A phishing campaign is targeting Call of Duty Mobile players with a fake free Call of Duty Points giveaway page that impersonates an official promotion and steals account credentials. The fraudulent site prompts victims to enter their email address and password, then sends them to a second page to capture a one-time two-factor authentication code. Researchers said the operation uses real-time credential relay against Activision’s legitimate login flow, allowing attackers to intercept the 2FA code before it expires and take over the account.
The scam has no connection to Activision and is designed to seize access to player accounts that may also be linked to Xbox, PlayStation, or Battle.net profiles. Because those accounts can store payment details and broader gaming identities, a successful compromise can expose more than in-game currency. Affected users were urged to change their Activision password immediately, review account activity, sign out of active sessions, and check saved payment methods for unauthorized charges.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Researchers reported a phishing campaign impersonating an official free Call of Duty Points giveaway page to steal Call of Duty Mobile players’ Activision credentials and one-time 2FA codes, enabling account takeover. The scam used real-time credential relay against Activision’s legitimate login flow and was described as having no connection to Activision.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.