Fraud network uses 4,700 fake shopping sites to steal credit cards

Share:

A financially motivated Chinese threat actor dubbed “SilkSpecter” is using thousands of fake online stores to steal the payment card details of online shoppers in the U.S. and Europe.

The fraud campaign started in October 2024, offering steep discounts for the upcoming Black Friday shopping period that usually sees elevated shopping activity.

EclecticIQ threat researcher Arda Buyukkaya, who discovered the campaign, told BleepingComputer that, as of the publishing of their report, SilkSpecter operates 4,695 fraudulent domains.

These sites impersonate well-known brands such as the North Face, Lidl, Bath & Body Works, L.L. Bean, Wayfair, Makita, IKEA, and Gardena.

In many cases, the domain names used in the campaign include the ‘Black Friday’ string, clearly targeting online shoppers looking for discount deals.

Stealing credit card information

SilkSpecter websites are well-designed and typically named after the impersonated brand to appear authentic at a quick glance. However, their sites usually use top-level domains like ‘.shop,’ ‘.store,’ ‘.vip,’ and ‘.top,’ which are not generally associated with large brands or trustworthy e-commerce sites.

Depending on the victim’s location, the website uses Google Translate to automatically adjust the language on the fraud sites accordingly.

The phishing sites integrate Stripe, a legitimate and trusted payment processor, which adds to the site’s legitimacy while still allowing them to steal credit card information.

SilkSpecter also uses tracking tools like OpenReplay, TikTok Pixel, and Meta Pixel on the sites. These tools help them monitor visitor behavior and possibly adjust their tactics to increase the operation’s effectiveness.

When users attempt to purchase from those sites, they are redirected to a payment page that prompts them to enter their credit/debit card number, expiration date, and CVV code. A phone number is also requested at the final step.

Exfiltrating the payment card details to the attacker
Exfiltrating the payment card details to the attacker
Source: EclecticIQ

Apart from stealing the money for the order by abusing the Stripe service, the phishing kit also sends the entered card details to an attacker-controlled server.

EclecticIQ believes the phone number is stolen to be used later in voice or SMS phishing attacks required for handling two-factor authentication (2FA) prompts when exploiting the payment card data.

SilkSpecter is believed to be Chinese, based on their use of Chinese IP addresses and ASNs, Chinese domain registrars, linguistic evidence in the sites’ code, and previous use of the Chinese Software as a Service (SaaS) platform named “oemapps” (prior to Stripe).

BlackFriday shoppers are recommended only to visit official brand websites and avoid clicking on ads, links from social media posts, or promoted results on Google Search.

Finally, cardholders should activate all available protection measures on their financial accounts, including multi-factor authentication, and monitor their statements regularly.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:37 am, Feb 3, 2025
weather icon 1°C
L: -1° | H: 2°
broken clouds
Humidity: 93 %
Pressure: 1025 mb
Wind: 3 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 63%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:35 am
Sunset: 4:53 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
-1° | 2°°C 0 mm 0% 9 mph 95 % 1025 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
6° | 10°°C 0.2 mm 20% 14 mph 96 % 1026 mb 0 mm/h
Wed Feb 05 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 8 mph 89 % 1045 mb 0 mm/h
Thu Feb 06 9:00 pm
weather icon
2° | 8°°C 0 mm 0% 9 mph 82 % 1045 mb 0 mm/h
Fri Feb 07 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 10 mph 95 % 1038 mb 0 mm/h
Today 3:00 am
weather icon
1° | 3°°C 0 mm 0% 4 mph 93 % 1025 mb 0 mm/h
Today 6:00 am
weather icon
1° | 2°°C 0 mm 0% 4 mph 93 % 1025 mb 0 mm/h
Today 9:00 am
weather icon
3° | 3°°C 0 mm 0% 4 mph 93 % 1025 mb 0 mm/h
Today 12:00 pm
weather icon
6° | 6°°C 0 mm 0% 4 mph 86 % 1025 mb 0 mm/h
Today 3:00 pm
weather icon
7° | 7°°C 0 mm 0% 9 mph 94 % 1023 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 6°°C 0 mm 0% 5 mph 95 % 1024 mb 0 mm/h
Today 9:00 pm
weather icon
5° | 5°°C 0 mm 0% 5 mph 95 % 1024 mb 0 mm/h
Tomorrow 12:00 am
weather icon
6° | 6°°C 0 mm 0% 6 mph 95 % 1024 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,263.32
-7.34%
Ethereum(ETH)
€2,410.22
-21.35%
Tether(USDT)
€0.98
0.08%
XRP(XRP)
€2.05
-27.71%
Solana(SOL)
€182.03
-13.79%
USDC(USDC)
€0.98
0.01%
Dogecoin(DOGE)
€0.222705
-26.67%
Shiba Inu(SHIB)
€0.000013
-26.74%
Pepe(PEPE)
€0.000009
-27.69%
Scroll to Top