Cyber Security News

Threats Actors Registering Fake Shopping Domains to Attack Users in this Holiday Season

The 2025 holiday shopping season faces a significant cybersecurity threat as threat actors launch a massive campaign of fake online retail stores.

These fraudulent domains are designed to impersonate well-known global brands, tricking unsuspecting consumers into revealing sensitive financial information or downloading malware.

The operation is highly organized, leveraging automated tools to mass-produce counterfeit websites that closely mimic the look and feel of legitimate retailers like Zalando, Birkenstock, and IKEA.

This malicious campaign utilizes a network of over 200 newly registered domains, primarily established through Chinese infrastructure providers.

By exploiting the surge in online shopping traffic during events like Black Friday and Singles’ Day, criminals aim to maximize their reach.

The attack vectors include social media promotions on platforms like TikTok and Facebook, which lure users to these fake storefronts.

Once a victim visits the site, they are often presented with counterfeit checkout systems that harvest credit card details or redirect them to malicious payloads.

Bfore.ai analysts identified this campaign in November 2025, noting its reliance on privacy-protected WHOIS data to obscure the identity of the perpetrators.

The researchers highlighted that the operation exhibits signs of an “industrialized” fraud model, with distinct clusters of activity traced back to specific hosting providers and autonomous systems.

This sophisticated infrastructure allows the attackers to quickly pivot and deploy new domains as old ones are detected and taken down.

The impact on consumers is severe, extending beyond immediate financial loss to potential identity theft.

The scale of the operation suggests a financially motivated group with the resources to sustain a prolonged attack.

Deceptive Lures and Evasion Techniques

The campaign employs a variety of deceptive tactics to evade detection and manipulate user trust.

One notable method involves “agenda-oriented” campaigns, where domains like “peaceforsecurity[.]com” are repurposed to sell fashion items.

Agenda-oriented campaigns (Source – Bfore.ai)

This tactic likely aims to bypass security filters by using keywords unrelated to typical retail fraud.

Another technique creates ambiguity by mixing brand names, such as a “lululemonsalehub” domain promoting unrelated hair products.

Ambiguous cross-branding campaigns (Source – Bfore.ai)

These inconsistencies can confuse users while exploiting brand recognition. Furthermore, the attackers use generic templates populated with nonsensical names and “free shipping” offers to create a sense of legitimacy.

Generic sale lures (Source – Bfore.ai)

Technical analysis reveals the use of identical JavaScript libraries and checkout URL patterns, such as:-

/collections/all
/products/item123

Finally, seasonal urgency is manufactured through domains like “mango-flashsale[.]com”, which mimics legitimate sales events to prompt hasty decisions.

Seasonal sale lures to create urgency (Source – Bfore.ai)

These sophisticated lures, combined with shared nameservers and backend infrastructure, demonstrate the evolving complexity of modern retail phishing operations.

Follow us on Google NewsLinkedIn, and X to Get More Instant UpdatesSet CSN as a Preferred Source in Google.

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago