain and email rotation once complaints or blacklisting occur.
MITRE ATT&CK Mapping
| ATT&CK Tactic | Technique | Why It Matches |
|---|---|---|
| Reconnaissance | T1593 Search Open Websites/Domains | Harvesting business information |
| Reconnaissance | T1589 Gather Victim Identity Information | Collecting business contacts |
| Resource Development | T1583 Acquire Infrastructure | Continuous domain registrations |
| Resource Development | T1584 Compromise Infrastructure | Compromised infrastructure is observed |
| Initial Access | T1566.002 Spearphishing Link | Victims receive emails leading to websites |
| Initial Access | T1566.001 Spearphishing Attachment | Registration form sent via email attachment |
| Impact | T1657 Financial Theft | Primary objective is fraud |
| Defense Evasion | Infrastructure Rotation | Domain rotation and privacy-protected WHOIS |
| Defense Evasion | T1036 Masquerading | Fake legal firms and fake USPTO identities |
IOCs
Note: We have shared the IOCs through our feeds which you can access through the following link: dPhish Feeds
Atomic Indicators of Compromise (IOCs)
- Domains
| Indicator | Category | Notes |
|---|---|---|
| marksfilers.com | Trademark Scam | Core campaign website |
| trademarkcrown.com | Trademark Scam | Scam reports observed |
| shieldmymark.com | Trademark Scam | Shares telephone number with marksfilers.com |
| brandfilers.com | Trademark Scam | Scam reports observed |
| trademarksregistery.com | Trademark Scam | Trademark-themed service |
| patentregistersau.com | Patent Scam | Patent registration services |
| book2publish.com | Publishing Scam | Publishing-related services |
| publishswiftly.com | Publishing Scam | Publishing-related services |
| stellarbookspublishing.com | Publishing Scam | Publishing-related services |
| elitewritershub.com | Publishing Scam | Writing/Publishing services |
| kdppropublishers.com | Amazon/KDP Scam | Amazon publishing services |
| theamzpropublishers.com | Amazon Scam | Amazon-focused services |
| ecommerceautomized.com | eCommerce Scam | eCommerce services |
- Email Domains
| Indicator | Purpose |
|---|---|
| diwanlegal.com |
Fraudulent legal correspondence |
| diwanlegalgroup.com |
Email infrastructure |
| usptopatentoffice.com |
Government impersonation emails |
| vmi3425606.contaboserver.net |
Email hosting server |
- Email Client Hosting IP
| IP Address | Category |
|---|---|
| 147.93.138.92 |
Email Hosting |
- Payment Infrastructure
| Indicator | Description |
|---|---|
| invoice-nest.com |
Payment platform used during the victim payment stage |
| https://invoice-nest.com/nuvei/pay/019fa86b-8a25-7218-86a7-74bbc190**** |
Observed Nuvei payment URL |
- Telephone Numbers
| Country | Phone Number |
|---|---|
| Saudi Arabia | +966 (58) 160-8869 |
| United States | +1 (213) 328-3053 |
| United States | +1 (210) 984-1333 |
| United States | +1 (313) 631-9666 |
| United States | +1 (516) 855-6614 |
| United States | +1 (213) 285-0690 |
| United States | +1 (888) 627-6104 |
| United States | +1 (980) 223-4655 |
| Canada | +1 (604) 520-8541 |
| Australia | +61 (08) 6118-3206 |
| United Kingdom | +44 (204) 600-6556 |