Also known as: APT28, Pawn Storm, Fancy Bear, Sednit, web skimmers
SilkSpecter is identified as a China‑based financially driven threat group that strategically targets e‑commerce shoppers during high traffic periods such as Black Friday and other holiday sales events. The actors orchestrate mass phishing campaigns that direct victims to look‑alike merchant fronts hosted on the oemapps SaaS platform, using Chinese‑hosted CDN servers to serve content. Their deception extends to the use of legitimate payment processing services like Stripe; once a transaction is initiated, SilkSpecter obtains cardholder data and personally identifiable information by embedding tracking mechanisms such as the "trusttollsvg" icon and the "/homeapi/collect" endpoint within the fake storefront. Beyond surface phishing, SilkSpecter has demonstrated the capability to set up expansive command‑and‑control infrastructures—over 89 IP addresses and more than 4,000 domain names—primarily utilizing TLDs that are commonly associated with low‑cost or malicious activity (.top, .shop, .store, .vip). The actors exploit these domains to host phishing kits, collect credentials, and exfiltrate data. They also leverage legitimate cloud services for storage and communication, making detection more challenging. While the group’s primary objective remains financial gain through card skimming and personal data theft, their operational footprint suggests an evolving technical arsenal that includes obfuscation techniques, process injection, and social engineering tactics tailored to high‑volume retail environments. This combination of phishing sophistication, cloud integration, and large‑scale domain sprawl positions SilkSpecter as a persistent threat to merchants and shoppers alike.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
SilkSpecter is a financially motivated Chinese threat actor that exploits peak e‑commerce shopping periods—most notably Black Friday—to steal credit card and personal data through sophisticated phishing and fake‑store operations. They employ legitimate payment processors, deceptive UI elements, and a large network of domains to harvest victim information stealthily. The actor’s reach extends across multiple sectors but focuses on individuals and merchants involved in online retail.
Goals & Targeting
SilkSpecter’s strategic focus is driven by the lucrative financial gains obtainable from compromised payment data. By targeting e‑commerce shoppers during peak transaction windows—particularly Black Friday—they maximize their chances of capturing fresh cardholder information before merchant fraud detection systems notice anomalies. The actor prefers sectors with high electronic commerce presence: retail, financial services, and telecommunications within the United States and China. Victims typically include individual consumers who enter payment details on counterfeit storefronts, as well as merchants whose online portals inadvertently expose transaction flow to the threat group through compromised third‑party payment processors.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
SilkSpecter’s campaign cycles seem tightly aligned with major retail sales events, indicating a predictable operational tempo. The actor launches thousands of domain fronting sites in the weeks leading up to high‑traffic shopping holidays, often under short‑lived domains (.top, .store) to evade persistence detection. Victims are primarily individual shoppers or small merchants who use popular payment processors, allowing SilkSpecter to harvest card data just downstream of the transaction flow. The group’s notable past operations include the 2024 Black Friday phishing wave and ongoing smaller skimming campaigns that target niche e‑commerce niches such as travel booking and specialty retail. Defense attempts have focused on monitoring for unusual payment gateway traffic, but the actor's use of legitimate infrastructure makes it difficult to discern malicious activity early. Consequently, victims often suffer significant data loss before remediation is enacted.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence is derived mainly from the Eclecticiq blog, which provides detailed operational specifics and has been corroborated by several linked ATT&CK techniques and tools. While coverage of persistence mechanisms and long‑term activity is limited, confidence in the group’s financial motive and phishing methodology remains high. Gaps exist regarding early/last sighting dates, depth of malware analysis, and any lateral movement capabilities beyond initial collection.
No campaigns linked yet.
No observed data linked yet.
23
Techniques
43
Tools
0
Campaigns
26
IOCs
0
Observed Data
9
Tactics