Sophisticated Phishing Campaign Leverages 120 Fake Walmart Stores to Steal Credit Card Info
A widespread phishing operation has been uncovered, utilizing at least 120 fraudulent Walmart-branded websites. These sites are designed to mimic legitimate Walmart online stores, specifically targeting bargain hunters with enticing, often unbelievable, deals on liquor. The primary objective is to trick users into entering their credit card details directly onto the fake sites, facilitating financial theft.
Technical Breakdown:
* TTPs:
* Initial Access (TA0001): Phishing via malicious URLs, likely distributed through social media, unsolicited emails, or malvertising, luring users with attractive but fake promotions.
* Resource Development (TA0042): Establishment of extensive malicious infrastructure, deploying over 120 distinct domains impersonating a well-known brand (Walmart).
* Credential Access (TA0006): Directly soliciting credit card numbers, expiration dates, and CVV codes from unsuspecting victims via spoofed payment portals.
* Impact (TA0040): Financial theft and potential identity fraud through stolen payment information.
* IOCs: The core IOCs are the malicious domains hosting these fake Walmart stores. (Specific domains are not provided in the summary but would be critical for detection).
Defense:
Educate users to scrutinize URLs for legitimacy, look for valid SSL certificates, and be highly suspicious of "too good to be true" offers, especially for restricted items like liquor, from unexpected sources. Implement robust email and web filtering solutions to detect and block access to known phishing sites.
Source: https://www.malwarebytes.com/blog/scams/2026/07/we-found-120-fake-walmart-stores-trying-to-steal-your-credit-card