LIVE · cybersecurity feed
Live wire
Malware Hijacks Android Car Head UnitsCritical Flaw in NASA/JPL Open-Source Spacecraft Command Software Allowed Unauthenticated Command ExecutionCVE-2026-73570 · U.S. CISA adds Zimbra Collaboration Suite (ZCS) flaw to its Known Exploited Vulnerabilities catalogCVE-2024-3094 · Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2Hundreds of leaked AWS keys give full control over corporate accountsAndroid Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy BotnetMalware injected into popular Rust packages to steal developer credentialsSix Maximum-Severity Flaws Found in Cisco ProductsCritical Isolated-vm Vulnerability Leads to RCE on Host
e-commerce fraudhigh

Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams

Cybercriminals are orchestrating sophisticated, multinational fake online shop operations across Europe, impersonating major brands like Samsung, Nike, and Amazon. These scams leverage social media, WhatsApp, and email to trick consumers into purchasing counterfeit goods, sharing personal information, or falling victim to World Cup-themed promotions. The operations are highly organized, utilizing rotating domains, misleading redirects, and localized content to evade detection and maximize reach.

zeroday.news ·

A recent investigation by Bitdefender Labs has uncovered a significant escalation in fake online shop campaigns targeting consumers across 12 European countries between March and May 2026. These operations, far from being isolated incidents, are now functioning as coordinated, multinational businesses employing professional e-commerce tactics.

Attackers are impersonating globally recognized brands such as Samsung, Nike, Adidas, ZARA, H&M, Amazon, Lidl, and SHEIN. They employ a multi-channel approach, utilizing Facebook ads, WhatsApp messages, email, SMS, phone calls, and fraudulent websites to lure victims. The ultimate goals range from direct financial theft through fake payments to acquiring sensitive personal information or selling counterfeit merchandise.

Researchers mapped over 40 domains linked to these fraudulent activities, noting a pattern of reused infrastructure and tactics across different countries and brands. Methods to evade detection include rotating domain names, employing misleading redirects, and leveraging Unicode lookalike domains that visually mimic legitimate URLs. Some operators have even established counterfeit supply chains through platforms like WhatsApp, using password-protected catalogs to showcase their illicit goods.

Several campaigns have capitalized on the anticipation surrounding the 2026 FIFA World Cup, promising exclusive merchandise or special deals to exploit consumer excitement. For instance, one campaign offered Samsung Galaxy S26 Ultra devices at a 90% discount, while another promoted free Adidas Deutschland 2026 Fan Kits.

The scale and sophistication of these operations are notable. Campaigns are localized to specific European markets, with tailored messaging and content. For example, a ZARA and Nike impersonation campaign originating from a Polish hub used the same domain and advertising identity, indicating a shared operational backend.

WhatsApp has emerged as a significant platform for counterfeit goods distribution. One operator, identified as "Carl," contacted European users via WhatsApp, offering "1:1 quality" counterfeit products and directing them to password-protected Yupoo catalogs. This network appears to be China-based, with DHL shipping offered to Europe.

Beyond direct sales scams, some operations focus on subscription traps or data harvesting. Amazon clone sites were identified, designed to exploit the brand's trust to collect payment details or enroll unsuspecting users into unwanted subscriptions.

The investigation highlights the evolution of these fake-shop networks, which now operate with significant advertising budgets and infrastructure designed to bypass traditional security measures. The reuse of domain infrastructure and the adaptation of tactics across various brands underscore the organized nature of these cybercriminal enterprises.

e-commerce fraudcounterfeit goodsphishingscamscybercrime
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

If you're not using AI to attack your own systems, your adversaries will

Agents are also the new attack surface - cue defenders' existential angst

malware

Hackers infect Android car head units with proxy botnet malware

A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]

security

Named Pipes Under Attack: Securing Windows Interprocess Communication

Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict input validation, and narrowly scoped privileges can help secure named-pipe communication. [...]

security

Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

Plus: Apple sends out an “unprecedented” number of spyware warnings, Ukraine hits a Russian ecommerce giant with cyber and drone attacks, and more.

malwarehigh

Malware Hijacks Android Car Head Units

Researchers have identified new Android malware that hijacks car head units by exploiting their official update mechanisms. The malware installs proxy software, turning vehicles into nodes for the BADBOX botnet, primarily for ad fraud and to provide anonymized internet connections. This marks the first documented instance of malware specifically targeting car head units through their native update channels.

malware

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight

The spyware-equipped Manic, a persistent Grandoreiro campaign in Latin America and Europe, and an expanded ToxicPanda 2.0 malware. The post Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight appeared first on SecurityWeek.