Skip to content

Seller Offers Live Deep Link Keys Enabling Phishing on a Shared Domain Trusted by 2,553 Apps

Capability Listing Global Reach Mobile / Deep Linking Phishing Infrastructure

Seller Offers Live Deep Link Keys Enabling Phishing on a Shared Domain Trusted by 2,553 Apps

An actor posting as exfilar is selling three live production API keys for Branch, a mobile deep linking platform, which they say permit unlimited link creation on Branch's default shared link domain, bnc.lt. The seller states the domain is used for legitimate deep links by 2,553 mobile applications across banking, retail, travel, healthcare, and social sectors, and that links they generate are indistinguishable from genuine ones. The keys were reportedly harvested from publicly published developer packages rather than any intrusion. No application has been breached, and the named apps are users of the shared domain, not victims of a compromise. Price is $15,000.

Apps trusting domain2,553
Live keys3
Price$15,000
Actorexfilar

Listing details

TypeCapability sale, not a breach
PlatformBranch deep linking
SectorMobile app infrastructure
Listing$15,000, escrow, crypto
SourcePublic developer packages
Reach666 iOS, 1,887 Android apps
Observed
Actorexfilar

!Advertised capability

  • Link creation on shared domain
  • Custom link aliases
  • Preview title control
  • Preview description control
  • Preview image control
  • Arbitrary destination URLs
  • Platform-specific redirects
  • No observed rate limiting
  • Links persist without expiry
  • Attribution report on affected apps

Screenshots

Potential impact

Nothing has been stolen; what is being sold is borrowed reputation. A phishing link on a shared domain that thousands of legitimate apps use every day inherits their trust: corporate allowlists permit it, spam filters pass it, and it triggers no newly-registered-domain or typosquatting alerts. It also defeats the advice users are actually given, since checking the domain and the certificate both come back clean. Because the seller controls the link preview text and image as well as the destination, a message can be made to look like a notification from an app the recipient uses. The practical defence is to stop treating shared link domains as trustworthy by reputation, and for app operators to move to their own branded link domain where the platform allows it.

iStatus

Unverified

Dark Web Informer is not reproducing the keys, the packages they were taken from, the key format, the endpoints, the collection method, or the contact route, since together these would constitute working phishing infrastructure. The named applications are users of a shared domain and have not been compromised; nor is any intrusion into the platform claimed. The seller characterises this as an architectural weakness rather than a vulnerability, which the platform operator has not addressed publicly. This is the fifth listing from this actor in a week. The claim is unverified.

Want everything on this breach? Paid subscribers get the full claim details and more. Check out the threat feed, then after subscribing, search there for this alert. View pricing →

DARK WEB INFORMER - THREAT INTELLIGENCE

Latest