SilkSpecter is a financially motivated, Chinese-linked cybercriminal threat actor associated with large-scale payment card theft and online shopping fraud. The actor is known for operating thousands of fraudulent e-commerce sites that impersonate well-known retail brands and exploit seasonal shopping events, particularly Black Friday, to lure victims with steep discounts. Victims have primarily included online shoppers in the United States and Europe. SilkSpecter’s operations rely on convincing fake storefronts designed to resemble legitimate brand websites. The actor has used localization features to tailor content to a visitor’s language and geography, and has embedded commercial analytics and tracking technologies to monitor visitor behavior and optimize conversion. A notable aspect of the operation is the abuse of legitimate payment-processing services to increase trust while covertly capturing payment card data and related sensitive authentication information. Checkout workflows have also collected phone numbers, creating opportunities for follow-on social engineering such as voice or SMS-based fraud intended to facilitate unauthorized transactions or bypass payment verification steps. Attribution to China is supported by infrastructure and operational characteristics including use of Chinese hosting and registrar services, prior use of a Chinese SaaS platform to rapidly build phishing sites, and Mandarin-language artifacts in site code. SilkSpecter demonstrates strong capability in phishing-driven initial access against consumers, credential and payment-data theft, impersonation of trusted brands and financial entities, and data exfiltration at scale. The actor’s activity is best characterized as organized cyber-enabled financial fraud rather than espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
SilkSpecter is conducting sophisticated phishing campaigns targeting e-commerce shoppers in the US and Europe during Black Friday, stealing payment card data and sensitive authentication data through fake discount sites and abusing legitimate payment processors.
SilkSpecter is a Chinese fraud operation running nearly 5,000 fake shopping sites to steal credit card details and phone numbers, impersonating major brands and using sophisticated infrastructure and tracking.
Large-scale payment card theft/fraud operation using thousands of brand-impersonating fake e-commerce sites (notably themed around Black Friday) to capture card data and abuse legitimate payment processing (Stripe), with additional collection of phone numbers likely to facilitate follow-on SMS/voice phishing for 2FA bypass.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.