Researchers at German cybersecurity company Nebty have identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores.
The researchers describe it as the largest publicly documented fake-shop network by associated domain count. They found 118,787 .shop domains in the cluster, representing 2.72% of the .shop top-level domain (TLD) population they examined.
The operation copies legitimate retailers’ product catalogs, descriptions, branding, and images, sometimes even loading images directly from the real companies’ infrastructure.
As we have reported in the past, AI-powered website builders make it easy to clone major brands. However, Nebty’s findings are based on shared website and infrastructure characteristics, rather than evidence that every domain is operated by a single identified group.
BleepingComputer reports an important checkout-level detail: 96% of confirmed DoppelCart shops reportedly shared identical build files and used just 27 ecommerce backends.
The fake shops mimic more than 44,000 brands, with a median of two clones for each brand.
“However, some brands like SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA, and SPARK PAWS received more attention, with over 30 shops each.”
Nebty observed advertised discounts of up to 65%, a tactic designed to encourage shoppers to act before closely checking the domain, company details, or payment process.
The fraudulent checkout pages collect cardholder data and transmit it to attacker-controlled servers over WebSockets in real time. That may include card numbers, expiry dates, CVVs (card verification values), billing information, and even one-time confirmation codes issued by banks.
Capturing an authentication code in real time can help criminals to complete a payment while the victim is still going through the checkout flow.
How shoppers can stay safe
A professional-looking store, the use of HTTPS, authentic product images, and a familiar logo do not prove that a website is legitimate. Before entering payment details, shoppers should take a few minutes to verify where they are buying from.
- Check the web address carefully. If possible, reach the retailer through its official app, a saved bookmark, or a web address you already know, rather than sponsored search results or ads on social media.
- Be wary of unusually large discounts. A low price does not prove that a store is fake, but it is a reason to check the site more carefully.
- Search for the exact web address alongside terms such as “scam” or “reviews.” Check that the contact details, returns policy, and company information match the real retailer.
- Pay by credit card or another service with buyer protection. Avoid cryptocurrency, bank transfers, gift cards, and other payments that are difficult to reverse.
- Check every bank verification request carefully. Make sure the merchant and amount are correct, and never give a one-time code to a retailer or anyone who contacts you.
- Use an up-to-date, real-time anti-malware solution with web protection.
- If you’re unsure whether a store is genuine, use Malwarebytes Scam Guard to help you assess it.
If you’ve already paid, act quickly. Contact your card issuer, report the suspected fraud, ask about replacing or monitoring your card, and save screenshots, order confirmations, web addresses, and correspondence.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

