Cybercriminals have launched widespread campaigns impersonating major retail brands through sophisticated malvertising and phishing operations in the lead-up to Black Friday. Attackers are leveraging short-form video ads and modular scam kits to create convincing phantom storefronts and fake survey reward pages, targeting consumers searching for high-demand holiday gifts. These campaigns exploit the seasonal surge in online shopping and the high volume of ad approvals, making it easier for fraudulent ads to slip through and reach large audiences. Brands such as Amazon, Walmart, Home Depot, and others are being impersonated to lure victims into providing personal information or making fraudulent purchases.
Security researchers have observed that these scams are highly industrialized, with over 100 unique domains using similar fraud templates and dynamically swapping brand imagery to match trending products. The threat landscape includes not only traditional phishing and financial malware but also new vectors such as gaming-related scams and malvertising loops that redirect users to fake offers. The scale and sophistication of these operations highlight the need for increased vigilance from both consumers and ad operations teams during peak shopping periods like Black Friday and Cyber Monday.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Darktrace disclosed technical details and indicators of compromise from the November 2025 Black Friday phishing activity, including malicious domains and URLs. The report highlighted the use of short-lived infrastructure, cloud storage endpoints, and rapid domain registration to evade defenses.
CloudSEK detected more than 2,000 fake online stores exploiting Black Friday and festive sales, including two major domain clusters mimicking brands such as Amazon, Apple, and Samsung. The stores used shared phishing kits, fake trust signals, and shell checkout pages to harvest financial and personal data.
Confiant published findings on a 'Phantom Stores' campaign spreading ahead of Black Friday, using video ads and modular holiday-themed kits to impersonate retailers. The activity reflects a coordinated fake-store operation tailored for seasonal shopping traffic.
A large-scale, organized malvertising operation was detected redirecting Black Friday shoppers from legitimate websites to more than 100 domains impersonating major brands. The campaign used polished survey-and-reward pages to steal personal and payment information and showed signs of a single industrialized threat actor.
During the Black Friday shopping period in November 2025, Darktrace observed a significant increase in sophisticated phishing campaigns impersonating brands such as Amazon and Louis Vuitton. The campaigns used newly registered domains, redirect chains, and cloud-hosted infrastructure to deliver credential harvesters and scam storefronts.
Kaspersky reported heavy seasonal spam activity in early November 2025 as attackers prepared to exploit Black Friday shopping behavior. The activity included brand-themed lures and shopping-related fraud targeting online consumers.
Using telemetry from January through October 2025, Kaspersky observed sustained phishing, scam, spam, and banking-malware activity tied to e-commerce and major sales events. The data showed millions of blocked phishing attempts, widespread brand impersonation, and more than a million banking Trojan detections during the year.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 46 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
darktrace.com
Open sourcecloudsek.com
Open sourceblog.confiant.com
Open sourcesecurelist.com
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.