New Variant Of Texting Amazon Chodes

have at it see if you can tackle finding the group behind it at least they were honest about Indian in the text

2 Likes

It uses the phone number to harvest a SMS OTP.

I’m not going to give them a valid OTP so I can’t get much farther than that…

The comments in the css & javascript code (and debug statements to the js console!!) are in simplified (mainland) Chinese – so the “India” part may be a misdirection.

My static analysis of the javascript tells me that if the victim returns a valid OTP the browser will be redirected to Amazon.com. No idea if the scammers would call back or will just be content to run away with the stolen Amazon login credentials.

3 Likes