RESEARCHERS from Nebty have identified a vast network of fake online shops branded as “DoppelCart.” The cluster comprises almost 119,000 domains, with 118,787 of them using the .shop top‑level domain, amounting to about 2.72% of the .shop population they studied. The operation clones legitimate retailers by copying product catalogues, descriptions, branding and imagery, and in some cases even loads images from the real retailers’ infrastructure. While Nebty notes that these domains share website and infrastructure characteristics, this does not prove a single operator runs every domain.
Important checkout details have emerged: around 96% of confirmed DoppelCart shops reportedly shared identical build files and relied on just 27 ecommerce backends. The fake sites impersonate more than 44,000 brands, with some brands such as SodaStream and Daniel Wellington each targeted by more than 30 clones. Shoppers are lured by discounts of up to 65%, encouraging careful domain checks.
The fraudulent checkout pages capture cardholder data and transmit it to attacker‑controlled servers in real time via WebSockets, potentially exposing card numbers, expiry dates, CVVs, billing details and one‑time bank verification codes. The report highlights that even a professional appearance—HTTPS, familiar logos, and authentic product images—does not prove legitimacy.
Practical steps include verifying the retailer through official channels, avoiding unusually large discounts, using credit cards with buyer protection, and keeping security software up to date. If a payment has already been made, victims should contact their card issuer promptly and preserve evidence.