Users of the global online store Amazon have been targeted by a malicious campaign aimed at harvesting their registration details for the service.

The phishing emails claim to be from the vendor's customer service and are related to verifying a ticket number.
In a poor attempt to prevent the recipient from realizing the malicious activity, the scammers included Amazon's name in the return email address. Although the address is clearly fake (address-verification-amazon@amazon.400614-web2.neilmed.com), it may ultimately fool some less experienced users.
To achieve the theft of credentials, the body of the message contains a link that redirects to a malicious website, where a fake log-in page for Amazon has been placed.
Information entered in the provided fields is automatically sent to the scammers. If the Amazon account is not protected with two-factor authentication (2FA), cybercriminals could steal sensitive information, as well as make transactions in the victim's name.
A sample email was detected on Monday by MillerSmiles, which usually determines the approximate location of the server hosting the malicious website. However, in this case, it was not possible to collect information.
At this time, the malicious website is not operational, and instead of the phishing content it displays a 404 error.
