TRUSTMARKET Phishing Campaign Expands to Chileautos and New International Platforms
TRUSTMARKET Phishing Campaign Expands to Chileautos and New (TL-2026-2019), also tracked as TTPH, is a medium-severity phishing campaign, first published 2026-08-14. It has no confirmed attribution, affects Chileautos Chileautos automotive marketplace platform, maps to 10 MITRE ATT&CK techniques (T1036.005, T1056.003, T1204.001), and is covered by 9 detection rules and 29 indicators of compromise.
Key facts for TL-2026-2019
- Threat ID
- TL-2026-2019
- Also known as
- TTPH, Trusted Transaction Phishing
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- PHISHING
- First published
- 2026-08-14
- Last reviewed
- 2026-08-14
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- ecommerce, online marketplaces, real estate, travel and hospitality, automotive, mobility and rideshare, consumer retail
- Target regions
- chile, Latin America, united states of america, North America, lithuania, germany, netherlands, united kingdom, france, Europe, singapore, Asia
- Detection rules
- 9
- Indicators of compromise
- 29
CronUp CTI identified TRUSTMARKET, a multi-brand phishing operation active for at least six months that abuses legitimate marketplace/rental messaging to establish a transactional pretext before redirecting victims to brand-impersonating credential-harvesting kits. The campaign has expanded to Chileautos (Chile) and now spans 11+ platforms across the Americas, Europe, and Asia, using domains patterned on transactional keywords (verification, payout, confirmation).
How TRUSTMARKET Phishing Campaign Expands to Chileautos and New works
TRUSTMARKET is a phishing operation documented by CronUp Ciberseguridad on 2026-08-14 that CronUp classifies under a technique it calls TTPH (Trusted Transaction Phishing). Rather than relying on cold email lures, the operators abuse the legitimate in-platform messaging systems of marketplace, classifieds, real-estate, and mobility apps to contact users who are already mid-transaction (a buyer, seller, renter, or rider). The message introduces a plausible transactional pretext tied to that context — payment confirmation, fund receipt, sale validation, identity verification, account confirmation, shipment confirmation, or fund release — and directs the victim to an external, off-platform link to 'complete' the step. That link resolves to a brand-impersonating phishing kit, visually and structurally themed to the specific platform, which captures the victim's login and/or payment credentials.
The full operational chain, as documented by CronUp, is: legitimate platform -> in-platform messaging/comment -> transactional context -> social engineering -> payment/verification/payout pretext -> external redirect -> brand impersonation -> phishing kit -> credential capture.
CronUp assesses the campaign has been active for at least six months as of the report date and has expanded well beyond a single brand. The newest confirmed target is Chileautos, Chile's largest automotive marketplace, observed via the domain chileautos.veriify937.icu. Including Chileautos, CronUp has mapped TRUSTMARKET infrastructure impersonating 11 other platforms: eBay and Zillow (United States), Poshmark and Depop (fashion resale marketplaces, US/UK), Vinted (Lithuania), Kleinanzeigen (Germany), Marktplaats (Netherlands), Booking.com (Netherlands, travel), BlaBlaCar (France, rideshare), Carousell (Singapore), and Fincaraíz (Colombia, real estate). This spans e-commerce, C2C resale, real estate, travel, and mobility verticals across Latin America, North America, Europe, and Asia.
The domain infrastructure follows a highly consistent naming convention: a brand token (e.g. 'ebay', 'vinted', 'kleinanzeigen') combined or chained with transactional keywords such as verification, validation, confirmation, payment, payout, receivefunds, soldconfirm, ordersupport, checkout, and approveprocedure, registered across a wide spread of generic and low-cost TLDs (.shop, .click, .info, .help, .cyou, .cfd, .sbs, .icu, .one, .biz, .app, .world). CronUp also documents a set of TRUSTMARKET-fingerprinted domains (shared kit architecture and naming pattern) that are not yet mapped to a specific impersonated brand, suggesting either staging infrastructure or brands not yet identified.
The phishing kits themselves are multilingual, brand-specific in presentation, but architecturally reusable across brands — the same kit skeleton is re-skinned per target platform. CronUp notes the presence of Russian-language comments and artifacts inside the kit codebase, which it treats explicitly as an infrastructure-correlation signal rather than an attribution claim: the report states this does not permit attributing the operation to a Russian state or criminal actor, only that it is useful for clustering related infrastructure (a pattern CronUp has separately observed in unrelated phishing campaigns using Russian-hosted bulletproof infrastructure). No specific threat actor, group name, or nation-state sponsor is identified.
CronUp's recommended defensive posture is to move away from tracking individual domain IOCs — which rotate rapidly given the low-cost, disposable registration pattern — toward tracking the TTP itself: correlating infrastructure via DNS, TLS certificates, ASN, hosting provider, registrar, nameservers, favicon hashes, and phishing-kit HTML/JS fingerprints, and monitoring for new domain registrations combining a target brand name with transactional keywords.
MITRE ATT&CK techniques used in TL-2026-2019
Defense Evasion
T1036.005 Match Legitimate Resource Name or Location; T1684.001 Impersonation
Credential Access
T1056.003 Input Capture: Web Portal Capture
Execution
T1204.001 User Execution: Malicious Link
Initial Access
T1566 Phishing; T1566.002 Phishing: Spearphishing Link; T1566.003 Phishing: Spearphishing via Service
Resource Development
T1583.001 Acquire Infrastructure: Domains; T1588.002 Obtain Capabilities: Tool
Impact
Affected products and versions in TRUSTMARKET Phishing Campaign Expands to Chileautos and New
- Chileautos — Chileautos automotive marketplace platform
- eBay Inc. — eBay marketplace platform
- Poshmark, Inc. — Poshmark fashion marketplace platform
- Zillow Group — Zillow real estate platform
- Vinted UAB — Vinted fashion marketplace platform
- eBay Kleinanzeigen GmbH — Kleinanzeigen classifieds platform
- Marktplaats BV — Marktplaats classifieds platform
- Booking Holdings — Booking.com travel/reservations platform
- Depop Ltd — Depop fashion resale marketplace platform
- BlaBlaCar — BlaBlaCar rideshare/mobility platform
Remediation for TRUSTMARKET Phishing Campaign Expands to Chileautos and New
Immediate actions
- Block and monitor the listed TRUSTMARKET phishing domains, and any domain matching the observed naming pattern (brand token + verification/validation/confirmation/payout/receivefunds/soldconfirm/checkout), at DNS resolver and web proxy layers
- Alert and warn users of the affected marketplaces (Chileautos, eBay, Poshmark, Zillow, Vinted, Kleinanzeigen, Marktplaats, Booking.com, Depop, BlaBlaCar, Carousell, Fincaraíz) who report being asked to move a transaction off-platform to an external 'verification' or 'payout' link
- Report confirmed TRUSTMARKET phishing domains to their registrars and hosting providers for takedown
Workarounds
- Keep all transaction communication and payment/verification steps inside the official platform's app or website; treat any in-message request to continue on an external link as a phishing indicator
Longer-term hardening
- Deploy Digital Risk Protection monitoring for new domain registrations combining a protected brand name with transactional keywords (verification, validation, confirmation, payment, payout, receivefunds)
- Correlate emerging phishing infrastructure via DNS, TLS certificate, ASN, hosting provider, registrar, nameserver, favicon-hash, and phishing-kit HTML/JS fingerprint pivoting rather than tracking individual rotating domains
- Educate marketplace, classifieds, real-estate, and mobility-platform users that legitimate transaction verification and payment never require navigating to an external, off-platform site
Timeline of TRUSTMARKET Phishing Campaign Expands to Chileautos and New
- Estimated start of TRUSTMARKET operations, based on CronUp's assessment that the campaign shows indicators of at least six months of activity as of the 2026-08-14 report (exact origin date not disclosed by the source).
- CronUp issues guidance recommending Digital Risk Protection teams track brand-plus-transactional-keyword domain registration patterns and infrastructure fingerprints rather than individual rotating IOCs.
- CronUp publishes 'Phishing en Chileautos revela expansión de campaña TRUSTMARKET hacia nuevas plataformas y países,' documenting the full TTPH operational chain and the complete list of observed domain IOCs.
- CronUp documents Russian-language comments and artifacts within the phishing kit codebase, explicitly flagging this as an infrastructure-correlation signal rather than a basis for nation-state attribution.
- CronUp documents that the TRUSTMARKET phishing kits share a reusable, brand-agnostic architecture that is re-skinned per impersonated platform, with consistent transactional-keyword domain naming across brands.
- CronUp's analysis confirms TRUSTMARKET infrastructure impersonating 11 additional platforms beyond Chileautos: eBay, Poshmark, Zillow, Vinted, Kleinanzeigen, Marktplaats, Booking.com, Depop, BlaBlaCar, Carousell, and Fincaraíz.
- CronUp identifies TRUSTMARKET phishing infrastructure (chileautos.veriify937.icu) impersonating Chileautos, marking the campaign's confirmed expansion into the Chilean automotive marketplace.
Sources cited for TRUSTMARKET Phishing Campaign Expands to Chileautos and New
- Phishing en Chileautos revela expansión de campaña TRUSTMARKET hacia nuevas plataformas y países
- Phishing Avanzado, BEC y Abuso de Plataformas Legítimas: La Evolución del Riesgo para las Organizaciones
- MITRE ATT&CK: Phishing (T1566)
- MITRE ATT&CK: Phishing: Spearphishing via Service (T1566.003)
- MITRE ATT&CK: Impersonation (T1656)
- MITRE ATT&CK: Acquire Infrastructure: Domains (T1583.001)
- MITRE ATT&CK: Input Capture: Web Portal Capture (T1056.003)
- MITRE ATT&CK: Financial Theft (T1657)
Threats related to TRUSTMARKET Phishing Campaign Expands to Chileautos and New
- Formula 1 Phishing Campaign & Kit Analysis: Real-Time BIN-Routed Ticketing Fraud Kit Targets Middle East Banking Customers (SOCRadar STRU)
- Top Phishing-Kit Platforms Driving AiTM Session-Theft and MFA-Bypass Campaigns (SOCRadar, Aug 2026)
- Check Point Q2 2026 Brand Phishing Report: Microsoft Leads at 23%, ChatGPT Enters Top 10 Impersonated Brands
- GHOST STADIUM Phishing Campaign Clones FIFA World Cup 2026 Ticket Sites to Steal Card Data and OTPs
- Balonx Sistema: Mexican Phishing-as-a-Service Platform Combines Real-Time MITM, Android RAT, and AI Vishing to Target 20+ Financial Institutions
- Zscaler ThreatLabz 2026 Phishing Report: Volume Falls 20% as AI Trades Mass Spam for Targeted, Higher-Conversion Credential & Session-Theft Campaigns
Detection coverage for TL-2026-2019
As of 2026-08-14, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2019 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.