Threat Management, Threat Intelligence

Widespread Magecart campaign uncovered

A stock illustration that represents the concept of e-commerce phishing in pastel orange and cobalt blue, incorporating fake shopping carts and conceptual metaphors of stolen data and false security for an engaging and intuitive understanding of the concept. Utilize soft gradients and layered shadows to create a hint of spatial complexity and priority. --ar 16:9 --v 6.1 Job ID: b12556c8-93ea-4d94-91b3-9ca3f4a58a7b

More than 50 malicious scripts have been leveraged to deploy modular and localized payloads against PayPal, Stripe, PagSeguro, and other leading payment gateways as part of a widespread Magecart web skimming operation, Cyber Security News reports.

Attackers have used seemingly legitimate domains, such as googlemanageranalytic[.]com, gtm-analyticsdn[.]com, and jquery-stupify[.]com, to enable the clandestine execution of the nefarious scripts, which sought to obtain customers' personally identifiable information, email addresses, and credentials via fraudulent payment forms, according to Source Defense Research analysts. Obtaining such data has allowed subsequent account takeover intrusions, as well as persistent access, highlighting the growing sophistication of skimming attacks.

Such findings should prompt organizations with e-commerce platforms to not only bolster client-side security and adopt content security policies, but also monitor payment forms in real time to better defend against illicit code injections, researchers said.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds