PXMart
| Primary URL | Location | Industry | www[.]pxmart[.]com[.]tw |
Country
Taiwan
|
Retail
|
|---|
Profile
PXMart is a supermarket chain headquartered in Taiwan. The organisation operates under the alias PXMart for its retail activities. Its core business involves the sale of groceries, fresh produce, packaged foods, and household essentials. PXMart serves consumer markets primarily within Taiwan. The company maintains an official presence on social media platforms, including a Facebook page used for customer communication and promotions. As a retailer, PXMart provides both physical store locations and digital channels for reaching shoppers. The organisation’s positioning places it within the competitive landscape of Taiwan’s grocery retail sector. No explicit information is available regarding its ownership structure or parent‑subsidiary relationships. PXMart’s operational focus centers on delivering everyday goods to local communities. The retailer’s brand is recognized in the context of the 2020 cyber incident that targeted its online footprint.
In September 2020, cybercriminals launched a series of social engineering attacks that exploited COVID‑19 themes. The attackers impersonated medical authorities to lend credibility to their schemes. As part of the campaign, they cloned PXMart’s official Facebook page and posted fraudulent offers of free masks. The fake page was designed to lure users into divulging personal information or downloading malicious content. Parallel phishing campaigns pretended to come from trusted health organizations such as the World Health Organization or local health bureaus. These emails contained malicious attachments, notably macro‑laden PowerPoint files. When opened, the macros executed code that established a backdoor connection to the attackers’ command‑and‑control servers. Another tactic involved fabricated Zoom meeting notifications that created a sense of urgency. The deceptive Zoom messages prompted recipients to click links that harvested login credentials. The overall aim of the attacks was to compromise both business and medical‑facility networks. By gaining initial access through home‑office devices, the threat actors sought to spread malware deeper into enterprise infrastructure. The incidents highlighted the heightened risk posed by remote‑work environments during the pandemic. Rather than focusing solely on data theft, the attackers appeared intent on disrupting operations and sabotaging critical systems. The use of COVID‑19 lures demonstrated how crisis themes can be weaponized for large‑scale social engineering. The targeting of a well‑known supermarket chain’s Facebook page illustrated the attackers’ willingness to abuse trusted brand assets for malicious purposes.
