Threat Advisory

Silent Skimmer A Year-Long Web Skimming Campaign Targeting Online Payment Businesses

Threat: Malware
Criticality: High
[subscribe_to_unlock_form]

Summary:

A recently discovered threat campaign, known as "Silent Skimmer," has been actively targeting vulnerable online payment businesses across different industries. This financially motivated threat actor primarily operates in the Asia-Pacific and North America regions. The attacker gains initial access to web servers by exploiting vulnerabilities in web applications, particularly those using Internet Information Services (IIS). Once access is obtained, they deploy a range of tools and techniques, including open-source utilities and Living Off the Land Binaries and Scripts (LOLBAS), to compromise the payment checkout pages on victim websites and extract sensitive financial data from users.[/subscribe_to_unlock_form]

Summary:

A recently discovered threat campaign, known as "Silent Skimmer," has been actively targeting vulnerable online payment businesses across different industries. This financially motivated threat actor primarily operates in the Asia-Pacific and North America regions. The attacker gains initial access to web servers by exploiting vulnerabilities in web applications, particularly those using Internet Information Services (IIS). Once access is obtained, they deploy a range of tools and techniques, including open-source utilities and Living Off the Land Binaries and Scripts (LOLBAS), to compromise the payment checkout pages on victim websites and extract sensitive financial data from users.[emaillocker id="1283"]

The Silent Skimmer campaign leverages a variety of tactics, techniques, and procedures (TTPs) to achieve its objectives. The threat actor uses tools such as BadPotato, Godzilla Webshells, PowerShell RATs, and others to escalate privileges and maintain control over compromised web servers. They exploit vulnerabilities, including CVE-2019-18935, which can result in remote code execution. Once they gain access, the attacker deploys a malicious DLL to execute an HTML Application (HTA) that serves as a remote access tool (RAT). This RAT provides comprehensive control over victim computers. The attacker's ultimate goal is to compromise web servers' payment checkout pages and scrape payment data. They deploy JavaScript files to exfiltrate sensitive information when specific events occur. The network infrastructure used includes temporary virtual private servers (VPS) hosted on Microsoft Azure, with each VPS node online for a brief period to host command-and-control (C2) servers. Cloudflare is employed for exfiltrating data, utilizing fast flux to obscure traffic. The campaign targets a diverse range of industries, focusing on websites that collect payment data and exploit vulnerabilities in commonly used technologies.

The Silent Skimmer threat campaign is a sophisticated and financially motivated operation that has been active for an extended period, with an expanding geographic scope. The threat actor's ability to adjust network infrastructure based on victim locations demonstrates a level of sophistication. Their primary targets include web servers connected to the Internet, particularly those handling payment data. Given the campaign's evolution and the valuable data it seeks to compromise, it is crucial for organizations to bolster their web server security and remain vigilant against such threats, as similar attacks may continue to target vulnerable systems in various regions.

Threat Profile:

References:

The following reports contain further technical details:

https://thehackernews.com/2023/10/silent-skimmer-year-long-web-skimming.html

[/emaillocker]
crossmenu