TRUSTMARKET Phishing Campaign Expands to Chileautos and New International Platforms — Threadlinqs Intelligence
As of 2026-08-14, TRUSTMARKET Phishing Campaign Expands to Chileautos and New International Platforms is a medium-severity phishing threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 29 indicators of compromise.
Threat ID: TL-2026-2019 · Severity: MEDIUM · Status: ACTIVE · Category: PHISHING
CronUp CTI identified TRUSTMARKET, a multi-brand phishing operation active for at least six months that abuses legitimate marketplace/rental messaging to establish a transactional pretext before
TRUSTMARKET is a phishing operation documented by CronUp Ciberseguridad on 2026-08-14 that CronUp classifies under a technique it calls TTPH (Trusted Transaction Phishing). Rather than relying on cold email lures, the operators abuse the legitimate in-platform messaging systems of marketplace, classifieds, real-estate, and mobility apps to contact users who are already mid-transaction (a buyer, seller, renter, or rider). The message introduces a plausible transactional pretext tied to that context — payment confirmation, fund receipt, sale validation, identity verification, account confirmation, shipment confirmation, or fund release — and directs the victim to an external, off-platform link to 'complete' the step. That link resolves to a brand-impersonating phishing kit, visually and structurally themed to the specific platform, which captures the victim's login and/or payment credentials.
The full operational chain, as documented by CronUp, is: legitimate platform -> in-platform messaging/comment -> transactional context -> social engineering -> payment/verification/payout pretext -> external redirect -> brand impersonation -> phishing kit -> credential capture.
CronUp assesses the campaign has been active for at least six months as of the report date and has expanded well beyond a single brand. The newest confirmed target is Chileautos, Chile's largest automotive marketplace, observed via the domain chileautos.veriify937.icu. Including Chileautos, CronUp has mapped TRUSTMARKET infrastructure impersonating 11 other platforms: eBay and Zillow (United States), Poshmark and Depop (fashion resale marketplaces, US/UK), Vinted (Lithuania), Kleinanzeigen (Germany), Marktplaats (Netherlands), Booking.com (Netherlands, travel), BlaBlaCar (France, rideshare), Carousell (Singapore), and Fincaraíz (Colombia, real estate). This spans e-commerce, C2C resale, real estate, travel, and mobility verticals across Latin America, North America, Europe, and Asia.
The domain infrastructure follows a highly consistent naming convention: a brand token (e.g. 'ebay', 'vinted', 'kleinanzeigen') combined or chained with transactional keywords such as verification, validation, confirmation, payment, payout, receivefunds, soldconfirm, ordersupport, checkout, and approveprocedure, registered across a wide spread of generic and low-cost TLDs (.shop, .click, .info, .help, .cyou, .cfd, .sbs, .icu, .one, .biz, .app, .world). CronUp also documents a set of TRUSTMARKET-fingerprinted domains (shared kit architecture and naming pattern) that are not yet mapped to a specific impersonated brand, suggesting either staging infrastructure or brands not yet identified.
The phishing kits themselves are multilingual, brand-specific in presentation, but architecturally reusable across brands — the same kit skeleton is re-skinned per target platform. CronUp notes the presence of Russian-language comments and artifacts inside the kit codebase, which it treats explicitly as an infrastructure-correlation signal rather than an attribution claim: the report states this does not permit attributing the operation to a Russian state or criminal actor, only that it is useful for clustering related infrastructure (a pattern CronUp has separately observed in unrelated phishing campaigns using Russian-hosted bulletproof infrastructure). No specific threat actor, group name, or nation-state sponsor is identified.
CronUp's recommended defensive posture is to move away from tracking individual domain IOCs — which rotate rapidly given the low-cost, disposable registration pattern — toward tracking the TTP itself: correlating infrastructure via DNS, TLS certificates, ASN, hosting provider, registrar, nameservers, favicon hashes, and phishing-kit HTML/JS fingerprints, and monitoring for new domain registrations combining a target brand name with transactional keywords.
Target sectors: ecommerce, online marketplaces, real estate, travel and hospitality, automotive, mobility and rideshare, consumer retail
Target regions: chile, Latin America, united states of america, North America, lithuania, germany, netherlands, united kingdom, france, Europe, singapore, Asia
Timeline
- Estimated start of TRUSTMARKET operations, based on CronUp's assessment that the campaign shows indicators of at least six months of activity as of the 2026-08-14 report (exact origin date not disclosed by the source).
- CronUp identifies TRUSTMARKET phishing infrastructure (chileautos.veriify937.icu) impersonating Chileautos, marking the campaign's confirmed expansion into the Chilean automotive marketplace.
- CronUp's analysis confirms TRUSTMARKET infrastructure impersonating 11 additional platforms beyond Chileautos: eBay, Poshmark, Zillow, Vinted, Kleinanzeigen, Marktplaats, Booking.com, Depop, BlaBlaCar, Carousell, and Fincaraíz.
- CronUp documents that the TRUSTMARKET phishing kits share a reusable, brand-agnostic architecture that is re-skinned per impersonated platform, with consistent transactional-keyword domain naming across brands.
- CronUp documents Russian-language comments and artifacts within the phishing kit codebase, explicitly flagging this as an infrastructure-correlation signal rather than a basis for nation-state attribution.
- CronUp publishes 'Phishing en Chileautos revela expansión de campaña TRUSTMARKET hacia nuevas plataformas y países,' documenting the full TTPH operational chain and the complete list of observed domain IOCs.
- CronUp issues guidance recommending Digital Risk Protection teams track brand-plus-transactional-keyword domain registration patterns and infrastructure fingerprints rather than individual rotating IOCs.
Detections & IOCs
As of 2026-09-04, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 29 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
PHISHING, MEDIUM, threat intelligence, cybersecurity, T1583.001, T1588.002, T1566, T1566.002, T1566.003, T1204.001, T1056.003, T1684.001, T1036.005, T1657