Magecart Campaign Offers Customizable Payload
#1
Quote:Magecart has launched a new campaign offering a highly customizable payload along with JavaScript loaders and software bundles that can ensure the malicious payload isn't being executed in a debugger or sandbox, according to Fortinet researchers.
 
“This skimmer is called Inter. It is highly customizable, so it can be easily configured to fit the buyer’s needs and is reportedly being sold in underground forums for $1,300 per license. We started seeing attacks from this campaign on April 19,” the researchers wrote
 
“E-commerce websites use different platforms for handling payments. For instance, some websites handle the payments internally while others use external payment service providers (PSPs). Depending on which platform the compromised website uses, the campaign uses either a web skimmer or a fake payment form,” the report said.
 
The campaign reportedly injects a fake card payment form on a targeted web page and skims a victim's entered card information, whether or not the page is a checkout form, enabling the skimmer to be brought into the customer experience earlier, avoiding possible security software intended to catch it on the checkout page. Another feature allows Inter to avoid detection by hiding the stolen information in plain site, according to the report.

SOURCE: https://www.infosecurity-magazine.com/ne...gn-offers/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 19.6.0 / 19.6.1 Update
Changes in 19.6.0:...harlan4096 — 11:42
Free Download Manager 6.33.2.6656
Changes in 6.33.2....harlan4096 — 11:41
Vivaldi 7.9 Build 3970.45
Vivaldi 7.9 Build ...harlan4096 — 11:40
Apples Releases the 26.4 Versions of iOS...
Apple has just rel...harlan4096 — 11:38
Opera 129.0.5823.22
Hello! Opera st...harlan4096 — 11:37

[-]
Birthdays
Today's Birthdays
avatar (44)gapedDow
avatar (38)snorydar
Upcoming Birthdays
avatar (46)qaqapeti

[-]
Online Staff
There are no staff members currently online.

>