Cybercriminals Target Black Friday Shoppers with Phishing Attack

Black Friday Phishing Attack Featured

Scrooge appears to be hard at work before this holiday season officially starts. A week before Black Friday officially starts, shopping these deals has become dangerous. Cybercriminals have launched a phishing campaign with fake websites, designed to steal Black Friday shoppers’ information.

Black Friday Phishing Campaign

Starting as far back as early October, analysts at EclecticIQ started noticing a phishing campaign. It appears to be aimed at Black Friday shoppers in the United States and Europe. The same analysts believe Chinese cybercriminals, nicknamed SilkSpecter, are behind it, looking to cash in.

SilkSpecter is using fake, discounted products in this phishing scam to attract Black Friday shoppers and convince them to provide their cardholder data (CHD), Sensitive Authentication Data (SAD), and Personally Identifiable Information (PII).

Black Friday Phishing Attack Advertisement

When shoppers enter their information, the attackers steal the CHD via the Stripe payment process. The CHD is sent to a server controlled by SilkSpecter. Google Translate is used to make the language on the sites more credible, adjusting it for the IP locations of the victims.

It turns out this isn’t SilkSpecter’s first entry into the fake e-commerce sites space. They have set up similar phishing campaigns. All of them have been linked to a Chinese SaaS that analysts believe allows them to quickly create these sites. Most of the sites use domains with .top, .hip, .store, and .vip.

Good to know: you also need to look out for a “Your package cannot be delivered” text.

Discovery of the Black Friday Phishing Pattern

A pattern was noticed by analysts through the fake Black Friday phishing domains, and it was decided they can mostly all be linked back to SilkSpecter. Cybercrime itself is a bigger threat than you might image.

Each page included the “trusttollsvg” icon that made it appear to be a normal trusted site. Additionally, these pages all had a “homeapi/collect” endpoint. This would notify the cyberattackers when a URL was clicked or opened by a victim, who was lured there by a promising Black Friday discount.

Black Friday Phishing Attack Stealing Credentials

Various website trackers were set off once someone landed on a phishing page looking for a Black Friday deal. The trackers kept watch on the effectiveness of the phishing campaign as it collected PII, CHD, SAD data from unsuspecting shoppers using Stripe. Among the info collected was IP addresses, geolocation, browser type, and OS.

Additionally, victims of this phishing attack were asked to supply their phone numbers. It’s assumed that this information would also be exploited. The phone numbers could then be used for voice phishing or SMS phishing, pushing the victims to reveal other details, such as 2FA codes, identification details, and possibly account credentials.

It’s believed that SilkSpecter passed the phishing URLs around through social media accounts and SEO poisoning, baiting victims with Black Friday discounts.

Luckily, you don’t have to fall victims to the Black Friday phishing attack. Don’t access unknown websites, no matter how promising the deals sound. Stick to Amazon and other well-known sites. And, as always, you can stay tuned to Make Tech Easier, as we will be publishing some of the best Black Friday tech deals.

Image credit: All images by Canva and Image Playground.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Laura Tucker Avatar

Read next

Each year, roughly 27.7 million tonnes of dust lift off the Sahara, cross the Atlantic on the trade winds, and fall on the Amazon — carrying the phosphorus the rainforest needs to keep growing
The GPS satellites orbiting 20,200 kilometres overhead run their clocks about 38 microseconds faster per day than clocks on the ground — without Einstein’s relativity correcting for it, GPS would drift by roughly 10 kilometres every 24 hours
Behavioral scientists found that people without children develop a relationship to mortality that is psychologically distinct — without biological continuation, they must construct meaning through contribution, connection, and presence rather than lineage, and that construction is both harder and, when successful, more intentional than most people realize
Psychology says people who stack their plates and tidy up before leaving a restaurant aren’t trying to impress anyone — they never forgot what it felt like to be the one who had to clean up after people who didn’t
I grew up lower-middle class and I’ve noticed that every time I’m asked to describe my childhood I instinctively say “we weren’t rich but we had everything we needed” — and I’ve started wondering who I’m protecting with that sentence, my parents or myself
Psychology says the loneliest people in a room are often the most socially skilled because they learned early to perform connection instead of feel it
I’m 38 and I watched my parents retire with everything they worked for — a paid-off house, savings, good health — and then slowly, year by year, become two people who sit in separate rooms scrolling their phones because they forgot how to be interesting to each other
Psychology says the most dangerous form of loneliness isn’t being alone. It’s being surrounded by people while performing a version of yourself that none of them would recognize if they saw you at home on a Sunday afternoon.