> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Seller Offers Live Deep Link Keys Enabling Phishing on a Shared Domain Trusted by 2,553 Apps
- URL: https://darkwebinformer.com/seller-offers-live-deep-link-keys-enabling-phishing-on-a-shared-domain-trusted-by-2-553-apps/
- Published: 2026-08-12T18:18:26.000Z
- Updated: 2026-08-12T18:18:26.000Z
- Author: Dark Web Informer
- Tags: Data Breaches

Capability Listing Global Reach Mobile / Deep Linking Phishing Infrastructure 

## Seller Offers Live Deep Link Keys Enabling Phishing on a Shared Domain Trusted by 2,553 Apps

An actor posting as **exfilar** is selling three live production API keys for **Branch**, a mobile deep linking platform, which they say permit unlimited link creation on Branch's **default shared link domain**, **bnc.lt**. The seller states the domain is used for legitimate deep links by **2,553 mobile applications** across banking, retail, travel, healthcare, and social sectors, and that links they generate are indistinguishable from genuine ones. The keys were reportedly harvested from **publicly published developer packages** rather than any intrusion. **No application has been breached**, and the named apps are users of the shared domain, not victims of a compromise. Price is **$15,000**.

Severity HIGH 

Apps trusting domain2,553

Live keys3

Price$15,000

Actorexfilar

### ▣Listing details

TypeCapability sale, not a breach

PlatformBranch deep linking

SectorMobile app infrastructure

Listing$15,000, escrow, crypto

SourcePublic developer packages

Reach666 iOS, 1,887 Android apps

ObservedAug 12, 2026

Actorexfilar

### !Advertised capability

- Link creation on shared domain
- Custom link aliases
- Preview title control
- Preview description control
- Preview image control
- Arbitrary destination URLs
- Platform-specific redirects
- No observed rate limiting
- Links persist without expiry
- Attribution report on affected apps

### ◱Screenshots

[ ![Deep link API key sale listing screenshot, August 2026 (1 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598762.png) Screenshot 1 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598762.png) [ ![Deep link API key sale listing screenshot, August 2026 (2 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598763.png) Screenshot 2 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598763.png) [ ![Deep link API key sale listing screenshot, August 2026 (3 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598764.png) Screenshot 3 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598764.png) [ ![Deep link API key sale listing screenshot, August 2026 (4 of 4)](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598765.png) Screenshot 4 Redacted preview ](https://storage.ghost.io/c/6b/16/6b16ac9c-cd67-432f-b0f3-bbec941084ff/content/images/2026/08/9278935798662359876235987623598765.png) 

### ⚠Potential impact

Nothing has been stolen; what is being sold is **borrowed reputation**. A phishing link on a shared domain that thousands of legitimate apps use every day inherits their trust: **corporate allowlists permit it, spam filters pass it, and it triggers no newly-registered-domain or typosquatting alerts**. It also defeats the advice users are actually given, since checking the domain and the certificate both come back clean. Because the seller controls the link preview text and image as well as the destination, a message can be made to look like a notification from an app the recipient uses. The **practical defence is to stop treating shared link domains as trustworthy by reputation**, and for app operators to move to their own branded link domain where the platform allows it.

### iStatus

Unverified 

Dark Web Informer is **not reproducing the keys, the packages they were taken from, the key format, the endpoints, the collection method, or the contact route**, since together these would constitute working phishing infrastructure. The named applications are **users of a shared domain and have not been compromised**; nor is any intrusion into the platform claimed. The seller characterises this as an architectural weakness rather than a vulnerability, which the platform operator has not addressed publicly. This is the **fifth listing from this actor in a week**. The claim is **unverified**.

Want everything on this breach? **Paid subscribers** get the full claim details and more. Check out the [threat feed](https://darkwebinformer.com/threat-feed/), then after subscribing, search there for this alert. [View pricing →](https://darkwebinformer.com/pricing) 

[DARK WEB INFORMER](https://darkwebinformer.com/) \- THREAT INTELLIGENCE