Chinese Threat Actor Targets Black Friday Shoppers With Phishing Campaign

Stu Sjouwerman | Nov 26, 2024

holiday-shoppingResearchers at EclecticIQ warn that the financially motivated Chinese threat actor “SilkSpecter” has launched a phishing campaign targeting Black Friday shoppers across Europe and the US.

The crooks are offering fake discounted products to trick users into handing over their personal and financial information.

“Threat actor SilkSpecter targeted victims' Cardholder Data (CHD) by leveraging the legitimate payment processor Stripe,” the researchers write.

“This tactic allowed genuine transactions to be completed while covertly exfiltrating sensitive CHD to a server controlled by the attackers. SilkSpecter enhanced the phishing site’s credibility by using Google Translate to dynamically adjust the website's language based on each victim’s IP location, making it appear more convincing to an international audience.”

The phishing sites are also designed to collect users’ phone numbers, which may be used to launch additional social engineering attacks.

“Victims were also prompted to enter their phone numbers before completing their purchases,” the researchers write. “EclecticIQ analysts assess with medium confidence that this information could likely be leveraged in a second stage of the attack if SilkSpecter chooses to exploit the compromised credit or debit card details for financial fraud.

The phone numbers could enable attackers to conduct vishing (voice phishing) or smishing (SMS phishing) attacks, deceiving victims into providing additional sensitive information, such as 2FA codes, personal identification details, or even account credentials.”

The threat actor is likely directing users to the phishing sites via social media links and search engine optimization (SEO) poisoning.

These types of scams can be expected to continue throughout the holiday season. New-school security awareness training can give your organization an essential layer of defense against social engineering attacks. KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

EclecticIQ has the story.

Discover Your Organization’s Phish-prone™ Percentage

Ninety-one percent of data breaches begin with spear phishing. Launch our Free Phishing Security Test for up to 100 users to uncover your team's vulnerability and see how your security posture stacks up against industry benchmarks.

Get Your Free Phishing Security Test

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.