Blogs

TradeMark Scam Threat Intelligence Report

Aug 3, 2026 6 min read
TradeMark Scam Threat Intelligence Report

Executive Summary

This investigation identified a long-running fraudulent online service ecosystem masquerading as legitimate trademark registration and patent filing consulting businesses.

Analysis of infrastructure, communication channels, payment mechanisms, and website technologies indicates that these websites are not isolated entities, but rather components of a coordinated operation that reuses infrastructure, personnel, and operational procedures across multiple fraudulent brands.

The operation relies primarily on:

  • Spam-based lead generation
  • Social engineering via professional-looking email domains
  • Urgency in the email ex: Mentioning that a competing party has reached out to them to register the victim’s trademark for their use and hinder the victims’ utilization of their own trademark.
  • International call center operations
  • Legitimate payment processing platforms
  • Continuous domain rotation
  • Reusable website templates

Infrastructure analysis identified 16+ linked domains, multiple international telephone numbers, shared payment infrastructure, and common website technologies, indicating centralized management despite branding the services as independent companies.

1. Threat Actor Profile

1.1 Actor Assessment

The observed activity is assessed as the work of organized groups operating from Karachi, Sindh, Pakistan.

1.2 Motivation

Financial gain through the collection of fees for purported trademark and patent services.

1.3 Victimology

The campaign primarily targets small-to-medium organizations worldwide, with a particular focus on those based in the following countries and regions:

  • Saudi Arabia
  • United Arab Emirates
  • Qatar
  • Kuwait
  • Bahrain
  • United States
  • Canada
  • Australia
  • United Kingdom

1.4 Observed victim categories include:

  • Businesses and brand owners (targeted with claims of trademark conflicts, infringement risks, or the need for registration/monitoring services)
  • Authors and independent publishers (targeted with publishing, book marketing, and related service offers)
  • Amazon/KDP sellers and e-commerce operators (targeted with offers related to brand registry, publishing, or store optimization services)

2. Technical & Operational Infrastructure

2.1 Domain Layer

  • Registration Pattern:

Heavily relying on NameCheap but other registrars were observed as well such as: Name.com, Hostinger, Dynadot, Spaceship, Internet Domain Service BS Corp. WHOIS data is typically redacted.

  • Rotation Strategy:

New domains are introduced as older ones attract complaints.

  • Creation Date:

March 2024 – July 2026 (ongoing operation)

  • Active Registration Period:

Over 2 years (Mar 2024 – July 2026).

2.2 Email Infrastructure (Obfuscation Layer)

  • Tactic Observed: 

Use of clean, law-firm-sounding recent domains with no active websites (Mostly parked or completely empty).

  • Hosting:

Utilizing Contabo for the email client, which is connected to the SMTP server on Hostinger.

KEY OBSERVATION:

usptopatentoffice.com impersonates the official USPTO, marking an escalation from private law firms to government entities.

2.3 Telephony Layer

  • The threat actor utilized a combination of VoIP numbers associated with Pakistani-based call center infrastructure and registered local telephone numbers across multiple countries.
  • The VoIP numbers were primarily used to route victims responding to phishing emails to call center operators,
  • While the registered local numbers were subsequently used for direct communication with victims throughout the social engineering process.

2.4 Payment Layer

  • Analysis of the payment stage identified the use of a payment page hosted on invoice-nest.com.
    • https://invoice-nest.com/nuvei/pay/019fa86b-8a25-7218-86a7-74bbc190****
  • The payment page presented a Nuvei-branded payment interface, giving the appearance of a legitimate payment workflow.
  • The use of a legitimate-looking payment interface likely serves to increase victim trust and encourage completion of the requested payment.
  • This approach helps obscure the fraudulent nature of the campaign by embedding the payment stage within an interface that appears familiar and credible.

2.5 Website Technology Stack

Analysis of representative campaign websites identified consistent technology choices and web development patterns across multiple domains, indicating the likely use of reusable website templates and common development practices.

Hosting Infrastructure: Primarily Hostinger. Inaddition to Amazon Web Services (AWS)

Development Languages: PHP, jQuery, Bootstrap

Hosting Technology: LiteSpeed or Apache HTTP Server, with Nginx observed on a limited number of sites

Protection: Usually, Cloudflare

Features: Interactive customer engagement features such as live chat, contact forms, and consultation request forms were consistently implemented across campaign websites, supporting the social engineering workflow.

Additional: Multiple sites integrated third-party marketing and tracking services, including Google Tag Manager, Google Analytics (GA4), Facebook Pixel, Microsoft Clarity, and Google Ads Conversion Tracking.

Note: Technology overlap across multiple campaign domains including identical front-end frameworks, JavaScript libraries, analytics services, and UI components suggests centralized management or reuse of common website templates by the threat actor. 

2.6 False Location Claims

  • Multiple campaign websites claim to operate from specific physical addresses in various countries. Analysis indicates these addresses are virtual or fabricated, with no corresponding real-world presence or verifiable office locations. This tactic is used to create an appearance of legitimacy and geographic credibility while concealing the actual operational base.

3. Attack Pattern & Victim Flow

1. Reconnaissance – Automated scraping of business names, domains, and contact data.

2. Delivery – Unsolicited emails from professional-looking email domains
(e.g., diwanlegal.com, usptopatentoffice.com ).

3. Social Engineering – Urgency created with claims of trademark conflicts.

4. Conversion – Direct victim to payment pages or shared call centers.

5. Monetization – Collection of fees for trademark filing / monitoring / publishing services.

6. Evasion – Limited or no delivery of the promised services, combined with rapid domain and email rotation once complaints or blacklisting occur.

MITRE ATT&CK Mapping

ATT&CK Tactic Technique Why It Matches
Reconnaissance T1593 Search Open Websites/Domains Harvesting business information
Reconnaissance T1589 Gather Victim Identity Information Collecting business contacts
Resource Development T1583 Acquire Infrastructure Continuous domain registrations
Resource Development T1584 Compromise Infrastructure Compromised infrastructure is observed
Initial Access T1566.002 Spearphishing Link Victims receive emails leading to websites
Initial Access T1566.001 Spearphishing Attachment Registration form sent via email attachment
Impact T1657 Financial Theft Primary objective is fraud
Defense Evasion Infrastructure Rotation Domain rotation and privacy-protected WHOIS
Defense Evasion T1036 Masquerading Fake legal firms and fake USPTO identities

IOCs

Note: We have shared the IOCs through our feeds which you can access through the following link: dPhish Feeds

Atomic Indicators of Compromise (IOCs)

  1. Domains
Indicator Category Notes
marksfilers.com Trademark Scam Core campaign website
trademarkcrown.com Trademark Scam Scam reports observed
shieldmymark.com Trademark Scam Shares telephone number with marksfilers.com
brandfilers.com Trademark Scam Scam reports observed
trademarksregistery.com Trademark Scam Trademark-themed service
patentregistersau.com Patent Scam Patent registration services
book2publish.com Publishing Scam Publishing-related services
publishswiftly.com Publishing Scam Publishing-related services
stellarbookspublishing.com Publishing Scam Publishing-related services
elitewritershub.com Publishing Scam Writing/Publishing services
kdppropublishers.com Amazon/KDP Scam Amazon publishing services
theamzpropublishers.com Amazon Scam Amazon-focused services
ecommerceautomized.com eCommerce Scam eCommerce services

 

  1. Email Domains
Indicator Purpose
diwanlegal.com
Fraudulent legal correspondence
diwanlegalgroup.com
Email infrastructure
usptopatentoffice.com
Government impersonation emails
vmi3425606.contaboserver.net
Email hosting server

 

  1. Email Client Hosting IP
IP Address Category
147.93.138.92
Email Hosting

 

  1. Payment Infrastructure
Indicator Description
invoice-nest.com
Payment platform used during the victim payment stage
https://invoice-nest.com/nuvei/pay/019fa86b-8a25-7218-86a7-74bbc190****
Observed Nuvei payment URL

 

  1. Telephone Numbers
Country Phone Number
Saudi Arabia +966 (58) 160-8869
United States +1 (213) 328-3053
United States +1 (210) 984-1333
United States +1 (313) 631-9666
United States +1 (516) 855-6614
United States +1 (213) 285-0690
United States +1 (888) 627-6104
United States +1 (980) 223-4655
Canada +1 (604) 520-8541
Australia +61 (08) 6118-3206
United Kingdom +44 (204) 600-6556

 


Leave a Reply

Your email address will not be published. Required fields are marked *