Seller Offers Live Deep Link Keys Enabling Phishing on a Shared Domain Trusted by 2,553 Apps
An actor posting as exfilar is selling three live production API keys for Branch, a mobile deep linking platform, which they say permit unlimited link creation on Branch's default shared link domain, bnc.lt. The seller states the domain is used for legitimate deep links by 2,553 mobile applications across banking, retail, travel, healthcare, and social sectors, and that links they generate are indistinguishable from genuine ones. The keys were reportedly harvested from publicly published developer packages rather than any intrusion. No application has been breached, and the named apps are users of the shared domain, not victims of a compromise. Price is $15,000.
▣Listing details
!Advertised capability
- Link creation on shared domain
- Custom link aliases
- Preview title control
- Preview description control
- Preview image control
- Arbitrary destination URLs
- Platform-specific redirects
- No observed rate limiting
- Links persist without expiry
- Attribution report on affected apps
◱Screenshots
⚠Potential impact
Nothing has been stolen; what is being sold is borrowed reputation. A phishing link on a shared domain that thousands of legitimate apps use every day inherits their trust: corporate allowlists permit it, spam filters pass it, and it triggers no newly-registered-domain or typosquatting alerts. It also defeats the advice users are actually given, since checking the domain and the certificate both come back clean. Because the seller controls the link preview text and image as well as the destination, a message can be made to look like a notification from an app the recipient uses. The practical defence is to stop treating shared link domains as trustworthy by reputation, and for app operators to move to their own branded link domain where the platform allows it.
iStatus
UnverifiedDark Web Informer is not reproducing the keys, the packages they were taken from, the key format, the endpoints, the collection method, or the contact route, since together these would constitute working phishing infrastructure. The named applications are users of a shared domain and have not been compromised; nor is any intrusion into the platform claimed. The seller characterises this as an architectural weakness rather than a vulnerability, which the platform operator has not addressed publicly. This is the fifth listing from this actor in a week. The claim is unverified.
DARK WEB INFORMER - THREAT INTELLIGENCE