Domain thief Jianfei Wang is back. Keep an eye on your domains!

We originally planned to release the full story later. But since a well-known member of the community has already shared part of it on Twitter, we’ve decided not to wait any longer. Here’s the full story.

On September 14, 2023, David (@dvcrn) published a tweet stating that someone had successfully attempted to take over his d.pn domain by impersonating him to the registrar. He also shared several screenshots, which clearly showed the full identity of the person involved. Remember this name: JianFei Wang.

 

The original tweet is still available:

On September 19, 2023, JianFei Wang publicly claimed in a WeChat group that he had acquired the domain x.st.

 

Looking at the historical snapshots on the Internet Archive (https://web.archive.org), it is not difficult to see that the original owner of the domain had always been Harold (https://twitter.com/hrldcpr). At some point, however, the domain’s nameservers (NS) and registrant information were changed to details associated with JianFei Wang.

 

From the very beginning, this raised our suspicions for two reasons. First, the original owner had held the domain for years, suggesting that it was something he genuinely valued. Second, even if the domain had been offered for sale, its expected price would have been well beyond what JianFei Wang could reasonably afford.

 

As it turned out, our suspicions were well founded. On November 21, 2023, the original owner successfully recovered the domain.

On September 23, 2023, JianFei Wang once again publicly claimed in a WeChat group that he had purchased a new domain: interesti.ng.

This caught our attention once again. As we dug deeper, we discovered that it wasn’t just a single domain. Domains such as eveni.ng, exciti.ng, interesti.ng, lovi.ng, and morni.ng had originally belonged to Mark Kychma, but their WHOIS records were later changed to JianFei Wang’s information.

All of these domains have since been successfully recovered by their original owner. As it turned out, they were merely part of JianFei Wang’s “testing.”

On November 4, 2023, the WHOIS record for f.cd was changed. However, not long afterward, on November 24, 2023, the domain was locked again by the registry, suggesting that the issue had been discovered. Even so, the WHOIS record continued to list JianFei Wang as the registrant.

Single-character .cd domains are generally not available for public registration, yet he still attempted to obtain this one. We cannot determine exactly how the domain was acquired, but the fact that it was subsequently re-locked by the registry strongly suggests that its status did not comply with the registry’s policies.

Since there is insufficient information to establish how this domain was obtained, we will not examine this particular case any further.

 

On December 10, 2023, JianFei Wang once again revealed in a WeChat group that he had obtained the domain x.ke.

 

The domain had previously appeared in a .ke domain auction and was eventually purchased by someone, which immediately raised questions about how JianFei Wang came to possess it.

It wasn’t until a later conversation with Max (Nam.es) that we learned x.ke had been listed for sale on https://1-single-letter-domains.com. Even so, judging by its asking price, it was not the kind of domain JianFei Wang would typically be willing—or financially able—to purchase.

That said, we currently have no conclusive evidence that x.ke was stolen. As of today, the domain remains under his control.

The Spree Begins

On January 11, 2024, we unexpectedly discovered that the ownership of wm.mw had changed. Below is the WHOIS record from August 2023, before the ownership change:

By November 15, 2023, the WHOIS record had changed to:

By January 11, 2024, the WHOIS record had changed once again:

At that moment, we suddenly remembered seeing the same email address—frank@xrun.uk—while checking the WHOIS record for ho.st just a short time earlier.

The domain ho.st belongs to Host.io, a domain intelligence platform created by the team behind IPinfo.io. Anyone familiar with Host.io knows that ho.st has long been used as one of the company’s redirect domains, making it highly unlikely that it would ever be sold separately.

Yet, the WHOIS record showed that the contact email had been changed to frank@xrun.uk, which was clearly out of the ordinary. More importantly, it strongly suggested a connection between frank@xrun.uk and meetfeifei@gmail.com.

On January 15, 2024, we came across something even more unusual. While searching domain records, we noticed that the status of gov.cx had changed to pendingTransfer.

This immediately stood out because gov.cx is the official domain of the Government of Christmas Island. Seeing a government-owned domain enter a pendingTransfer state was highly abnormal and immediately raised our suspicions.

 

We then began checking other high-value domains. To our surprise, we found that a large number of premium domains had entered the pendingTransfer state at nearly the same time.

They all shared one notable characteristic: they were domains managed by CoCCA.

Among the affected domains were:

e.hn, h.hn, o.hn, p.hn, whois.hn, i.sb, technolo.gy, ener.gy, x.cx, t.cx, and many others.

The fact that so many single-character domains, owned by different registrants, had all entered the pendingTransfer state at roughly the same time was clearly abnormal.

However, after discovering this, we deliberately chose not to report it to CoCCA immediately. Instead, we decided to wait and see who these domains would ultimately end up with and which registrar they would be transferred to.

During the days that followed, we continued monitoring the situation and found even more domains entering the pendingTransfer state, including 4.gs, f.sb, k.hn, and others.

In the end, the outcome was exactly what we had anticipated.

Among them, 4.gs was successfully transferred to a registrar named InterCat Ltd. Shortly afterward, it was transferred once again—this time to West263 International Limited.

By the time the domain reached West263 International Limited, the WHOIS record had already been updated to list JianFei Wang’s information as the registrant.

Shortly afterward, f.sb and k.hn were also successfully transferred to the registrar InterCat Ltd.

We then investigated the registrar InterCat Ltd (https://intercat.org) and discovered that intercat.org was, in fact, a registrar established by JianFei Wang himself.

It appeared to have been created specifically to facilitate the transfer and handling of stolen (or captured) domains.

The registrar’s information is shown below:

 

The footer of the website also listed JianFei Wang’s contact information and even displayed the ICANN logo.

However, it is highly unlikely that he possessed the qualifications required to become an ICANN-accredited registrar.

By this point, the evidence was sufficient to conclude that this series of domain thefts was carried out by JianFei Wang.

At the same time, shortly after obtaining 4.gs, f.sb, and k.hn, he immediately created a “Domains for Sale” thread on the forum dalao.net. He also listed 4.gs for sale at a fixed price through West263 International Limited, while simultaneously listing the domain on Dan.com at a Buy Now price.

The asking prices were significantly below market value, strongly suggesting an attempt to quickly liquidate the stolen domains for cash.

At that point, we concluded that there was no reason to wait any longer.

To prevent unsuspecting buyers from purchasing stolen domains and suffering financial losses—and to prevent the domains from being transferred yet again—we immediately contacted the CoCCA team as well as Ben Dowling (https://twitter.com/coderholic), the owner of ho.st, and shared everything we had uncovered.

After learning of the situation, CoCCA responded immediately and began working with us. They were able to stop the transfer of most of the affected domains before the transfers could be completed.

CoCCA also shared with us a list of domains that had been involved in suspicious transfer activity, and it matched almost exactly what we had already identified.

 

For the domains that had already been successfully transferred, however, we were not the original registrants. As a result, CoCCA asked whether we could help contact the original owners so that they could file complaints with either their original registrar or directly with CoCCA. Once a complaint was received from the legitimate owner, CoCCA could place the affected domain under registry lock.

Through our efforts, we successfully reached the original owner of k.hn, who, coincidentally, was Chinese. After we explained the situation, he logged into his registrar account and discovered that the domain was indeed no longer in his account.

While reviewing his email history, he also found a reply from his registrar. Once again, the email contained the address frank@xrun.uk.

 

 

The email made the scheme fairly clear.

JianFei Wang had impersonated the original registrant by sending a fraudulent transfer request to the domain’s original registrar/registry, while copying frank@xrun.uk on the email. His apparent goal was to first move the domain into his own account at the same registrar, then obtain the domain’s authorization code (EPP/Auth Code) and complete the theft through a standard registrar transfer.

Because the legitimate owner was busy with work, he did not notice the registrar’s reply in time. The registrar, believing the email had genuinely come from the registrant, approved the request and processed the transfer.

The original owner of k.hn told us that the domain is extremely important to him. If he is ultimately unable to recover it, he intends to report the matter to the police.

At the same time, we advised him to file formal complaints with both his original registrar and CoCCA.

Later that same day, 4.gs, f.sb, and k.hn were all placed under lock. Their WHOIS records displayed the status:

Registrar: Registry Hold – Suspicious Activity

Pending the outcome of the investigation, the domains were placed under the temporary control of CoCCA.

This also reminded us of another incident.

Around the same time, someone in a WeChat group mentioned that they had unexpectedly received a WHOIS change notification from a registry. Without their knowledge, the registration information for their domain, www.sl, had been modified.

Fortunately, they discovered the change in time and were able to stop it before the transfer progressed any further.

Once again, we found the familiar name “frank” in the WHOIS records. The registrant information associated with the domain was entirely fabricated, suggesting that this may have been nothing more than another test run of the same method.

As we continued digging, we uncovered something even more astonishing.

Both InterCat Ltd (@InterCatLtd) and JianFei Wang (@meetfeifei) had openly and brazenly showcased the domains they had allegedly stolen on Twitter. The relevant posts have since been deleted from both accounts, but we preserved copies of the evidence.

Even more ironically, InterCat Ltd had once posted the following tweet:

Little did they realize that they themselves were the “mouse” stealing the cheese.

 

Although we had reached this point in our investigation, the story was far from over.

Our original plan had been to publish our findings the following month. However, after learning that JianFei Wang had also targeted one of Max’s domains—and that part of the story had already begun circulating publicly—we concluded that delaying publication no longer made sense.

We believed that once JianFei Wang became aware of the exposure, he would likely delete his tweets and deny any involvement. For that reason, we decided to publish the full investigation immediately.

Our goal is simple: to help maintain a safer, cleaner, and more trustworthy domain ecosystem.

 

We will also continue communicating with the victims of this incident.

The domains involved are collectively worth a substantial amount. The internet is not beyond the reach of the law, and conduct of this nature may constitute criminal or civil wrongdoing depending on the applicable jurisdiction. Even if someone is located overseas, victims can still report the matter to law enforcement if they choose to do so.

Finally, JianFei Wang claimed on Twitter that “it had nothing to do with me—it was done by a hacker friend.”

Yet the evidence we uncovered consistently points back to him. Given everything presented above, readers can draw their own conclusions.

One final warning.

Please exercise caution with the single-letter domains u.sv, d.sv, l.sv, and t.sv.

These domains have reportedly already been sold. According to statements attributed to JianFei Wang, they require a local attorney acting as trustee, with the domains registered using the attorney’s information. However, others have claimed that the so-called attorney was, in fact, JianFei Wang himself.

If those claims are accurate, the beneficial or effective control of these domains would still remain with him, regardless of whose name appears in the registration records. As a result, the domains could potentially be transferred away at any time. Buyers should therefore exercise extreme caution before purchasing any of them.

This is the email address of the account that controls the domains:

Because he used multiple email addresses, he accidentally exposed this particular email address on one of his domain sales pages:

https://dalao.net/thread-24673.htm