TRUSTMARKET Phishing Campaign Expands to Chileautos and New International Platforms

TRUSTMARKET Phishing Campaign Expands to Chileautos and New (TL-2026-2019), also tracked as TTPH, is a medium-severity phishing campaign, first published 2026-08-14. It has no confirmed attribution, affects Chileautos Chileautos automotive marketplace platform, maps to 10 MITRE ATT&CK techniques (T1036.005, T1056.003, T1204.001), and is covered by 9 detection rules and 29 indicators of compromise.

Key facts for TL-2026-2019

Threat ID
TL-2026-2019
Also known as
TTPH, Trusted Transaction Phishing
Severity
MEDIUM
Status
ACTIVE
Category
PHISHING
First published
2026-08-14
Last reviewed
2026-08-14
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
ecommerce, online marketplaces, real estate, travel and hospitality, automotive, mobility and rideshare, consumer retail
Target regions
chile, Latin America, united states of america, North America, lithuania, germany, netherlands, united kingdom, france, Europe, singapore, Asia
Detection rules
9
Indicators of compromise
29

CronUp CTI identified TRUSTMARKET, a multi-brand phishing operation active for at least six months that abuses legitimate marketplace/rental messaging to establish a transactional pretext before redirecting victims to brand-impersonating credential-harvesting kits. The campaign has expanded to Chileautos (Chile) and now spans 11+ platforms across the Americas, Europe, and Asia, using domains patterned on transactional keywords (verification, payout, confirmation).

How TRUSTMARKET Phishing Campaign Expands to Chileautos and New works

TRUSTMARKET is a phishing operation documented by CronUp Ciberseguridad on 2026-08-14 that CronUp classifies under a technique it calls TTPH (Trusted Transaction Phishing). Rather than relying on cold email lures, the operators abuse the legitimate in-platform messaging systems of marketplace, classifieds, real-estate, and mobility apps to contact users who are already mid-transaction (a buyer, seller, renter, or rider). The message introduces a plausible transactional pretext tied to that context — payment confirmation, fund receipt, sale validation, identity verification, account confirmation, shipment confirmation, or fund release — and directs the victim to an external, off-platform link to 'complete' the step. That link resolves to a brand-impersonating phishing kit, visually and structurally themed to the specific platform, which captures the victim's login and/or payment credentials.

The full operational chain, as documented by CronUp, is: legitimate platform -> in-platform messaging/comment -> transactional context -> social engineering -> payment/verification/payout pretext -> external redirect -> brand impersonation -> phishing kit -> credential capture.

CronUp assesses the campaign has been active for at least six months as of the report date and has expanded well beyond a single brand. The newest confirmed target is Chileautos, Chile's largest automotive marketplace, observed via the domain chileautos.veriify937.icu. Including Chileautos, CronUp has mapped TRUSTMARKET infrastructure impersonating 11 other platforms: eBay and Zillow (United States), Poshmark and Depop (fashion resale marketplaces, US/UK), Vinted (Lithuania), Kleinanzeigen (Germany), Marktplaats (Netherlands), Booking.com (Netherlands, travel), BlaBlaCar (France, rideshare), Carousell (Singapore), and Fincaraíz (Colombia, real estate). This spans e-commerce, C2C resale, real estate, travel, and mobility verticals across Latin America, North America, Europe, and Asia.

The domain infrastructure follows a highly consistent naming convention: a brand token (e.g. 'ebay', 'vinted', 'kleinanzeigen') combined or chained with transactional keywords such as verification, validation, confirmation, payment, payout, receivefunds, soldconfirm, ordersupport, checkout, and approveprocedure, registered across a wide spread of generic and low-cost TLDs (.shop, .click, .info, .help, .cyou, .cfd, .sbs, .icu, .one, .biz, .app, .world). CronUp also documents a set of TRUSTMARKET-fingerprinted domains (shared kit architecture and naming pattern) that are not yet mapped to a specific impersonated brand, suggesting either staging infrastructure or brands not yet identified.

The phishing kits themselves are multilingual, brand-specific in presentation, but architecturally reusable across brands — the same kit skeleton is re-skinned per target platform. CronUp notes the presence of Russian-language comments and artifacts inside the kit codebase, which it treats explicitly as an infrastructure-correlation signal rather than an attribution claim: the report states this does not permit attributing the operation to a Russian state or criminal actor, only that it is useful for clustering related infrastructure (a pattern CronUp has separately observed in unrelated phishing campaigns using Russian-hosted bulletproof infrastructure). No specific threat actor, group name, or nation-state sponsor is identified.

CronUp's recommended defensive posture is to move away from tracking individual domain IOCs — which rotate rapidly given the low-cost, disposable registration pattern — toward tracking the TTP itself: correlating infrastructure via DNS, TLS certificates, ASN, hosting provider, registrar, nameservers, favicon hashes, and phishing-kit HTML/JS fingerprints, and monitoring for new domain registrations combining a target brand name with transactional keywords.

MITRE ATT&CK techniques used in TL-2026-2019

Defense Evasion

T1036.005 Match Legitimate Resource Name or Location; T1684.001 Impersonation

Credential Access

T1056.003 Input Capture: Web Portal Capture

Execution

T1204.001 User Execution: Malicious Link

Initial Access

T1566 Phishing; T1566.002 Phishing: Spearphishing Link; T1566.003 Phishing: Spearphishing via Service

Resource Development

T1583.001 Acquire Infrastructure: Domains; T1588.002 Obtain Capabilities: Tool

Impact

T1657 Financial Theft

Affected products and versions in TRUSTMARKET Phishing Campaign Expands to Chileautos and New

  • Chileautos — Chileautos automotive marketplace platform
  • eBay Inc. — eBay marketplace platform
  • Poshmark, Inc. — Poshmark fashion marketplace platform
  • Zillow Group — Zillow real estate platform
  • Vinted UAB — Vinted fashion marketplace platform
  • eBay Kleinanzeigen GmbH — Kleinanzeigen classifieds platform
  • Marktplaats BV — Marktplaats classifieds platform
  • Booking Holdings — Booking.com travel/reservations platform
  • Depop Ltd — Depop fashion resale marketplace platform
  • BlaBlaCar — BlaBlaCar rideshare/mobility platform

Remediation for TRUSTMARKET Phishing Campaign Expands to Chileautos and New

Immediate actions

  • Block and monitor the listed TRUSTMARKET phishing domains, and any domain matching the observed naming pattern (brand token + verification/validation/confirmation/payout/receivefunds/soldconfirm/checkout), at DNS resolver and web proxy layers
  • Alert and warn users of the affected marketplaces (Chileautos, eBay, Poshmark, Zillow, Vinted, Kleinanzeigen, Marktplaats, Booking.com, Depop, BlaBlaCar, Carousell, Fincaraíz) who report being asked to move a transaction off-platform to an external 'verification' or 'payout' link
  • Report confirmed TRUSTMARKET phishing domains to their registrars and hosting providers for takedown

Workarounds

  • Keep all transaction communication and payment/verification steps inside the official platform's app or website; treat any in-message request to continue on an external link as a phishing indicator

Longer-term hardening

  • Deploy Digital Risk Protection monitoring for new domain registrations combining a protected brand name with transactional keywords (verification, validation, confirmation, payment, payout, receivefunds)
  • Correlate emerging phishing infrastructure via DNS, TLS certificate, ASN, hosting provider, registrar, nameserver, favicon-hash, and phishing-kit HTML/JS fingerprint pivoting rather than tracking individual rotating domains
  • Educate marketplace, classifieds, real-estate, and mobility-platform users that legitimate transaction verification and payment never require navigating to an external, off-platform site

Timeline of TRUSTMARKET Phishing Campaign Expands to Chileautos and New

  • Estimated start of TRUSTMARKET operations, based on CronUp's assessment that the campaign shows indicators of at least six months of activity as of the 2026-08-14 report (exact origin date not disclosed by the source).
  • CronUp issues guidance recommending Digital Risk Protection teams track brand-plus-transactional-keyword domain registration patterns and infrastructure fingerprints rather than individual rotating IOCs.
  • CronUp publishes 'Phishing en Chileautos revela expansión de campaña TRUSTMARKET hacia nuevas plataformas y países,' documenting the full TTPH operational chain and the complete list of observed domain IOCs.
  • CronUp documents Russian-language comments and artifacts within the phishing kit codebase, explicitly flagging this as an infrastructure-correlation signal rather than a basis for nation-state attribution.
  • CronUp documents that the TRUSTMARKET phishing kits share a reusable, brand-agnostic architecture that is re-skinned per impersonated platform, with consistent transactional-keyword domain naming across brands.
  • CronUp's analysis confirms TRUSTMARKET infrastructure impersonating 11 additional platforms beyond Chileautos: eBay, Poshmark, Zillow, Vinted, Kleinanzeigen, Marktplaats, Booking.com, Depop, BlaBlaCar, Carousell, and Fincaraíz.
  • CronUp identifies TRUSTMARKET phishing infrastructure (chileautos.veriify937.icu) impersonating Chileautos, marking the campaign's confirmed expansion into the Chilean automotive marketplace.

Sources cited for TRUSTMARKET Phishing Campaign Expands to Chileautos and New

Threats related to TRUSTMARKET Phishing Campaign Expands to Chileautos and New

Detection coverage for TL-2026-2019

As of 2026-08-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2019 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats