Amazon Phishers Prime Their Lures Ahead of Deal Season

Amazon’s Prime Day has become one of the biggest online shopping events of the year — and, predictably, one of the busiest periods for phishing crews. Attackers have ramped up campaigns that impersonate Amazon notifications, using the shopping frenzy as cover to harvest credit card numbers, login credentials, and personal data.

The timing is especially favorable to criminals this year. With pandemic-driven lockdowns pushing more consumers to shop online, and several big-box retailers cancelling Black Friday promotions, Prime Day has become an even larger target for fraudsters. Researchers have observed attackers deploying a range of tactics, from newly registered domains to abused legitimate link-shortening services, in an effort to make their lures harder to spot.

The “Account on Hold” Campaign

The most prevalent lure observed by researchers is an email that claims there is a problem with the credit card linked to the recipient’s Amazon account. The message states the account has been placed “on hold” until the customer updates their payment information — a classic setup for stealing card data.

Several campaigns use this same general approach with varying levels of sophistication. The more convincing examples mirror Amazon’s official email design closely, with meticulous HTML/CSS coding and images embedded directly from Amazon’s own servers. Attackers host the malicious content on legitimate websites and send the messages from newly registered domains (NRDs).

The sender addresses in one campaign follow two identifiable patterns:

  • no-reply-amazon-notify<11 alphanumeric characters>@<newly registered domain>
  • mail-services-amazon-prime-<11 alphanumeric characters>@<newly registered domain>

The malicious links embedded in these emails point either to other NRDs or to pages hosted via Sniply, a legitimate link-shortening tool that attackers abuse to host look-alike Amazon login pages. Observed Sniply URLs include:

  • hxxps://snip[.]ly/xjey66?.amazon-prime-services=
  • hxxps://snip[.]ly/o1u9cb?amazon.data.prime=
  • hxxps://snip[.]ly/9axm0u?ad-amazon.isuue-id=

The consistent patterns in both sender addresses and link formats strongly suggest the use of a phishing kit. At the time of analysis, Sniply had already blocked access to the malicious pages, but the ease with which attackers can register new domains means similar campaigns can be relaunched quickly.

These lures are particularly difficult for traditional defenses to catch because the URLs resolve to legitimate domains and the emails carry no malicious payload. The attack only becomes dangerous when the user clicks through and lands on a spoofed Amazon page.

The “Prime Membership Expired” Variant

In the days leading up to Prime Day, researchers also spotted a campaign claiming the recipient’s Prime membership has expired. The email urges the target to click a link and update the payment method on file to continue enjoying Prime benefits. The message is brief and carries familiar Amazon branding.

This variant uses display name spoofing to make the email appear to come from “Amazon Prime.” However, an inspection of the email headers reveals the real “envelope-from” address is ad4@dianefloresbrown[.]com, and the message was routed via wineu[.]mail. At the time of analysis, these domains did not resolve to any IP addresses, and all IPs in the header were private addresses, providing the attacker a degree of anonymity.

Researchers link this campaign to malicious Amazon-related spoofs dating back to 2016, with the infrastructure still being updated on an almost daily basis.

The phishing pages used in this campaign share a distinctive URL structure. Each time the link is clicked, a new URL is generated to evade detection and web crawlers. The variable parts of the URL include:

  • hxxps://asxtbibcx[.]com/amazon/ama/ACCESS744558886441BNG5F7558DERS85699SVB/F<hashed and base64-encoded GMT/UTC timestamp>/?dispatch=<randomly generated alphanumeric characters>

Once the victim clicks through, the attack walks them through a multi-step process that mimics account verification. The target is asked to provide payment information and personally identifying details before being redirected to the real Amazon site, where a screen confirms the account was “successfully updated” and logs the user out. No cookies are stored during the redirect, indicating the attacker only seeks the data entered during the fake verification flow.

The captured sensitive data is sent to the email addresses btsmpil@gmail[.]com and kabiyesi@zoho[.]com.

Loose Ends: Source Code Left Exposed

One attacker made a notable mistake: the index of their malicious website was left publicly accessible. This allowed researchers to view the underlying source code and examine the scripts driving the phishing operation.

The code review revealed several artifacts that could help link the attacker to future campaigns. For example, the HTML uses div classes that consistently follow a naming convention with the prefix “tajouri” and the identifier “containtindex.” The main index page also contains code for generating unique URLs per visitor and blocking web crawlers. A screen name, “AYB SCH,” was found embedded in the code among a collection of profanities.

Another page, corresponding to the “Account Verification” step, also contains the same div class format along with French text in HTML <title> tags that translates to slang for “shut up.” While these quirks offer little insight into the operator’s identity, they provide potential fingerprints for associating the attacker with other campaigns or phishing kits in the future.

The phishing infrastructure appears to be run from overseas, based on the ISPs observed, by individuals with solid programming skills. The taunting behavior embedded in the code suggests the operators view their work as a game, aiming to outwit security teams while leaving breadcrumbs behind.

Indicators of Compromise

Sender Domains:

  • kimakxbisakok[.]com
  • kauadalahmantanterinda[.]com
  • ikannilakayarasa[.]com
  • bilangbabiamadia[.]com
  • com-accountingproved.com
  • dianefloresbrown[.]com
  • wineu[.]mail

Sender IP Addresses:

  • 36[.]71[.]143[.]138
  • 36[.]68[.]138[.]85

Sender Email Addresses (examples):

  • no-reply-amazon-notify5jsciki79he@kimakxbisakok[.]com
  • no-reply-amazon-notifyhrbdqdoupsz@kauadalahmantanterinda[.]com
  • mail-services-amazon-prime-pswrpeavczy@com-accountingproved[.]com
  • mail-services-amazon-prime-2av302jgvrp@com-accountingproved[.]com

Attacker Email Addresses:

  • btsmpil@gmail[.]com
  • kabiyesi@zoho[.]com

Malicious Links:

  • hxxps://snip[.]ly/xjey66?.amazon-prime-services=
  • hxxps://snip[.]ly/o1u9cb?amazon.data.prime=
  • hxxps://snip[.]ly/9axm0u?ad-amazon.isuue-id=
  • hxxps://interistingkostins[.]com/MwM7tEj
  • hxxps://asxtbibcx[.]com/amazon/ama/ACCESS744558886441BNG5F7558DERS85699SVB/F<hashed and base64-encoded GMT/UTC timestamp>/?dispatch=<randomly generated alphanumeric characters>