A sophisticated phishing campaign targeting Amazon Prime users has emerged, leveraging counterfeit renewal notifications to harvest login credentials, payment details, and personal verification data.
Discovered by the Cofense Phishing Defense Center (PDC) on February 18, 2025, the attack employs multi-stage deception tactics.
This include the spoofed emails, fake security alerts, and fraudulent payment portals designed to mimic Amazon’s official interfaces.
Researchers at Cofense noted that the campaign’s technical execution reveals advanced social engineering strategies, with threat actors exploiting Google Docs redirects and QR code-based payloads to bypass automated security filters.
The attack begins with a spoofed email masquerading as an Amazon Prime renewal notice.
The email body warns recipients that their payment method is invalid and urges immediate action via a “Update Information” button.
While the sender’s display name (“Prime Notification”) appears legitimate, the originating domain uses a lesser-known URL (hXXps[:]//docs[.]google[.]com/drawings/d/1rSqoqN1uTTbP4qnfKzx2ZbvSı), a critical red flag.
Clicking the button redirects users to a fake Amazon security portal hosted on Google Docs, which requests account verification under the pretext of preventing unauthorized access.
Example of obfuscated URL:
hXXps[:]//qr-codes[.]io/unPek2 This intermediate page primes victims for credential theft by mimicking Amazon’s security protocols. Users are then directed to a counterfeit login page that captures usernames and passwords.
Unlike generic phishing sites, this campaign employs dynamic HTML injection to replicate Amazon’s multi-factor authentication (MFA) interface, including CSS stylesheets and JavaScript validation scripts.
After harvesting credentials, the attack escalates to data exfiltration. Victims are prompted to “confirm their identity” by submitting their mother’s maiden name, date of birth, and phone number—details often used for account recovery.
A subsequent page requests billing addresses, enabling threat actors to reroute physical mail or execute identity theft.
The final stage captures full credit card details, including CVV codes, through a counterfeit payment portal.
The campaign’s infrastructure relies on decentralized hosting, with phishing pages distributed across Google Docs, QR code generators (qr-codes[.]io), and compromised domains in Sri Lanka (recordzonerequiredaccountpaneluseraccpymntnew[.]srilankaı).
The use of QR codes (hXXps://qr-codes[.]io/unPek2) complicates URL analysis for both users and automated scanners.
Amazon has reiterated that legitimate communications will never direct users to third-party platforms like Google Docs.
Users are advised to manually navigate to Amazon’s official site to verify account statuses. Organizations should deploy email security solutions capable of detecting domain spoofing and inspect embedded links for redirect chains.
Enabling MFA remains critical, as stolen credentials alone cannot compromise accounts with hardware-based authentication.
This campaign shows the persistent threat of phishing-as-a-service (PhaaS) platforms, which enable even low-skilled actors to deploy complex attacks.
Continuous user education and proactive threat hunting are essential to counter these evolving tactics.
Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -> Try for free
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…
The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…
CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…
Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…
You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…
Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…