Cybercriminals Registering Fake Shopping Domains to Target Users This Holiday Season
Cybersecurity researchers have identified an extensive operation designed to commit fraud through counterfeit e-commerce websites during the holiday shopping season. A report released in November 2025 by PreCrime™ Labs, part of BforeAI, uncovered a…
Cybersecurity researchers have identified an extensive operation designed to commit fraud through counterfeit e-commerce websites during the holiday shopping season. A report released in November 2025 by PreCrime™ Labs, part of BforeAI, uncovered a coordinated campaign involving the mass registration of fake online shop domains.
These fake sites are intended to impersonate legitimate retailers, steal financial data, and distribute malware through their counterfeit checkout systems. The investigation analyzed 244 domains registered since the start of the year, revealing a strategy targeting major retail events such as Black Friday and Singles’ Day.
Telemetry data suggests a well-structured operation primarily based on Chinese infrastructure. Of the identified domains, 79 were registered in China, with West263 International Limited and Dynadot as the top registrars.
Industrialized Infrastructure and TTPs
The campaign is characterized by a highly organized infrastructure-as-a-service model. October saw the peak registration activity, with 78 new domains created to capture early holiday traffic. Over 50% of WHOIS entries use privacy protection to obscure attribution, though backend ASN metadata invariably points to Chinese or Hong Kong hosting providers.
These fake sites are intended to impersonate legitimate retailers, steal financial data, and distribute malware through their counterfeit checkout systems.
Threat actors employ automated tools to mass-produce these storefronts. Cross-referencing through OSINT revealed shared JavaScript libraries, identical checkout templates (often mimicking Shopify structures), and reused tracking pixels across multiple domains. DNSlytics analysis showed that while some domains use Cloudflare for obfuscation, hosting blocks are frequently recycled for new domain clusters every few weeks.
The report identified several strategies used to deceive consumers:
Agenda-Oriented Campaigns: Domains like “peaceforsecurity[.]com” mimic high-end fashion stores, potentially exploiting charitable sentiments to evade detection. Ambiguous Cross-Branding: Attackers mix brands to confuse consumers, such as “lululemonsalehub[.]com” promoting unrelated products while referencing various brands. Seasonal Urgency: Domains such as “mango-flashsale[.]com” use crude templates and "free shipping" offers to obtain Personally Identifiable Information (PII) and credit card details.
This campaign underscores the importance of continuous monitoring of domain registration trends, particularly those aligned with major retail periods to maximize visibility on social platforms like TikTok and Facebook.
BforeAI has escalated confirmed domains to registrars like GMO and Dynadot for immediate suspension. Although server takedowns have rendered several clusters non-resolving, the resilient nature of these operators suggests a likely pivot to new TLDs such as .top, .shop, and .vip.
Based on reporting by GBHackers.
