CloudSEK Detects Over 2,000 Holiday-Themed Fake Stores Exploiting Black Friday and Festive Sales

CloudSEK Detects Over 2,000 Holiday-Themed Fake Stores Exploiting Black Friday and Festive Sales

Two large, coordinated clusters of holiday-themed fake storefronts were identified: one with 750+ largely Amazon-typosquatted domains using shared CDN-hosted assets and urgency templates, and a second .shop ecosystem reusing an identical Black Friday modal and JavaScript body across many impersonating domains. These scams harvest full billing/payment details via fraudulent checkout flows and shell payment redirections to enable immediate financial theft and mass data harvesting. #Amazon #PayPal

Keypoints

  • Two distinct clusters of fake holiday storefronts were discovered: Cluster A (750+ Amazon-themed/typosquatted sites) and Cluster B (a widespread .shop ecosystem impersonating many consumer brands).
  • Both clusters reuse identical templates and holiday assets (flipclock timers, urgency banners, fake trust badges, live purchase pop-ups) indicating reuse of a centralized phishing kit or distributed scam framework.
  • Fraudulent checkout flows capture full billing and payment details, often redirecting payments through shell merchant sites (e.g., georgmat[.]com) to complete unauthorized transactions and reduce detection risk.
  • A shared CDN reference (cdn.cloud360[.]top) and a consistent flipclock HTML/CSS pattern were primary pivots to enumerate Cluster A; a SHA-256 body hash of a common JavaScript (095a3ebc…) served as a reliable pivot for Cluster B.
  • FOFA-based pivots revealed massive scale: >750 domains linked via CDN assets for Cluster A and 200K+ FOFA matches (active/historical) for Cluster B’s template indicators across the .shop TLD.
  • Threat actors leverage SEO abuse, messaging platforms, possible paid ads, and redirect/affiliate chains to drive traffic; many domains are reverse-proxied via Cloudflare to hide origin infrastructure.
  • Impacts include direct consumer financial loss from fraudulent transactions, long-term exposure of personal/payment data, increased operational burden for banks/payment processors, and erosion of trust in legitimate brands.

MITRE Techniques

  • No MITRE ATT&CK technique IDs are explicitly mentioned in the article; the report describes phishing/typosquatting, template reuse, domain acquisition, and data-harvesting behaviors without direct ATT&CK references.

Indicators of Compromise

  • [Domain ] Amazon-typosquatted and template-linked phishing storefronts – amaboxreturns[.]com, amaznshop[.]com, and 750+ related domains from Cluster A
  • [Domain (.shop) ] Brand-impersonating .shop fake stores – amazfitsafe[.]shop, xiaomidea[.]shop, and many hundreds/thousands of similar .shop entries (200K+ FOFA matches including active and historical domains)
  • [CDN / Resource URL ] Shared asset host used across Cluster A – cdn.cloud360[.]top
  • [Shell payment redirect domains ] Shell merchant/payment redirection hosts used to process fraudulent transactions – georgmat[.]com, thewonsel[.]com, and other shell domains (e.g., kinwony[.]com, hwujo[.]com)
  • [File hash ] Core JavaScript template body SHA-256 used across .shop templates – 095a3ebc77f4e46b3adda543b61d90b7d3f20b41532c07772edd31908d060bb2
  • [ASN / Hosting ] Hosting and infrastructure identifiers linked to campaign hosting – ASN 13335 (CLOUDFLARENET), ASN 24429 (TAOBAO Zhejiang Taobao Network Co.), and Cloudflare Spectrum entries (209242)


Read more: https://www.cloudsek.com/blog/cloudsek-detects-over-2-000-holiday-themed-fake-stores-exploiting-black-friday-and-festive-sales