Over a thousand online shops hacked to show fake product listings

Teilen:

A phishing campaign dubbed ‘Phish n’ Ships’ has been underway since at least 2019, infecting over a thousand legitimate online stores to promote fake product listings for hard-to-find items.

Unsuspecting users clicking on those products are redirected to a network of hundreds of fake web stores that steal their personal details and money without shipping anything.

According to HUMAN’s Satori Threat Intelligence team that discovered Phish n’ Ships, the campaign has impacted hundreds of thousands of consumers, causing estimated losses of tens of millions of dollars.

The Phish n’ Ships operation

The attack starts by infecting legitimate sites with malicious scripts by exploiting known vulnerabilities (n-days), misconfigurations, or compromised administrator credentials.

Once a site is compromised, the threat actors upload inconspicuously named scripts such as “zenb.php” and “khyo.php,” with which they upload fake product listings.

These items are complete with SEO-optimized metadata to increase their visibility on Google search results, from where victims can be drawn.

When victims click on these links, they are redirected through a series of steps that ultimately lead to fraudulent websites, often mimicking the interface of the compromised e-store or using a similar design.

All of these fake shops are connected to a network of fourteen IP addresses, according to Satori researchers, and they all contain a particular string in the URL that makes them identifiable.

Attempting to purchase the item on the fake shop takes victims through a fake checkout process designed to appear legitimate but does not include any data verification, a sign of potential fraud.

Fake order page
Fake order page
Source: HUMAN

The malicious sites steal the information victims enter in the order fields, including their credit card details, and complete the payment using a semi-legitimate payment processor account controlled by the attacker.

The purchased item is never shipped to the buyer, so the victims lose both their money and data.

Satori has found that over the five years during which Phish n’ Ships has been active, the threat actors abused multiple payment providers to cash out the proceeds of the scam.

More recently, they adapted to implementing a payment mechanism on some of the fake e-shop sites so they can snatch the victim’s credit card details directly.

Campaign disrupted

HUMAN and its partners coordinated a response to Phish n’ Ships, informing many of the impacted organizations and reporting the fake listings to Google so they could be removed.

As of writing, most malicious search results have been cleaned, and nearly all identified shops have been taken offline.

Also, payment processors who facilitated cashouts for the fraudsters were informed accordingly and removed the offending accounts from their platforms, significantly disrupting the threat actor’s ability to generate profit.

Despite all that, the threat actors can adapt to this disruption. Although Satori continues monitoring the activity for resurgence, it’s unlikely that they will give up and not try to establish a new shopper-defrauding network.

Consumers are recommended to look out for unusual redirects when browsing e-commerce platforms, validate they are on the correct shop URL when attempting to buy an item, and report fraudulent charges to their bank and authorities as soon as possible.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:06 pm, Juni 28, 2025
Wetter-Symbol 30°C
L: 29° | H: 31°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 50 %
Druck: 1023 mb
Wind: 11 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 40%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:45 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
29° | 31°°C 0 mm 0% 11 mph 63 % 1024 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
18° | 31°°C 0 mm 0% 7 mph 83 % 1025 mb 0 mm/h
Mo. Juni 30 10:00 pm
Wetter-Symbol
21° | 36°°C 1 mm 100% 8 mph 67 % 1021 mb 0 mm/h
Di. Juli 01 10:00 pm
Wetter-Symbol
21° | 32°°C 0.74 mm 74% 12 mph 73 % 1019 mb 0 mm/h
Mi. Juli 02 10:00 pm
Wetter-Symbol
17° | 25°°C 1 mm 100% 18 mph 85 % 1021 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
25° | 28°°C 0 mm 0% 11 mph 51 % 1023 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
22° | 25°°C 0 mm 0% 8 mph 63 % 1024 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 7 mph 76 % 1025 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 5 mph 83 % 1025 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 5 mph 75 % 1025 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
24° | 24°°C 0 mm 0% 5 mph 53 % 1025 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
29° | 29°°C 0 mm 0% 6 mph 40 % 1024 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
31° | 31°°C 0 mm 0% 5 mph 33 % 1023 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,492.05
0.62%
Ethereum(ETH)
€2,069.99
0.11%
Fesseln(USDT)
€0.85
-0.02%
XRP(XRP)
€1.88
6.04%
Solana(SOL)
€125.38
3.61%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.138521
2.24%
Shiba Inu(SHIB)
€0.000009
2.14%
Pepe(PEPE)
€0.000008
3.14%
Nach oben scrollen