RetailPhish is a financially motivated phishing and purchase-scam campaign that impersonates major sportswear and retail brands, including Nike, Adidas, Puma, and Marathon Sport, across multiple languages and regions. The operation has been observed using a staged social-engineering funnel delivered primarily through WhatsApp. Victims are first attracted with a brand-themed lure, then pressured to virally forward the offer, after which the operators harvest personally identifiable information and finally request a nominal shipping payment in order to capture payment card details. The campaign is associated with fake online storefront and merchandise offers tied to major sporting-event interest, particularly football-themed consumer demand. Its tradecraft centers on spoofing trusted brands, social amplification through messaging platforms, and fraudulent payment collection for goods that never arrive. In addition to monetizing direct victim payments, the operation is linked to theft of personal and card data, indicating a broader fraud objective beyond simple non-delivery scams. RetailPhish should be understood as a scam-focused threat cluster rather than a nation-state actor. Its known behavior aligns with phishing, spoofing, credential and payment-data harvesting, and financial fraud targeting consumers in multiple regions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.