Back to advisories
High
2 min read

ZamaniMart - New Phishing Campaign Targeting Victims in Nigeria

This threat group employs a deceptive shopping module to lure victims via WhatsApp, aiming to collect sensitive financial information.

Alert: ZamaniMart - New Phishing Campaign Targeting Victims in Nigeria

Threat Overview

This threat group employs a deceptive shopping module to lure victims via WhatsApp, aiming to collect sensitive financial information, including credit card details and login credentials. They then transfer funds from the victims' accounts.

Campaign Evidence

The following screenshots demonstrate the phishing infrastructure and tactics used by this campaign:

ZamaniMart Phishing Site

The main phishing storefront mimics legitimate e-commerce platforms.

ZamaniMart Payment Page

Fake payment pages are designed to harvest card details.

ZamaniMart WhatsApp Promotion

WhatsApp is used as the primary distribution channel for fake deals.

ZamaniMart Order Confirmation

Fake order confirmations are sent to build victim trust.

Campaign Details

Attack Vector

  • WhatsApp messages promoting fake online shopping deals
  • Links to convincing but fraudulent e-commerce websites
  • Social engineering to build trust

Technical Analysis

The "ZamaniMart" campaign uses:

  1. Fake Storefronts: Professional-looking but fraudulent websites
  2. Payment Capture: Fake payment pages that harvest card details
  3. Account Takeover: Stolen credentials used to access bank accounts
  4. Funds Transfer: Rapid movement of stolen funds

Indicators of Compromise

Domains (partial list)

  • zamanimart[.]com
  • zamani-deals[.]ng
  • Various typosquatting domains

Behavioral Indicators

  • Unsolicited WhatsApp messages about deals
  • Pressure to act quickly
  • Requests for card details on non-secure pages

Victim Impact

  • Direct financial loss through fraudulent transactions
  • Identity theft from harvested personal information
  • Compromised bank accounts
  • Emotional distress

Protective Measures

  1. Verify Websites: Check for HTTPS and legitimate domain names
  2. Be Suspicious: Question unsolicited offers, especially via WhatsApp
  3. Use Secure Payment: Only pay through verified payment gateways
  4. Enable Alerts: Set up transaction notifications on your accounts
  5. Report: Alert your bank and authorities immediately if victimized

Response Actions

If you've interacted with this campaign:

  1. Do not provide any more information
  2. Contact your bank immediately
  3. Change passwords for any compromised accounts
  4. Report to WhiteHat NG and law enforcement

WhiteHat NG Phishing Alert