Monday, July 15, 2024
EHA

Threat Actors Abusing 404 Pages to Hide Credit Card Stealing Malware

A new web skimming campaign has been discovered, which targets multiple organizations in the food and retail industries. This campaign was unique as it included three advanced concealment techniques.

One involved using the 404 error page to hide malicious code, making it difficult to mitigate and detect, whereas the other two were obfuscation techniques. 

A web Skimming attack is when threat actors insert malicious codes into the website to extract data from an HTML form when the victims fill it. It is one of the sophisticated techniques threat actors use for various data extraction attacks.

Document
FREE Demo

Deploy Advanced AI-Powered Email Security Solution

Implementing AI-Powered Email security solutions “Trustifi” can secure your business from today’s most dangerous email threats, such as Email Tracking, Blocking, Modifying, Phishing, Account Take Over, Business Email Compromise, Malware & Ransomware

A new campaign with 3 variations

The new campaign targeted multiple Magento and WooCommerce websites and consisted of three main parts: loader, malicious attack code, and data exfiltration. However, according to the reports shared with Cyber Security News, this campaign directly exploited multiple victim websites. 

The Loader is a JavaScript code snippet used for loading the complete malicious code of the attack. The malicious attack code is the primary JavaScript code used for executing the attack and other purposes, including detecting sensitive inputs, reading the data, disrupting the checkout process, and injecting fake forms. Data exfiltration is the method used for sending stolen data to the command and control (C2) server.

Magecart attack infrastructure
Magecart attack infrastructure (Source: Akamai)

However, there were 3 variations discovered in this campaign. These variations were improvements developed by the attacker within a short period of time to prevent detection and mitigation.

Two variations were similar, but the third one was unique as the attackers used the website’s default 404 error page to hide their malicious code.

Fake form hidden while the user is prompted to re-enter their information
Fake form is hidden while the user is prompted to re-enter their information (Source: Akamai)

Using the website’s default 404 error page is unique and can result in improved hiding and evasion. Though the loaders on the affected websites were removed, the malicious comments on the website’s default 404 page still remain. This can potentially allow the skimmer to reactivate the attack. 

A complete report has been published by Akamai, which provides detailed information about the campaign, variations, and other information. 

Indicators of Compromise

  • Pmdresearch[.]com
  • secures-tool[.]com
  • adsometric[.]com
  • cngresearch[.]com

Protect yourself from vulnerabilities using Patch Manager Plus to patch over 850 third-party applications quickly. Take advantage of the free trial to ensure 100% security.

Website

Latest articles

Critical Cellopoint Secure Email Gateway Flaw Let Attackers Execute Arbitrary Code

A critical vulnerability has been discovered in the Cellopoint Secure Email Gateway, identified as...

Singapore Banks to Phase out OTPs for Bank Account Logins Within 3 Months

The Monetary Authority of Singapore (MAS) and The Association of Banks in Singapore (ABS)...

GuardZoo Android Malware Attacking military personnel via WhatsApp To Steal Sensitive Data

A Houthi-aligned group has been deploying Android surveillanceware called GuardZoo since October 2019 to...

ViperSoftX Weaponizing AutoIt & CLR For Stealthy PowerShell Execution

ViperSoftX is an advanced malware that has become more complicated since its recognition in...

Malicious NuGet Campaign Tricking Developers To Inject Malicious Code

Hackers often target NuGet as it's a popular package manager for .NET, which developers...

Akira Ransomware Attacking Airline Industry With Legitimate Tools

Airlines often become the target of hackers as they contain sensitive personal and financial...

DarkGate Malware Exploiting Excel Files And SMB File Shares

DarkGate, a Malware-as-a-Service (MaaS) platform, experienced a surge in activity since September 2023, employing...
Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Free Webinar

Low Rate DDoS Attack

9 of 10 sites on the AppTrana network have faced a DDoS attack in the last 30 days.
Some DDoS attacks could readily be blocked by rate-limiting, IP reputation checks and other basic mitigation methods.
More than 50% of the DDoS attacks are employing botnets to send slow DDoS attacks where millions of IPs are being employed to send one or two requests per minute..
Key takeaways include:

  • The mechanics of a low-DDoS attack
  • Fundamentals of behavioural AI and rate-limiting
  • Surgical mitigation actions to minimize false positives
  • Role of managed services in DDoS monitoring

Related Articles