Fraud network uses 4,700 fake shopping sites to steal credit cards

Share:

A financially motivated Chinese threat actor dubbed “SilkSpecter” is using thousands of fake online stores to steal the payment card details of online shoppers in the U.S. and Europe.

The fraud campaign started in October 2024, offering steep discounts for the upcoming Black Friday shopping period that usually sees elevated shopping activity.

EclecticIQ threat researcher Arda Buyukkaya, who discovered the campaign, told BleepingComputer that, as of the publishing of their report, SilkSpecter operates 4,695 fraudulent domains.

These sites impersonate well-known brands such as the North Face, Lidl, Bath & Body Works, L.L. Bean, Wayfair, Makita, IKEA, and Gardena.

In many cases, the domain names used in the campaign include the ‘Black Friday’ string, clearly targeting online shoppers looking for discount deals.

Stealing credit card information

SilkSpecter websites are well-designed and typically named after the impersonated brand to appear authentic at a quick glance. However, their sites usually use top-level domains like ‘.shop,’ ‘.store,’ ‘.vip,’ and ‘.top,’ which are not generally associated with large brands or trustworthy e-commerce sites.

Depending on the victim’s location, the website uses Google Translate to automatically adjust the language on the fraud sites accordingly.

The phishing sites integrate Stripe, a legitimate and trusted payment processor, which adds to the site’s legitimacy while still allowing them to steal credit card information.

SilkSpecter also uses tracking tools like OpenReplay, TikTok Pixel, and Meta Pixel on the sites. These tools help them monitor visitor behavior and possibly adjust their tactics to increase the operation’s effectiveness.

When users attempt to purchase from those sites, they are redirected to a payment page that prompts them to enter their credit/debit card number, expiration date, and CVV code. A phone number is also requested at the final step.

Exfiltrating the payment card details to the attacker
Exfiltrating the payment card details to the attacker
Source: EclecticIQ

Apart from stealing the money for the order by abusing the Stripe service, the phishing kit also sends the entered card details to an attacker-controlled server.

EclecticIQ believes the phone number is stolen to be used later in voice or SMS phishing attacks required for handling two-factor authentication (2FA) prompts when exploiting the payment card data.

SilkSpecter is believed to be Chinese, based on their use of Chinese IP addresses and ASNs, Chinese domain registrars, linguistic evidence in the sites’ code, and previous use of the Chinese Software as a Service (SaaS) platform named “oemapps” (prior to Stripe).

BlackFriday shoppers are recommended only to visit official brand websites and avoid clicking on ads, links from social media posts, or promoted results on Google Search.

Finally, cardholders should activate all available protection measures on their financial accounts, including multi-factor authentication, and monitor their statements regularly.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:38 pm, Apr 21, 2025
weather icon 15°C
L: 13° | H: 16°
heavy intensity rain
Humidity: 70 %
Pressure: 1010 mb
Wind: 7 mph W
Wind Gust: 0 mph
UV Index: 0
Precipitation: 4.6 mm
Clouds: 40%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:51 am
Sunset: 8:06 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
13° | 16°°C 1 mm 100% 8 mph 86 % 1012 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
8° | 17°°C 0 mm 0% 11 mph 93 % 1017 mb 0 mm/h
Wed Apr 23 10:00 pm
weather icon
9° | 16°°C 1 mm 100% 15 mph 93 % 1016 mb 0 mm/h
Thu Apr 24 10:00 pm
weather icon
9° | 13°°C 0.2 mm 20% 4 mph 82 % 1022 mb 0 mm/h
Fri Apr 25 10:00 pm
weather icon
8° | 16°°C 0 mm 0% 8 mph 89 % 1022 mb 0 mm/h
Today 4:00 pm
weather icon
14° | 15°°C 1 mm 100% 8 mph 70 % 1010 mb 0 mm/h
Today 7:00 pm
weather icon
14° | 15°°C 1 mm 100% 4 mph 75 % 1010 mb 0 mm/h
Today 10:00 pm
weather icon
12° | 13°°C 0 mm 0% 6 mph 86 % 1012 mb 0 mm/h
Tomorrow 1:00 am
weather icon
10° | 10°°C 0 mm 0% 6 mph 92 % 1014 mb 0 mm/h
Tomorrow 4:00 am
weather icon
8° | 8°°C 0 mm 0% 5 mph 93 % 1015 mb 0 mm/h
Tomorrow 7:00 am
weather icon
9° | 9°°C 0 mm 0% 4 mph 89 % 1016 mb 0 mm/h
Tomorrow 10:00 am
weather icon
11° | 11°°C 0 mm 0% 7 mph 67 % 1017 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
16° | 16°°C 0 mm 0% 8 mph 44 % 1017 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€76,532.21
4.28%
Ethereum(ETH)
€1,418.74
3.46%
Tether(USDT)
€0.87
0.02%
XRP(XRP)
€1.85
3.60%
Solana(SOL)
€120.95
1.40%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.140690
4.78%
Shiba Inu(SHIB)
€0.000011
2.56%
Pepe(PEPE)
€0.000007
7.97%
Scroll to Top