Inside Intelligence Center: Financially Motivated Chinese Threat Actor SilkSpecter Targeting Black Friday Shoppers
ID: 5b6b4bf1-7837-5d0b-8b0e-d5bf5c23b576
STIX ID: report--5b6b4bf1-7837-5d0b-8b0e-d5bf5c23b576
Feed Name: EclecticIQ
**Executive Summary:** EclecticIQ uncovered a large-scale financially motivated phishing campaign dubbed "SilkSpecter" that used fake Black Friday e-commerce sites (often created via the Chinese SaaS oemapps) to collect CHD, SAD, PII and phone numbers from shoppers in Europe and the USA by processing payments through Stripe while covertly exfiltrating the captured data to attacker-controlled servers; the campaign employed multilingual pages (Google Translate), trackers (OpenReplay, TikTok Pixel, Meta Pixel), typosquatted domains across .top/.shop/.store/.vip, and repeatable IOCs such as the "/homeapi/collect" endpoint, a "trusttollsvg" asset, and specific file hashes and domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
