A new web skimming campaign has been discovered, which targets multiple organizations in the food and retail industries. This campaign was unique as it included three advanced concealment techniques.
One involved using the 404 error page to hide malicious code, making it difficult to mitigate and detect, whereas the other two were obfuscation techniques.
A web Skimming attack is when threat actors insert malicious codes into the website to extract data from an HTML form when the victims fill it. It is one of the sophisticated techniques threat actors use for various data extraction attacks.
Implementing AI-Powered Email security solutions “Trustifi” can secure your business from today’s most dangerous email threats, such as Email Tracking, Blocking, Modifying, Phishing, Account Take Over, Business Email Compromise, Malware & Ransomware
The new campaign targeted multiple Magento and WooCommerce websites and consisted of three main parts: loader, malicious attack code, and data exfiltration. However, according to the reports shared with Cyber Security News, this campaign directly exploited multiple victim websites.
The Loader is a JavaScript code snippet used for loading the complete malicious code of the attack. The malicious attack code is the primary JavaScript code used for executing the attack and other purposes, including detecting sensitive inputs, reading the data, disrupting the checkout process, and injecting fake forms. Data exfiltration is the method used for sending stolen data to the command and control (C2) server.
However, there were 3 variations discovered in this campaign. These variations were improvements developed by the attacker within a short period of time to prevent detection and mitigation.
Two variations were similar, but the third one was unique as the attackers used the website’s default 404 error page to hide their malicious code.
Using the website’s default 404 error page is unique and can result in improved hiding and evasion. Though the loaders on the affected websites were removed, the malicious comments on the website’s default 404 page still remain. This can potentially allow the skimmer to reactivate the attack.
A complete report has been published by Akamai, which provides detailed information about the campaign, variations, and other information.
Protect yourself from vulnerabilities using Patch Manager Plus to patch over 850 third-party applications quickly. Take advantage of the free trial to ensure 100% security.
A new project has exposed a critical attack vector that exploits protocol vulnerabilities to disrupt…
A threat actor known as #LongNight has reportedly put up for sale remote code execution…
Ivanti disclosed two critical vulnerabilities, identified as CVE-2025-4427 and CVE-2025-4428, affecting Ivanti Endpoint Manager Mobile…
Hackers are increasingly targeting macOS users with malicious clones of Ledger Live, the popular application…
The European Union has escalated its response to Russia’s ongoing campaign of hybrid threats, announcing…
Venice.ai has rapidly emerged as a disruptive force in the AI landscape, positioning itself as…