惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Recent Announcements
Recent Announcements
博客园 - Franky
博客园 - 三生石上(FineUI控件)
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Apple Machine Learning Research
Apple Machine Learning Research
云风的 BLOG
云风的 BLOG
人人都是产品经理
人人都是产品经理
博客园 - 【当耐特】
L
LangChain Blog
Stack Overflow Blog
Stack Overflow Blog
H
Help Net Security
爱范儿
爱范儿
罗磊的独立博客
博客园_首页
美团技术团队
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
月光博客
月光博客
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 叶小钗
V
Visual Studio Blog
T
Tailwind CSS Blog

Human Risk Management Blog

Future-Proofing Organizations in the Face of AI What Security Can Learn From Dinosaurs Inside the OS-Aware Phishing Kit Profiling Your Device CyberheistNews Vol 16 #30 [Protect Your Users] AI Hallucinations Are Fueling Phishing Attacks Majority of Organizations Hit by Targeted Impersonation Attacks The Open-Source Paradox: Navigating the New Frontier of AI Supply Chain Risk Introducing The Hybrid Nudge Experience: Outbound Email Security Built for Your Risk Appetite Elevating the SOC Experience: Smarter Automation, Richer Threat Intelligence, and AI-Native Investigation New Phishing Tools Enable Attackers to Easily Bypass Multifactor Authentication From Inbox to Encryption: How Ransomware Delivery Has Evolved Attackers Exploit AI Hallucinations to Send Users to Phishing Sites Warning: ARToken Phishing Kit Automates BEC Attacks The New Face of AI Risk Trust Nothing: Tips to Secure AI Tools and Agents CyberheistNews Vol 16 #29 ClickFix Social Engineering is Now the Leading Malware Delivery Method Beyond the Checkbox: How a Proactive Partnership Led to Turnkey Hazing Compliance Trust, Verify, Protect: Modernizing Email Security for the Cloud Report: Social Engineering Remains a Central Part of AI-assisted Attacks ClickFix Social Engineering is Now the Leading Malware Delivery Method CyberheistNews Vol 16 #28 Your 2026 Phishing by Industry Benchmarks: The Findings on Human Risk Scammers Can Use AI Tools to Pinpoint Your Location Based on a Photo Report: Attackers Are Using AI to Automate Social Engineering Your KnowBe4 Fresh Compliance Plus Content Updates from June 2026 From Awareness to Digital Workforce Security Your KnowBe4 Fresh Content Updates from June 2026 Threat Actor Uses Phishing to Breach Orgs for Ransomware Gangs Invoice Phishing Attacks Are Abusing the Shop App Phishing Campaign Impersonates Interpol to Deliver Ransomware Prompt Injection and the Rise of Agentic Risk Hyper-Targeted Social Engineering Needs Real-Time Video Response
Free Gift Fallacy: How Attackers Harvest Credit Cards via...
KnowBe4 Threat Lab · 2026-05-28 · via Human Risk Management Blog

KnowBe4 Threat LabsLead Analysts: Jeewan Singh Jalal, Dilsha Dines, Karthikeyan Dharmaraj

The classic 'survey reward' scam is back and hitting harder than ever. KnowBe4 Threat Labs is tracking a massive, high-volume campaign that is not only impersonating a wide array of trusted global brands across retail, logistics, and healthcare, but is using hundreds of newly registered domains (NRDs) and sophisticated psychological priming to fly past traditional security defenses. The result: attackers are harvesting high-value Personally Identifiable Information (PII) and financial data from unsuspecting users on an unprecedented scale.

Campaign Summary

  • Vector and type: Email Phishing
  • Techniques: Brand Impersonation, Social Engineering, Credit Card Harvesting
  • Bypassed SEG detection: Yes (via rapid domain rotation)
  • Targets: Organizations and consumers globally

Multi-Sector Brand Impersonation

The campaign utilizes a "spray and pray" approach, rotating through pixel-perfect templates of various household names. This diversification ensures that regardless of a victim’s shopping habits or service providers, they are likely to see a brand they trust.

Top Impersonated Brands Observed:

  • Retail: Costco, Kroger, Harbor Freight, Tractor Supply Co., Sam’s Club, Dick’s Sporting Goods
  • Travel/Auto: Marriott, AAA (American Automobile Association)
  • Logistics: FedEx
  • Financial & Health: EquityFirst Financial, BlueCross BlueShield

Image Phishing Lure: Sample email templates demonstrating the campaign's use of multi-sector brand impersonation to gain user trust.

The initial attack vector utilizes an email or SMS message lure promising a high-value incentive, such as premium electronics (e.g., iPhone, Apple Watch, Airpods, and Beats by Dre headphones), contingent upon the victim completing a short customer satisfaction survey. This tactic employs psychological priming and scarcity by often incorporating live countdown timers or claims of limited stock to induce immediate action.

The Attack Flow: Psychological Funnel

This campaign represents a sophisticated evolution beyond simple credential harvesting. Rather than immediately demanding a password, attackers use a multi-stage funnel designed to incrementally build trust through micro-commitments, exploiting the victim's sense of justification and reward.

Examples of landing pages created to trap the users with free gift scams.

The attack initiates with The Survey (Pretexting). The victim is presented with 10–15 brief, legitimate-looking questions regarding their experience with the targeted brand. This step is a form of labor that creates a psychological investment, convincing the victim that they have earned the high-value prize through their effort.

The funnel reinforces this belief with Social Proof. The reward landing page features simulated social media comment sections, displaying purported winners who claim to have already received their prizes. This manufactured credibility leverages human bias to overcome lingering suspicion.

The final stage is The Final Payment Lure. The victim is requested to pay a small delivery fee, typically $5.00–$10.00. This seemingly negligible cost legitimizes the high-value item, coercing the user into willingly entering their credit card and Personally Identifiable Information (PII) on the payment page.

The moment the user submits their payment details, the data is instantly exfiltrated to the attacker's command and control (C2C) infrastructure.

Example of the data exfiltration process, highlighting the immediate transfer of captured credit card details and PII to the attacker’s control C2C.

Technical Artifacts and Infrastructure

The campaign's success relies on a "churn and burn" domain strategy. Our analysis shows that attackers are registering hundreds of new domains daily to stay ahead of blocklists.

Technical Indicator Observed Behavior Confidence
Rapid Domain Churn

Use of hundreds of NRDs

(Newly Registered Domains) with a lifespan of <48 hours

HIGH

TLD Concentration

High usage of low-cost TLDs

HIGH

High-Fidelity CSS

Use of “pixel-perfect” clones of official brand landing pages to evade visual scrutiny

HIGH

Social Engineering

Use of scarcity (countdown timers) and social proof (fake comments)

HIGH

MITRE ATT&CK Mapping

  • T1583.001 (Acquire Infrastructure: Domains): Automated registration of infrastructure to host harvesting kits.
  • T1566.002 (Phishing: Spearphishing Link): High-volume email distribution using trusted brand lures.
  • T1598 (Phishing for Information): Multi-stage surveys used to collect PII and financial credentials.

How to Stay Safe

This campaign highlights the evolving nature of social engineering, where attackers move beyond simple link-clicking to complex, multi-stage interactions. Securing the digital workforce requires moving from a reactive, 'training-first' approach to a Risk-First strategy. To defend against these threats, KnowBe4 recommends:

  • Perimeter Defense: Implement advanced security controls to address infrastructure-level threats like newly registered domain (NRD) churn and high-fidelity brand impersonation.
  • DNS Filtering: Implement policies that automatically flag or block Newly Registered Domains (NRDs) that are less than 30 days old.
  • Critical Thinking: Remind users that legitimate corporations will never ask for credit card information via a third-party survey link to pay for a free reward.
  • Risk-First Security Awareness: Leverage AI-driven, individualized training that prepares users for the complete spectrum of social engineering: phishing, vishing, and deepfakes. By using a dynamic Risk Score to deliver just-in-time coaching, organizations can ensure employees recognize the hallmarks of high-pressure social engineering tactics before they engage with the lure.

Indicators of Compromise (IOCs)

The threat landscape evolves rapidly. For the most current list of domains, hashes, and behavioral signatures related to this campaign, please refer to the latest intelligence update from KnowBe4 Threat Labs.

View the full IOC list on X: https://x.com/Kb4Threatlabs

For real-time updates and ongoing threat intelligence, follow the KnowBe4 Threat Lab analysts on X: @Kb4Threatlabs