Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors SilkSpecter

Also known as: APT28, Pawn Storm, Fancy Bear, Sednit, web skimmers

Description

SilkSpecter is identified as a China‑based financially driven threat group that strategically targets e‑commerce shoppers during high traffic periods such as Black Friday and other holiday sales events. The actors orchestrate mass phishing campaigns that direct victims to look‑alike merchant fronts hosted on the oemapps SaaS platform, using Chinese‑hosted CDN servers to serve content. Their deception extends to the use of legitimate payment processing services like Stripe; once a transaction is initiated, SilkSpecter obtains cardholder data and personally identifiable information by embedding tracking mechanisms such as the "trusttollsvg" icon and the "/homeapi/collect" endpoint within the fake storefront. Beyond surface phishing, SilkSpecter has demonstrated the capability to set up expansive command‑and‑control infrastructures—over 89 IP addresses and more than 4,000 domain names—primarily utilizing TLDs that are commonly associated with low‑cost or malicious activity (.top, .shop, .store, .vip). The actors exploit these domains to host phishing kits, collect credentials, and exfiltrate data. They also leverage legitimate cloud services for storage and communication, making detection more challenging. While the group’s primary objective remains financial gain through card skimming and personal data theft, their operational footprint suggests an evolving technical arsenal that includes obfuscation techniques, process injection, and social engineering tactics tailored to high‑volume retail environments. This combination of phishing sophistication, cloud integration, and large‑scale domain sprawl positions SilkSpecter as a persistent threat to merchants and shoppers alike.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Retail
Government
Telecommunications
Maritime
Manufacturing

Targeted Countries / Regions

CN
US

AI Analysis

Grounded in web research
· 3 days ago

Executive Summary

SilkSpecter is a financially motivated Chinese threat actor that exploits peak e‑commerce shopping periods—most notably Black Friday—to steal credit card and personal data through sophisticated phishing and fake‑store operations. They employ legitimate payment processors, deceptive UI elements, and a large network of domains to harvest victim information stealthily. The actor’s reach extends across multiple sectors but focuses on individuals and merchants involved in online retail.

Goals & Targeting

SilkSpecter’s strategic focus is driven by the lucrative financial gains obtainable from compromised payment data. By targeting e‑commerce shoppers during peak transaction windows—particularly Black Friday—they maximize their chances of capturing fresh cardholder information before merchant fraud detection systems notice anomalies. The actor prefers sectors with high electronic commerce presence: retail, financial services, and telecommunications within the United States and China. Victims typically include individual consumers who enter payment details on counterfeit storefronts, as well as merchants whose online portals inadvertently expose transaction flow to the threat group through compromised third‑party payment processors.

Enhanced Description

Key Capabilities

  • Phishing campaigns with domain spoofing and deceptive UI elements
  • Use of legitimate payment processors for data harvesting
  • Deployment of large CDN‑based infrastructure and thousands of domains
  • Tracking via custom endpoints such as "/homeapi/collect" and unique icons like "trusttollsvg"
  • Data exfiltration through cloud storage services
  • Obfuscated scripts and credential sprawl tactics
  • Leveraging process injection, PowerShell, and RATs for persistence and lateral movement

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Collection
Exfiltration

ATT&CK Techniques

T1566.001
T1114.003
T1082
T1059.001
T1140
T1027
T1055
T1078.004
T1105
T1530
T1063
T1098
T1036.001
T1497

Software / Tooling

Emotet
SocGholish
Akira
Black Basta
Agent Tesla
Havex RAT
Cobalt Strike
Spear‑phishing Kit
PowerShell scripts
Rhadamanthys
Matrix
Netsupport Manager
KongTuke
MintsLoader
Leverage

Campaigns & Victims

SilkSpecter’s campaign cycles seem tightly aligned with major retail sales events, indicating a predictable operational tempo. The actor launches thousands of domain fronting sites in the weeks leading up to high‑traffic shopping holidays, often under short‑lived domains (.top, .store) to evade persistence detection. Victims are primarily individual shoppers or small merchants who use popular payment processors, allowing SilkSpecter to harvest card data just downstream of the transaction flow. The group’s notable past operations include the 2024 Black Friday phishing wave and ongoing smaller skimming campaigns that target niche e‑commerce niches such as travel booking and specialty retail. Defense attempts have focused on monitoring for unusual payment gateway traffic, but the actor's use of legitimate infrastructure makes it difficult to discern malicious activity early. Consequently, victims often suffer significant data loss before remediation is enacted.

IOC Patterns

  • Spear‑phishing emails with malicious web links
  • Fake e‑commerce storefronts hosted behind Chinese CDN servers
  • Use of tracking endpoints like "/homeapi/collect"
  • Deployment of the "trusttollsvg" icon to mimic legitimate brand elements
  • Mass distribution of domains with low‑cost TLDs (.top, .shop, .store, .vip)

Recommended Actions

  • Implement targeted user education campaigns that highlight suspicious e‑commerce sites during major sales events.
  • Enforce anti‑phishing and URL filtering solutions capable of blocking known malicious domains and short‑lived domain patterns.
  • Monitor outbound traffic to legitimate payment processors for anomalous data transfer volumes or repeated new IP source addresses.
  • Deploy DLP sensors on PCI‑compliance network segments to flag unauthorized cardholder data movement.
  • Apply multi‑factor authentication to all merchant portal accounts and enforce strict least‑privilege principles.
  • Regularly audit CDN configurations and third‑party hosting services for unexpected content changes.
  • Use behavioral analytics to detect abnormal credential submissions or repeated form interactions from a single source.

Suggested Tags

APT
financial-threat-actor
phishing
e-commerce-theft
card-skimming
China-based
Black Friday
data-exfiltration

Confidence Assessment

The intelligence is derived mainly from the Eclecticiq blog, which provides detailed operational specifics and has been corroborated by several linked ATT&CK techniques and tools. While coverage of persistence mechanisms and long‑term activity is limited, confidence in the group’s financial motive and phishing methodology remains high. Gaps exist regarding early/last sighting dates, depth of malware analysis, and any lateral movement capabilities beyond initial collection.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 16 Filename 2 SHA-256 Hash 2

References

  1. www.recordedfuture.com — Cited by web research for: T1083
  2. redcanary.com — Cited by web research for: T1027
  3. attack.mitre.org — Cited by web research for: Leverage
  4. blog.eclecticiq.com — Cited by web research for: Phishing campaigns
  5. www.newsweek.com — Cited by web research for: U.S.News

Intel Summary

23

Techniques

43

Tools

0

Campaigns

26

IOCs

0

Observed Data

9

Tactics

Tags

Phishing
Data Exfiltration
APT29
Cyber_Crime
Fraudulent_Activities
E-Commerce_Sector
Payment_Processing
APT
financial-threat-actor
phishing
e-commerce-theft
card-skimming
China-based
Black Friday
data-exfiltration

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.