Threat Advisory

New Magecart-Style Campaign Abusing Legitimate Websites to Attack Others

Threat: Malware
Targeted Region: North America, Latin America, and Europe
Targeted Sector: Retail & E-Commerce
Criticality: High
[subscribe_to_unlock_form]

Summary:

Researchers have identified a new web skimmer campaign based on Magecart style. The campaign tries to steal credit card information and Personally Identifiable Information (PII) from e-commerce websites. This campaign differs from others because the hijacked websites are being utilised as "improvised" command-and-control (C2) servers. This enables the attackers to spread the malicious code quietly. Researchers have identified victims of various sizes in North America, Latin America, and Europe, putting the personal data of thousands of site visitors at risk. The attackers employ evasion techniques, including obfuscating the attack using Base64 and disguising it as popular third-party services like Google Analytics or Google Tag Manager.[/subscribe_to_unlock_form]

Summary:

Researchers have identified a new web skimmer campaign based on Magecart style. The campaign tries to steal credit card information and Personally Identifiable Information (PII) from e-commerce websites. This campaign differs from others because the hijacked websites are being utilised as "improvised" command-and-control (C2) servers. This enables the attackers to spread the malicious code quietly. Researchers have identified victims of various sizes in North America, Latin America, and Europe, putting the personal data of thousands of site visitors at risk. The attackers employ evasion techniques, including obfuscating the attack using Base64 and disguising it as popular third-party services like Google Analytics or Google Tag Manager.[emaillocker id="1283"]

The attackers breach vulnerable legitimate sites and inject web skimmer code, taking advantage of the sites' good reputation. This allows them to fly under the radar and makes it challenging to detect and respond to the attacks. Vulnerable e-commerce websites turn into the main targets for the skimmers, while the infected sites serve as a "distribution center" for malware. In certain circumstances, the infected websites unintentionally distribute the malware to other vulnerable websites.

The campaign takes advantage of flaws in systems like Magento, WooCommerce, WordPress, and Shopify to highlight the wide range of flaws in digital commerce platforms. In order to further hide their true targets, the attackers mask the skimmer code as third-party services like Google Tag Manager or Facebook Pixel. They also use JavaScript code snippets as loaders to fetch the full attack code from the host victim’s website, minimizing the chances of detection.

The two different versions of the obfuscated skimmer code intercept and exfiltrate credit card numbers and personally identifiable information (PII) as an encoded string over an HTTP request to a server that is under the attackers' control. The script flags the browser after obtaining a user's information, preventing additional theft during the same session, to avoid duplicating data and raising suspicion. This strategy makes the Magecart-style attack more elusive. A Magecart-style web skimmer campaign is targeting e-commerce websites, putting personal and financial information at risk. Robust security measures, vulnerability assessments, and education are crucial for prevention and detection.

 

Threat Profile:

Tactic Technique Id Technique
Initial Access T1566 Phishing
Execution T1059 Command and Scripting Interpreter
Persistence T1505 Server Software Component
Defense Evasion T1078 Valid Accounts
T1550 Use Alternate Authentication Material
Impact T1486 Data Encrypted for Impact
T1485 Data Destruction

 

References:

The following reports contain further technical details:

https://thehackernews.com/2023/06/magento-woocommerce-wordpress-and.html

[/emaillocker]
crossmenu