HomeSecurity18,000 new malicious domains with "Black Friday" and "Christmas" themes

18,000 new malicious domains with “Black Friday” and “Christmas” themes

The 2025 holiday season is approaching and has already become one of the most explosive areas of activity for cybercriminals. Security researchers have identified an unprecedented wave of attacks that exploit the global rise of e-commerce. As consumers flock to online deals, digital attackers are setting up entire infrastructures for large-scale fraud.

Malicious domains: The new "showcase" of attacks

One of the most characteristic examples of this outbreak is the mass creation of fake websites that imitate popular retailers. Cybercriminals use automated tools to produce thousands of deceptive domains, which completely simulate the environment of legitimate e-shops with the aim of stealing payment details and personal data.

See also: Delivery of malicious content via Apple Podcasts?

In the last three months alone, over 18,000 holiday-themed domains, many of which use variations of common words like “Christmas,” “Black Friday,” “Flash Sale,” and other high-search keywords. These websites are barely distinguishable from the real thing, making them difficult for users rushing to complete purchases.

18,000 new malicious domains "Black Friday" "Christmas"

It is worth noting that a large portion of these remain “dormant” for days or weeks, in an attempt to evade automated detection systems. Once activated, they turn into fully functional phishing tools, pages for alleged gift cards or fake order forms.

SEO Poisoning: Hackers Promote “Monkey” Sites to the Top

Fortinet researchers discovered that this massive infrastructure is designed to support extensive SEO poisoning campaigns — a tactic where criminals artificially inflate the popularity of fraudulent URLs to appear at the top of search results. In this way, malicious sites appear next to legitimate stores, targeting peak traffic periods.

See also: Guest access to Teams can remove Defender protection

1.57 million stolen accounts on the "black" market

The explosion in attacks is accompanied by a worrying increase in credential theft. According to reports from Fortinet, over 1.57 million credentials from popular e-commerce platforms are currently circulating on underground forums.

These files — known as stealer logs— include passwords, cookies, session tokens, and other data stored in browsers. With them, attackers can bypass verification systems and take over accounts without being noticed.

18,000 new malicious domains with "Black Friday" and "Christmas" themes

Critical vulnerabilities in e-commerce platforms in the spotlight

CVE-2025-54236: The Adobe Magento "loophole"

A significant part of this year's campaign relies on exploiting critical flaws in popular e-commerce platforms. The most actively exploited vulnerability concerns CVE-2025-54236, a serious bug in Adobe Magento that results from incomplete login validation.

With this technique, attackers can perform Remote Code Execution (RCE), bypassing authentication processes and gaining full access to admin panels. They then install JavaScript web skimmers that intercept card data during purchase completion.

See also: Bloody Wolf expands attacks with Java-based NetSupport RAT

CVE-2025-61882: Attacks on Oracle E-Business Suite

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

At the same time, there is increased activity in exploiting the CVE-2025-61882 in Oracle E-Business Suite. This vulnerability also allows RCE, allowing ransomware groups to paralyze entire inventory and logistics systems.

In both cases, hackers use automated scripts that "scan" the internet for unpatched systems, turning a simple technical weakness into a gateway for widespread data theft.

18,000 new malicious domains with "Black Friday" and "Christmas" themes

What it means for merchants and consumers

This year’s period demonstrates in the most emphatically way that e-commerce businesses need immediate software updates, enhanced fraud filters and manual transaction monitoring. For consumers, paying attention to suspicious URLs, using unique passwords and enabling 2FA are now essential defenses in an ever-changing digital landscape.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS