Amazon will celebrate Prime Day next week. Amidstthe frenzy of cheap TVs and e-books, watch out for phishing emails lurking in your inbox.
Researchers from security firm McAfee recently revealed details about a so-called phishing kit, which contains the tools a would-be hacker to launch a phishing campaign designed to target Amazon customers. The kit is called 16Shop and has been used in phishing campaigns targeting Apple users. Its author is named DevilScreaM.

In both the Apple and Amazon phishing campaigns, 16Shop makes it easy for anyone to create an email that appears to come from a major tech company, with a PDF. This PDF contains links to malicious websites that are designed to look, in this latest case, like an Amazon login page.
Those who click on it will reveal to the hackers the credentials of their Amazon accounts and any other services for which they reuse the same password. As with the previous Apple campaign, these links direct victims to a page that asks not only for their name, but also for their birthday, home address, credit card information and social security number.

"Using large companies as bait gives campaigns," said McAfee chief Raj Samani.
Cybercriminals of emails, providing them with an opportunity to send malicious messages.
Also, consumers expect more marketing and advertisement emails at certain times of the year – Black Friday, Christmas, Easter – and fall victim to phishing emails as they are careless.
McAfee says DevilScreaM created a Facebook group to sell licenses and provide product support — like any good software startup would — about two years ago. By November 2018, the group had 200 members. As of last month, it had reached 300 members and 200 positions. More than 200 malicious URLs were identified. It’s unclear how many people have fallen victim to the illegal operation, but it’s certainly a number.

McAfee has informed Facebook about the issue but, so far, we have not had any official statement from the giant.
Ways of Protection
Don't open attachments unless you're sure they come from someone you trust.
Don't type your information into a website that isn't legitimate, which means carefully examining the specific URL.
Using a password manager can be particularly helpful.
