Editorial mirrorBrand mentions redacted to public IDs. Hover to inspect. Everything else is theatre.How it works
THE ENABLERS REGISTRYRegistrar accountability archive
Archive LiveRead-only public record · No ads · No tracking
Case file folder with redacted documents and confidential investigation report.
CASE / MOZ FAKE EXTENSIONS PAID MEDIA

150+ Fake [REDACTED] Extensions: One Backend, One Network

The Enablers Registry·Editorial mirror·/moz-fake-extensions-paid-media

Public record copy. Brand names withheld, public accreditation numbers preserved. If the body below says “we”, that means the original publisher, not this mirror. TER only preserves, redacts, and re-contextualizes.

Investigation • 6—8 min read

150+ Fake [REDACTED] Extensions — One Backend & Paid Media

Media blamed “Russian bears” for 150+ fake [REDACTED] extensions. Our findings show Nigerian infrastructure (IP 185.208.156.66), recycled possibly phishing kits, and how paid articles helped spread the myth.

Originally published on Medium — THE ENABLERS REGISTRY

The Misleading Narrative

A story about "150+ fake [REDACTED] extensions" tied to a supposed "Russian trail" was amplified across major crypto and security outlets. It sounds dramatic, but our analysis shows this narrative is misleading — and worse, it shields the real perpetrators.

150+ Low-Quality Extensions on a Single Backend

All extensions in this campaign were:

  • Non-unique, copy-paste quality.
  • Only logos and names varied.
  • All connected to a single backend.
Backend IP: 185.208.156.66
The backend domain was [REDACTED]/app.php. Most domains tied to this IP are now dead, but archives preserved snapshots through Urlscan and WebArchive.

Our Actions Against This Campaign

As a volunteer threat intelligence group specializing in possibly phishing and scam infrastructure takedowns, we:

  • Submitted reports directly to [REDACTED] to flag malicious extensions.
  • Escalated to [REDACTED], requesting professional assistance to accelerate banning.
  • Published a report on Chainabuse for community visibility.
  • Injected millions of empty seed phrases into the attackers' backend to pollute stolen data.

Why This Is Not "Russian" Infrastructure

Russian-speaking threat actors typically use:

  • Distributed backends (IANA #1910 Workers, Firebase, Amazon, unique links per campaign).
  • Obfuscation and redundancy to avoid single points of failure.

Instead, this campaign showed:

  • A Nigerian hosting provider.
  • Neighboring domains tied to bank scams, fake crypto wallets, fake delivery scams.
  • A [REDACTED] account receiving stolen data linked to a Nigerian operator.
"Russian groups build sophisticated infrastructures. This was cheap, centralized, and unsophisticated — exactly what we've seen before on Nigerian servers."

The Paid Media Problem

Paid media placements create serious consequences:

  1. One paid article in a respected outlet gets published.
  2. Hundreds of smaller sites, blogs, and [REDACTED] channels rewrite or translate it.
  3. Within days, it becomes a massive fake narrative with the illusion of credibility.
"Victims see 'the Russian trail,' believe the case is closed, and stop reporting to authorities. Real criminals remain untouched."

Example: Angel Drainer

Every major outlet ran headlines about "Angel Drainer shutdown after devs identified." But was it true — or just another paid placement repeated until it looked credible? For criminals, buying articles is pocket change; for victims, it changes everything.

Cybersecurity Companies Buying Their Own PR

Cybersecurity companies pay tens of thousands of dollars for articles about themselves, their research, and their impact. This raises fundamental questions:

  • Why does a real cybersecurity group need to pay for coverage?
  • Are they trying to bury the real hacker's trail?
  • Or leverage the hacker's identity for blackmail or competitive gain?
  • Is the purpose to strengthen trust — or manipulate perception for profit?
"If cybersecurity becomes another PR game, where facts are shaped by who pays more, then trust in this field collapses."

Evidence of the Market

The practice is not hidden:

  • On Fiverr, Upwork, and specialized PR markets, you can directly purchase "guest posts."
  • Providers send Google Sheets with dozens of outlets and prices — including well-known cybersecurity brands.
  • Some promise: "for an extra fee, no sponsored label."

Stated goals for buying articles include:

  • Link Building (SEO).
  • Traffic & Sales.
  • Brand Awareness.
  • Reputation Management (burying negatives).
  • Social Verification.
  • Publication Lists for Visa Applications.

Costs mentioned include over $20,000 for paid interview slots from major crypto media outlets.

"This is not journalism. It is a market — where credibility is bought and sold."

Business vs. Lies

Publishing paid content is not illegal — it's business. But when it crosses into publishing false claims, misdirecting investigations, and disguising PR as fact, it becomes part of the problem.

Conclusion

THE ENABLERS REGISTRY is a volunteer cybersecurity initiative that doesn't get paid, sell ads, or profit. The facts are clear:

  • 150+ [REDACTED] extensions routed to a single backend on Nigerian hosting.
  • Data went to a Nigerian [REDACTED] account.
  • The "Russian trail" narrative is fabricated.
  • Paid media coverage amplified this fabrication until it looked like truth.
  • Even cybersecurity companies themselves pay for self-promotion.
"Selling ads is business. Selling lies as facts shields criminals. And when even cybersecurity sells narratives, the victims — and justice — lose."

Disclaimer

We are not accusing any individual, company, or media outlet. All facts are open-source and verifiable through public archives, scanners, and reports. The real question: why are such narratives controlled and amplified? Who benefits when an unknown security company publishes an inaccurate mega-investigation that shifts attention away from real actors?

#MozillaExtensions #PaidMedia #Disinformation #ThreatIntel #OSINT

Share This Investigation

Related Investigations

[REDACTED] TDS: 1,500 Panels Exposed, Zero Legit Uses
INVESTIGATION
[REDACTED] TDS: 1,500 Panels Exposed, Zero Legit Uses
[REDACTED] BlockBlasters Malware: Platform Negligence Exposed
INVESTIGATION
[REDACTED] BlockBlasters Malware: Platform Negligence Exposed
Scammers Exposed: 4 Scam Backends Dissected
INVESTIGATION
Scammers Exposed: 4 Scam Backends Dissected

Continue browsing the ledger

This page is the editorial mirror. Brand names are redacted to public IANA / business identifiers. Use the index to navigate other case files.

Open registrar ledger → All briefings