Two large, coordinated clusters of holiday-themed fake storefronts were identified: one with 750+ largely Amazon-typosquatted domains using shared CDN-hosted assets and urgency templates, and a second .shop ecosystem reusing an identical Black Friday modal and JavaScript body across many impersonating domains. These scams harvest full billing/payment details via fraudulent checkout flows and shell payment redirections to enable immediate financial theft and mass data harvesting. #Amazon #PayPal
Keypoints
- Two distinct clusters of fake holiday storefronts were discovered: Cluster A (750+ Amazon-themed/typosquatted sites) and Cluster B (a widespread .shop ecosystem impersonating many consumer brands).
- Both clusters reuse identical templates and holiday assets (flipclock timers, urgency banners, fake trust badges, live purchase pop-ups) indicating reuse of a centralized phishing kit or distributed scam framework.
- Fraudulent checkout flows capture full billing and payment details, often redirecting payments through shell merchant sites (e.g., georgmat[.]com) to complete unauthorized transactions and reduce detection risk.
- A shared CDN reference (cdn.cloud360[.]top) and a consistent flipclock HTML/CSS pattern were primary pivots to enumerate Cluster A; a SHA-256 body hash of a common JavaScript (095a3ebcβ¦) served as a reliable pivot for Cluster B.
- FOFA-based pivots revealed massive scale: >750 domains linked via CDN assets for Cluster A and 200K+ FOFA matches (active/historical) for Cluster Bβs template indicators across the .shop TLD.
- Threat actors leverage SEO abuse, messaging platforms, possible paid ads, and redirect/affiliate chains to drive traffic; many domains are reverse-proxied via Cloudflare to hide origin infrastructure.
- Impacts include direct consumer financial loss from fraudulent transactions, long-term exposure of personal/payment data, increased operational burden for banks/payment processors, and erosion of trust in legitimate brands.
MITRE Techniques
- No MITRE ATT&CK technique IDs are explicitly mentioned in the article; the report describes phishing/typosquatting, template reuse, domain acquisition, and data-harvesting behaviors without direct ATT&CK references.
Indicators of Compromise
- [Domain ] Amazon-typosquatted and template-linked phishing storefronts β amaboxreturns[.]com, amaznshop[.]com, and 750+ related domains from Cluster A
- [Domain (.shop) ] Brand-impersonating .shop fake stores β amazfitsafe[.]shop, xiaomidea[.]shop, and many hundreds/thousands of similar .shop entries (200K+ FOFA matches including active and historical domains)
- [CDN / Resource URL ] Shared asset host used across Cluster A β cdn.cloud360[.]top
- [Shell payment redirect domains ] Shell merchant/payment redirection hosts used to process fraudulent transactions β georgmat[.]com, thewonsel[.]com, and other shell domains (e.g., kinwony[.]com, hwujo[.]com)
- [File hash ] Core JavaScript template body SHA-256 used across .shop templates β 095a3ebc77f4e46b3adda543b61d90b7d3f20b41532c07772edd31908d060bb2
- [ASN / Hosting ] Hosting and infrastructure identifiers linked to campaign hosting β ASN 13335 (CLOUDFLARENET), ASN 24429 (TAOBAO Zhejiang Taobao Network Co.), and Cloudflare Spectrum entries (209242)