Visa: New Baka Skimmer Designed to Avoid Detection
#1
Information 
Quote:Visa has issued a warning about new digital skimming malware with a sophisticated design intended to circumvent detection by security tools.
 
The card giant said its Payment Fraud Disruption (PFD) group first discovered the “Baka” skimmer in February whilst analyzing a command and control (C2) server associated with the ImageID variant. PFD subsequently founded seven servers hosting the Baka skimming kit.
 
“While the skimmer itself is basic and contains the expected features offered by many e-commerce skimming kits (e.g. data exfiltration using image requests and configurable target form fields), the Baka skimming kit’s advanced design indicates it was created by a skilled developer,” it said.
 
“The skimmer loads dynamically to avoid static malware scanners and uses unique encryption parameters for each victim to obfuscate the malicious code. PFD assesses that this skimmer variant avoids detection and analysis by removing itself from memory when it detects the possibility of dynamic analysis with developer tools or when data has been successfully exfiltrated.”
 
It’s currently unclear just how widespread the threat is. Visa said that it has identified the malware on “several” merchant websites around the world using its eCommerce Threat Disruption (eTD) capabilities.
 
However, the firm issued several recommendations for e-commerce providers including: regular scans for C2 communications, close vetting of third-party code and Content Delivery Networks (CDNs), regular website scanning and testing for malware an vulnerabilities, regular patching of shopping cart and other software and web application firewalls (WAFs) to block malicious traffic.
 
Visa also recommended merchants to restrict access to administrative portals, deploy two-factor authentication and to consider using a fully hosted checkout solution separate from the main e-commerce site.

Read more: https://www.infosecurity-magazine.com/ne...-designed/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Visa: New Baka Skimmer Designed to Avoid Detection - by silversurfer - 07 September 20, 14:54

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Ashampoo WinOptimizer 2026
Ashampoo WinOptimize...jasonX — 07:32
XYplorer
What's new in Rele...Kool — 06:46
QOwnNotes
26.4.21 26.4.20  ...Kool — 06:43
Random YouTube Vidoes
The Wait is Over! ...jasonX — 06:32
Ashampoo Snap Pro 26
Ashampoo Snap Pro 26...jasonX — 06:20

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (51)steakelask
avatar (45)Termoplenka
avatar (51)Toligo

[-]
Online Staff
zevish's profile zevish

>