Darknet

Multi-platform Credit Card SKimmer hits Shopify, Bigcommerce, and Others

Security experts from SanSec, warn of a multi-platform credit card skimmer that targets online stores running on Shopify, BigCommerce, Zencart, and Woocommerce.

This new skimmer can also target the hosted platforms like BigCommerce and Shopify even though it does not allow custom Javascript on checkout pages.

Expert says that this skimmer shows a fake payment form that was designed to record customer keystrokes before they enter the actual checkout page. 

Once the customers have provided their credit card details, the skimmer will throw an error message saying “Paypal Checkout failed processing your order. You will be redirected to Shopify Checkout” and the customer is redirected to the real payment page:

                                                   Fake Checkout Form

“Notably, so many different platforms are compromised in the same campaign. Hackers might have breached a shared component used by all affected merchants”, say the researchers from SanSec.

This multi-platform skimmer uses programmatically generated exfiltration domains.  It keeps a counter and uses base64 encoding to produce a new domain name. This will lead to, for example, these exfiltration domains (zg9tywlubmftzw5ldza[.]com, zg9tywlubmftzw5ldze[.]com, and so on).

Therefore, this campaign shows that platforms are no boundary to the profitable fraud of online skimming. Wherever customers enter their payment details, they are in danger. Merchants should implement measures to actively counter this.

Sansec researchers have spotted multiple Magecart campaigns using new evasion techniques. In early December they have revealed a campaign that was hiding the malware in CSS files. The experts analyzed multiple Magecart attack techniques over the past months, attackers compromised websites by hiding malicious code in multiple components of the sites, including live chat windows, images, and favicons.

You can follow us on LinkedinTwitterFacebook for daily Cyber security and hacking news updates.

Also Read

Stealthy Magecart Attack Accidentally Leaks the List of Infected Stores

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago