The network is concentrated in the .SHOP top-level domain, where its sites account for 2.72 percent of all registered domains, Nebty said in a report shared with BleepingComputer. The company's latest scans show that more than 105,000 DoppelCart shops are still active.
Nebty says 96 percent of the shops confirmed to be part of DoppelCart share identical build files and resolve to 27 commerce backends. The sites impersonate legitimate businesses by copying product catalogs, descriptions, branding and images, sometimes loading assets directly from the real company's servers.
Nebty CEO Benedikt Scheungraber told BleepingComputer that the shops mimic 44,182 different brands, with a median of two clones for each. Some brands drew heavier attention, including SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA and SPARK PAWS, each with more than 30 fake shops.
The fraudulent sites lure bargain-hunting shoppers with discounts of up to 65 percent. When Nebty tested several checkout pages, it found code that collects card numbers, expiration dates, security codes, cardholder names, email addresses, phone numbers and physical addresses, transmitting each field over WebSockets to a command-and-control server in real time. The checkout code can also relay the one-time confirmation code issued by a victim's bank, which attackers may use to bypass security protections.
Some of the fake stores display the impersonated brand's legitimate support address, meaning customers who never receive their purchases end up contacting the real company. Nebty says it attempted to contact the main hosting provider for DoppelCart sites but received no response. The company has created a searchable database to help businesses identify whether they are being impersonated and take protective action.