Tuesday, March 25, 2025
HomeMalwareMagecart Threat Actors Using Highly Evasive Skimmer to Steal Credit Card Data

Magecart Threat Actors Using Highly Evasive Skimmer to Steal Credit Card Data

Published on

SIEM as a Service

Follow Us on Google News

Cybersecurity researchers at Cyble Research & Intelligence Labs have identified a tweet with a JavaScript skimmer that is mentioned by a security analyst on Twitter. 

The Magecart threat group has created this skimmer that mainly steals data related to payments from the Magento website, which is an e-commerce platform.

By exploiting the security flaws in the popular CMS, the operators of Magecart attack the Magento e-commerce websites. By doing so the attackers are able to inject malicious JavaScript into the source code of the website as a result of this exploit.

Data Involve

There is malicious code embedded in the checkout page and payment form of the compromised website which attempts to collect the following payment information:- 

  • Credit card number
  • Debit card number
  • Credit card owner’s name
  • Debit card  owner’s name
  • Credit CVV number
  • Debit CVV number
  • Credit card expiry date
  • Debit card expiry date

There is also a check written into the malicious code which determines that the data is in the right format and displays that information.

Magento Card-Skimming

An open-source e-commerce platform, Magento is completely based on PHP, and it’s a platform that facilitates the creation of e-commerce websites for programmers.

The Magento card skimming technique exploits vulnerabilities in Magento’s e-commerce software to steal credit cards from customers. While they do so, they are able to access the source code of the website.

According to the report, Once the threat actors have obtained access to the compromised website, they inject malicious JavaScript into it. By doing this, the threat actors track all the payment forms and checkout processes to steal customers’ financial data.

As soon as the JavaScript is executed, it checks for the presence of anti-skimmer features, which prevent the skimmer from detecting it. In this way, it is prevented from loading when the browser is using its dev tool at the same time.

A JavaScript file retrieves the payment information from the victim once they have entered it into the form. Thereafter, the POST method is used in order to send the Base64-encoded data through this method to the URL included in the script.

Recommendations

Following are some of the best cybersecurity practices that we believe to be essential:-

  • Consider using an anti-virus and internet security software package that has a reputable name in the industry.
  • The use of warez and torrent websites for downloading pirated software must be avoided.
  • Where possible, you should enforce multi-factor authentication in all areas of your business and use strong passwords.
  • Make sure you verify the authenticity of any links and email attachments before you open them. 
  • Make sure that employees are aware of what threats may exist, such as phishing websites and URLs that are untrusted.
  • Updating your operating system, applications, and devices is essential.
  • Ensure that URLs that are likely to be used for spreading malware, such as torrents and warez sites, are blocked.
  • In order to protect the data from being stolen by malware, you need to monitor the beacon at the network level.
  • On the employee’s systems, make sure that a Data Loss Prevention (DLP) Solution is enabled.

Download Free SWG – Secure Web Filtering – E-book

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

FBI Warns Against Using Unsafe File Converter Tools

The FBI Denver Field Office has sounded the alarm about a burgeoning scam involving...

Ingress NGINX RCE Vulnerability Allows Attackers to Compromise Entire Cluster

A series of remote code execution (RCE) vulnerabilities known as "IngressNightmare" have been discovered...

Hackers Deploy Fake Semrush Ads to Steal Google Account Credentials

In a recent cybersecurity threat, hackers have been using fake Semrush ads to target...

Pocket Card Users Targeted in Sophisticated Phishing Campaign

A new phishing campaign targeting Japanese Pocket Card users has been uncovered by Symantec....

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

New Rust-Based Linux Kernel Module Unveiled to Detect Rootkits

A recent development in Linux kernel security has led to the creation of a...

SvcStealer Malware Strikes, Harvesting Sensitive Data from Browsers and Applications

A new strain of malware, known as SvcStealer, has emerged as a significant threat...

Attackers Leverage Weaponized CAPTCHAs to Execute PowerShell and Deploy Malware

In a recent surge of sophisticated cyberattacks, threat actors have been utilizing fake CAPTCHA...