Quick Summary
The Securityish Brief
Cybersecurity researchers have uncovered a significant web skimming campaign that has been ongoing since January 2022. This campaign specifically targets major payment networks such as American Express, Diners Club, Discover, JCB Co., Ltd., Mastercard, and UnionPay. Silent Push, the cybersecurity firm that reported the findings, noted that enterprise organizations using these payment providers are at the highest risk of being impacted.
The digital skimming attacks involve compromising legitimate e-commerce sites and injecting malicious JavaScript code that stealthily collects credit card information and personal details from users during the checkout process. This type of attack falls under the Magecart umbrella, which refers to a group of cybercriminals initially focused on Magento software but has since expanded to various platforms.
Silent Push discovered the campaign by analyzing a suspicious domain linked to a now-sanctioned bulletproof hosting provider. The domain, cdn-cookie[.]com, hosts obfuscated JavaScript payloads like “recorder.js” and “tab-gtm.js” that facilitate credit card skimming. The skimmer is designed to evade detection by checking for the presence of a WordPress admin toolbar and will self-destruct if it detects that an administrator is present.
Additionally, the skimmer checks if Stripe is selected as a payment option and manipulates the user interface to display a fake payment form. This deception leads victims to enter their credit card details into a fraudulent form, which is then sent to the attackers. The stolen data includes not only payment information but also names, phone numbers, email addresses, and shipping addresses, which are exfiltrated via HTTP POST requests.
The implications of this attack are significant, as it highlights the advanced techniques employed by attackers who have a deep understanding of web technologies. Organizations must be vigilant in monitoring their e-commerce platforms and ensuring that security measures are in place to protect against such sophisticated threats.
Understanding the Risks of Web Skimming
This ongoing campaign serves as a reminder of the vulnerabilities present in online payment systems. Users should be cautious when entering sensitive information on e-commerce sites, especially if they notice any unusual behavior during the checkout process. Organizations must regularly audit their websites for potential vulnerabilities and implement robust security measures to mitigate the risk of similar attacks.
- American Express: A major payment network targeted in the skimming campaign.
- Diners Club: Another payment provider affected by the ongoing web skimming attacks.
- Discover: This payment network is also among those targeted by the cybercriminals.
- JCB Co., Ltd.: A payment network that has been compromised in this web skimming campaign.
- Mastercard: One of the major payment providers impacted by the malicious activities.
- UnionPay: Another significant payment network affected by the skimming attacks.
Key Takeaways
- Regularly monitor your e-commerce site for any unauthorized changes or suspicious activity.
- Implement security measures such as Content Security Policy (CSP) to prevent script injection.
- Educate users about the signs of phishing and fake payment forms during checkout.
- Conduct regular security audits and vulnerability assessments on your payment systems.
- Stay informed about the latest cybersecurity threats and update your defenses accordingly.
Key Terms & Concepts
- Web Skimming: In this article, web skimming refers to a type of cyber attack where malicious code is injected into e-commerce sites to steal payment information.
- Magecart: Magecart is a term used to describe a coalition of cybercriminal groups that target online stores to steal payment data.
- JavaScript Payloads: JavaScript payloads are pieces of code injected into websites to perform malicious actions, such as stealing user data.
- HTTP POST Request: An HTTP POST request is a method used to send data to a server, often used in web forms to submit user information.
- Content Security Policy (CSP): CSP is a security feature that helps prevent various attacks, including cross-site scripting, by controlling which resources can be loaded on a web page.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.