July 15, 2019 By David Bisson < 1 min read

Digital attackers are now abusing the 16Shop phishing kit to target Amazon users for the purpose of stealing access to their accounts.

In May 2019, McAfee Labs observed a phishing kit targeting Amazon account holders. A closer look at the kit revealed several similarities to 16Shop, a phishing tool that McAfee’s researchers first observed preying upon Apple users in November 2018. At around the same time of its analysis, the security firm noticed that those actors to whom it previously attributed the creation of this phishing kit had changed their social media profile picture to a modified Amazon logo. These two developments led researchers to conclude that those behind this phishing kit had decided to create a new version and go after Amazon users.

This new variant of the kit uses attack emails to trick users into visiting a fake Amazon website. There, users receive prompts to update their accounts by resubmitting a variety of information, including their payment card details.

Amazon-Related Phishing Campaigns

Threat actors have targeted Amazon users with phishing scams even before the above campaign. In 2016, for instance, ThreatPost reported on a spear phishing campaign that leveraged malicious macros concealed in Microsoft Word documents to infect Amazon customers with Locky ransomware. Two years later, Infosecurity Magazine covered a phishing campaign that leveraged fake Amazon order confirmation emails to steal customers’ Amazon credentials.

How to Defend Against 16Shop Attacks

One of the best ways to defend your organization against phishing attacks motivated by 16Shop and other tools is by using ahead-of-threat detection to spot potentially malicious domains before they become active. Information security personnel should also help their organizations conduct test phishing engagements with their entire workforce so that all employees can learn how to spot, and not fall for, a phish.

More from

How a new wave of deepfake-driven cybercrime targets businesses

5 min read - As deepfake attacks on businesses dominate news headlines, detection experts are gathering valuable insights into how these attacks came into being and the vulnerabilities they exploit.Between 2023 and 2024, frequent phishing and social engineering campaigns led to account hijacking and theft of assets and data, identity theft, and reputational damage to businesses across industries.Call centers of major banks and financial institutions are now overwhelmed by an onslaught of deepfake calls using voice cloning technology in efforts to break into customer…

Grandoreiro banking trojan unleashed: X-Force observing emerging global campaigns

16 min read - Since March 2024, IBM X-Force has been tracking several large-scale phishing campaigns distributing the Grandoreiro banking trojan, which is likely operated as a Malware-as-a-Service (MaaS). Analysis of the malware revealed major updates within the string decryption and domain generating algorithm (DGA), as well as the ability to use Microsoft Outlook clients on infected hosts to spread further phishing emails. The latest malware variant also specifically targets over 1500 global banks, enabling attackers to perform banking fraud in over 60 countries…

New cybersecurity sheets from CISA and NSA: An overview

4 min read - The Cybersecurity and Infrastructure Security Agency (CISA) and National Security Agency (NSA) have recently released new CSI (Cybersecurity Information) sheets aimed at providing information and guidelines to organizations on how to effectively secure their cloud environments.This new release includes a total of five CSI sheets, covering various aspects of cloud security such as threat mitigation, identity and access management, network security and more. Here's our overview of the new CSI sheets, what they address and the key takeaways from each.Implementing…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today