NordVPN’s Threat Intelligence team has released a major new report uncovering three global scam operations that are reshaping the cybersecurity threat landscape.
The findings reveal a troubling pattern — cybercriminals are industrializing deception, blending outdated technologies, fake online stores, and cryptocurrency phishing to reach millions of users worldwide, says Domininkas Virbickas, Product Director at NordVPN.
Key highlights from the report include:
° Old editor, new scam. Attackers are exploiting CVE‑2009‑2265, a 15‑year‑old flaw in the obsolete FCKeditor tool. Over 1,300 compromised domains — including corporate and research sites — have been hijacked to deliver malware and redirect traffic to phishing pages. These campaigns abuse trusted websites to bypass normal security filters, turning legitimate domains into tools for fraud.
° Advance fee – cryptocurrency trap. Investigators exposed a global phishing network of over 100 fake crypto domains, using mass “erroneous deposit” emails promising 15 Bitcoin windfalls. Victims are tricked into logging in to cloned platforms and later paying fake “GAS fees,” enabling both financial theft and identity compromise.
° Chinese‑linked fake e‑commerce network. The team also discovered an organized web of 800+ fake stores built on WordPress and WooCommerce. These sites share the same contact address — support@carpartsoffice.com — and lure buyers with huge discounts. All point to a centralized fraud operation, showcasing how automation enables single actors to run massive fake‑shop ecosystems across multiple regions.




