Phishing Campaign Baits Hook With Malicious Amazon PDFs

Jan. 29, 2025, 12:31 p.m.

Description

A new phishing tactic has emerged, using PDF documents to trick victims by announcing expired Amazon Prime memberships. The campaign targets users via email, containing PDF attachments that lead to fake Amazon pages requesting personal and credit card information. Researchers from Palo Alto Networks Unit42 discovered 31 PDF files linking to these phishing sites, none of which had been submitted to VirusTotal. The attack chain begins with an email containing a PDF attachment, which redirects victims to subdomains of duckdns[.]org hosting the phishing website. The campaign uses cloaking techniques to redirect scans and analysis attempts to benign domains. Four initial links were identified as potential threats in this sophisticated phishing operation.

Date

  • Created: Jan. 29, 2025, 1:42 a.m.
  • Published: Jan. 29, 2025, 1:42 a.m.
  • Modified: Jan. 29, 2025, 12:31 p.m.

Indicators

  • https://rediahxjasdusgasdzxcsdefwgasdgasdasdzxdz.duckdns.org/agungggg1298w862847
  • https://zmehiasdhg7uw.redirectme.net/xn28lGa
  • https://redixajcdkashdufzxcsfgfasd.duckdns.org/CCq8SKn
  • https://redirjhmxnasmdhuewfmkxchbnvjxfasdfasd.duckdns.org/XOZLaMh

Attack Patterns

  • T1185
  • T1204.001
  • T1566.002
  • T1204.002
  • T1566.001
  • T1192
  • T1204
  • T1566

Additional Informations

  • Retail
  • Technology