A sophisticated wave of fake e-commerce scams, orchestrated by Chinese-speaking threat actors, is targeting shoppers worldwide by spoofing trusted brands such as Apple, Harbor Freight Tools, Michael Kors, REI, Wayfair, and Wrangler Jeans.
The operation, recently uncovered by Silent Push Threat Analysts, leverages a vast and rapidly evolving infrastructure to deceive consumers and steal payment credentials using real payment widgets such as Google Pay, MasterCard, PayPal, and Visa.
This expansive phishing campaign was initially detected through a lead from Mexican journalist Ignacio Gómez Villaseñor, who observed Spanish-language sites mimicking legitimate “Hot Sale 2025” shopping event portals in Mexico.
However, further investigation by Silent Push revealed the campaign’s true scope: thousands of fake retail websites targeting both English- and Spanish-speaking shoppers in multiple countries, far beyond its Mexican origins.
Technical Infrastructure Points to Chinese Origin
Threat analysts identified a distinct technical fingerprint across the network, including the use of Chinese terminology and code artifacts, strongly indicating the involvement of Chinese developers.
These actors have built and maintained an extensive infrastructure supporting thousands of fraudulent domains.
The campaign’s sites are not merely phishing for data they use cloned web content and payment integration techniques to create convincing shopping experiences that persuade victims to enter their sensitive information.
One notable tactic is the deployment of genuine Google Pay widgets on scam websites, such as rizzingupcart[.]com, which adds a deceptive layer of legitimacy.
While Google Pay utilizes virtual card numbers to enhance security, the attackers bypass this by simply never delivering the goods after the payment, thus sidestepping the need to access the raw card data.
Analysts noted a pattern of brand-switching within the same domain sites would spoof multiple major brands, sometimes even displaying content mismatches, such as harborfrieght[.]shop (a misspelled Harbor Freight Tools site) featuring a clone of the Wrangler Jeans web page.

Such sloppiness, however, does not diminish the risk, as thousands of these domains remain active, constantly recycling layouts and content to evade detection.
Exploiting Payment Services
The fraudulent marketplaces do more than just phish they actively abuse online payment ecosystems.
By integrating payment options like MasterCard, PayPal, and Visa (and even security techniques like Google Pay), the threat actors increase their chances of convincing consumers to commit to purchases.
According to independent tests cited in Publimetro México, these scam sites can simulate real checkout flows, displaying logos and timers to foster trust while surreptitiously capturing payment credentials.
Though many of the scam domains are quickly taken down by hosting providers or flagged by web security firms, the campaign’s sheer scale and agility present ongoing challenges for defenders.
The persistence and global reach of these fake marketplaces highlight the limitations of traditional reactive cybersecurity measures, prompting companies like Silent Push to deploy proactive Indicators Of Future Attack (IOFA) intelligence feeds for early detection.
Silent Push Threat Analysts continue to monitor this rapidly adapting threat, warning that these phishing sites represent significant risks to consumers and brands alike.
Enterprises are encouraged to integrate advanced threat intelligence into their security protocols and to educate users about the risks of unfamiliar e-commerce sites, especially around major online retail events.
Sample Indicators of Compromise (IOCs)
| Domain | Description |
|---|---|
| cotswoldoutdoor-euro[.]shop | Fake outdoor retailer |
| harborfrieght[.]shop | Misspelled Harbor Freight |
| portal[.]oemsaas[.]shop | Phishing SaaS portal |
| rizzingupcart[.]com | Google Pay phishing site |
| brooksbrothersofficial[.]com | Brooks Brothers spoof |
| josbankofficial[.]com | Jos. A. Bank spoof |
| nordstromltems[.]com | Nordstrom spoof (typo) |
| guitarcentersale[.]com | Guitar Center spoof |
| tommyilfigershop[.]com | Tommy Hilfiger spoof (typo) |
| tumioutlets[.]com | Tumi fake outlet |
Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant updates