{"id":25414,"date":"2024-11-01T09:10:09","date_gmt":"2024-11-01T17:10:09","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2024\/11\/01\/news-19144\/"},"modified":"2024-11-01T09:10:09","modified_gmt":"2024-11-01T17:10:09","slug":"news-19144","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/11\/01\/news-19144\/","title":{"rendered":"1,000+ web shops infected by &#8220;Phish \u2018n Ships&#8221; criminals who create fake product listings for in-demand products"},"content":{"rendered":"\n<p>Researchers at the Satori Threat Intelligence and Research team have published their findings about a group of cybercriminals that infect legitimate web shops to create and promote fake product listings.<\/p>\n<p>The threat, dubbed &#8220;Phish \u2018n Ships&#8221; by the researchers, <a href=\"https:\/\/www.humansecurity.com\/learn\/blog\/satori-threat-intelligence-alert-phish-n-ships-fakes-online-shops-to-steal-money-and-credit-card-information\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">reportedly<\/a> infected more than 1,000 websites and built 121 fake web stores to trick consumers. Estimated losses are in the region of tens of millions of dollars over the past five years.<\/p>\n<p>The group infected legitimate web shops with a malicious payload that would redirect visitors to web shops under their own control. While visiting such an affected web shop the visitor would be served fake product listings. When they clicked on the link for that item, hundreds of thousands of victims were redirected.<\/p>\n<p>The fraudsters also made sure that their fake product listings contained metadata that put them near the top of search engine rankings for those items. SEO poisoning is a technique employed by cybercriminals to manipulate search engine results, making harmful websites or advertisements appear at the top of search results.<\/p>\n<p>On the fake web shop, one of four targeted third-party payment processors collects credit card info and confirms a \u201cpurchase,\u201d but the product never arrives.<\/p>\n<p>The fraudsters used several established vulnerabilities to infect a wide variety of web shops.<\/p>\n<p>For the users it\u2019s not just the payment for an article they\u2019ll never receive and the disappointment about not getting that sought-after article, but there is also the risk of providing cybercriminals with their payment card information.<\/p>\n<p>The campaign has been disrupted for a large part due to the efforts of the researchers, but they warn that part of it is still active.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-so-what-can-consumers-do-to-stay-safe\">So, what can consumers do to stay safe?<\/h2>\n<p>Keep an eye on the website displayed in the address bar. Did the advertisement you clicked on take you to the expected web shop? And when the checkout process runs through a different web shop, this is another reason for alarm.<\/p>\n<p>Be especially cautious when you are looking for hard-to-get items, because this is what the group specializes in.<\/p>\n<p>If you are suspicious, it\u2019s a good idea to try the input validation of the shipping information. The fraudsters do not care whether you fill out a real phone number or street address since they have no intention of shipping anything, so the validation process does not work. On a legitimate web shop this should work and warn visitors about invalid entries.<\/p>\n<p>Malwarebytes\u2019 web protection module and Browser Guard block the IP addresses in use by this group.<\/p>\n<hr class=\"wp-block-separator has-text-color has-cyan-bluish-gray-color has-alpha-channel-opacity has-cyan-bluish-gray-background-color has-background is-style-wide\" \/>\n<p><strong>We don\u2019t just report on threats\u2014we remove them<\/strong><\/p>\n<p>Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by&nbsp;<a href=\"https:\/\/www.malwarebytes.com\/for-home\">downloading Malwarebytes today<\/a>.<\/p>\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2024\/11\/1000-web-shops-infected-by-phish-n-ships-criminals-who-create-fake-product-listings-for-in-demand-products\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Fraudsters running the Phish &#8216;n Ships campaign infected legitimate website and used SEO poisoning to redirect shoppers to their fake web shops <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[11539,32,29164,10574,28480],"class_list":["post-25414","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-fake","tag-news","tag-payment-processor","tag-scams","tag-web-shops"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25414","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=25414"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/25414\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=25414"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=25414"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=25414"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}