Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A January 2025 phishing campaign impersonated Amazon with emails claiming that recipients’ Prime memberships had expired. The messages carried PDF attachments whose links redirected to fake Amazon pages asking for personal and credit-card information. Amazon was impersonated; the reporting does not implicate Amazon in operating the campaign.

How the PDF phishing campaign worked

Palo Alto Networks Unit 42 documented the chain as email → PDF attachment → link inside the PDF → initial URL → redirects to a phishing site impersonating Amazon. The PDF was a delivery vehicle for the link, not proof that the destination was safe. Dark Reading reported that the lure claimed an Amazon Prime membership had expired and that the imitation pages requested personal details and credit-card information.

Unit 42’s indicator-of-compromise record includes a sample URL sequence that reached a credit-card information entry page on January 24, 2025. This is a record of what investigators observed then, not evidence that the page or its URLs remain active today. Unit 42’s January 24, 2025 indicator record and Dark Reading’s January 28, 2025 report describe the campaign.

What investigators found

Unit 42 said it collected 31 PDF files containing links to the phishing sites. During that investigation, none of the associated PDFs it found had yet been submitted to VirusTotal. That statement describes the files and submissions at the time; it is not a current VirusTotal status or a measure of how widely the campaign reached.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The IOC record lists four initial URLs, with observed link counts of 24, 3, 3, and 1 respectively. These are historical observations from the January 2025 investigation, not a current blocklist or proof that the URLs are still reachable. The figures also do not establish a victim count, loss total, or campaign success rate.

Why the destinations could evade scans

Unit 42 reported that links in the PDFs redirected to subdomains of duckdns[.]org hosting phishing pages. It also said the pages used cloaking: scans and other analysis attempts could be redirected to benign domains instead of the phishing content. Most initial and intermediate staging domains were hosted on the same IP address.

Because of that cloaking, a benign result from an automated scan would not, by itself, disprove the behavior researchers documented. The available reporting concerns the investigation in January 2025; it does not establish whether the domains or URLs are live now. Do not visit the listed indicators to test them.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to handle an unexpected Amazon account email

  • Do not follow an attachment’s sign-in or payment link. A PDF can contain a clickable link, and the file format does not make the destination trustworthy.
  • Check the account through a known channel. If a message claims there is a Prime membership or payment issue, open the Amazon app or type a known Amazon address yourself rather than using the PDF’s link.
  • Report the message through an established process. Use your workplace’s security-reporting route or your mail provider’s reporting function, as applicable.

These steps follow from the documented attack path; the reports do not describe controlled testing of a security product or establish that any particular product would detect the campaign.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
The Standards Real Book, C Version
  • Used Book in Good Condition

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.