Cybercriminals Target Black Friday Shoppers with Phishing Attack

Black Friday Phishing Attack Featured

Scrooge appears to be hard at work before this holiday season officially starts. A week before Black Friday officially starts, shopping these deals has become dangerous. Cybercriminals have launched a phishing campaign with fake websites, designed to steal Black Friday shoppers’ information.

Black Friday Phishing Campaign

Starting as far back as early October, analysts at EclecticIQ started noticing a phishing campaign. It appears to be aimed at Black Friday shoppers in the United States and Europe. The same analysts believe Chinese cybercriminals, nicknamed SilkSpecter, are behind it, looking to cash in.

SilkSpecter is using fake, discounted products in this phishing scam to attract Black Friday shoppers and convince them to provide their cardholder data (CHD), Sensitive Authentication Data (SAD), and Personally Identifiable Information (PII).

Black Friday Phishing Attack Advertisement

When shoppers enter their information, the attackers steal the CHD via the Stripe payment process. The CHD is sent to a server controlled by SilkSpecter. Google Translate is used to make the language on the sites more credible, adjusting it for the IP locations of the victims.

It turns out this isn’t SilkSpecter’s first entry into the fake e-commerce sites space. They have set up similar phishing campaigns. All of them have been linked to a Chinese SaaS that analysts believe allows them to quickly create these sites. Most of the sites use domains with .top, .hip, .store, and .vip.

Good to know: you also need to look out for a “Your package cannot be delivered” text.

Discovery of the Black Friday Phishing Pattern

A pattern was noticed by analysts through the fake Black Friday phishing domains, and it was decided they can mostly all be linked back to SilkSpecter. Cybercrime itself is a bigger threat than you might image.

Each page included the “trusttollsvg” icon that made it appear to be a normal trusted site. Additionally, these pages all had a “homeapi/collect” endpoint. This would notify the cyberattackers when a URL was clicked or opened by a victim, who was lured there by a promising Black Friday discount.

Black Friday Phishing Attack Stealing Credentials

Various website trackers were set off once someone landed on a phishing page looking for a Black Friday deal. The trackers kept watch on the effectiveness of the phishing campaign as it collected PII, CHD, SAD data from unsuspecting shoppers using Stripe. Among the info collected was IP addresses, geolocation, browser type, and OS.

Additionally, victims of this phishing attack were asked to supply their phone numbers. It’s assumed that this information would also be exploited. The phone numbers could then be used for voice phishing or SMS phishing, pushing the victims to reveal other details, such as 2FA codes, identification details, and possibly account credentials.

It’s believed that SilkSpecter passed the phishing URLs around through social media accounts and SEO poisoning, baiting victims with Black Friday discounts.

Luckily, you don’t have to fall victims to the Black Friday phishing attack. Don’t access unknown websites, no matter how promising the deals sound. Stick to Amazon and other well-known sites. And, as always, you can stay tuned to Make Tech Easier, as we will be publishing some of the best Black Friday tech deals.

Image credit: All images by Canva and Image Playground.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Laura Tucker Avatar

Read next

When the SS Great Eastern laid the first working transatlantic telegraph cable in 1866, a message that had taken ten days by steamship suddenly crossed the ocean in minutes, and the financial markets of London and New York were forced, within a single trading week, to invent the modern concept of synchronised global price.
The Big Ear telescope was scanning at 1420.4056 megahertz on the night of 15 August 1977, the exact frequency at which hydrogen atoms vibrate across the universe, because Giuseppe Cocconi and Philip Morrison had argued years earlier that any species trying to be found would broadcast on that channel — and then, for 72 seconds, something did.
When Cingular chief Stan Sigman backed the original iPhone before its 2007 unveiling, he accepted terms American carriers usually refused: no logo on the device, no control over its software, no preloaded apps, and a share of monthly subscriber revenue flowing back to Apple, after signing on without seeing a prototype
In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Bell Labs engineer Karl Jansky pointed a rotating antenna at the sky in 1932 looking for sources of transatlantic radio static, he kept picking up a faint hiss that peaked every 23 hours and 56 minutes, and he eventually realized he had become the first human to hear the center of the Milky Way.
When Harvard astronomer Cecilia Payne submitted her 1925 doctoral thesis arguing that the Sun was made almost entirely of hydrogen, the field’s senior figure Henry Norris Russell talked her into adding a line calling the result ‘almost certainly not real,’ and then published the same conclusion himself four years later to widespread acclaim.