More than 50 malicious scripts have been leveraged to deploy modular and localized payloads against PayPal, Stripe, PagSeguro, and other leading payment gateways as part of a widespread Magecart web skimming operation, Cyber Security News reports.
Attackers have used seemingly legitimate domains, such as googlemanageranalytic[.]com, gtm-analyticsdn[.]com, and jquery-stupify[.]com, to enable the clandestine execution of the nefarious scripts, which sought to obtain customers' personally identifiable information, email addresses, and credentials via fraudulent payment forms, according to Source Defense Research analysts. Obtaining such data has allowed subsequent account takeover intrusions, as well as persistent access, highlighting the growing sophistication of skimming attacks.
Such findings should prompt organizations with e-commerce platforms to not only bolster client-side security and adopt content security policies, but also monitor payment forms in real time to better defend against illicit code injections, researchers said.
Attackers have used seemingly legitimate domains, such as googlemanageranalytic[.]com, gtm-analyticsdn[.]com, and jquery-stupify[.]com, to enable the clandestine execution of the nefarious scripts, which sought to obtain customers' personally identifiable information, email addresses, and credentials via fraudulent payment forms, according to Source Defense Research analysts. Obtaining such data has allowed subsequent account takeover intrusions, as well as persistent access, highlighting the growing sophistication of skimming attacks.
Such findings should prompt organizations with e-commerce platforms to not only bolster client-side security and adopt content security policies, but also monitor payment forms in real time to better defend against illicit code injections, researchers said.




