PULSE NAME
Financially Motivated Chinese Threat Actor SilkSpecter Targeting Black Friday Shoppers
WHITE SilkSpecter AlienVault 2024-11-14 Modified: 2024-11-15
13
IOCs
MEDIUM VOLUME
A Chinese financially motivated threat actor, dubbed SilkSpecter, has been uncovered targeting e-commerce shoppers in Europe and USA with a phishing campaign leveraging Black Friday discounts. The actor uses fake discounted products as lures to steal Cardholder Data, Sensitive Authentication Data, and Personally Identifiable Information. SilkSpecter exploits the legitimate payment processor Stripe to complete genuine transactions while covertly exfiltrating sensitive data. The phishing sites use Google Translate to dynamically adjust the language based on the victim's IP location. The campaign is linked to a Chinese SaaS platform, oemapps, which enables the creation of convincing fake e-commerce sites. The phishing domains primarily use .top, .shop, .store, and .vip TLDs, often typosquatting legitimate e-commerce organizations.
Indicators of Compromise (2 / 13 total)
All FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 587b05cd8d59f9820d2cf168b07d46b1519d12ee7a2f7062a2490da0a99ccb50 2024-11-14
FileHash-SHA256 9a049fe87fe472bd6e2a9f361b78a64576be9f827f9668af69bec03f5cbef0da 2024-11-14