Mianju (面具): Mapping the Largest Chinese Scam Infrastructure via a Single Fingerprint
ID: b1c7c0a5-8758-4428-b2c8-c47a16cf65c4
STIX ID: report--b1c7c0a5-8758-4428-b2c8-c47a16cf65c4
Threat Score
70/100
The report details an investigation that exposed a large, automated Chinese fraud/scam infrastructure ("面具" / mianju) consisting of tens of thousands of victim domains and multiple C2/redirect layers. Using Webamon fingerprinting and OSINT, the author maps ~59k password-gated scam pages, identifies primary domains (sqlq.com, urldance.com, 51.la) and a legitimacy front (zhimianjun.com), and documents operator techniques including DGA-like domain batches and fake Cloudflare-style error pages to maintain deception.
