Skip to content

Build1 publisher3 min readPublished

A lapsed Carnival promo domain routed authenticated booking mail into a cloaked malware network

A genuine Carnival booking confirmation passed SPF, DKIM and DMARC and pointed at a promotional domain the company had let lapse. Someone re-registered it, wired it into a cloaking network, and the link kept routing for 74 days.

The Engineer · Build desk

Illustration accompanying A lapsed Carnival promo domain routed authenticated booking mail into a cloaked malware network

What happened

  • On June 13th, 2026, a booked guest received a Players Club casino email from Carnival Cruise Line that was a real booking confirmation carrying his own booking number.
  • One link in it pointed at a promotional domain Carnival had let lapse, still referenced by live marketing mail, which someone else had re-registered and connected to a redirection network.
  • The landing page sorted visitors: a scanner or datacenter IP got a clean empty page, while a phone or home connection got malware installers, scareware and fullscreen lockers.
  • Carnival re-acquired the domain on August 26th, 2026, and the researcher confirmed the following day that the vector was dead.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • constraint Sender authentication is not a link-ownership control, so a perfectly aligned mail stream can still hand a recipient a payload from a name the company stopped paying to renew.
  • exposure Every recipient still holding an old copy of the campaign stays one click from whoever currently owns the domain, and that exposure lasts as long as the registration lapse does.
  • cost Per-advertiser reporting bills the person who noticed for all the capture work and buys nothing durable, because the service acts on the advertiser and not on the entry domain.
  • decision A team that treats a urlscan or reputation verdict as sign-off on an outbound link now needs a residential-browser check, since the cloak is built to feed scanners the clean page.

Nothing in the email had to be forged. Carnival's own template kept pointing at a promotional domain the company had let lapse, and someone else re-registered it and wired it into a redirection network [3]. An href is an instruction to fetch whatever the current holder of that name serves at click time. The screenshot of the sorting page in the published account is from cclpromos.com, dated June 13th, 2026 [4].

The three authentication checks passed on mail whose link served malware [2]. Alignment proves who sent the message, and nothing about who controls the hostnames inside it [21].

The domain resolved into a parked-domain monetization service, and the response depended on the visitor: automated clients got a compliant parking page, real browsers were handed to an advertiser, and which advertiser changed between visits [10]. Command-line tools and headless browsers failed the fingerprint check and received a benign skeleton [5]. A phone or a home connection got malware installers, scareware and fullscreen lockers [6]. It was not account-specific either, since a second booked guest who received the same email saw the same behavior from a different computer and inbox [17].

Public reputation services returned clean verdicts throughout, which the researcher reads as those services being handed the same skeleton his own automated checks received [11]. urlscan.io came back flagging the page as one of "10,000+ similar pages" [12]. For a clean verdict from an automated checker to transfer to your recipients, the checker would have to pass the same geography, device and automation checks a real browser passes. On the researcher's reading, traffic that fails those checks is sorted away from the buyers with the strictest policies, and he says plainly that this is his reading and not a documented fact [19][16].

He reported individual advertisers to the monetization service, and the service acted on each one only after he had captured and handed over proof for that specific advertiser [13]. Every removal was replaced, the entry domain stayed live, and the email link kept routing into it until Carnival re-acquired the name [14]. That was August 26th, 2026, seventy-four days after the first click [7][18]. "Reporting a cloaked page is slow work, and doing it per advertiser is the slowest version of it," he wrote [15].

The machinery itself is documented. Trinity Cyber published it in November 2025, where Tanner Piliego and Jared Grumbein named the redirection layer PseudoTDS and the browser-hijacker family PhantomJack and traced the initial redirects through the Trillion ad-tech network, formerly Trellian [8]. In that report victims arrive by mistyping a domain; the delivery path here is an authenticated marketing email, which the author identifies as the new part [9].

The inventory that would have caught this is unglamorous: every hostname that appears in a live mail template, mapped to a registrar record with a renewal date and a named owner. Carnival's fix was a registrar transaction, and the vector was dead the next day [7].

What to watch

  • Whether Carnival publishes a retired-domain policy that ties registrar renewal dates to hostnames still present in live mail templates.</br>
  • Whether the parked-domain monetization service moves from acting on individual advertiser complaints to screening re-registered names that still receive brand email traffic.
  • Whether Trinity Cyber or others document PseudoTDS reached through another brand's authenticated mail, which would make the delivery path a pattern rather than one case.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories