216.73.216.6

Phishing Campaign Baits Hook With Malicious Amazon PDFs

· Published 29/01/2025 01:42 · Modified 29/01/2025 12:31

Export JSON

Essential information

Published
29/01/2025 01:42
Modified
29/01/2025 12:31
Tags
2025-01-29 credit card fraud phishing
Related entities
4 observables, 8 techniques (mitre), 2 others

Description

A new tactic has emerged, using PDF documents to trick victims by announcing expired Amazon Prime memberships. The campaign targets users via email, containing PDF attachments that lead to fake Amazon pages requesting personal and credit card information. Researchers from Palo Alto Networks Unit42 discovered 31 PDF files linking to these sites, none of which had been submitted to VirusTotal. The attack chain begins with an email containing a PDF attachment, which redirects victims to subdomains of duckdns[.]org hosting the website. The campaign uses cloaking techniques to redirect scans and analysis attempts to benign domains. Four initial links were identified as potential threats in this sophisticated operation.

External references