Date: November 18, 2024
The Black Friday and Cyber Monday sales across top brands have also given leeway to a threat actor, SilkSpecter, to steal personal data and money.
Black Friday and Cyber Monday are two of the biggest online and offline shopping events in the U.S. and beyond that offer extremely rare discounts and price drops. The entire period is known as Cyber Week, which attracted a record high of over 200.4 million shoppers last year from across the globe. An online threat actor by the name of SilkSpecter is misusing this period to steal credit information, and personal data, and conduct monetary transactions by creating fake redirections of top brands.
The heightened online shopping activity in November attracts multiple scammers who fool genuine innocent shoppers into too-good-to-be-true deals on websites that accurately mimic top brands. The research team at EclecticIQ reported the fraudulent campaigns and their respective websites caught on their radar till now.
The report highlights a common pattern in all these fake websites. The main domain contained the original brand name but contained the .top, .shop, .store, and .vip top-level suffixes. Here’s the latest list of top malicious websites identified by the EclecticIQ’s research team:
The entire list goes beyond 4,000 malicious website domains and users are advised to practice extreme precaution when coming across, URLs with themes like ‘discount,’ ‘Black Friday,’ or similar sales events. Additionally, look for the specific path ‘/homeapi/collect’ and domains incorporating ‘trusttollsvg’.”
Along with too-good-to-be-true deals, other identification factors of fake websites include poor design, typos, and insecure internal subdomains. Lack of contact info or suspicious contact information is another common indicator. Users should also thoroughly review the return and shipping policies and match them with the original brand website’s policies.
Even the FBI has warned online shoppers that-
“If a deal looks too good to be true, it probably is! Steer clear of unfamiliar sites offering unrealistic discounts on brand-name merchandise. Scammers frequently prey on Black Friday and Cyber Monday bargain hunters by advertising ‘One-Day Only’ promotions from recognized brands. Without a skeptical eye, consumers may end up paying for an item, giving away personal information, and receive nothing in return except a compromised identity.”
The above warning includes users of all mainstream internet browsers like Safari, Chrome, Firefox, Edge, and others.
By Arpit Dubey
Arpit is a dreamer, wanderer, and tech nerd who loves to jot down tech musings and updates. Armed with a Bachelor's in Business Administration and a knack for crafting compelling narratives and a sharp specialization in everything from Predictive Analytics to FinTech—and let’s not forget SaaS, healthcare, and more. Arpit crafts content that’s as strategic as it is compelling. With a Logician mind, he is always chasing sunrises and tech advancements while secretly preparing for the robot uprising.
Reddit Unveils AI-Powered Search Tool for Smarter Results
Reddit launched Reddit Answers, an AI-powered search tool that curates and summarizes discussions to enhance user experience and reduce reliance on Google.
OpenAI Scraps o3 Model, Pushes for Unified GPT-5 in a Major AI Overhaul
OpenAI is canceling its o3 AI model and merging it into GPT-5 for a simpler, more powerful system. A big move to stay ahead in the AI race.
Virtual Reality in Healthcare: Revolutionizing Patient Care
Experience the power of virtual reality in healthcare as it transforms medical training, patient care, and treatment methods with immersive technology for better accuracy, efficiency, and improved outcomes.
Google I/O 2025: Dates Announced for the Tech Giant’s Biggest Event of the Year
Google I/O 2025 is set for May 20-21! Expect big AI reveals, Android 16 updates, and more. Registrations are open for keynotes, demos, and game-changing tech innovations!