Summary:
Researchers have identified a new web skimmer campaign based on Magecart style. The campaign tries to steal credit card information and Personally Identifiable Information (PII) from e-commerce websites. This campaign differs from others because the hijacked websites are being utilised as "improvised" command-and-control (C2) servers. This enables the attackers to spread the malicious code quietly. Researchers have identified victims of various sizes in North America, Latin America, and Europe, putting the personal data of thousands of site visitors at risk. The attackers employ evasion techniques, including obfuscating the attack using Base64 and disguising it as popular third-party services like Google Analytics or Google Tag Manager.[/subscribe_to_unlock_form]
Summary:
Researchers have identified a new web skimmer campaign based on Magecart style. The campaign tries to steal credit card information and Personally Identifiable Information (PII) from e-commerce websites. This campaign differs from others because the hijacked websites are being utilised as "improvised" command-and-control (C2) servers. This enables the attackers to spread the malicious code quietly. Researchers have identified victims of various sizes in North America, Latin America, and Europe, putting the personal data of thousands of site visitors at risk. The attackers employ evasion techniques, including obfuscating the attack using Base64 and disguising it as popular third-party services like Google Analytics or Google Tag Manager.[emaillocker id="1283"]
The attackers breach vulnerable legitimate sites and inject web skimmer code, taking advantage of the sites' good reputation. This allows them to fly under the radar and makes it challenging to detect and respond to the attacks. Vulnerable e-commerce websites turn into the main targets for the skimmers, while the infected sites serve as a "distribution center" for malware. In certain circumstances, the infected websites unintentionally distribute the malware to other vulnerable websites.
The campaign takes advantage of flaws in systems like Magento, WooCommerce, WordPress, and Shopify to highlight the wide range of flaws in digital commerce platforms. In order to further hide their true targets, the attackers mask the skimmer code as third-party services like Google Tag Manager or Facebook Pixel. They also use JavaScript code snippets as loaders to fetch the full attack code from the host victim’s website, minimizing the chances of detection.
The two different versions of the obfuscated skimmer code intercept and exfiltrate credit card numbers and personally identifiable information (PII) as an encoded string over an HTTP request to a server that is under the attackers' control. The script flags the browser after obtaining a user's information, preventing additional theft during the same session, to avoid duplicating data and raising suspicion. This strategy makes the Magecart-style attack more elusive. A Magecart-style web skimmer campaign is targeting e-commerce websites, putting personal and financial information at risk. Robust security measures, vulnerability assessments, and education are crucial for prevention and detection.
Threat Profile:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1059 | Command and Scripting Interpreter |
| Persistence | T1505 | Server Software Component |
| Defense Evasion | T1078 | Valid Accounts |
| T1550 | Use Alternate Authentication Material | |
| Impact | T1486 | Data Encrypted for Impact |
| T1485 | Data Destruction |
References:
The following reports contain further technical details:
https://thehackernews.com/2023/06/magento-woocommerce-wordpress-and.html
[/emaillocker]