<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=magecart%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 28 Jul 2026 09:30:26 +0200</lastBuildDate>
<pubDate>Tue, 28 Jul 2026 09:30:26 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=magecart%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=magecart%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Magecart Evolves and Attackers Weaponize Ethereum Blockchain for Digital Skimming]]></title>
<description><![CDATA[Digital skimming has officially entered the decentralized era, bringing in a new era for a major source of crime and fraud. Researchers at Source Defense have uncovered that a large-scale… The post Magecart Evolves and Attackers Weaponize Ethereum Blockchain for…
Read more →
The post Magecart Evo...]]></description>
<link>https://tsecurity.de/de/3621358/it-security-nachrichten/magecart-evolves-and-attackers-weaponize-ethereum-blockchain-for-digital-skimming/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621358/it-security-nachrichten/magecart-evolves-and-attackers-weaponize-ethereum-blockchain-for-digital-skimming/</guid>
<pubDate>Wed, 24 Jun 2026 14:38:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Digital skimming has officially entered the decentralized era, bringing in a new era for a major source of crime and fraud. Researchers at Source Defense have uncovered that a large-scale… The post Magecart Evolves and Attackers Weaponize Ethereum Blockchain for…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/magecart-evolves-and-attackers-weaponize-ethereum-blockchain-for-digital-skimming/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/magecart-evolves-and-attackers-weaponize-ethereum-blockchain-for-digital-skimming/">Magecart Evolves and Attackers Weaponize Ethereum Blockchain for Digital Skimming</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Evolves and Attackers Weaponize Ethereum Blockchain for Digital Skimming]]></title>
<description><![CDATA[Digital skimming has officially entered the decentralized era, bringing in a new era for a major source of crime and fraud. Researchers at Source Defense have uncovered that a large-scale...
The post Magecart Evolves and Attackers Weaponize Ethereum Blockchain for Digital Skimming appeared first ...]]></description>
<link>https://tsecurity.de/de/3621249/it-security-nachrichten/magecart-evolves-and-attackers-weaponize-ethereum-blockchain-for-digital-skimming/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3621249/it-security-nachrichten/magecart-evolves-and-attackers-weaponize-ethereum-blockchain-for-digital-skimming/</guid>
<pubDate>Wed, 24 Jun 2026 14:08:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1024" height="768" src="https://www.cyberdefensemagazine.com/wp-content/uploads/2026/06/Magecart-article-cover-edited.png" class="webfeedsFeaturedVisual wp-post-image" alt="" link_thumbnail="" decoding="async" fetchpriority="high" srcset="https://www.cyberdefensemagazine.com/wp-content/uploads/2026/06/Magecart-article-cover-edited.png 1024w, https://www.cyberdefensemagazine.com/wp-content/uploads/2026/06/Magecart-article-cover-edited-768x576.png 768w" sizes="(max-width: 1024px) 100vw, 1024px"><p>Digital skimming has officially entered the decentralized era, bringing in a new era for a major source of crime and fraud. Researchers at Source Defense have uncovered that a large-scale...</p>
<p>The post <a href="https://www.cyberdefensemagazine.com/magecart-evolves-and-attackers-weaponize-ethereum-blockchain-for-digital-skimming/" data-wpel-link="internal">Magecart Evolves and Attackers Weaponize Ethereum Blockchain for Digital Skimming</a> appeared first on <a href="https://www.cyberdefensemagazine.com/" data-wpel-link="internal">Cyber Defense Magazine</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart-Kampagne: Hacker stehlen Kartendaten über Stripe und GTM - BornCity]]></title>
<description><![CDATA[Hacker kapern Checkout-Seiten via Stripe-API und Google Tag Manager. Neue Betrugswelle trifft Magento-Shops und Kunden.]]></description>
<link>https://tsecurity.de/de/3577923/hacking/magecart-kampagne-hacker-stehlen-kartendaten-ueber-stripe-und-gtm-borncity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3577923/hacking/magecart-kampagne-hacker-stehlen-kartendaten-ueber-stripe-und-gtm-borncity/</guid>
<pubDate>Sat, 06 Jun 2026 17:08:01 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Hacker</b> kapern Checkout-Seiten via Stripe-API und Google Tag Manager. Neue Betrugswelle trifft Magento-Shops und Kunden.]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Daily Summary 2026-06-05]]></title>
<description><![CDATA[134 posts were published in the last hour 21:34 : New Gafgyt Variant Targets Multiple Linux Architectures With Modular Propagation 21:34 : Hola Browser for Windows Delivery Pipeline Compromised to Deliver Cryptominer 21:34 : New Magecart Attack Turns Stripe into…
Read more →
The post IT Security ...]]></description>
<link>https://tsecurity.de/de/3576684/it-security-nachrichten/it-security-news-daily-summary-2026-06-05/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576684/it-security-nachrichten/it-security-news-daily-summary-2026-06-05/</guid>
<pubDate>Sat, 06 Jun 2026 00:36:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>134 posts were published in the last hour 21:34 : New Gafgyt Variant Targets Multiple Linux Architectures With Modular Propagation 21:34 : Hola Browser for Windows Delivery Pipeline Compromised to Deliver Cryptominer 21:34 : New Magecart Attack Turns Stripe into…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-06-05/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-daily-summary-2026-06-05/">IT Security News Daily Summary 2026-06-05</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Magecart Attack Turns Stripe into a Malware Command Server]]></title>
<description><![CDATA[A new form of credit card skimming malware has been discovered hiding inside one of the most trusted payment platforms on the internet. Researchers have found a Magecart attack that uses Stripe, the widely used online payment service, as both…
Read more →
The post New Magecart Attack Turns Stripe...]]></description>
<link>https://tsecurity.de/de/3576621/it-security-nachrichten/new-magecart-attack-turns-stripe-into-a-malware-command-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576621/it-security-nachrichten/new-magecart-attack-turns-stripe-into-a-malware-command-server/</guid>
<pubDate>Fri, 05 Jun 2026 23:38:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new form of credit card skimming malware has been discovered hiding inside one of the most trusted payment platforms on the internet. Researchers have found a Magecart attack that uses Stripe, the widely used online payment service, as both…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-magecart-attack-turns-stripe-into-a-malware-command-server/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-magecart-attack-turns-stripe-into-a-malware-command-server/">New Magecart Attack Turns Stripe into a Malware Command Server</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Magecart Attack Turns Stripe into a Malware Command Server]]></title>
<description><![CDATA[A new form of credit card skimming malware has been discovered hiding inside one of the most trusted payment platforms on the internet. Researchers have found a Magecart attack that uses Stripe, the widely used online payment service, as both its command center and its data dump. Instead of point...]]></description>
<link>https://tsecurity.de/de/3576499/it-security-nachrichten/new-magecart-attack-turns-stripe-into-a-malware-command-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3576499/it-security-nachrichten/new-magecart-attack-turns-stripe-into-a-malware-command-server/</guid>
<pubDate>Fri, 05 Jun 2026 22:22:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new form of credit card skimming malware has been discovered hiding inside one of the most trusted payment platforms on the internet. Researchers have found a Magecart attack that uses Stripe, the widely used online payment service, as both its command center and its data dump. Instead of pointing stolen card data to a […]</p>
<p>The post <a href="https://cybersecuritynews.com/new-magecart-attack-turns-stripe/">New Magecart Attack Turns Stripe into a Malware Command Server</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Magecart Attack Abuses Stripe as Malware C2]]></title>
<description><![CDATA[A novel Magecart campaign that weaponizes legitimate cloud services to evade detection: attackers are storing a JavaScript skimmer inside Stripe customer metadata and delivering it to victim checkouts via Google Tag Manager. The combination makes Stripe both the command server for arbitrary code ...]]></description>
<link>https://tsecurity.de/de/3575444/it-security-nachrichten/new-magecart-attack-abuses-stripe-as-malware-c2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575444/it-security-nachrichten/new-magecart-attack-abuses-stripe-as-malware-c2/</guid>
<pubDate>Fri, 05 Jun 2026 15:08:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A novel Magecart campaign that weaponizes legitimate cloud services to evade detection: attackers are storing a JavaScript skimmer inside Stripe customer metadata and delivering it to victim checkouts via Google Tag Manager. The combination makes Stripe both the command server for arbitrary code and the durable exfiltration sink for stolen card data, using domains (googletagmanager.com […]</p>
<p>The post <a href="https://gbhackers.com/magecart-abuses-stripe-c2/">New Magecart Attack Abuses Stripe as Malware C2</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Magecart Attack Abuses Stripe as Malware C2]]></title>
<description><![CDATA[A novel Magecart campaign that weaponizes legitimate cloud services to evade detection: attackers are storing a JavaScript skimmer inside Stripe customer metadata and delivering it to victim checkouts via Google Tag Manager. The combination makes Stripe both the command server…
Read more →
The po...]]></description>
<link>https://tsecurity.de/de/3575437/it-security-nachrichten/new-magecart-attack-abuses-stripe-as-malware-c2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575437/it-security-nachrichten/new-magecart-attack-abuses-stripe-as-malware-c2/</guid>
<pubDate>Fri, 05 Jun 2026 15:08:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A novel Magecart campaign that weaponizes legitimate cloud services to evade detection: attackers are storing a JavaScript skimmer inside Stripe customer metadata and delivering it to victim checkouts via Google Tag Manager. The combination makes Stripe both the command server…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-magecart-attack-abuses-stripe-as-malware-c2/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-magecart-attack-abuses-stripe-as-malware-c2/">New Magecart Attack Abuses Stripe as Malware C2</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-06-05 15h : 5 posts]]></title>
<description><![CDATA[5 posts were published in the last hour 13:4 : New Magecart Attack Abuses Stripe as Malware C2 13:4 : Chinese APT VerdantBamboo Uses BRICKSTORM Malware to Compromise Firewalls and Appliances 13:4 : Agentic AI Red Teaming Reveals Zero-Click Human-in-the-Loop…
Read more →
The post IT Security News ...]]></description>
<link>https://tsecurity.de/de/3575436/it-security-nachrichten/it-security-news-hourly-summary-2026-06-05-15h-5-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575436/it-security-nachrichten/it-security-news-hourly-summary-2026-06-05-15h-5-posts/</guid>
<pubDate>Fri, 05 Jun 2026 15:08:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>5 posts were published in the last hour 13:4 : New Magecart Attack Abuses Stripe as Malware C2 13:4 : Chinese APT VerdantBamboo Uses BRICKSTORM Malware to Compromise Firewalls and Appliances 13:4 : Agentic AI Red Teaming Reveals Zero-Click Human-in-the-Loop…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-05-15h-5-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-06-05-15h-5-posts/">IT Security News Hourly Summary 2026-06-05 15h : 5 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Hackers Turn Stripe Into Malware Command-and-Control Server]]></title>
<description><![CDATA[Threat actors linked to the Magecart syndicate have developed a novel skimming technique that abuses Stripe and Google Tag Manager (GTM) to steal credit card data. Discovered by Sansec, this campaign hides malicious infrastructure behind trusted domains like Stripe and Google. By using these high...]]></description>
<link>https://tsecurity.de/de/3575034/it-security-nachrichten/magecart-hackers-turn-stripe-into-malware-command-and-control-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3575034/it-security-nachrichten/magecart-hackers-turn-stripe-into-malware-command-and-control-server/</guid>
<pubDate>Fri, 05 Jun 2026 12:22:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Threat actors linked to the Magecart syndicate have developed a novel skimming technique that abuses Stripe and Google Tag Manager (GTM) to steal credit card data. Discovered by Sansec, this campaign hides malicious infrastructure behind trusted domains like Stripe and Google. By using these highly reputable platforms, the skimmer effortlessly bypasses standard Content Security Policy […]</p>
<p>The post <a href="https://cyberpress.org/magecart-abuses-stripe-c2/">Magecart Hackers Turn Stripe Into Malware Command-and-Control Server</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Credit card theft campaign abuses Stripe to host stolen payment info]]></title>
<description><![CDATA[A new Magecart campaign is using Stripe's API infrastructure to host the credit card-stealing payload and the data exfiltrated from checkout pages. [...]]]></description>
<link>https://tsecurity.de/de/3573878/it-security-nachrichten/credit-card-theft-campaign-abuses-stripe-to-host-stolen-payment-info/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3573878/it-security-nachrichten/credit-card-theft-campaign-abuses-stripe-to-host-stolen-payment-info/</guid>
<pubDate>Thu, 04 Jun 2026 22:52:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new Magecart campaign is using Stripe's API infrastructure to host the credit card-stealing payload and the data exfiltrated from checkout pages. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Hackers Abuse Google Tag Manager to Inject Credit Card Skimmers]]></title>
<description><![CDATA[Online shoppers have long been targets of digital theft, but a recent wave of attacks has raised the stakes in a troubling new way. Hackers tied to the notorious Magecart group are now hiding credit card skimmers inside Google Tag…
Read more →
The post Magecart Hackers Abuse Google Tag Manager to...]]></description>
<link>https://tsecurity.de/de/3509688/it-security-nachrichten/magecart-hackers-abuse-google-tag-manager-to-inject-credit-card-skimmers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3509688/it-security-nachrichten/magecart-hackers-abuse-google-tag-manager-to-inject-credit-card-skimmers/</guid>
<pubDate>Tue, 12 May 2026 11:37:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Online shoppers have long been targets of digital theft, but a recent wave of attacks has raised the stakes in a troubling new way. Hackers tied to the notorious Magecart group are now hiding credit card skimmers inside Google Tag…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/magecart-hackers-abuse-google-tag-manager-to-inject-credit-card-skimmers/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/magecart-hackers-abuse-google-tag-manager-to-inject-credit-card-skimmers/">Magecart Hackers Abuse Google Tag Manager to Inject Credit Card Skimmers</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Campaign Uses Google Tag Manager To Steal Credit Card Data]]></title>
<description><![CDATA[In the relentless shadow war of e-commerce security, trust is the ultimate vulnerability. Threat actors are now weaponizing one of the internet’s most ubiquitous and trusted tools: Google Tag Manager (GTM). By exploiting this platform, a notorious Magecart group is silently injecting custom scrip...]]></description>
<link>https://tsecurity.de/de/3509642/it-security-nachrichten/magecart-campaign-uses-google-tag-manager-to-steal-credit-card-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3509642/it-security-nachrichten/magecart-campaign-uses-google-tag-manager-to-steal-credit-card-data/</guid>
<pubDate>Tue, 12 May 2026 11:25:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In the relentless shadow war of e-commerce security, trust is the ultimate vulnerability. Threat actors are now weaponizing one of the internet’s most ubiquitous and trusted tools: Google Tag Manager (GTM). By exploiting this platform, a notorious Magecart group is silently injecting custom scripts into e-commerce sites to siphon customer credit card details. This tactic […]</p>
<p>The post <a href="https://cyberpress.org/magecart-abuses-tag-manager/">Magecart Campaign Uses Google Tag Manager To Steal Credit Card Data</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Hackers Abuse Google Tag Manager to Inject Credit Card Skimmers]]></title>
<description><![CDATA[Online shoppers have long been targets of digital theft, but a recent wave of attacks has raised the stakes in a troubling new way. Hackers tied to the notorious Magecart group are now hiding credit card skimmers inside Google Tag Manager (GTM) containers, turning a widely trusted web tool into a...]]></description>
<link>https://tsecurity.de/de/3509558/it-security-nachrichten/magecart-hackers-abuse-google-tag-manager-to-inject-credit-card-skimmers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3509558/it-security-nachrichten/magecart-hackers-abuse-google-tag-manager-to-inject-credit-card-skimmers/</guid>
<pubDate>Tue, 12 May 2026 10:54:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Online shoppers have long been targets of digital theft, but a recent wave of attacks has raised the stakes in a troubling new way. Hackers tied to the notorious Magecart group are now hiding credit card skimmers inside Google Tag Manager (GTM) containers, turning a widely trusted web tool into a silent weapon against unsuspecting […]</p>
<p>The post <a href="https://cybersecuritynews.com/magecart-hackers-abuse-google-tag-manager/">Magecart Hackers Abuse Google Tag Manager to Inject Credit Card Skimmers</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Hackers Exploit Google Tag Manager to Inject Credit Card Skimmers]]></title>
<description><![CDATA[Magecart-style attackers are once again abusing trusted web services, this time weaponizing Google Tag Manager (GTM) to inject credit card skimmers into ecommerce websites stealthily. Because GTM is widely used and loaded from the trusted domain googletagmanager.com, malicious scripts can…
Read m...]]></description>
<link>https://tsecurity.de/de/3509311/it-security-nachrichten/magecart-hackers-exploit-google-tag-manager-to-inject-credit-card-skimmers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3509311/it-security-nachrichten/magecart-hackers-exploit-google-tag-manager-to-inject-credit-card-skimmers/</guid>
<pubDate>Tue, 12 May 2026 09:10:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Magecart-style attackers are once again abusing trusted web services, this time weaponizing Google Tag Manager (GTM) to inject credit card skimmers into ecommerce websites stealthily. Because GTM is widely used and loaded from the trusted domain googletagmanager.com, malicious scripts can…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/magecart-hackers-exploit-google-tag-manager-to-inject-credit-card-skimmers/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/magecart-hackers-exploit-google-tag-manager-to-inject-credit-card-skimmers/">Magecart Hackers Exploit Google Tag Manager to Inject Credit Card Skimmers</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[IT Security News Hourly Summary 2026-05-12 09h : 8 posts]]></title>
<description><![CDATA[8 posts were published in the last hour 7:5 : Magecart Hackers Exploit Google Tag Manager to Inject Credit Card Skimmers 7:4 : OpenAI Launches ‘Daybreak’: GPT-5.5 Powered To Detect Sotfware Vulnerability 7:4 : State of ransomware in 2026 7:4…
Read more →
The post IT Security News Hourly Summary 2...]]></description>
<link>https://tsecurity.de/de/3509309/it-security-nachrichten/it-security-news-hourly-summary-2026-05-12-09h-8-posts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3509309/it-security-nachrichten/it-security-news-hourly-summary-2026-05-12-09h-8-posts/</guid>
<pubDate>Tue, 12 May 2026 09:10:30 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>8 posts were published in the last hour 7:5 : Magecart Hackers Exploit Google Tag Manager to Inject Credit Card Skimmers 7:4 : OpenAI Launches ‘Daybreak’: GPT-5.5 Powered To Detect Sotfware Vulnerability 7:4 : State of ransomware in 2026 7:4…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-12-09h-8-posts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/it-security-news-hourly-summary-2026-05-12-09h-8-posts/">IT Security News Hourly Summary 2026-05-12 09h : 8 posts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Hackers Exploit Google Tag Manager to Inject Credit Card Skimmers]]></title>
<description><![CDATA[Magecart-style attackers are once again abusing trusted web services, this time weaponizing Google Tag Manager (GTM) to inject credit card skimmers into ecommerce websites stealthily. Because GTM is widely used and loaded from the trusted domain googletagmanager.com, malicious scripts can blend i...]]></description>
<link>https://tsecurity.de/de/3509276/it-security-nachrichten/magecart-hackers-exploit-google-tag-manager-to-inject-credit-card-skimmers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3509276/it-security-nachrichten/magecart-hackers-exploit-google-tag-manager-to-inject-credit-card-skimmers/</guid>
<pubDate>Tue, 12 May 2026 08:53:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Magecart-style attackers are once again abusing trusted web services, this time weaponizing Google Tag Manager (GTM) to inject credit card skimmers into ecommerce websites stealthily. Because GTM is widely used and loaded from the trusted domain googletagmanager.com, malicious scripts can blend in with legitimate site functionality, making detection significantly harder. Once embedded into a compromised […]</p>
<p>The post <a href="https://gbhackers.com/magecart-hackers-exploit-google-tag-manager/">Magecart Hackers Exploit Google Tag Manager to Inject Credit Card Skimmers</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Use SVG Onload Trick to Hide Magecart Skimmer on Magento Checkout Pages]]></title>
<description><![CDATA[A massive Magecart campaign compromising 99 Magento e-commerce stores using an innovative evasion technique. Discovered on April 7, 2026, the attack relies on invisible Scalable Vector Graphics (SVG) elements to inject credit card skimmers directly into checkout pages. This “double-tap” skimmer d...]]></description>
<link>https://tsecurity.de/de/3422732/it-security-nachrichten/hackers-use-svg-onload-trick-to-hide-magecart-skimmer-on-magento-checkout-pages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3422732/it-security-nachrichten/hackers-use-svg-onload-trick-to-hide-magecart-skimmer-on-magento-checkout-pages/</guid>
<pubDate>Fri, 10 Apr 2026 09:07:17 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A massive Magecart campaign compromising 99 Magento e-commerce stores using an innovative evasion technique. Discovered on April 7, 2026, the attack relies on invisible Scalable Vector Graphics (SVG) elements to inject credit card skimmers directly into checkout pages. This “double-tap” skimmer displays a highly convincing fake payment overlay before silently redirecting shoppers to the legitimate […]</p>
<p>The post <a href="https://cybersecuritynews.com/svg-onload-trick-magecart-skimmer/">Hackers Use SVG Onload Trick to Hide Magecart Skimmer on Magento Checkout Pages</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Use SVG onload Trick to Hide Magecart Skimmer on Magento Checkout Pages]]></title>
<description><![CDATA[Security researchers have uncovered a stealthy Magecart campaign abusing SVG image elements to hide credit card skimmers on Magento checkout pages, impacting nearly 100 online stores. According to Sansec, attackers deployed a sophisticated skimmer designed to evade traditional security tools whil...]]></description>
<link>https://tsecurity.de/de/3420725/it-security-nachrichten/hackers-use-svg-onload-trick-to-hide-magecart-skimmer-on-magento-checkout-pages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3420725/it-security-nachrichten/hackers-use-svg-onload-trick-to-hide-magecart-skimmer-on-magento-checkout-pages/</guid>
<pubDate>Thu, 09 Apr 2026 16:08:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security researchers have uncovered a stealthy Magecart campaign abusing SVG image elements to hide credit card skimmers on Magento checkout pages, impacting nearly 100 online stores. According to Sansec, attackers deployed a sophisticated skimmer designed to evade traditional security tools while silently harvesting payment data. The campaign primarily targets Magento-based e-commerce platforms, with evidence suggesting […]</p>
<p>The post <a href="https://cyberpress.org/hackers-use-svg-onload-trick-to-hide-magecart-skimmer-on-magento-checkout-pages/">Hackers Use SVG onload Trick to Hide Magecart Skimmer on Magento Checkout Pages</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers Deploy Hidden Magecart Skimmer on Magento Using SVG onload Abuse]]></title>
<description><![CDATA[Security researchers at Sansec uncovered a large-scale Magecart campaign targeting Magento e-commerce platforms. Nearly 100 online stores were infected with a sophisticated credit card skimmer. To evade security scanners and steal shopper payment data seamlessly, attackers concealed the malicious...]]></description>
<link>https://tsecurity.de/de/3420620/it-security-nachrichten/attackers-deploy-hidden-magecart-skimmer-on-magento-using-svg-onload-abuse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3420620/it-security-nachrichten/attackers-deploy-hidden-magecart-skimmer-on-magento-using-svg-onload-abuse/</guid>
<pubDate>Thu, 09 Apr 2026 15:37:29 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security researchers at Sansec uncovered a large-scale Magecart campaign targeting Magento e-commerce platforms. Nearly 100 online stores were infected with a sophisticated credit card skimmer. To evade security scanners and steal shopper payment data seamlessly, attackers concealed the malicious payload…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/attackers-deploy-hidden-magecart-skimmer-on-magento-using-svg-onload-abuse/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/attackers-deploy-hidden-magecart-skimmer-on-magento-using-svg-onload-abuse/">Attackers Deploy Hidden Magecart Skimmer on Magento Using SVG onload Abuse</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers Deploy Hidden Magecart Skimmer on Magento Using SVG onload Abuse]]></title>
<description><![CDATA[Security researchers at Sansec uncovered a large-scale Magecart campaign targeting Magento e-commerce platforms. Nearly 100 online stores were infected with a sophisticated credit card skimmer. To evade security scanners and steal shopper payment data seamlessly, attackers concealed the malicious...]]></description>
<link>https://tsecurity.de/de/3420575/it-security-nachrichten/attackers-deploy-hidden-magecart-skimmer-on-magento-using-svg-onload-abuse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3420575/it-security-nachrichten/attackers-deploy-hidden-magecart-skimmer-on-magento-using-svg-onload-abuse/</guid>
<pubDate>Thu, 09 Apr 2026 15:23:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security researchers at Sansec uncovered a large-scale Magecart campaign targeting Magento e-commerce platforms. Nearly 100 online stores were infected with a sophisticated credit card skimmer. To evade security scanners and steal shopper payment data seamlessly, attackers concealed the malicious payload inside an invisible SVG image element. Threat intelligence suggests the attackers likely breached the sites […]</p>
<p>The post <a href="https://gbhackers.com/attackers-deploy-hidden-magecart-skimmer-on-magento/">Attackers Deploy Hidden Magecart Skimmer on Magento Using SVG onload Abuse</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Hackers Uses 100+ Domains to Hijack eStores Checkouts and Steal Card Data]]></title>
<description><![CDATA[A sophisticated and long-running Magecart campaign has been quietly operating for over 24 months, infecting e-commerce websites across at least 12 countries using more than 100 malicious domains to steal payment card data in real time and banks, not merchants,…
Read more →
The post Magecart Hacke...]]></description>
<link>https://tsecurity.de/de/3400520/it-security-nachrichten/magecart-hackers-uses-100-domains-to-hijack-estores-checkouts-and-steal-card-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3400520/it-security-nachrichten/magecart-hackers-uses-100-domains-to-hijack-estores-checkouts-and-steal-card-data/</guid>
<pubDate>Wed, 01 Apr 2026 21:20:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated and long-running Magecart campaign has been quietly operating for over 24 months, infecting e-commerce websites across at least 12 countries using more than 100 malicious domains to steal payment card data in real time and banks, not merchants,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/magecart-hackers-uses-100-domains-to-hijack-estores-checkouts-and-steal-card-data/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/magecart-hackers-uses-100-domains-to-hijack-estores-checkouts-and-steal-card-data/">Magecart Hackers Uses 100+ Domains to Hijack eStores Checkouts and Steal Card Data</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Hackers Uses 100+ Domains to Hijack eStores Checkouts and Steal Card Data]]></title>
<description><![CDATA[A sophisticated and long-running Magecart campaign has been quietly operating for over 24 months, infecting e-commerce websites across at least 12 countries using more than 100 malicious domains to steal payment card data in real time and banks, not merchants, are bearing the heaviest financial b...]]></description>
<link>https://tsecurity.de/de/3400229/it-security-nachrichten/magecart-hackers-uses-100-domains-to-hijack-estores-checkouts-and-steal-card-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3400229/it-security-nachrichten/magecart-hackers-uses-100-domains-to-hijack-estores-checkouts-and-steal-card-data/</guid>
<pubDate>Wed, 01 Apr 2026 19:21:52 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated and long-running Magecart campaign has been quietly operating for over 24 months, infecting e-commerce websites across at least 12 countries using more than 100 malicious domains to steal payment card data in real time and banks, not merchants, are bearing the heaviest financial blow. Security researchers at ANY.RUN has uncovered a large-scale Magecart […]</p>
<p>The post <a href="https://cybersecuritynews.com/magecart-hijack-estore-checkouts/">Magecart Hackers Uses 100+ Domains to Hijack eStores Checkouts and Steal Card Data</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Major Cyber Attacks in March 2026: OAuth Phishing, SVG Smuggling, Magecart, and More ]]></title>
<description><![CDATA[March 2026 brought a wave of cyber attacks that reflected how quickly modern threats can move from subtle early signals to serious business impact. ANY.RUN analysts identified and explored several major threats this month, exposing phishing campaigns, stealthy malware, payment-skimming activity, ...]]></description>
<link>https://tsecurity.de/de/3399241/it-security-nachrichten/major-cyber-attacks-in-march-2026-oauth-phishingsvg-smugglingmagecart-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3399241/it-security-nachrichten/major-cyber-attacks-in-march-2026-oauth-phishingsvg-smugglingmagecart-and-more/</guid>
<pubDate>Wed, 01 Apr 2026 14:08:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>March 2026 brought a wave of cyber attacks that reflected how quickly modern threats can move from subtle early signals to serious business impact. ANY.RUN analysts identified and explored several major threats this month, exposing phishing campaigns, stealthy malware, payment-skimming activity, and resilient botnet infrastructure affecting organizations across industries.  From Microsoft 365 token abuse and registry-hidden RAT delivery to card theft, macOS backdoor activity, […]</p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/major-cyber-attacks-march-2026/">Major Cyber Attacks in March 2026: OAuth Phishing, SVG Smuggling, Magecart, and More </a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN's Cybersecurity Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Active Magecart Campaign Targets Spain, Steals Card Data via Hijacked eStores for Bank Fraud]]></title>
<description><![CDATA[2026-03-26 • ANY.RUN
     • khr0x, raptur3
     • js.magecart
    
    
    Open article on Malpedia]]></description>
<link>https://tsecurity.de/de/3392155/malware-trojaner-viren/active-magecart-campaign-targets-spain-steals-card-data-via-hijacked-estores-for-bank-fraud/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3392155/malware-trojaner-viren/active-magecart-campaign-targets-spain-steals-card-data-via-hijacked-estores-for-bank-fraud/</guid>
<pubDate>Mon, 30 Mar 2026 09:31:53 +0200</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<!--  -->
<div>
    2026-03-26 • ANY.RUN
     • khr0x, raptur3
     • js.magecart
    
    <br>
    <a href="https://malpedia.caad.fkie.fraunhofer.de/library/1047d16c-eae0-43d4-a5b8-8687a1b73a61/">Open article on Malpedia</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Global Magecart Campaign Puts Banks Under Pressure, Leveraging Redsys Payment Mimicry and Hijacking ]]></title>
<description><![CDATA[A large-scale magecart operation remained active for over 24 months, leveraging an infrastructure of 100+ domains. While the targeted victims are e-commerce websites, the actual pressure falls on banks and payment systems. As ANY.RUN’s analysis shows, threat actors applied multi-step checkout hij...]]></description>
<link>https://tsecurity.de/de/3382848/it-security-nachrichten/globalmagecartcampaignputs-banks-under-pressureleveragingredsyspayment-mimicryandhijacking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3382848/it-security-nachrichten/globalmagecartcampaignputs-banks-under-pressureleveragingredsyspayment-mimicryandhijacking/</guid>
<pubDate>Thu, 26 Mar 2026 11:36:47 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A large-scale magecart operation remained active for over 24 months, leveraging an infrastructure of 100+ domains. While the targeted victims are e-commerce websites, the actual pressure falls on banks and payment systems. As ANY.RUN’s analysis shows, threat actors applied multi-step checkout hijacking, payment page mimicry, and WebSocket-based exfiltration of card data.  This report provides both executive-level insights and technical analysis of the campaign.  Key Takeaways  Campaign Overview  A […]</p>
<p>The post <a rel="nofollow" href="https://any.run/cybersecurity-blog/banks-magecart-campaign/">Global Magecart Campaign Puts Banks Under Pressure, Leveraging Redsys Payment Mimicry and Hijacking </a> appeared first on <a rel="nofollow" href="https://any.run/cybersecurity-blog">ANY.RUN's Cybersecurity Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Code Security and Magecart: Getting the Threat Model Right]]></title>
<description><![CDATA[When a Magecart payload hides inside the EXIF data of a dynamically loaded third-party favicon, no repository scanner will catch it – because the malicious code never actually touches your repo. As teams adopt Claude Code Security for static analysis,…
Read more →
The post Claude Code Security an...]]></description>
<link>https://tsecurity.de/de/3359282/it-security-nachrichten/claude-code-security-and-magecart-getting-the-threat-model-right/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3359282/it-security-nachrichten/claude-code-security-and-magecart-getting-the-threat-model-right/</guid>
<pubDate>Wed, 18 Mar 2026 14:22:15 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When a Magecart payload hides inside the EXIF data of a dynamically loaded third-party favicon, no repository scanner will catch it – because the malicious code never actually touches your repo. As teams adopt Claude Code Security for static analysis,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/claude-code-security-and-magecart-getting-the-threat-model-right/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/claude-code-security-and-magecart-getting-the-threat-model-right/">Claude Code Security and Magecart: Getting the Threat Model Right</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Code Security and Magecart: Getting the Threat Model Right]]></title>
<description><![CDATA[When a Magecart payload hides inside the EXIF data of a dynamically loaded third-party favicon, no repository scanner will catch it – because the malicious code never actually touches your repo. As teams adopt Claude Code Security for static analysis, this is the exact technical boundary where AI...]]></description>
<link>https://tsecurity.de/de/3359191/it-security-nachrichten/claude-code-security-and-magecart-getting-the-threat-model-right/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3359191/it-security-nachrichten/claude-code-security-and-magecart-getting-the-threat-model-right/</guid>
<pubDate>Wed, 18 Mar 2026 13:51:26 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[When a Magecart payload hides inside the EXIF data of a dynamically loaded third-party favicon, no repository scanner will catch it – because the malicious code never actually touches your repo. As teams adopt Claude Code Security for static analysis, this is the exact technical boundary where AI code scanning stops and client-side runtime execution begins.
A detailed analysis of where Claude]]></content:encoded>
</item>
<item>
<title><![CDATA[Claude Code Security und die Herausforderungen von Magecart-Angriffen]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Die Bedrohung durch Magecart-Angriffe zeigt die Grenzen traditioneller Code-Sicherheitslösungen auf. Diese Angriffe nutzen Schwachstellen in der Lieferkette aus, indem sie schädlichen Code in Drittanbieter-Ressourcen verstecken, die zur Laufzeit im Browser ausgeführt werden...]]></description>
<link>https://tsecurity.de/de/3359133/it-security-nachrichten/claude-code-security-und-die-herausforderungen-von-magecart-angriffen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3359133/it-security-nachrichten/claude-code-security-und-die-herausforderungen-von-magecart-angriffen/</guid>
<pubDate>Wed, 18 Mar 2026 13:37:59 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-magecart-code-security.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-magecart-code-security.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-magecart-code-security-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-magecart-code-security-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-magecart-code-security-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-magecart-code-security-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/03/ai-magecart-code-security-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Die Bedrohung durch Magecart-Angriffe zeigt die Grenzen traditioneller Code-Sicherheitslösungen auf. Diese Angriffe nutzen Schwachstellen in der Lieferkette aus, indem sie schädlichen Code in Drittanbieter-Ressourcen verstecken, die zur Laufzeit im Browser ausgeführt werden. Claude Code Security bietet zwar Schutz für den eigenen Code, kann jedoch solche Angriffe nicht erkennen, da sie außerhalb […]</p>
<div><a href="https://www.it-boltwise.de/claude-code-security-und-die-herausforderungen-von-magecart-angriffen.html">... den vollständigen Artikel <strong>»Claude Code Security und die Herausforderungen von Magecart-Angriffen«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/claude-code-security-und-die-herausforderungen-von-magecart-angriffen.html">Claude Code Security und die Herausforderungen von Magecart-Angriffen</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE® x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BA Hit by Global Web Skimming Group: Experts]]></title>
<description><![CDATA[RiskIQ claims notorious Magecart group to blame]]></description>
<link>https://tsecurity.de/de/3264466/it-security-nachrichten/ba-hit-by-global-web-skimming-group-experts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264466/it-security-nachrichten/ba-hit-by-global-web-skimming-group-experts/</guid>
<pubDate>Fri, 06 Feb 2026 13:41:44 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[RiskIQ claims notorious Magecart group to blame]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Back Again as Feedify is Hit]]></title>
<description><![CDATA[Malicious script injected into supplier’s JavaScript library]]></description>
<link>https://tsecurity.de/de/3264446/it-security-nachrichten/magecart-back-again-as-feedify-is-hit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264446/it-security-nachrichten/magecart-back-again-as-feedify-is-hit/</guid>
<pubDate>Fri, 06 Feb 2026 13:41:34 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Malicious script injected into supplier’s JavaScript library]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Skimmed Newegg Cards for a Month]]></title>
<description><![CDATA[Discovery of infamous code points to another breach at a major e-tailer]]></description>
<link>https://tsecurity.de/de/3264419/it-security-nachrichten/magecart-skimmed-newegg-cards-for-a-month/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264419/it-security-nachrichten/magecart-skimmed-newegg-cards-for-a-month/</guid>
<pubDate>Fri, 06 Feb 2026 13:41:23 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Discovery of infamous code points to another breach at a major e-tailer]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Hits Popular Customer Review Plugin]]></title>
<description><![CDATA[Supply chain attack stopped early after quick work from Shopper Approved]]></description>
<link>https://tsecurity.de/de/3264332/it-security-nachrichten/magecart-hits-popular-customer-review-plugin/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264332/it-security-nachrichten/magecart-hits-popular-customer-review-plugin/</guid>
<pubDate>Fri, 06 Feb 2026 13:40:44 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Supply chain attack stopped early after quick work from Shopper Approved]]></content:encoded>
</item>
<item>
<title><![CDATA[No Cookies for CartThief, a New Magecart Variant]]></title>
<description><![CDATA[New iteration of Magecart malware obfuscates data collection, says The Media Trust.]]></description>
<link>https://tsecurity.de/de/3264318/it-security-nachrichten/no-cookies-for-cartthief-a-new-magecart-variant/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264318/it-security-nachrichten/no-cookies-for-cartthief-a-new-magecart-variant/</guid>
<pubDate>Fri, 06 Feb 2026 13:40:38 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[New iteration of Magecart malware obfuscates data collection, says The Media Trust.]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Attackers Exploit Magento Zero-Days]]></title>
<description><![CDATA[Popular web form extension software targeted by digital skimmers]]></description>
<link>https://tsecurity.de/de/3264271/it-security-nachrichten/magecart-attackers-exploit-magento-zero-days/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264271/it-security-nachrichten/magecart-attackers-exploit-magento-zero-days/</guid>
<pubDate>Fri, 06 Feb 2026 13:40:16 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Popular web form extension software targeted by digital skimmers]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Strikes Again, and Kitronik Is Latest Victim]]></title>
<description><![CDATA[Payment-card-swiping malware continues to attack.]]></description>
<link>https://tsecurity.de/de/3264218/it-security-nachrichten/magecart-strikes-again-and-kitronik-is-latest-victim/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264218/it-security-nachrichten/magecart-strikes-again-and-kitronik-is-latest-victim/</guid>
<pubDate>Fri, 06 Feb 2026 13:39:53 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Payment-card-swiping malware continues to attack.]]></content:encoded>
</item>
<item>
<title><![CDATA[Skimmed BA and Newegg Customer Card Details Up for Sale]]></title>
<description><![CDATA[Dark web trawl reveals Magecart criminals are monetizing stolen data]]></description>
<link>https://tsecurity.de/de/3264174/it-security-nachrichten/skimmed-ba-and-newegg-customer-card-details-up-for-sale/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264174/it-security-nachrichten/skimmed-ba-and-newegg-customer-card-details-up-for-sale/</guid>
<pubDate>Fri, 06 Feb 2026 13:39:33 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dark web trawl reveals Magecart criminals are monetizing stolen data]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Black Hats Battle it Out On Infected Site]]></title>
<description><![CDATA[One group attempts to sabotage skimming operation of the other]]></description>
<link>https://tsecurity.de/de/3264149/it-security-nachrichten/magecart-black-hats-battle-it-out-on-infected-site/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264149/it-security-nachrichten/magecart-black-hats-battle-it-out-on-infected-site/</guid>
<pubDate>Fri, 06 Feb 2026 13:39:23 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[One group attempts to sabotage skimming operation of the other]]></content:encoded>
</item>
<item>
<title><![CDATA[Sotheby’s Site Infected with Magecart for Over a Year]]></title>
<description><![CDATA[US site formerly known as Viyet was affected]]></description>
<link>https://tsecurity.de/de/3264100/it-security-nachrichten/sothebys-site-infected-with-magecart-for-over-a-year/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264100/it-security-nachrichten/sothebys-site-infected-with-magecart-for-over-a-year/</guid>
<pubDate>Fri, 06 Feb 2026 13:39:00 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[US site formerly known as Viyet was affected]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Delivers Malware to 1-800-FLOWERS]]></title>
<description><![CDATA[1-800-Flowers' Canadian website is the latest victim in card-skimming malware attacks.]]></description>
<link>https://tsecurity.de/de/3264082/it-security-nachrichten/magecart-delivers-malware-to-1-800-flowers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3264082/it-security-nachrichten/magecart-delivers-malware-to-1-800-flowers/</guid>
<pubDate>Fri, 06 Feb 2026 13:38:52 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[1-800-Flowers' Canadian website is the latest victim in card-skimming malware attacks.]]></content:encoded>
</item>
<item>
<title><![CDATA[New Magecart Group Hits Hundreds of Sites Via Supply Chain]]></title>
<description><![CDATA[Attack targets French ad agency]]></description>
<link>https://tsecurity.de/de/3263933/it-security-nachrichten/new-magecart-group-hits-hundreds-of-sites-via-supply-chain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3263933/it-security-nachrichten/new-magecart-group-hits-hundreds-of-sites-via-supply-chain/</guid>
<pubDate>Fri, 06 Feb 2026 13:37:46 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Attack targets French ad agency]]></content:encoded>
</item>
<item>
<title><![CDATA[Kathmandu Probes Possible Card Skimming Breach]]></title>
<description><![CDATA[Kiwi clothing store may have been a Magecart victim]]></description>
<link>https://tsecurity.de/de/3263636/it-security-nachrichten/kathmandu-probes-possible-card-skimming-breach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3263636/it-security-nachrichten/kathmandu-probes-possible-card-skimming-breach/</guid>
<pubDate>Fri, 06 Feb 2026 13:35:17 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kiwi clothing store may have been a Magecart victim]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Swoops in to Strike Atlanta Hawks Shop]]></title>
<description><![CDATA[Card-skimming malware targets NBA team's online store.]]></description>
<link>https://tsecurity.de/de/3263471/it-security-nachrichten/magecart-swoops-in-to-strike-atlanta-hawks-shop/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3263471/it-security-nachrichten/magecart-swoops-in-to-strike-atlanta-hawks-shop/</guid>
<pubDate>Fri, 06 Feb 2026 13:33:27 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Card-skimming malware targets NBA team's online store.]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Skimming Code Found on GitHub]]></title>
<description><![CDATA[Malwarebytes warns code was injected into 200 e-commerce sites]]></description>
<link>https://tsecurity.de/de/3263455/it-security-nachrichten/magecart-skimming-code-found-on-github/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3263455/it-security-nachrichten/magecart-skimming-code-found-on-github/</guid>
<pubDate>Fri, 06 Feb 2026 13:33:17 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Malwarebytes warns code was injected into 200 e-commerce sites]]></content:encoded>
</item>
<item>
<title><![CDATA[New Magecart Group Targets 201 Campus E-Stores]]></title>
<description><![CDATA[Mirrorthief gang targeted PrismWeb e-commerce platform]]></description>
<link>https://tsecurity.de/de/3263421/it-security-nachrichten/new-magecart-group-targets-201-campus-e-stores/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3263421/it-security-nachrichten/new-magecart-group-targets-201-campus-e-stores/</guid>
<pubDate>Fri, 06 Feb 2026 13:32:54 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mirrorthief gang targeted PrismWeb e-commerce platform]]></content:encoded>
</item>
<item>
<title><![CDATA[Forbes Site Up, Then Down Again after Magecart Attack]]></title>
<description><![CDATA[Forbes.com was hit with credit card skimming malware.]]></description>
<link>https://tsecurity.de/de/3263379/it-security-nachrichten/forbes-site-up-then-down-again-after-magecart-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3263379/it-security-nachrichten/forbes-site-up-then-down-again-after-magecart-attack/</guid>
<pubDate>Fri, 06 Feb 2026 13:32:26 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Forbes.com was hit with credit card skimming malware.]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Campaign Offers Customizable Payload]]></title>
<description><![CDATA[Magecart has new offering of highly customizable payload along with JavaScript loaders.]]></description>
<link>https://tsecurity.de/de/3263149/it-security-nachrichten/magecart-campaign-offers-customizable-payload/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3263149/it-security-nachrichten/magecart-campaign-offers-customizable-payload/</guid>
<pubDate>Fri, 06 Feb 2026 13:30:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Magecart has new offering of highly customizable payload along with JavaScript loaders.]]></content:encoded>
</item>
<item>
<title><![CDATA[BA’s Magecart Breach Lands it £183m GDPR Fine]]></title>
<description><![CDATA[Airline appeals after ICO takes action]]></description>
<link>https://tsecurity.de/de/3263136/it-security-nachrichten/bas-magecart-breach-lands-it-183m-gdpr-fine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3263136/it-security-nachrichten/bas-magecart-breach-lands-it-183m-gdpr-fine/</guid>
<pubDate>Fri, 06 Feb 2026 13:29:53 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Airline appeals after ICO takes action]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Blitz Stuns 962 E-commerce Sites in 24 Hours]]></title>
<description><![CDATA[New automated campaign is claimed to be largest to date]]></description>
<link>https://tsecurity.de/de/3263133/it-security-nachrichten/magecart-blitz-stuns-962-e-commerce-sites-in-24-hours/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3263133/it-security-nachrichten/magecart-blitz-stuns-962-e-commerce-sites-in-24-hours/</guid>
<pubDate>Fri, 06 Feb 2026 13:29:51 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[New automated campaign is claimed to be largest to date]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Hackers Scan for Misconfigured S3 Buckets]]></title>
<description><![CDATA[Automated campaign spells trouble for thousands of websites]]></description>
<link>https://tsecurity.de/de/3263114/it-security-nachrichten/magecart-hackers-scan-for-misconfigured-s3-buckets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3263114/it-security-nachrichten/magecart-hackers-scan-for-misconfigured-s3-buckets/</guid>
<pubDate>Fri, 06 Feb 2026 13:29:38 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Automated campaign spells trouble for thousands of websites]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Group Spotted Operating From War Zone]]></title>
<description><![CDATA[Luhansk-based server supports attacks on hundreds of e-com sites]]></description>
<link>https://tsecurity.de/de/3263078/it-security-nachrichten/magecart-group-spotted-operating-from-war-zone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3263078/it-security-nachrichten/magecart-group-spotted-operating-from-war-zone/</guid>
<pubDate>Fri, 06 Feb 2026 13:29:14 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Luhansk-based server supports attacks on hundreds of e-com sites]]></content:encoded>
</item>
<item>
<title><![CDATA[PCI Council & Retail ISAC Issue Magecart Warning]]></title>
<description><![CDATA[PCI SSC and RH-ISAC issue joint alert on Magecart attacks]]></description>
<link>https://tsecurity.de/de/3263018/it-security-nachrichten/pci-council-retail-isac-issue-magecart-warning/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3263018/it-security-nachrichten/pci-council-retail-isac-issue-magecart-warning/</guid>
<pubDate>Fri, 06 Feb 2026 13:28:34 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[PCI SSC and RH-ISAC issue joint alert on Magecart attacks]]></content:encoded>
</item>
<item>
<title><![CDATA[Vendor Blocks 65,000 Magecart Data Theft Attempts in July]]></title>
<description><![CDATA[Malwarebytes warns of summer threat for e-commerce stores]]></description>
<link>https://tsecurity.de/de/3263015/it-security-nachrichten/vendor-blocks-65000-magecart-data-theft-attempts-in-july/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3263015/it-security-nachrichten/vendor-blocks-65000-magecart-data-theft-attempts-in-july/</guid>
<pubDate>Fri, 06 Feb 2026 13:28:32 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Malwarebytes warns of summer threat for e-commerce stores]]></content:encoded>
</item>
<item>
<title><![CDATA[Formjacking Now Accounts For Most Web Breaches]]></title>
<description><![CDATA[Magecart and similar attacks siphon payment details direct from websites]]></description>
<link>https://tsecurity.de/de/3262941/it-security-nachrichten/formjacking-now-accounts-for-most-web-breaches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3262941/it-security-nachrichten/formjacking-now-accounts-for-most-web-breaches/</guid>
<pubDate>Fri, 06 Feb 2026 13:27:43 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Magecart and similar attacks siphon payment details direct from websites]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Group Goes After Commercial Router Users]]></title>
<description><![CDATA[Digital skimming takes a new turn in the quest for more victims]]></description>
<link>https://tsecurity.de/de/3262745/it-security-nachrichten/magecart-group-goes-after-commercial-router-users/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3262745/it-security-nachrichten/magecart-group-goes-after-commercial-router-users/</guid>
<pubDate>Fri, 06 Feb 2026 13:25:34 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Digital skimming takes a new turn in the quest for more victims]]></content:encoded>
</item>
<item>
<title><![CDATA[#VB2019: Magecart Attack Groups Move to More Targeted Efforts]]></title>
<description><![CDATA[How Magecart attack groups have succeeded, and are moving forwards in attack tactics]]></description>
<link>https://tsecurity.de/de/3262716/it-security-nachrichten/vb2019-magecart-attack-groups-move-to-more-targeted-efforts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3262716/it-security-nachrichten/vb2019-magecart-attack-groups-move-to-more-targeted-efforts/</guid>
<pubDate>Fri, 06 Feb 2026 13:25:14 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[How Magecart attack groups have succeeded, and are moving forwards in attack tactics]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Group Linked to Dridex and Carbanak Malware]]></title>
<description><![CDATA[Malwarebytes digs into WHOIS data to uncover new intel]]></description>
<link>https://tsecurity.de/de/3262614/it-security-nachrichten/magecart-group-linked-to-dridex-and-carbanak-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3262614/it-security-nachrichten/magecart-group-linked-to-dridex-and-carbanak-malware/</guid>
<pubDate>Fri, 06 Feb 2026 13:24:06 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Malwarebytes digs into WHOIS data to uncover new intel]]></content:encoded>
</item>
<item>
<title><![CDATA[Fashion Site Sixth June Leaking Card Data to Magecart Hackers]]></title>
<description><![CDATA[Researcher claims firm has failed to respond to his outreach]]></description>
<link>https://tsecurity.de/de/3262589/it-security-nachrichten/fashion-site-sixth-june-leaking-card-data-to-magecart-hackers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3262589/it-security-nachrichten/fashion-site-sixth-june-leaking-card-data-to-magecart-hackers/</guid>
<pubDate>Fri, 06 Feb 2026 13:23:49 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researcher claims firm has failed to respond to his outreach]]></content:encoded>
</item>
<item>
<title><![CDATA[Magento 1 End-of-Life Offers Opportunities for Hackers]]></title>
<description><![CDATA[Magecart attackers could benefit from a 2020 windfall]]></description>
<link>https://tsecurity.de/de/3262537/it-security-nachrichten/magento-1-end-of-life-offers-opportunities-for-hackers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3262537/it-security-nachrichten/magento-1-end-of-life-offers-opportunities-for-hackers/</guid>
<pubDate>Fri, 06 Feb 2026 13:23:13 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Magecart attackers could benefit from a 2020 windfall]]></content:encoded>
</item>
<item>
<title><![CDATA[Macy’s Online Customers Hit by Magecart Breach]]></title>
<description><![CDATA[Hackers stole personal and payment details in October]]></description>
<link>https://tsecurity.de/de/3262486/it-security-nachrichten/macys-online-customers-hit-by-magecart-breach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3262486/it-security-nachrichten/macys-online-customers-hit-by-magecart-breach/</guid>
<pubDate>Fri, 06 Feb 2026 13:22:39 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Hackers stole personal and payment details in October]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Hackers Open Fire at Smith & Wesson Customers]]></title>
<description><![CDATA[Digital skimmers try to disguise scheme using security vendor as cover]]></description>
<link>https://tsecurity.de/de/3262412/it-security-nachrichten/magecart-hackers-open-fire-at-smith-wesson-customers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3262412/it-security-nachrichten/magecart-hackers-open-fire-at-smith-wesson-customers/</guid>
<pubDate>Fri, 06 Feb 2026 13:21:52 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Digital skimmers try to disguise scheme using security vendor as cover]]></content:encoded>
</item>
<item>
<title><![CDATA[UK Fashion Store Sweaty Betty Suffers Magecart Heist]]></title>
<description><![CDATA[Digital skimmers stole customer card data for over a week]]></description>
<link>https://tsecurity.de/de/3262398/it-security-nachrichten/uk-fashion-store-sweaty-betty-suffers-magecart-heist/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3262398/it-security-nachrichten/uk-fashion-store-sweaty-betty-suffers-magecart-heist/</guid>
<pubDate>Fri, 06 Feb 2026 13:21:43 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Digital skimmers stole customer card data for over a week]]></content:encoded>
</item>
<item>
<title><![CDATA[Aussie Bushfires Donation Site Hit by Magecart Thieves]]></title>
<description><![CDATA[Data thieves hit new low in bid to harvest payment details]]></description>
<link>https://tsecurity.de/de/3262263/it-security-nachrichten/aussie-bushfires-donation-site-hit-by-magecart-thieves/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3262263/it-security-nachrichten/aussie-bushfires-donation-site-hit-by-magecart-thieves/</guid>
<pubDate>Fri, 06 Feb 2026 13:20:12 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Data thieves hit new low in bid to harvest payment details]]></content:encoded>
</item>
<item>
<title><![CDATA[Suspected Magecart Hackers Arrested in Indonesia]]></title>
<description><![CDATA[Three men thought to have used stolen cards to buy luxury goods]]></description>
<link>https://tsecurity.de/de/3262185/it-security-nachrichten/suspected-magecart-hackers-arrested-in-indonesia/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3262185/it-security-nachrichten/suspected-magecart-hackers-arrested-in-indonesia/</guid>
<pubDate>Fri, 06 Feb 2026 13:19:23 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Three men thought to have used stolen cards to buy luxury goods]]></content:encoded>
</item>
<item>
<title><![CDATA[Web Owners Ignore Alerts as Magecart Hits 40 More Sites]]></title>
<description><![CDATA[Notorious group continues to wreak havoc]]></description>
<link>https://tsecurity.de/de/3262014/it-security-nachrichten/web-owners-ignore-alerts-as-magecart-hits-40-more-sites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3262014/it-security-nachrichten/web-owners-ignore-alerts-as-magecart-hits-40-more-sites/</guid>
<pubDate>Fri, 06 Feb 2026 13:17:29 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Notorious group continues to wreak havoc]]></content:encoded>
</item>
<item>
<title><![CDATA[Volusion Magecart Breach Could Net Fraudsters $130m+]]></title>
<description><![CDATA[Gemini Advisory claims as many as 20 million card records may have been compromised]]></description>
<link>https://tsecurity.de/de/3261919/it-security-nachrichten/volusion-magecart-breach-could-net-fraudsters-130m/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3261919/it-security-nachrichten/volusion-magecart-breach-could-net-fraudsters-130m/</guid>
<pubDate>Fri, 06 Feb 2026 13:16:34 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gemini Advisory claims as many as 20 million card records may have been compromised]]></content:encoded>
</item>
<item>
<title><![CDATA[NutriBullet Experiences Multiple Magecart Skimmer Infections]]></title>
<description><![CDATA[Magecart hits manufacturer NutriBullet with skimming attack]]></description>
<link>https://tsecurity.de/de/3261898/it-security-nachrichten/nutribullet-experiences-multiple-magecart-skimmer-infections/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3261898/it-security-nachrichten/nutribullet-experiences-multiple-magecart-skimmer-infections/</guid>
<pubDate>Fri, 06 Feb 2026 13:16:19 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Magecart hits manufacturer NutriBullet with skimming attack]]></content:encoded>
</item>
<item>
<title><![CDATA[Tupperware Site Hacked by Digital Skimming Gang]]></title>
<description><![CDATA[Homeware giant gets the Magecart treatment]]></description>
<link>https://tsecurity.de/de/3261859/it-security-nachrichten/tupperware-site-hacked-by-digital-skimming-gang/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3261859/it-security-nachrichten/tupperware-site-hacked-by-digital-skimming-gang/</guid>
<pubDate>Fri, 06 Feb 2026 13:15:53 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Homeware giant gets the Magecart treatment]]></content:encoded>
</item>
<item>
<title><![CDATA[More S3 Buckets Compromised with Magecart and Malicious Redirector]]></title>
<description><![CDATA[Malicious code spread via misconfigured AWS infrastructure]]></description>
<link>https://tsecurity.de/de/3261472/it-security-nachrichten/more-s3-buckets-compromised-with-magecart-and-malicious-redirector/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3261472/it-security-nachrichten/more-s3-buckets-compromised-with-magecart-and-malicious-redirector/</guid>
<pubDate>Fri, 06 Feb 2026 13:11:34 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Malicious code spread via misconfigured AWS infrastructure]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Attackers Target Retail Brands Under Lockdown]]></title>
<description><![CDATA[As stores go online only, data thieves line up]]></description>
<link>https://tsecurity.de/de/3261429/it-security-nachrichten/magecart-attackers-target-retail-brands-under-lockdown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3261429/it-security-nachrichten/magecart-attackers-target-retail-brands-under-lockdown/</guid>
<pubDate>Fri, 06 Feb 2026 13:11:05 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[As stores go online only, data thieves line up]]></content:encoded>
</item>
<item>
<title><![CDATA[North Korean Hackers Behind Magecart Attacks]]></title>
<description><![CDATA[Sansec claims Pyongyang-sponsored attackers struck Claire’s]]></description>
<link>https://tsecurity.de/de/3261312/it-security-nachrichten/north-korean-hackers-behind-magecart-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3261312/it-security-nachrichten/north-korean-hackers-behind-magecart-attacks/</guid>
<pubDate>Fri, 06 Feb 2026 13:09:46 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sansec claims Pyongyang-sponsored attackers struck Claire’s]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Group Made Millions Targeting 570+ Sites]]></title>
<description><![CDATA[Gemini Advisory warns Keeper group is still at large]]></description>
<link>https://tsecurity.de/de/3261293/it-security-nachrichten/magecart-group-made-millions-targeting-570-sites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3261293/it-security-nachrichten/magecart-group-made-millions-targeting-570-sites/</guid>
<pubDate>Fri, 06 Feb 2026 13:09:33 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gemini Advisory warns Keeper group is still at large]]></content:encoded>
</item>
<item>
<title><![CDATA[UltraRank Digital Skimming Group Hit Hundreds of Sites]]></title>
<description><![CDATA[Five-year history of Magecart-like gang uncovered by Group-IB]]></description>
<link>https://tsecurity.de/de/3260966/it-security-nachrichten/ultrarank-digital-skimming-group-hit-hundreds-of-sites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3260966/it-security-nachrichten/ultrarank-digital-skimming-group-hit-hundreds-of-sites/</guid>
<pubDate>Fri, 06 Feb 2026 13:06:07 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Five-year history of Magecart-like gang uncovered by Group-IB]]></content:encoded>
</item>
<item>
<title><![CDATA[Credit Card Skimmer Hits Over 1500 Websites]]></title>
<description><![CDATA[Magecart-linked Inter skimmer hits over 1500 websites]]></description>
<link>https://tsecurity.de/de/3260908/it-security-nachrichten/credit-card-skimmer-hits-over-1500-websites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3260908/it-security-nachrichten/credit-card-skimmer-hits-over-1500-websites/</guid>
<pubDate>Fri, 06 Feb 2026 13:05:35 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Magecart-linked Inter skimmer hits over 1500 websites]]></content:encoded>
</item>
<item>
<title><![CDATA[Largest Ever Magecart Campaign Hits 2000 E-Stores]]></title>
<description><![CDATA[Sansec warns that tens of thousands of customers may have been affected]]></description>
<link>https://tsecurity.de/de/3260850/it-security-nachrichten/largest-ever-magecart-campaign-hits-2000-e-stores/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3260850/it-security-nachrichten/largest-ever-magecart-campaign-hits-2000-e-stores/</guid>
<pubDate>Fri, 06 Feb 2026 13:04:56 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Sansec warns that tens of thousands of customers may have been affected]]></content:encoded>
</item>
<item>
<title><![CDATA[Gold Bullion Seller Hit by Magecart Attack]]></title>
<description><![CDATA[JM Bullion waited several months to inform customers]]></description>
<link>https://tsecurity.de/de/3260533/it-security-nachrichten/gold-bullion-seller-hit-by-magecart-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3260533/it-security-nachrichten/gold-bullion-seller-hit-by-magecart-attack/</guid>
<pubDate>Fri, 06 Feb 2026 13:01:30 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[JM Bullion waited several months to inform customers]]></content:encoded>
</item>
<item>
<title><![CDATA[Over 4000 UK Retailers Compromised by Magecart Attacks]]></title>
<description><![CDATA[NCSC notifies SMBs after proactive scanning program]]></description>
<link>https://tsecurity.de/de/3258817/it-security-nachrichten/over-4000-uk-retailers-compromised-by-magecart-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3258817/it-security-nachrichten/over-4000-uk-retailers-compromised-by-magecart-attacks/</guid>
<pubDate>Fri, 06 Feb 2026 12:42:48 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[NCSC notifies SMBs after proactive scanning program]]></content:encoded>
</item>
<item>
<title><![CDATA[Digital Skimming is Now the Preserve of Non-Magecart Groups]]></title>
<description><![CDATA[Commodity kit invites new entrants into the market]]></description>
<link>https://tsecurity.de/de/3258014/it-security-nachrichten/digital-skimming-is-now-the-preserve-of-non-magecart-groups/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3258014/it-security-nachrichten/digital-skimming-is-now-the-preserve-of-non-magecart-groups/</guid>
<pubDate>Fri, 06 Feb 2026 12:33:22 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Commodity kit invites new entrants into the market]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Hackers Hide in 404 Error Pages]]></title>
<description><![CDATA[Akamai spots new digital skimming campaign]]></description>
<link>https://tsecurity.de/de/3257053/it-security-nachrichten/magecart-hackers-hide-in-404-error-pages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3257053/it-security-nachrichten/magecart-hackers-hide-in-404-error-pages/</guid>
<pubDate>Fri, 06 Feb 2026 11:38:41 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Akamai spots new digital skimming campaign]]></content:encoded>
</item>
<item>
<title><![CDATA[eSkimming Attacks Fuelled with Persistent Threats, Evolving Tactics, and Unfinished Recovery]]></title>
<description><![CDATA[eSkimming attacks, commonly known as Magecart attacks, continue to plague e-commerce websites across the globe, stealing payment card data from unsuspecting customers at checkout. These malicious campaigns inject JavaScript code into compromised websites, capturing sensitive financial information...]]></description>
<link>https://tsecurity.de/de/3242056/it-security-nachrichten/eskimming-attacks-fuelled-with-persistent-threats-evolving-tactics-and-unfinished-recovery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3242056/it-security-nachrichten/eskimming-attacks-fuelled-with-persistent-threats-evolving-tactics-and-unfinished-recovery/</guid>
<pubDate>Thu, 29 Jan 2026 15:50:05 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>eSkimming attacks, commonly known as Magecart attacks, continue to plague e-commerce websites across the globe, stealing payment card data from unsuspecting customers at checkout. These malicious campaigns inject JavaScript code into compromised websites, capturing sensitive financial information as users complete…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/eskimming-attacks-fuelled-with-persistent-threats-evolving-tactics-and-unfinished-recovery/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/eskimming-attacks-fuelled-with-persistent-threats-evolving-tactics-and-unfinished-recovery/">eSkimming Attacks Fuelled with Persistent Threats, Evolving Tactics, and Unfinished Recovery</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[eSkimming Attacks Fuelled with Persistent Threats, Evolving Tactics, and Unfinished Recovery]]></title>
<description><![CDATA[eSkimming attacks, commonly known as Magecart attacks, continue to plague e-commerce websites across the globe, stealing payment card data from unsuspecting customers at checkout. These malicious campaigns inject JavaScript code into compromised websites, capturing sensitive financial information...]]></description>
<link>https://tsecurity.de/de/3242033/it-security-nachrichten/eskimming-attacks-fuelled-with-persistent-threats-evolving-tactics-and-unfinished-recovery/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3242033/it-security-nachrichten/eskimming-attacks-fuelled-with-persistent-threats-evolving-tactics-and-unfinished-recovery/</guid>
<pubDate>Thu, 29 Jan 2026 15:35:44 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>eSkimming attacks, commonly known as Magecart attacks, continue to plague e-commerce websites across the globe, stealing payment card data from unsuspecting customers at checkout. These malicious campaigns inject JavaScript code into compromised websites, capturing sensitive financial information as users complete their purchases. Unlike traditional malware that requires system access, eSkimming operates entirely within the browser […]</p>
<p>The post <a href="https://cybersecuritynews.com/eskimming-attacks-fuelled-with-persistent-threats/">eSkimming Attacks Fuelled with Persistent Threats, Evolving Tactics, and Unfinished Recovery</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[eSkimming Attacks Surge with Evolving Tactics and Ongoing Recovery Challenges]]></title>
<description><![CDATA[A new longitudinal study of Magecart-style eSkimming attacks overturns the assumption that discovery equals recovery. Instead of being a one-time incident that ends with script removal, eSkimming is emerging as a long-lived, shape‑shifting threat that lingers on previously compromised sites…
Read...]]></description>
<link>https://tsecurity.de/de/3239780/it-security-nachrichten/eskimming-attacks-surge-with-evolving-tactics-and-ongoing-recovery-challenges/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3239780/it-security-nachrichten/eskimming-attacks-surge-with-evolving-tactics-and-ongoing-recovery-challenges/</guid>
<pubDate>Wed, 28 Jan 2026 16:23:12 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new longitudinal study of Magecart-style eSkimming attacks overturns the assumption that discovery equals recovery. Instead of being a one-time incident that ends with script removal, eSkimming is emerging as a long-lived, shape‑shifting threat that lingers on previously compromised sites…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/eskimming-attacks-surge-with-evolving-tactics-and-ongoing-recovery-challenges/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/eskimming-attacks-surge-with-evolving-tactics-and-ongoing-recovery-challenges/">eSkimming Attacks Surge with Evolving Tactics and Ongoing Recovery Challenges</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Magecart Attack Inject Malicious JavaScript to Skim Payment Data]]></title>
<description><![CDATA[A new Magecart-style campaign has emerged, targeting online shoppers through malicious JavaScript code designed to steal payment information directly from ecommerce websites. The attack works by injecting hidden scripts into compromised shopping sites, allowing attackers to intercept sensitive da...]]></description>
<link>https://tsecurity.de/de/3226394/it-security-nachrichten/new-magecart-attack-inject-malicious-javascript-to-skim-payment-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3226394/it-security-nachrichten/new-magecart-attack-inject-malicious-javascript-to-skim-payment-data/</guid>
<pubDate>Wed, 21 Jan 2026 17:35:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new Magecart-style campaign has emerged, targeting online shoppers through malicious JavaScript code designed to steal payment information directly from ecommerce websites. The attack works by injecting hidden scripts into compromised shopping sites, allowing attackers to intercept sensitive data when customers enter their credit card details during checkout. Magecart attacks represent a significant threat to […]</p>
<p>The post <a href="https://cybersecuritynews.com/new-magecart-attack-inject-malicious-javascript/">New Magecart Attack Inject Malicious JavaScript to Skim Payment Data</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Online shoppers at risk as Magecart skimming hits major payment networks]]></title>
<description><![CDATA[A Magecart campaign is skimming card data from online checkouts tied to major payment networks, including AmEx, Diners Club, and Mastercard. This article has been indexed from Malwarebytes Read the original article: Online shoppers at risk as Magecart skimming hits…
Read more →
The post Online sh...]]></description>
<link>https://tsecurity.de/de/3212627/it-security-nachrichten/online-shoppers-at-risk-as-magecart-skimming-hits-major-payment-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3212627/it-security-nachrichten/online-shoppers-at-risk-as-magecart-skimming-hits-major-payment-networks/</guid>
<pubDate>Wed, 14 Jan 2026 14:05:16 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A Magecart campaign is skimming card data from online checkouts tied to major payment networks, including AmEx, Diners Club, and Mastercard. This article has been indexed from Malwarebytes Read the original article: Online shoppers at risk as Magecart skimming hits…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/online-shoppers-at-risk-as-magecart-skimming-hits-major-payment-networks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/online-shoppers-at-risk-as-magecart-skimming-hits-major-payment-networks/">Online shoppers at risk as Magecart skimming hits major payment networks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages]]></title>
<description><![CDATA[A sophisticated web-skimming campaign targeting online shoppers has emerged with renewed intensity in 2026, compromising e-commerce websites and extracting sensitive payment information during checkout processes. The attack, identified as part of the broader Magecart family of threats, represents...]]></description>
<link>https://tsecurity.de/de/3212233/it-security-nachrichten/new-magecart-attack-steals-customers-credit-cards-from-website-checkout-pages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3212233/it-security-nachrichten/new-magecart-attack-steals-customers-credit-cards-from-website-checkout-pages/</guid>
<pubDate>Wed, 14 Jan 2026 11:05:57 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated web-skimming campaign targeting online shoppers has emerged with renewed intensity in 2026, compromising e-commerce websites and extracting sensitive payment information during checkout processes. The attack, identified as part of the broader Magecart family of threats, represents an evolving…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-magecart-attack-steals-customers-credit-cards-from-website-checkout-pages/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-magecart-attack-steals-customers-credit-cards-from-website-checkout-pages/">New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages]]></title>
<description><![CDATA[A sophisticated web-skimming campaign targeting online shoppers has emerged with renewed intensity in 2026, compromising e-commerce websites and extracting sensitive payment information during checkout processes. The attack, identified as part of the broader Magecart family of threats, represents...]]></description>
<link>https://tsecurity.de/de/3212178/it-security-nachrichten/new-magecart-attack-steals-customers-credit-cards-from-website-checkout-pages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3212178/it-security-nachrichten/new-magecart-attack-steals-customers-credit-cards-from-website-checkout-pages/</guid>
<pubDate>Wed, 14 Jan 2026 10:49:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated web-skimming campaign targeting online shoppers has emerged with renewed intensity in 2026, compromising e-commerce websites and extracting sensitive payment information during checkout processes. The attack, identified as part of the broader Magecart family of threats, represents an evolving challenge to online retail security. Threat researchers have documented extensive infrastructure associated with this long-running […]</p>
<p>The post <a href="https://cybersecuritynews.com/new-magecart-attack-steals-customers-credit-cards/">New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Magecart Campaign Steals Credit Card Details During Online Checkouts]]></title>
<description><![CDATA[Cybersecurity researchers at Silent Push Preemptive Cyber Defense have uncovered an extensive and sophisticated web-skimming campaign that has been actively stealing credit card data from e-commerce websites since at least January 2022. The ongoing operation, operating under the umbrella term…
Re...]]></description>
<link>https://tsecurity.de/de/3211722/it-security-nachrichten/new-magecart-campaign-steals-credit-card-details-during-online-checkouts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3211722/it-security-nachrichten/new-magecart-campaign-steals-credit-card-details-during-online-checkouts/</guid>
<pubDate>Wed, 14 Jan 2026 06:20:10 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybersecurity researchers at Silent Push Preemptive Cyber Defense have uncovered an extensive and sophisticated web-skimming campaign that has been actively stealing credit card data from e-commerce websites since at least January 2022. The ongoing operation, operating under the umbrella term…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/new-magecart-campaign-steals-credit-card-details-during-online-checkouts/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/new-magecart-campaign-steals-credit-card-details-during-online-checkouts/">New Magecart Campaign Steals Credit Card Details During Online Checkouts</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Widespread Magecart Campaign Targets Users of All Major Credit Cards]]></title>
<description><![CDATA[Researchers at Silent Push have exposed a global Magecart campaign stealing credit card data since 2022. Learn how this invisible web-skimming attack targets major networks like Mastercard and Amex, and how to stay safe. This article has been indexed from…
Read more →
The post Widespread Magecart...]]></description>
<link>https://tsecurity.de/de/3210405/it-security-nachrichten/widespread-magecart-campaign-targets-users-of-all-major-credit-cards/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3210405/it-security-nachrichten/widespread-magecart-campaign-targets-users-of-all-major-credit-cards/</guid>
<pubDate>Tue, 13 Jan 2026 15:35:52 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Researchers at Silent Push have exposed a global Magecart campaign stealing credit card data since 2022. Learn how this invisible web-skimming attack targets major networks like Mastercard and Amex, and how to stay safe. This article has been indexed from…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/widespread-magecart-campaign-targets-users-of-all-major-credit-cards/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/widespread-magecart-campaign-targets-users-of-all-major-credit-cards/">Widespread Magecart Campaign Targets Users of All Major Credit Cards</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Silent Push Exposes Magecart Network Operating Since Early 2022]]></title>
<description><![CDATA[Silent Push reveals a sophisticated Magecart network using web skimmers to steal credit card data from online shoppers, highlighting the need for enhanced cybersecurity measures. The post Silent Push Exposes Magecart Network Operating Since Early 2022 appeared first on Security…
Read more →
The p...]]></description>
<link>https://tsecurity.de/de/3210276/it-security-nachrichten/silent-push-exposes-magecart-network-operating-since-early-2022/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3210276/it-security-nachrichten/silent-push-exposes-magecart-network-operating-since-early-2022/</guid>
<pubDate>Tue, 13 Jan 2026 14:35:13 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Silent Push reveals a sophisticated Magecart network using web skimmers to steal credit card data from online shoppers, highlighting the need for enhanced cybersecurity measures. The post Silent Push Exposes Magecart Network Operating Since Early 2022 appeared first on Security…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/silent-push-exposes-magecart-network-operating-since-early-2022/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/silent-push-exposes-magecart-network-operating-since-early-2022/">Silent Push Exposes Magecart Network Operating Since Early 2022</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Global Magecart Campaign Targets Six Card Networks]]></title>
<description><![CDATA[Silent Push has discovered a new Magecart campaign targeting six major payment network providers that has been running since 2022 This article has been indexed from www.infosecurity-magazine.com Read the original article: Global Magecart Campaign Targets Six Card Networks
Read more →
The post Glo...]]></description>
<link>https://tsecurity.de/de/3209951/it-security-nachrichten/global-magecart-campaign-targets-six-card-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3209951/it-security-nachrichten/global-magecart-campaign-targets-six-card-networks/</guid>
<pubDate>Tue, 13 Jan 2026 12:20:19 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Silent Push has discovered a new Magecart campaign targeting six major payment network providers that has been running since 2022 This article has been indexed from www.infosecurity-magazine.com Read the original article: Global Magecart Campaign Targets Six Card Networks</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/global-magecart-campaign-targets-six-card-networks/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/global-magecart-campaign-targets-six-card-networks/">Global Magecart Campaign Targets Six Card Networks</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Global Magecart Campaign Targets Six Card Networks]]></title>
<description><![CDATA[Silent Push has discovered a new Magecart campaign targeting six major payment network providers that has been running since 2022]]></description>
<link>https://tsecurity.de/de/3209903/it-security-nachrichten/global-magecart-campaign-targets-six-card-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3209903/it-security-nachrichten/global-magecart-campaign-targets-six-card-networks/</guid>
<pubDate>Tue, 13 Jan 2026 12:05:31 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Silent Push has discovered a new Magecart campaign targeting six major payment network providers that has been running since 2022]]></content:encoded>
</item>
<item>
<title><![CDATA[Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows]]></title>
<description><![CDATA[A large-scale web skimming operation has emerged across the internet, targeting online shoppers and account holders with unprecedented scope. Security researchers have identified an over 50-script global campaign that intercepts sensitive information during checkout and account creation processes...]]></description>
<link>https://tsecurity.de/de/3186865/it-security-nachrichten/massive-magecart-with-50-malicious-scripts-hijacking-checkout-and-account-creation-flows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3186865/it-security-nachrichten/massive-magecart-with-50-malicious-scripts-hijacking-checkout-and-account-creation-flows/</guid>
<pubDate>Tue, 30 Dec 2025 20:35:28 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A large-scale web skimming operation has emerged across the internet, targeting online shoppers and account holders with unprecedented scope. Security researchers have identified an over 50-script global campaign that intercepts sensitive information during checkout and account creation processes. The attack demonstrates a significant evolution in how cybercriminals target e-commerce platforms, moving beyond simple credit card […]</p>
<p>The post <a href="https://cybersecuritynews.com/massive-magecart-with-50-malicious-scripts/">Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows</a> appeared first on <a href="https://cybersecuritynews.com/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows]]></title>
<description><![CDATA[A large-scale web skimming operation has emerged across the internet, targeting online shoppers and account holders with unprecedented scope. Security researchers have identified an over 50-script global campaign that intercepts sensitive information during checkout and account creation processes...]]></description>
<link>https://tsecurity.de/de/3186861/it-security-nachrichten/massive-magecart-with-50-malicious-scripts-hijacking-checkout-and-account-creation-flows/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3186861/it-security-nachrichten/massive-magecart-with-50-malicious-scripts-hijacking-checkout-and-account-creation-flows/</guid>
<pubDate>Tue, 30 Dec 2025 20:35:23 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A large-scale web skimming operation has emerged across the internet, targeting online shoppers and account holders with unprecedented scope. Security researchers have identified an over 50-script global campaign that intercepts sensitive information during checkout and account creation processes. The attack…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/massive-magecart-with-50-malicious-scripts-hijacking-checkout-and-account-creation-flows/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/massive-magecart-with-50-malicious-scripts-hijacking-checkout-and-account-creation-flows/">Massive Magecart with 50+ Malicious Scripts Hijacking Checkout and Account Creation Flows</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Campaign Deploys 50+ Malicious Scripts to Hijack E-Commerce Transactions]]></title>
<description><![CDATA[A sophisticated and expansive Magecart campaign has been uncovered, marking a dangerous evolution in client-side attacks. Security researchers have identified a global operation utilizing over 50 distinct malicious scripts to hijack checkout and account creation flows across dozens of e-commerce…...]]></description>
<link>https://tsecurity.de/de/3186675/it-security-nachrichten/magecart-campaign-deploys-50-malicious-scripts-to-hijack-e-commerce-transactions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3186675/it-security-nachrichten/magecart-campaign-deploys-50-malicious-scripts-to-hijack-e-commerce-transactions/</guid>
<pubDate>Tue, 30 Dec 2025 18:35:37 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A sophisticated and expansive Magecart campaign has been uncovered, marking a dangerous evolution in client-side attacks. Security researchers have identified a global operation utilizing over 50 distinct malicious scripts to hijack checkout and account creation flows across dozens of e-commerce…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/magecart-campaign-deploys-50-malicious-scripts-to-hijack-e-commerce-transactions/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/magecart-campaign-deploys-50-malicious-scripts-to-hijack-e-commerce-transactions/">Magecart Campaign Deploys 50+ Malicious Scripts to Hijack E-Commerce Transactions</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[52: Magecart]]></title>
<description><![CDATA[Credit card skimming is growing in popularity. Gas pumps all over are seeing skimmers attached to them. It’s growing in popularity because it’s really effective. Hackers have noticed how effective it is and have began skimming credit cards from websites.GuestThanks to Yonathan Klijnsma from RiskI...]]></description>
<link>https://tsecurity.de/de/3106010/podcasts/52-magecart/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3106010/podcasts/52-magecart/</guid>
<pubDate>Wed, 19 Nov 2025 00:38:09 +0100</pubDate>
<category>🎥 Podcasts</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Credit card skimming is growing in popularity. Gas pumps all over are seeing skimmers attached to them. It’s growing in popularity because it’s really effective. Hackers have noticed how effective it is and have began skimming credit cards from websites.</p><p>Guest</p><p>Thanks to <a href="https://twitter.com/ydklijnsma">Yonathan Klijnsma</a> from <a href="https://www.riskiq.com/">RiskIQ</a>.</p><p>Sponsors</p><p>This episode was sponsored by <a href="https://linode.com/darknet?utm_source=darknet&amp;utm_medium=podcast&amp;utm_content=20%20dollar&amp;utm_campaign=darknet20">Linode</a>. Linode supplies you with virtual servers. Visit <a href="https://linode.com/darknet?utm_source=darknet&amp;utm_medium=podcast&amp;utm_content=20%20dollar&amp;utm_campaign=darknet20">linode.com/darknet</a> and when signing up with a new account use code darknet2019 to get a $20 credit on your next project.</p><p>Support for this episode comes from <a href="https://honeybook.com/darknet">Honeybook</a>. HoneyBook is an online business management tool that organizes your client communications, bookings, contracts, and invoices – all in one place. Visit <a href="https://honeybook.com/darknet">honeybook.com/darknet</a> to get 50% off your subscription.</p><p>This episode was sponsored by CMD. Securing Linux systems is hard, let CMD help you with that. Visit <a href="https://cmd.com/dark">https://cmd.com/dark</a> to get a free demo.</p><p><br></p><p>Visit <a href="https://darknetdiaries.com/episode/darknetdiaries.com">darknetdiaries.com</a> for full show notes and transcripts.</p><p> </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Smashing Security podcast #440: How to hack a prison, and the hidden threat of online checkouts]]></title>
<description><![CDATA[A literal insider threat: we head to a Romanian prison where “self-service” web kiosks allowed inmates to run wild. Then we head to the checkout aisle to ask why JavaScript on payment pages went feral, and how new PCI DSS rules are finally muzzling Magecart-style skimmers.

Plus: Graham reveals...]]></description>
<link>https://tsecurity.de/de/3056372/it-security-nachrichten/smashing-security-podcast-440-how-to-hack-a-prison-and-the-hidden-threat-of-online-checkouts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3056372/it-security-nachrichten/smashing-security-podcast-440-how-to-hack-a-prison-and-the-hidden-threat-of-online-checkouts/</guid>
<pubDate>Thu, 23 Oct 2025 01:49:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A literal insider threat: we head to a Romanian prison where “self-service” web kiosks allowed inmates to run wild. Then we head to the checkout aisle to ask why JavaScript on payment pages went feral, and how new PCI DSS rules are finally muzzling Magecart-style skimmers.

Plus: Graham reveals his new-found superpower with Keyboard Maestro, and Scott describes a slick new way to whip up beautiful how-to videos with Screen Studio.

All this and more is discussed in episode 440 of "Smashing Security" podcast with cybersecurity veteran Graham Cluley, and special guest Scott Helme.]]></content:encoded>
</item>
<item>
<title><![CDATA[New Magecart Attack Injects Malicious JavaScript to Steal Payment Data]]></title>
<description><![CDATA[A new Magecart-style campaign has emerged that leverages malicious JavaScript injections to skim payment data from online checkout forms. The threat surfaced after security researcher sdcyberresearch posted a cryptic tweet hinting at an active campaign hosted on cc-analytics[.]com. Subsequent ana...]]></description>
<link>https://tsecurity.de/de/2989438/hacking/new-magecart-attack-injects-malicious-javascript-to-steal-payment-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2989438/hacking/new-magecart-attack-injects-malicious-javascript-to-steal-payment-data/</guid>
<pubDate>Wed, 17 Sep 2025 16:49:06 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new Magecart-style campaign has emerged that leverages malicious JavaScript injections to skim payment data from online checkout forms. The threat surfaced after security researcher sdcyberresearch posted a cryptic tweet hinting at an active campaign hosted on cc-analytics[.]com. Subsequent analysis revealed a heavily obfuscated script that hooks into checkout fields, collects credit card and billing […]</p>
<p>The post <a href="https://gbhackers.com/magecart-attack-2/">New Magecart Attack Injects Malicious JavaScript to Steal Payment Data</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Leeds United And Reflectiz Partner To Share Insights On Proactive Web Security After Cyber Attack]]></title>
<description><![CDATA[Leeds, UK, June 27th, 2025, CyberNewsWire – Leeds United FC, a globally recognized football club, and Reflectiz, a leading provider ofproactive web security, today announced an upcoming webinar titled “Beyond the Breach:How Leeds United Achieved Proactive Web Security After a Magecart Attack.” Th...]]></description>
<link>https://tsecurity.de/de/2855453/hacking/leeds-united-and-reflectiz-partner-to-share-insights-on-proactive-web-security-after-cyber-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2855453/hacking/leeds-united-and-reflectiz-partner-to-share-insights-on-proactive-web-security-after-cyber-attack/</guid>
<pubDate>Fri, 27 Jun 2025 15:48:35 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Leeds, UK, June 27th, 2025, CyberNewsWire – Leeds United FC, a globally recognized football club, and Reflectiz, a leading provider ofproactive web security, today announced an upcoming webinar titled “Beyond the Breach:How Leeds United Achieved Proactive Web Security After a Magecart Attack.” Thisessential webinar will delve into the critical topic of client-side security, offering invaluablelessons […]</p>
<p>The post <a href="https://gbhackers.com/leeds-united-and-reflectiz-partner-to-share-insights-on-proactive-web-security-after-cyber-attack/">Leeds United And Reflectiz Partner To Share Insights On Proactive Web Security After Cyber Attack</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hundreds of E-Commerce Sites Hacked In Supply-Chain Attack]]></title>
<description><![CDATA[An anonymous reader quotes a report from Ars Technica: Hundreds of e-commerce sites, at least one owned by a large multinational company, were backdoored by malware that executes malicious code inside the browsers of visitors, where it can steal payment card information and other sensitive data, ...]]></description>
<link>https://tsecurity.de/de/2759026/it-security-nachrichten/hundreds-of-e-commerce-sites-hacked-in-supply-chain-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2759026/it-security-nachrichten/hundreds-of-e-commerce-sites-hacked-in-supply-chain-attack/</guid>
<pubDate>Mon, 05 May 2025 23:03:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An anonymous reader quotes a report from Ars Technica: Hundreds of e-commerce sites, at least one owned by a large multinational company, were backdoored by malware that executes malicious code inside the browsers of visitors, where it can steal payment card information and other sensitive data, security researchers said Monday. The infections are the result of a supply-chain attack that compromised at least three software providers with malware that remained dormant for six years and became active only in the last few weeks. At least 500 e-commerce sites that rely on the backdoored software were infected, and it's possible that the true number is double that, researchers from security firm Sansec said. Among the compromised customers was a $40 billion multinational company, which Sansec didn't name. In an email Monday, a Sansec representative said that "global remediation [on the infected customers] remains limited."
 
"Since the backdoor allows uploading and executing arbitrary PHP code, the attackers have full remote code execution (RCE) and can do essentially anything they want," the representative wrote. "In nearly all Adobe Commerce/Magento breaches we observe, the backdoor is then used to inject skimming software that runs in the user's browser and steals payment information (Magecart)." The three software suppliers identified by Sansec were Tigren, Magesolution (MGS), and Meetanshi. All three supply software that's based on Magento, an open source e-commerce platform used by thousands of online stores. A software version sold by a fourth provider named Weltpixel has been infected with similar code on some of its customers' stores, but Sansec so far has been unable to confirm whether it was the stores or Weltpixel that were hacked. Adobe has owned Megento since 2018.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Hundreds+of+E-Commerce+Sites+Hacked+In+Supply-Chain+Attack%3A+https%3A%2F%2Fit.slashdot.org%2Fstory%2F25%2F05%2F05%2F2034207%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fit.slashdot.org%2Fstory%2F25%2F05%2F05%2F2034207%2Fhundreds-of-e-commerce-sites-hacked-in-supply-chain-attack%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://it.slashdot.org/story/25/05/05/2034207/hundreds-of-e-commerce-sites-hacked-in-supply-chain-attack?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Advanced Multi-Stage Carding Attack Hits Magento Site Using Fake GIFs and Reverse Proxy Malware]]></title>
<description><![CDATA[A multi-stage carding attack has been uncovered targeting a Magento eCommerce website running an outdated version 1.9.2.4. This version, unsupported by Adobe since June 2020, left the site vulnerable due to unpatched security flaws. The malware employed a deceptive .gif file, tampered browser ses...]]></description>
<link>https://tsecurity.de/de/2747291/hacking/advanced-multi-stage-carding-attack-hits-magento-site-using-fake-gifs-and-reverse-proxy-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2747291/hacking/advanced-multi-stage-carding-attack-hits-magento-site-using-fake-gifs-and-reverse-proxy-malware/</guid>
<pubDate>Mon, 28 Apr 2025 18:21:12 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A multi-stage carding attack has been uncovered targeting a Magento eCommerce website running an outdated version 1.9.2.4. This version, unsupported by Adobe since June 2020, left the site vulnerable due to unpatched security flaws. The malware employed a deceptive .gif file, tampered browser sessionStorage data, and a malicious reverse proxy server to steal credit card […]</p>
<p>The post <a href="https://gbhackers.com/advanced-multi-stage-carding-attack-hits-magento-site/">Advanced Multi-Stage Carding Attack Hits Magento Site Using Fake GIFs and Reverse Proxy Malware</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p><!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr><p>GBhackers.</p>
<hr />
<p><strong>Neuer Artikel Titel:</strong> Multi-Stufen-Cardingangriff auf Magento-Website mit gefälschten GIFs und Reverse Proxy Malware – Experten warnen vor Sicherheitslücken bei veralteten Systemen</p>
<p><strong>Artikel Inhalt:</strong> <p>Ein mehrstufiger Cardinganfall hat sich gegen eine Magento eKaufplattform ergeben, die eine veraltete Version 1.9.2.4 betreibt. Diese Version ist seit Juni 2020 von Adobe nicht länger unterstützt und somit anfällig für ungesicherte Schwachstellen.</p></p>
<p>Der Angreifer nutzte ein irreführendes .gif-File, manipulierte browserseitige SessionStorage Daten sowie einen bösartigen Reverse Proxy Server zur Diebstahl von Kreditkartendaten [1], Login Credentials und Cookies. Der Angriff störte den Checkout Prozess durch die Verhinderung einer korrekten Karteneingabe und Bestellabwicklung.</p>
<p>Die Attacke unterstreicht das kritische Risiko, Software-Updates zu vernachlässigen bei komplexen Plattformen wie Magento, wo eine Migration auf neuere Versionen (z.B., Magento 2) sowohl kostspielig als auch zeitaufwendig sein kann [1].</p>

<section id="attack_mechanismus">
<h3>Intriger Mechanismus: Fake GIFs und Reverse Proxy Taktiken</h3>
<p>Die Infektion begann mit verdächtigem JavaScript-Code, der in den Checkout Seite zwischen legitimen Bing UET Tracking Tags eingebettet war. Eine genauere Inspektion offenbarte eine versteckte Referenz auf einen Magento Verzeichnis Pfad – dynamisch konstruiert durch verschleierte String Manipulation (z.B., Konkatenation von “rep” und "lace" unter Ignorieren irreführender Begriffe wie „bing“).</p>
<p>Dies führte zu einem falschen Dateipfad, "/media/magentothem/img/line.gif", der stattdessen ein bösartiges PHP-Skript enthielt [1]. Das Skripte wurde durch die Dekodierung seiner verschleierten “backend_url” auf einen Remote Server (217.12.207.38) verweist, welcher eine Reverse Proxy Orchestrierte.</p>
<p>Im Gegensatz zu einem regulären Proxy oder VPN, der Benutzeridentitäten maskiert, interceptierte dieser Reverse Proxy sämtlichen Site-Traffic – erfasste Header, POST Daten, Cookies und Session Tokens - während gleichzeitig Antworten umgeschrieben wurden. Dies machte die Interception nahezu unsichtbar für Nutzer und Administratoren [1]. Tampered Location Headers und Cookies sorgten dafür dass sich das Backend Servers Identität verborgen blieb.</p>
<p>Zusätzlich wurde eine zweite Injektion in der Checkout Template Datei (onestepcheckout.phtml) verwendet, um einen benutzer-spezifischen Schlüssel aus dem Browser UserAgent String zu generieren – welcher Clientseitige Payloads über sessionStorage ausführte und Kreditkarten Diebstahl diskret während des Checkouts durchführten ohne persistente Spuren hinterlassen.</p>
</section>

<section id="warnungen">
<h3>Dringende Warnung: Sicherheitsmaßnahmen & Abhilfemaßnahmen</h3>
<p>Laut <a href="https://sucuri.net/blog/magento-carding/">Sucuri Report</a> unterstreicht dieser MageCart-ähnliche Angriff die anhaltenden Risiken für eKaufplattformen, insbesondere solche auf veralten System wie Magento 1 [2]. Der mehrschichtig aufgebauten Angriffsmechanismus – der Serverseitige Reverse Proxy Interception mit Client Seitiger SessionStorage Ausnutzung demonstriert das ausgefeilte Planung von Bedrohungsakteuren.</p>
<p>Reverse proxy: Für Website Administratoren ist die Vorrangigkeit für Kern Updates und Sicherheits Patches, Migration auf unterstützte Plattformen wie Magento 2 sowie der Einsatz Web Application Firewalls (WAFs) zur Abwehr solcher Angriffe ein klares Zeichen [1]. Kleine Unternehmen ohne technische Expertise werden dringend dazu aufgefordert sichere Experten zu beauftragen um das Vertrauen von Kunden zu schützen und Strafzahlungen durch Zahlungsverarbeitern, wie Visa für die Identifizierung als häufiger Punkt der Kaufkompromittierung vermeiden.</p>
<p>Für Shopper ist Vorsicht geboten – Tools wie Sitecheck können veraltete Plattformen aufdecken [1], während Browser Sicherheits Plugins und Skript Blocker zusätzliche Schutz vor bösartigen JavaScripts bieten. Letztendlich dient dieser Fall als kritische Warnung: Die Vernachlässigung der eKauf Sicherheit gefährdet nicht nur Kundendaten, sondern riskiert auch erhebliche Reputations- und finanzielle Schäden in einer Ära zunehmend ausgefeilter Cyber Bedrohungen [1].</p>
<section id="weiteres_lesen">

<h3>Weiterführende Informationen</h3>
<ul><li> <a href = "https://gbhackers.com/advanced-multi-stage-carding-attack-hits-magento-site/">GBHackers Artikel</a></li> </ul>


 </section>



</article>

---

**Anmerkungen:**

*   Ich habe die Struktur des Artikels verbessert, indem ich ihn in sinnvolle Abschnitte unterteilt.
*   Die Hintergrundinformationen wurden erweitert und präzisiert (siehe [1] & [2]). Ich habe Links zu externen Quellen hinzugefügt um weitere Informationen bereitzustellen. Die Referenzen sind wichtig für Glaubwürdigkeit.
*  Ich habe die Sprache klarer, journalistischer gestaltet.

**Hinweis:** Es ist ratsam, alle URLs und Verweise auf Originalquellen in der final veröffentlichten Version des Artikels zu überprüfen und ggf. anzupassen. Ich kann keine Garantie dafür übernehmen dass diese Links aktuell sind oder funktionieren.<!-- END: Dynamically Added Content --><!-- START: Dynamically Added Content --><br><h3>KI generiertes Nachrichten Update</h3><hr><p>GBhackers.</p>
<hr />
<p><strong>Neuer Artikel Titel:</strong> Multi-Stufen-Cardingangriff auf Magento-Website mit gefälschten GIFs und Reverse Proxy Malware – Experten warnen vor veralteten Systemen</p>
<p><strong>Artikel Inhalt:</strong> <p>Ein mehrstufiger Cardinganfall hat sich gegen eine Magento eKaufplattform ergeben, die eine veraltete Version 1.9.2.4 betreibt. Diese Version wurde seit Juni 2020 von Adobe nicht länger unterstützt und ließ das Unternehmen aufgrund ungepatchter Sicherheitslücken anfällig für Angriffe werden.</p></p>
<p>Der Malware-Angreifer nutzte ein irreführendes .gif-File, manipulierte browserseitige SessionStorage Daten sowie einen bösartigen Reverse Proxy Server zur Diebstahl von Kreditkartendaten [1], Login Credentials und Cookies. Der Angriff störte den Checkout Prozess durch die Verhinderung einer korrekten Karteneingabe und Bestellabwicklung.</p>
<p>Die Attacke unterstreicht das kritische Risiko, Software-Updates zu vernachlässigen – insbesondere bei komplexen Plattformen wie Magento [2], wo eine Migration auf neuere Versionen (z.B., Magento 2) kostspielig und zeitaufwendig sein kann.</p>

<p style="text-align: justify;"><b>Intrinsicher Angriff Mechanismus: Fake GIFs & Reverse Proxy Taktiken</b></p>
<p>[3] Die Infektion begann mit verdächtigem JavaScript Code, der in Bing UET Tracking Tags zwischen legitimen Checkout Elementen eingebettet war. Eine genauere Inspektion offenbarte eine versteckte Referenz auf einen Magento Verzeichnis Pfad – dynamisch konstruiert durch verschleierte String Manipulation (z.B., Konkatenation von “rep” und "lace" unter Ignorieren irreführender Begriffe wie „bing“). Dies führte zu einem falschen Dateipfad, "/media/magentothem/img/line.gif", der stattdessen ein bösartiges PHP-Skript enthielt.</p>
<p>[3] Das Dekodierung des verschleierten “backend_url” zeigte auf einen Remote Server (217.12.207.38), welcher eine Reverse Proxy Orchestrierte und die gesamte Site Traffic abfing, Header, POST Daten, Cookies sowie Session Tokens erfasste – während gleichzeitig Antworten umgeschrieben wurden, um legitime Domain Interaktionen zu imitieren.</p>
<p>[4] Dies machte das Abfangen nahezu unsichtbar für Benutzer und Administratoren. Tamperte Location Headers und Cookies sorgten dafür dass die Identität des Backend Servers verborgen blieb. Zusätzlich wurde eine zweite Injektion in der Checkout Template Datei (onestepcheckout.phtml) verwendet, um einen benutzer-spezifischen Schlüssel aus dem UserAgent String zu extrahieren – welcher Clientseitige Payloads über sessionStorage ausführte und den Kartendiebstahl diskret während des Checkouts durchführte - ohne persistente Spuren nach der Session hinterlassen.</p>

<p style="text-align: justify;"><b>Dringende Warnung für Sicherheit & Mitigation Maßnahmen</b></p>
<p>[5] Laut Sucuri Report unterstreicht dieser MageCart Style Angriff die anhaltenden Risiken von eKaufplattformen, insbesondere solchen auf veralten System wie Magento 1. Der mehrschrittige Ansatz des Angreifers – kombinierend Serverseitiges Reverse Proxy Interception mit Client-Seitiger SessionStorage Ausnutzung - demonstriert das fortschrittliche Planung der Bedrohungsakteure.</p>
<p>[6]  Reverse proxy: Für Website Administratoren ist die Vorrangigkeit von Kern Updates und Sicherheits Patches, Migration auf unterstützte Plattformen wie Magento 2 sowie Deployment Web Application Firewalls (WAFs) zur Abwehr solcher Angriffe ein klares Zeichen. Kleine Unternehmen ohne technische Expertise werden dringend dazu aufgefordert sichere Experten zu engagieren um das Vertrauen der Kunden zu schützen – und Strafzahlungen von Zahlungsverarbeitern, beispielsweise Visa für die Identifizierung als häufiger Punkt des Kaufkompromisses vermeiden.</p>
<p>[6] Für Shopper ist Vorsicht geboten: Tools wie Sitecheck können veraltete Plattformen aufdecken - während Browser Sicherheits Plugins und Skript Blocker zusätzliche Schutz vor bösartigem JavaScript bieten.  Letztendlich dient dieser Fall als kritische Warnung – das Vernachlässigen der eKaufplattform Sicherheit gefährdet nicht nur Kundendaten, sondern riskiert auch erhebliche Reputations- & Finanzielle Schäden in einer Zeit von zunehmend ausgefeilten Cyber Bedrohungen.</p>

<p style="text-align: justify;"><b>Quellen</b></p>
<ul><li>[1] <a href=“https://gbhackers.com/advanced-multi-stage-carding-attack-hits-magento-site/">Advanced Multi-Stage Carding Attack Hits Magento Site Using Fake GIFs and Reverse Proxy Malware</a></li>
    <br/>
  </ul>

<ul><li>[2] <a href=“https://tsecurity.de/de/2747291/IT+Sicherheit/Hacker/Advanced+Multi-Stage+Carding+Attack+Hits+Magento+Site+Using+Fake+GIFs+and+Reverse+Proxy+Malware/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a></li>
    <br/>

  </ul>

<ul><li>[3] <a href=“https://gbhackers.com/advanced-multi-stage-carding-attack-hits-magento-site/" >Advanced Multi-Stage Carding Attack Hits Magento Site Using Fake GIFs and Reverse Proxy Malware</a></li>
    <br/>

  </ul>

<ul><li>[4] <a href=“https://gbhackers.com/advanced-multi-stage-carding-attack-hits-magento-site/" >Advanced Multi-Stage Carding Attack Hits Magento Site Using Fake GIFs and Reverse Proxy Malware</a></li>
    <br/>

  </ul>

<ul><li>[5] <a href=“https://gbhackers.com/advanced-multi-stage-carding-attack-hits-magento-site/" >Advanced Multi-Stage Carding Attack Hits Magento Site Using Fake GIFs and Reverse Proxy Malware</a></li>
    <br/>

  </ul>

<ul><li>[6] <a href=“https://gbhackers.com/advanced-multi-stage-carding-attack-hits-magento-site/" >Advanced Multi-Stage Carding Attack Hits Magento Site Using Fake GIFs and Reverse Proxy Malware</a></li>
    <br/>

  </ul>

<h2><strong>Anmerkungen:</strong> Ich habe die Struktur des Artikels verbessert, indem ich ihn in sinnvolle Abschnitte gegliedert und Unterabsätze hinzugefügt. Die Informationen aus der externen Quelle wurden integriert (mit Quellenangaben). Der Text wurde auf journalistische Sprache optimiert und redundante Passagen entfernt.  Die Links zu den Originalquellen sind beibehalten worden, um die Nachvollziehbarkeit sicherzustellen.</h2>
<p><strong>Verbesserungen:</strong></p>
<ul>
<li>Klarere Einleitung mit Hervorhebung des Hauptproblems (Cardinganfall).</li>
<li>Strukturierung in Abschnitte für bessere Lesbarkeit und Übersichtlichkeit: Angriff Mechanismus, Dringende Warnung etc..</li>
<li>Hinzufügen von Quellenangaben ([1], [2] usw.) zur Nachvollziehbarkeit.  Die Links wurden beibehalten um die Quelle zu verlinken.</li>
<li>Verbesserte Sprache für eine klarere und prägnantere Darstellung der Informationen.</li>
</ul>
<p>Ich hoffe, diese Überarbeitung entspricht Ihren Anforderungen!</p><!-- END: Dynamically Added Content -->]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Launches New Attack Using Malicious JavaScript to Steal Credit Card Data]]></title>
<description><![CDATA[The notorious Magecart group has been identified by the Yarix Incident Response Team as the culprits behind a recent credit card data theft operation on an e-commerce platform. This latest assault on consumer data showcases the group’s evolving tactics to infiltrate and compromise online payment ...]]></description>
<link>https://tsecurity.de/de/2736444/hacking/magecart-launches-new-attack-using-malicious-javascript-to-steal-credit-card-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2736444/hacking/magecart-launches-new-attack-using-malicious-javascript-to-steal-credit-card-data/</guid>
<pubDate>Tue, 22 Apr 2025 14:22:05 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The notorious Magecart group has been identified by the Yarix Incident Response Team as the culprits behind a recent credit card data theft operation on an e-commerce platform. This latest assault on consumer data showcases the group’s evolving tactics to infiltrate and compromise online payment systems. Initial Access and Web Shell Deployment The attack began […]</p>
<p>The post <a href="https://gbhackers.com/magecart-launches-new-attack-using-malicious-javascript/">Magecart Launches New Attack Using Malicious JavaScript to Steal Credit Card Data</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart-Angriff auf Magento: Kreditkartendaten über Image-Tags abgefangen]]></title>
<description><![CDATA[Hacker starten derzeit Angriffe auf Magento, um Kreditkartendaten zu stehlen. Der Schadcode lauert zwischen Image-Tags.
Der Artikel Magecart-Angriff auf Magento: Kreditkartendaten über Image-Tags abgefangen erschien zuerst auf TARNKAPPE.INFO]]></description>
<link>https://tsecurity.de/de/2622087/malware-trojaner-viren/magecart-angriff-auf-magento-kreditkartendaten-ueber-image-tags-abgefangen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2622087/malware-trojaner-viren/magecart-angriff-auf-magento-kreditkartendaten-ueber-image-tags-abgefangen/</guid>
<pubDate>Wed, 19 Feb 2025 13:01:16 +0100</pubDate>
<category>⚠️ Malware / Trojaner / Viren</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hacker starten derzeit Angriffe auf Magento, um Kreditkartendaten zu stehlen. Der Schadcode lauert zwischen Image-Tags.</p>
<p>Der Artikel <a href="https://tarnkappe.info/artikel/cyberangriffe/magecart-angriff-auf-magento-kreditkartendaten-ueber-image-tags-abgefangen-310501.html">Magecart-Angriff auf Magento: Kreditkartendaten über Image-Tags abgefangen</a> erschien zuerst auf <a href="https://tarnkappe.info/">TARNKAPPE.INFO</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybercriminals Embedded Credit Card Stealer Script Within  Tag]]></title>
<description><![CDATA[Cybersecurity researchers have uncovered a new MageCart malware campaign targeting e-commerce websites running on the Magento platform. This attack exploits  HTML tags to conceal malicious JavaScript skimmers, enabling cybercriminals to steal sensitive payment information while evading detection ...]]></description>
<link>https://tsecurity.de/de/2620597/hacking/cybercriminals-embedded-credit-card-stealer-script-within-tag/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2620597/hacking/cybercriminals-embedded-credit-card-stealer-script-within-tag/</guid>
<pubDate>Tue, 18 Feb 2025 18:19:25 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cybersecurity researchers have uncovered a new MageCart malware campaign targeting e-commerce websites running on the Magento platform. This attack exploits &lt;img&gt; HTML tags to conceal malicious JavaScript skimmers, enabling cybercriminals to steal sensitive payment information while evading detection by security tools. MageCart, a term used to describe credit card skimming malware, has evolved with increasingly […]</p>
<p>The post <a href="https://gbhackers.com/cybercriminals-embedded-credit-card-stealer/">Cybercriminals Embedded Credit Card Stealer Script Within &lt;img&gt; Tag</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybercriminals Exploit Onerror Event in Image Tags to Deploy Payment Skimmers]]></title>
<description><![CDATA[Cybersecurity researchers have flagged a credit card stealing malware campaign that has been observed targeting e-commerce sites running Magento by disguising the malicious content within image tags in HTML code in order to stay under the radar.
MageCart is the name given to a malware that's capa...]]></description>
<link>https://tsecurity.de/de/2619251/it-security-nachrichten/cybercriminals-exploit-onerror-event-in-image-tags-to-deploy-payment-skimmers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2619251/it-security-nachrichten/cybercriminals-exploit-onerror-event-in-image-tags-to-deploy-payment-skimmers/</guid>
<pubDate>Tue, 18 Feb 2025 07:03:03 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersecurity researchers have flagged a credit card stealing malware campaign that has been observed targeting e-commerce sites running Magento by disguising the malicious content within image tags in HTML code in order to stay under the radar.
MageCart is the name given to a malware that's capable of stealing sensitive payment information from online shopping sites. The attacks are known to]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Exploiting Google Tag Managers to Steal Credit Card from eCommerce Sites]]></title>
<description><![CDATA[In a concerning development, cybercriminals are leveraging Google Tag Manager (GTM), a legitimate tool widely used by eCommerce websites, to deploy malicious scripts designed to steal credit card information. This attack vector, often referred to as Magecart or e-skimming, has been observed targe...]]></description>
<link>https://tsecurity.de/de/2605445/hacking/hackers-exploiting-google-tag-managers-to-steal-credit-card-from-ecommerce-sites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2605445/hacking/hackers-exploiting-google-tag-managers-to-steal-credit-card-from-ecommerce-sites/</guid>
<pubDate>Mon, 10 Feb 2025 20:04:31 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In a concerning development, cybercriminals are leveraging Google Tag Manager (GTM), a legitimate tool widely used by eCommerce websites, to deploy malicious scripts designed to steal credit card information. This attack vector, often referred to as Magecart or e-skimming, has been observed targeting platforms like Magento, WordPress, and OpenCart, among others. The abuse of GTM […]</p>
<p>The post <a href="https://gbhackers.com/hackers-exploiting-google-tag-managers-to-steal-credit-card/">Hackers Exploiting Google Tag Managers to Steal Credit Card from eCommerce Sites</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Attackers Abuse Google Ad Tool to Steal Data]]></title>
<description><![CDATA[Attackers are smuggling payment card-skimming malicious code into checkout pages on Magento-based e-commerce sites by abusing the Google Tag Manager ad tool.]]></description>
<link>https://tsecurity.de/de/2604964/it-security-nachrichten/magecart-attackers-abuse-google-ad-tool-to-steal-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2604964/it-security-nachrichten/magecart-attackers-abuse-google-ad-tool-to-steal-data/</guid>
<pubDate>Mon, 10 Feb 2025 16:33:13 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Attackers are smuggling payment card-skimming malicious code into checkout pages on Magento-based e-commerce sites by abusing the Google Tag Manager ad tool.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cisco Merch Shoppers Stung In Magecart Attack]]></title>
<description><![CDATA[]]></description>
<link>https://tsecurity.de/de/2323274/it-security-nachrichten/cisco-merch-shoppers-stung-in-magecart-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2323274/it-security-nachrichten/cisco-merch-shoppers-stung-in-magecart-attack/</guid>
<pubDate>Mon, 09 Sep 2024 16:19:24 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
</item>
<item>
<title><![CDATA[Cisco merch shoppers stung in Magecart attack]]></title>
<description><![CDATA[The 'security issue' was caused by a 9.8-rated Magento flaw Adobe patched back in June Bad news for anyone who purchased a Cisco hoodie earlier this month: Suspected Russia-based attackers injected data-stealing JavaScript into the networking giant's online store selling Cisco-branded merch.…]]></description>
<link>https://tsecurity.de/de/2320159/it-security-nachrichten/cisco-merch-shoppers-stung-in-magecart-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2320159/it-security-nachrichten/cisco-merch-shoppers-stung-in-magecart-attack/</guid>
<pubDate>Fri, 06 Sep 2024 22:33:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>The 'security issue' was caused by a 9.8-rated Magento flaw Adobe patched back in June</h4> <p>Bad news for anyone who purchased a Cisco hoodie earlier this month: Suspected Russia-based attackers injected data-stealing JavaScript into the networking giant's online store selling Cisco-branded merch.…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[WordPress malware pinpoints WooCommerce sites for Magecart attacks]]></title>
<description><![CDATA[Some cybercriminals have targeted WooCommerce online stores with a sizable number of customers fit enough for a Magecart attack in the nearest future. This discovery was done by researchers from Sucuri, a website security firm. Ensure your online safety – read our OmniWatch review, a tool dedicat...]]></description>
<link>https://tsecurity.de/de/2096603/it-security-nachrichten/wordpress-malware-pinpoints-woocommerce-sites-for-magecart-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/2096603/it-security-nachrichten/wordpress-malware-pinpoints-woocommerce-sites-for-magecart-attacks/</guid>
<pubDate>Thu, 04 Apr 2024 09:37:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Some cybercriminals have targeted WooCommerce online stores with a sizable number of customers fit enough for a Magecart attack in the nearest future. This discovery was done by researchers from Sucuri, a website security firm. Ensure your online safety – read our OmniWatch review, a tool dedicated to removing your personal information from the dark […]</p>
<p>The post <a href="https://secureblitz.com/wordpress-magecart-attacks/">WordPress malware pinpoints WooCommerce sites for Magecart attacks</a> appeared first on <a href="https://secureblitz.com/">SecureBlitz Cybersecurity</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rogue WordPress Plugin Exposes E-Commerce Sites to Credit Card Theft]]></title>
<description><![CDATA[Threat hunters have discovered a rogue WordPress plugin that's capable of creating bogus administrator users and injecting malicious JavaScript code to steal credit card information.
The skimming activity is part of a Magecart campaign targeting e-commerce websites, according to Sucuri.
"As with ...]]></description>
<link>https://tsecurity.de/de/1966995/it-security-nachrichten/rogue-wordpress-plugin-exposes-e-commerce-sites-to-credit-card-theft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1966995/it-security-nachrichten/rogue-wordpress-plugin-exposes-e-commerce-sites-to-credit-card-theft/</guid>
<pubDate>Fri, 22 Dec 2023 18:50:28 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Threat hunters have discovered a rogue WordPress plugin that's capable of creating bogus administrator users and injecting malicious JavaScript code to steal credit card information.
The skimming activity is part of a Magecart campaign targeting e-commerce websites, according to Sucuri.
"As with many other malicious or fake WordPress plugins it contains some deceptive information at]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Campaign Hijacks 404 Pages to Steal Data]]></title>
<description><![CDATA[The novel technique helps hide the cybercriminal campaign's efforts to steal credit card information from visitors to major websites, and it represents an evolution for Magecart.]]></description>
<link>https://tsecurity.de/de/1894358/it-security-nachrichten/magecart-campaign-hijacks-404-pages-to-steal-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1894358/it-security-nachrichten/magecart-campaign-hijacks-404-pages-to-steal-data/</guid>
<pubDate>Fri, 20 Oct 2023 19:17:33 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The novel technique helps hide the cybercriminal campaign's efforts to steal credit card information from visitors to major websites, and it represents an evolution for Magecart.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google To Add E2EE To 2FA Authenticator Cloud Backups - ThreatWire]]></title>
<description><![CDATA[Author: Hak5 - Bewertung: 223x - Views:4346 ThreatWire Totem Board - Limited Edition! - https://snubsie.com/threatwire-products/tw-totem 

Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ 

Support ThreatWire! https://www.patreon.com/shannonmorse  

Follow Shannon on So...]]></description>
<link>https://tsecurity.de/de/1888377/it-security-video/google-to-add-e2ee-to-2fa-authenticator-cloud-backups-threatwire/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1888377/it-security-video/google-to-add-e2ee-to-2fa-authenticator-cloud-backups-threatwire/</guid>
<pubDate>Wed, 24 May 2023 10:15:40 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/flNka1HWGhM/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Hak5 - Bewertung: 223x - Views:4346 <br/></p><p><iframe id="ytplayer" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/flNka1HWGhM?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>ThreatWire Totem Board - Limited Edition! - https://snubsie.com/threatwire-products/tw-totem 

Shop ThreatWire Merch on Teespring! - https://morsecode.creator-spring.com/ 

Support ThreatWire! https://www.patreon.com/shannonmorse  

Follow Shannon on Social Media: https://snubsie.com/links 

Flaws in a DNA Sequencer could lead to hacks, Magecart is back with some shiny upgrades, and Cloud backups of 2FA codes? Better make sure they’re encrypted! All that coming up now on ThreatWire.

 #threatwire #hak5

ThreatWire by Shannon Morse is a weekly news journalism show covering cybersecurity topics for network admins, information security professionals, and consumers.
 
Watch this on youtube: https://youtu.be/flNka1HWGhM

Chapters:
00:00 DNA Sequencing Flaws
02:19 Magecart’s Shiny Upgrades
04:10 Insecure 2FA Cloud Backups 

Links:
Resources for stories are available on Patreon exclusively, to protect our channel from being inappropriately flagged as “malicious content”. All links included in my videos are news articles or sources related to each story and are both appropriate for the discussion and legitimate. Access source links at https://www.patreon.com/shannonmorse  


Hak5 -- Cyber Security Education, Inspiration, News & Community since 2005:

-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆
Our Site → https://www.hak5.org
Shop →  http://hakshop.myshopify.com/
Subscribe → https://www.youtube.com/user/Hak5Darren?sub_confirmation=1
Support → https://www.patreon.com/threatwire
Contact Us → http://www.twitter.com/hak5
-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆-----☆

____________________________________________
Founded in 2005, Hak5's mission is to advance the InfoSec industry. We do this through our award winning educational podcasts, leading pentest gear, and inclusive community – where all hackers belong.<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Hackers Perfect Fake Checkout Pages]]></title>
<description><![CDATA[Author: Seytonic - Bewertung: 2489x - Views:43710 PlexTrac 👉 https://plextrac.com/seytonic/




0:00 Intro
0:35 How it Works
2:09 What it Magecart
3:11 Other Magecart hacks
4:46 PlexTrac
5:44 Outro


Sources:
https://www.bleepingcomputer.com/news/security/hackers-swap-stealth-for-realistic-checko...]]></description>
<link>https://tsecurity.de/de/1888372/it-security-video/magecart-hackers-perfect-fake-checkout-pages/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1888372/it-security-video/magecart-hackers-perfect-fake-checkout-pages/</guid>
<pubDate>Wed, 24 May 2023 10:15:38 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/MkvWqz_o-1Y/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<p>Author: Seytonic - Bewertung: 2489x - Views:43710 <br/></p><p><iframe id="ytplayer" type="text/html" width="100%" height="auto" src="https://www.youtube.com/embed/MkvWqz_o-1Y?autoplay=1&origin=http://tsecurity.de" frameborder="0"></iframe></p><p>PlexTrac 👉 https://plextrac.com/seytonic/




0:00 Intro
0:35 How it Works
2:09 What it Magecart
3:11 Other Magecart hacks
4:46 PlexTrac
5:44 Outro


Sources:
https://www.bleepingcomputer.com/news/security/hackers-swap-stealth-for-realistic-checkout-forms-to-steal-credit-cards/
https://www.malwarebytes.com/blog/threat-intelligence/2023/04/kritec-art
https://ico.org.uk/media/action-weve-taken/mpns/2618421/ba-penalty-20201016.pdf


===============================================
My Website: https://www.seytonic.com/
Follow me on TWTR: https://twitter.com/seytonic
Follow me on INSTA: https://www.instagram.com/jhonti/
===============================================<br/></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attention Online Shoppers: Don't Be Fooled by Their Sleek, Modern Looks — It's Magecart!]]></title>
<description><![CDATA[An ongoing Magecart campaign has attracted the attention of cybersecurity researchers for leveraging realistic-looking fake payment screens to capture sensitive data entered by unsuspecting users.
"The threat actor used original logos from the compromised store and customized a web element known ...]]></description>
<link>https://tsecurity.de/de/1884396/it-security-nachrichten/attention-online-shoppers-dont-be-fooled-by-their-sleek-modern-looks-its-magecart/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1884396/it-security-nachrichten/attention-online-shoppers-dont-be-fooled-by-their-sleek-modern-looks-its-magecart/</guid>
<pubDate>Fri, 28 Apr 2023 11:34:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[An ongoing Magecart campaign has attracted the attention of cybersecurity researchers for leveraging realistic-looking fake payment screens to capture sensitive data entered by unsuspecting users.
"The threat actor used original logos from the compromised store and customized a web element known as a modal to perfectly hijack the checkout page," Jérôme Segura, director of threat intelligence at]]></content:encoded>
</item>
<item>
<title><![CDATA[The best defense against cyber threats for lean security teams]]></title>
<description><![CDATA[H0lyGh0st, Magecart, and a slew of state-sponsored hacker groups are diversifying their tactics and shifting their focus to… you. That is, if you’re in charge of cybersecurity for a small-to-midsize enterprise (SME). Why? Bad actors know that SMEs typically have a smaller security budget, less in...]]></description>
<link>https://tsecurity.de/de/1841826/it-security-nachrichten/the-best-defense-against-cyber-threats-for-lean-security-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1841826/it-security-nachrichten/the-best-defense-against-cyber-threats-for-lean-security-teams/</guid>
<pubDate>Thu, 30 Mar 2023 04:48:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>H0lyGh0st, Magecart, and a slew of state-sponsored hacker groups are diversifying their tactics and shifting their focus to… you. That is, if you’re in charge of cybersecurity for a small-to-midsize enterprise (SME). Why? Bad actors know that SMEs typically have a smaller security budget, less infosec manpower, and possibly weak or missing security controls to protect their data and infrastructure. So, how can you prepare for the imminent onslaught from new and emerging threat groups? … <a href="https://www.helpnetsecurity.com/2023/03/30/best-defense-against-cyber-threats-lean-security-teams/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a rel="nofollow" href="https://www.helpnetsecurity.com/2023/03/30/best-defense-against-cyber-threats-lean-security-teams/">The best defense against cyber threats for lean security teams</a> appeared first on <a rel="nofollow" href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anomali Cyber Watch: Account takeover, APT, Banking trojans, China, Cyberespionage, India, Malspam, North Korea, Phishing, Skimmers, Ukraine, and Vulnerabilities]]></title>
<description><![CDATA[None selected Skip to content Using Anomali Inc Mail with screen readers yury 1 of 52 ACW Inbox Yury Polozov  Attachments Mar 27, 2023, 10:11 AM (1 day ago) to me, Marketing, Research Dear Jarom and Marketing, ACW is ready https://ui.threatstream.com/tip/6397663 -- Yury Polozov | Sr. Threat Intel...]]></description>
<link>https://tsecurity.de/de/1839873/it-security-nachrichten/anomali-cyber-watch-account-takeover-apt-banking-trojans-china-cyberespionage-india-malspam-north-korea-phishing-skimmers-ukraine-and-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1839873/it-security-nachrichten/anomali-cyber-watch-account-takeover-apt-banking-trojans-china-cyberespionage-india-malspam-north-korea-phishing-skimmers-ukraine-and-vulnerabilities/</guid>
<pubDate>Tue, 28 Mar 2023 23:34:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>None selected Skip to content Using Anomali Inc Mail with screen readers yury 1 of 52 ACW Inbox Yury Polozov <ypolozov> Attachments Mar 27, 2023, 10:11 AM (1 day ago) to me, Marketing, Research Dear Jarom and Marketing, ACW is ready https://ui.threatstream.com/tip/6397663 -- Yury Polozov | Sr. Threat Intelligence Analyst | ATR | www.anomali.com Phone: +1-347-276-5554 3 Attachments • Scanned by Gmail</ypolozov>@anomali.com&gt;</p>

<div>
<p> </p>

<h1><b>Anomali Cyber Watch: Bitter Spies on Chinese Nuclear Energy, Kimsuky Takes Over Google Account to Infect Connected Android Devices, Bad Magic APT Targets Occupied Parts of Ukraine, and More.</b></h1>

<p>The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics:<b> Account takeover, APT, Banking trojans, China, Cyberespionage, India, Malspam, North Korea, Phishing, Skimmers, Ukraine, </b> and <b>Vulnerabilities</b>. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity. <img src="https://anomali-labs-public.s3.amazonaws.com/img/6397663.png"><br><b>Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.</b></p>

<div class="trending-threats-article">
<h2>Trending Cyber News and Threat Intelligence</h2>

<h3><a href="https://www.intezer.com/blog/research/phishing-campaign-targets-nuclear-energy-industry/" target="_blank">Phishing Campaign Targets Chinese Nuclear Energy Industry</a></h3>

<p>(published: March 24, 2023)</p>

<p>Active since 2013, the Bitter (T-APT-17) group is suspected of being sponsored by the Indian government. Intezer researchers discovered a new Bitter campaign targeting academic, government, and other organizations in the nuclear energy industry in China. The techniques are consistent with previously-observed Bitter campaigns. The intrusion starts with a phishing email purported to be from a real employee in the Embassy of Kyrgyzstan. Observed malicious attachments were either Microsoft Compiled HTML Help (CHM) files, or Microsoft Excel files with Equation Editor exploits. The purpose of the payloads are to create persistence via scheduled tasks and download further malware payloads (previous Bitter campaigns used browser credential stealer, file stealer, keylogger, and remote access tool plugins). The attackers relied on LZX compression and string concatenation for detection evasion.<br><b>Analyst Comment:</b> Many advanced attacks start with basic techniques such as unwarranted email with malicious attachment that requires the user to open it. It is important to teach your users basic online hygiene and phishing awareness. It is safe to recommend never opening attached CHM files and keeping your MS Office fully updated. All known indicators associated with this Bitter campaign are available in the Anomali platform and customers are advised to block these on their infrastructure.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/attackpattern/10171" target="_blank">[MITRE ATT&amp;CK] T1589.002 - Gather Victim Identity Information: Email Addresses</a> | <a href="https://ui.threatstream.com/attackpattern/10001" target="_blank">[MITRE ATT&amp;CK] T1566.001 - Phishing: Spearphishing Attachment</a> | <a href="https://ui.threatstream.com/attackpattern/3712" target="_blank">[MITRE ATT&amp;CK] T1059.001: PowerShell</a> | <a href="https://ui.threatstream.com/attackpattern/9752" target="_blank">[MITRE ATT&amp;CK] T1203 - Exploitation For Client Execution</a> | <a href="https://ui.threatstream.com/attackpattern/9931" target="_blank">[MITRE ATT&amp;CK] T1053.005 - Scheduled Task/Job: Scheduled Task</a> | <a href="https://ui.threatstream.com/attackpattern/9928" target="_blank">[MITRE ATT&amp;CK] T1218.007 - Signed Binary Proxy Execution: Msiexec</a> | <a href="https://ui.threatstream.com/attackpattern/9597" target="_blank">[MITRE ATT&amp;CK] T1036 - Masquerading</a> | <a href="https://ui.threatstream.com/attackpattern/13021" target="_blank">[MITRE ATT&amp;CK] Picus: The System Information Discovery Technique Explained - MITRE ATT&amp;CK T1082</a> | <a href="https://ui.threatstream.com/attackpattern/9715" target="_blank">[MITRE ATT&amp;CK] T1071.001 - Application Layer Protocol: Web Protocols</a> | <a href="https://ui.threatstream.com/attackpattern/9617" target="_blank">[MITRE ATT&amp;CK] T1041 - Exfiltration Over C2 Channel</a><br><b>Tags:</b> actor:Bitter, APT, Cyberespionage, Spearphishing, source-country:India, source-country:IN, target-country:China, target-country:CN, target-industry:Nuclear, target-industry:Energy, target-industry:Research, target-industry:Government, file-type:RAR, file-type:CHM, file-type:XLS, file-type:EXE, file-type:MSI, Equation Editor exploit, LZX compression, String concatenation, PowerShell, malware-type:Downloader, Windows</p>

<h3><a href="https://www.bleepingcomputer.com/news/security/north-korean-hackers-using-chrome-extensions-to-steal-gmail-emails/" target="_blank">North Korean Hackers Using Chrome Extensions to Steal Gmail Emails</a></h3>

<p>(published: March 22, 2023)</p>

<p>North Korea-sponsored Kimsuky (Thallium, Velvet Chollima) group has been observed chaining two attack methods — a malicious Chrome extension and Android applications. A spearphishing email urges the target to install an extension for their Chromium-based browser (Chrome, Microsoft Edge, Naver Whale). This malicious extension steals Google account credentials and Gmail content, abusing the Devtools API for exfiltration. With the Google account access, the actors abuse the web-to-phone synchronization feature of Google Play to install a malicious app on target’s linked Android devices. Kimsuki uses the "internal testing only" setting to place the app on Google Play. It is a custom Android RAT dubbed FastViewer (Fastfire, Fastspy DEX) seen in previous Kimsuki campaigns. It can activate the camera, drop, create, delete, or steal files, get contact lists, monitor or send SMS, perform calls, perform keylogging, and view the desktop.<br><b>Analyst Comment:</b> This attack was targeting experts on the Korean Peninsula and North Korea issues, but it has potential to expand to other entities in Europe, North America, and South Korea, while remaining narrowly-targeted to a limited number of targets. It is important to have protocols in place to follow precautions when receiving emails and identify the malicious ones. A regular review of the lists of installed extensions and apps is good to limit the possible exposure and detect the malicious additions. All known indicators associated with this Kimsuki campaign are available in the Anomali platform and customers are advised to block these on their infrastructure.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/attackpattern/9883" target="_blank">[MITRE ATT&amp;CK] T1566 - Phishing</a> | <a href="https://ui.threatstream.com/attackpattern/9668" target="_blank">[MITRE ATT&amp;CK] T1114 - Email Collection</a> | <a href="https://ui.threatstream.com/attackpattern/17846" target="_blank">[MITRE ATT&amp;CK] T1616 - Call Control</a> | <a href="https://ui.threatstream.com/attackpattern/17818" target="_blank">[MITRE ATT&amp;CK] T1533 - Data From Local System</a> | <a href="https://ui.threatstream.com/attackpattern/18653" target="_blank">[MITRE ATT&amp;CK] T1417.001 - Input Capture: Keylogging</a> | <a href="https://ui.threatstream.com/attackpattern/18649" target="_blank">[MITRE ATT&amp;CK] T1636.004 - Protected User Data: Sms Messages</a> | <a href="https://ui.threatstream.com/attackpattern/18648" target="_blank">[MITRE ATT&amp;CK] T1636.003 - Protected User Data: Contact List</a> | <a href="https://ui.threatstream.com/attackpattern/17802" target="_blank">[MITRE ATT&amp;CK] T1512 - Capture Camera</a><br><b>Tags:</b> mitre-group:Kimsuky, actor:Thallium, actor:Velvet Chollima, source-country:North Korea, source-country:KP, target-country:South Korea, target-country:KR, Devtools API, file-type:JSON, file-type:JS, Chrome Extension, malware:AF, Microsoft Edge, Whale browser, Gmail, malware:FastViewer, malware:Fastfire, malware:Fastspy DEX, malware-type:RAT, Web-to-phone synchronization, Mobile, Android</p>

<h3><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/03/new-kritec-skimmer" target="_blank">New Kritec Magecart Skimmer Found on Magento Stores</a></h3>

<p>(published: March 22, 2023)</p>

<p>While verifying previously-reported injections of a WebSocket skimmer abusing Google Tag Manager, Malwarebytes researchers detected a completely new skimmer dubbed Kritec. The Kritec skimmer is being injected near the Google Tag Manager script, but it is not embedded in the Google Tag Manager library itself and it does not use WebSocket. Kritec calls out a first domain (encoded in Base64), gets a Base64 response containing a URL pointing to the actual skimming code, which is heavily obfuscated (likely via Obfuscator[.]io). Kritec infrastructure is hidden behind the Cloudflare protection.<br><b>Analyst Comment:</b> Site administrators should keep their systems updated and secure the administrator panel with two-factor authentication or other access restrictions. If your site was infected, perform a core file integrity check, query for any files containing the same injection, and check any recently modified or added files. All known network indicators associated with Kritec are available in the Anomali platform and customers are advised to block these on their infrastructure.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/attackpattern/10012" target="_blank">[MITRE ATT&amp;CK] T1190 - Exploit Public-Facing Application</a> | <a href="https://ui.threatstream.com/attackpattern/9591" target="_blank">[MITRE ATT&amp;CK] T1027 - Obfuscated Files Or Information</a> | <a href="https://ui.threatstream.com/attackpattern/9838" target="_blank">[MITRE ATT&amp;CK] T1140 - Deobfuscate/Decode Files Or Information</a><br><b>Tags:</b> malware:Kritec, Magecart, malware-type:Skimmer, Google Tag Manager, WebSockets, Base64, Cloudflare, Obfuscator[.]io, Magento store, Website compromise</p>

<h3><a href="https://securelist.com/bad-magic-apt/109087/" target="_blank">Bad Magic: New APT Found in the Area of Russo-Ukrainian Conflict</a></h3>

<p>(published: March 21, 2023)</p>

<p>Since October 2022, a new advanced persistent threat (APT) group dubbed Bad Magic has been able to breach an unnamed amount of government, agriculture and transportation organizations in Donetsk, Lugansk, and Crimea regions (parts of Ukraine currently controlled by Russia). The attack starts with a URL pointing to a ZIP archive containing a decoy document and a malicious LNK file with a double extension (such as .PDF.LNK). Its execution triggers a download and execution of an MSI dropper package with a VBS dropper script and a PowerShell-based backdoor dubbed PowerMagic. The same targets were also infected with the CommonMagic malicious framework (likely deployed by the PowerMagic backdoor). CommonMagic has standalone modules communicating via named pipes: information-stealing (screenshotting module, collecting data from removable USB drives module), traffic encryption, and networking modules. CommonMagic uses OneDrive remote folders, Microsoft Graph API, the RapidJSON library, and the RC5Simple encryption library.<br><b>Analyst Comment:</b> Users are advised to parse their mail on their desktop/notebook computers where they would be able to spot the extensions of files they are prompted to open. Avoid opening LNK and double-extension files. All known indicators associated with this Bad Magic campaign are available in the Anomali platform and customers are advised to block these on their infrastructure.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/attackpattern/9638" target="_blank">[MITRE ATT&amp;CK] T1105 - Ingress Tool Transfer</a> | <a href="https://ui.threatstream.com/attackpattern/9928" target="_blank">[MITRE ATT&amp;CK] T1218.007 - Signed Binary Proxy Execution: Msiexec</a> | <a href="https://ui.threatstream.com/attackpattern/9615" target="_blank">[MITRE ATT&amp;CK] T1204.002 - User Execution: Malicious File</a> | <a href="https://ui.threatstream.com/attackpattern/9591" target="_blank">[MITRE ATT&amp;CK] T1027 - Obfuscated Files Or Information</a> | <a href="https://ui.threatstream.com/attackpattern/9649" target="_blank">[MITRE ATT&amp;CK] T1053 - Scheduled Task/Job</a> | <a href="https://ui.threatstream.com/attackpattern/9770" target="_blank">[MITRE ATT&amp;CK] T1070.004 - Indicator Removal on Host: File Deletion</a> | <a href="https://ui.threatstream.com/attackpattern/9671" target="_blank">[MITRE ATT&amp;CK] T1113 - Screen Capture</a> | <a href="https://ui.threatstream.com/attackpattern/9663" target="_blank">[MITRE ATT&amp;CK] T1025 - Data From Removable Media</a> | <a href="https://ui.threatstream.com/attackpattern/9716" target="_blank">[MITRE ATT&amp;CK] T1573 - Encrypted Channel</a><br><b>Tags:</b> actor:Bad Magic, malware:PowerMagic, malware-type:Backdoor, PowerShell, malware:CommonMagic, malware-type:Framework, APT, target-industry:Government, target-industry:Agriculture, target-industry:Transportation, target-region:Lugansk, target-region:Crimea, target-region:Donetsk, Named pipes, WindowsActiveXTaskTrigger, OneDrive remote folder, Microsoft Graph API, OAuth refresh token, RapidJSON, RC5Simple, file-type:ZIP, file-type:PDF, file-type:XLSX, file-type:DOCX, file-type:MSI, file-type:DAT, file-type:VBS, file-type:EXE, Windows</p>

<h3><a href="https://www.cleafy.com/cleafy-labs/nexus-a-new-android-botnet" target="_blank">Nexus: a New Android Botnet?</a></h3>

<p>(published: March 21, 2023)</p>

<p>Cleafy researchers analyzed a new Android banking botnet named Nexus that was first detected in August 2022. It has some overlaps with the source code originally stolen from the Sova banking botnet. In January 2023, the actors behind Nexus started offering it on the Malware-as-a-Service basis. The malware is offered for a steep price and detected infections are in the hundreds, but it still has the marks of a testing/beta version. Nexus terminates itself if the location is in ten ex-Soviet countries or Indonesia. Its main focus is credentials stealing, injections for account takeover attacks targeting banking portals and cryptocurrency services (450 financial applications), and SMS interception.<br><b>Analyst Comment:</b> Users should keep their mobile devices updated and avail of mobile antivirus and VPN protection services. Install only applications that you actually need, use the official Google Play store and check the app description and reviews. All known indicators associated with this Nexus campaign are available in the Anomali platform and customers are advised to block these on their infrastructure.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/attackpattern/18619" target="_blank">[MITRE ATT&amp;CK] T1417.002 - Input Capture: Gui Input Capture</a> | <a href="https://ui.threatstream.com/attackpattern/17842" target="_blank">[MITRE ATT&amp;CK] T1582 - Sms Control</a><br><b>Tags:</b> malware:Nexus, malware-type:Botnet, malware-type:Banker, malware-type:Trojan, detection:Sova, detection:Boogr, Account takeover, Malware-as-a-Service, target-industry:Financial, target-industry:Cryptocurrency, Mobile, Android</p>
</div>
</div>

<p>6397663.txt Displaying 6397663.txt.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Threat Actors Use the MageCart Malware in New Credit Card Data Stealing Campaign]]></title>
<description><![CDATA[A new credit card hacking campaign is wreaking havoc, but this time it’s a little bit different. Instead of injecting the JavaScript code into the HTML of the store or of the checkout pages, this time threat actors are hiding the malicious code inside the “Authorize.net” payment gateway module fo...]]></description>
<link>https://tsecurity.de/de/1832624/it-security-nachrichten/threat-actors-use-the-magecart-malware-in-new-credit-card-data-stealing-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1832624/it-security-nachrichten/threat-actors-use-the-magecart-malware-in-new-credit-card-data-stealing-campaign/</guid>
<pubDate>Thu, 23 Mar 2023 10:50:15 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new credit card hacking campaign is wreaking havoc, but this time it’s a little bit different. Instead of injecting the JavaScript code into the HTML of the store or of the checkout pages, this time threat actors are hiding the malicious code inside the “Authorize.net” payment gateway module for WooCommerce. By doing so, the […]</p>
<p>The post <a rel="nofollow" href="https://heimdalsecurity.com/blog/threat-actors-use-the-magecart-malware-in-new-credit-card-data-stealing-campaign/">Threat Actors Use the MageCart Malware in New Credit Card Data Stealing Campaign</a> appeared first on <a rel="nofollow" href="https://heimdalsecurity.com/blog">Heimdal Security Blog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Best Defense Against Cyber Threats for Lean Security Teams]]></title>
<description><![CDATA[H0lyGh0st, Magecart, and a slew of state-sponsored hacker groups are diversifying their tactics and shifting their focus to…
You.
That is, if you're in charge of cybersecurity for a small-to-midsize enterprise (SME).
Why? Bad actors know that SMEs typically have a smaller security budget, less in...]]></description>
<link>https://tsecurity.de/de/1829882/it-security-nachrichten/the-best-defense-against-cyber-threats-for-lean-security-teams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1829882/it-security-nachrichten/the-best-defense-against-cyber-threats-for-lean-security-teams/</guid>
<pubDate>Tue, 21 Mar 2023 12:50:18 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[H0lyGh0st, Magecart, and a slew of state-sponsored hacker groups are diversifying their tactics and shifting their focus to…
You.
That is, if you're in charge of cybersecurity for a small-to-midsize enterprise (SME).
Why? Bad actors know that SMEs typically have a smaller security budget, less infosec manpower, and possibly weak or missing security controls to protect their data and]]></content:encoded>
</item>
<item>
<title><![CDATA[Anomali Cyber Watch: FortiOS Zero-Day Has Been Exploited by an APT, Two RATs Spread by Four Types of JAR Polyglot Files, Promethium APT Continued Android Targeting]]></title>
<description><![CDATA[The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: APT, DDoS, Polyglot, RATs, Russia, Skimmers, Trojanized apps, and Ukraine. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs fo...]]></description>
<link>https://tsecurity.de/de/1774675/it-security-nachrichten/anomali-cyber-watch-fortios-zero-day-has-been-exploited-by-an-apt-two-rats-spread-by-four-types-of-jar-polyglot-files-promethium-apt-continued-android-targeting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1774675/it-security-nachrichten/anomali-cyber-watch-fortios-zero-day-has-been-exploited-by-an-apt-two-rats-spread-by-four-types-of-jar-polyglot-files-promethium-apt-continued-android-targeting/</guid>
<pubDate>Wed, 18 Jan 2023 18:46:09 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: <b>APT, DDoS, Polyglot, RATs, Russia, Skimmers, Trojanized apps,</b> and <b>Ukraine</b>. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.</p>

<p><img src="https://www.anomali.com/images/uploads/blog/acw-011823.png"><br><em>Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.</em></p>

<h2>Trending Cyber News and Threat Intelligence</h2>

<div class="trending-threat-article">
<h3><a href="https://www.bleepingcomputer.com/news/security/malicious-lolip0p-pypi-packages-install-info-stealing-malware/" target="_blank">Malicious ‘Lolip0p’ PyPi Packages Install Info-Stealing Malware</a></h3>

<p>(published: January 16, 2023)</p>

<p>On January 10, 2023, Fortinet researchers detected actor Lolip0p offering malicious packages on the Python Package Index (PyPI) repository. The packages came with detailed, convincing descriptions pretending to be legitimate HTTP clients or, in one case, a legitimate improvement for a terminal user interface. Installation of the libraries led to infostealing malware targeting browser data and authentication (Discord) tokens.<br><b>Analyst Comment:</b> Free repositories such as PyPI become increasingly abused by threat actors. Before adding a package, software developers should review its author and reviews, and check the source code for any suspicious or malicious intent.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/attackpattern/9612" target="_blank">[MITRE ATT&amp;CK] T1204 - User Execution</a> | <a href="https://ui.threatstream.com/attackpattern/9599" target="_blank">[MITRE ATT&amp;CK] T1555 - Credentials From Password Stores</a><br><b>Tags:</b> actor:Lolip0p, Malicious package, malware-type:Infostealer, Discord, PyPi, Social engineering, Windows</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.fortinet.com/blog/psirt-blogs/analysis-of-fg-ir-22-398-fortios-heap-based-buffer-overflow-in-sslvpnd" target="_blank">Analysis of FG-IR-22-398 – FortiOS - Heap-Based Buffer Overflow in SSLVPNd</a></h3>

<p>(published: January 11, 2023)</p>

<p>In December 2022, the Fortinet network security company fixed a critical, heap-based buffer overflow vulnerability (FG-IR-22-398, CVE-2022-42475) in FortiOS SSL-VPN. The vulnerability was exploited as a zero-day by an advanced persistent threat (APT) actor who was customizing a Linux implant specifically for FortiOS of relevant FortiGate hardware versions. The targeting was likely aimed at governmental or government-related targets. The attribution is not clear, but the compilation timezone UTC+8 may point to China, Russia, and some other countries.<br><b>Analyst Comment:</b> Users of the affected products should make sure that the December 2022 FortiOS security updates are implemented. Zero-day based attacks can sometimes be detected by less conventional methods, such as behavior analysis, and heuristic and machine learning based detection systems. Network defenders are advised to monitor for suspicious traffic, such as suspicious TCP sessions with Get request for payloads.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/attackpattern/12893" target="_blank">[MITRE ATT&amp;CK] T1622 - Debugger Evasion</a> | <a href="https://ui.threatstream.com/attackpattern/10012" target="_blank">[MITRE ATT&amp;CK] T1190 - Exploit Public-Facing Application</a> | <a href="https://ui.threatstream.com/attackpattern/9638" target="_blank">[MITRE ATT&amp;CK] T1105 - Ingress Tool Transfer</a> | <a href="https://ui.threatstream.com/attackpattern/9628" target="_blank">[MITRE ATT&amp;CK] T1090 - Proxy</a> | <a href="https://ui.threatstream.com/attackpattern/9767" target="_blank">[MITRE ATT&amp;CK] T1070 - Indicator Removal On Host</a><br><b>Tags:</b> FG-IR-22-398, CVE-2022-42475, Heap-Based Buffer Overflow, malware-type:Backdoor, malware-type:Implant, detection:Elf/BakSo, detection:Bakso.Linux.Backdoor, file-type:ELF, port:80, port:443, port:444, port:20443, port:30080, port:30081, port:30443, port:8033, port:8443, APT, target-industry:Government, SSLVPNd, Fortinet, FortiOS, Zero-day, Linux</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.deepinstinct.com/blog/malicious-jars-and-polyglot-files-who-do-you-think-you-jar" target="_blank">Malicious JARs and Polyglot Files: “Who Do You Think You JAR?”</a></h3>

<p>(published: January 11, 2023)</p>

<p>Deep Instinct researchers have detected a number of malicious JAR files appended in the beginning to masquerade as being of a different file type. Some files were functional polyglot files: MSI+JAR and CAB+JAR polyglots. Other files had non-functioning PE or binary junk beginning. Two types of payloads were remote access trojans (RATs): StrRAT and Ratty. It is possible that all studied samples were created by the same actor, as some shared C2, and many shared the same BelCloud LTD hosting.<br><b>Analyst Comment:</b> Appended JAR files are misidentified by the Linux file command. Network defenders should monitor as JAR all files passed as an argument to the java or javaw process with -jar as an argument.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/attackpattern/10028" target="_blank">[MITRE ATT&amp;CK] T1566.002 - Phishing: Spearphishing Link</a> | <a href="https://ui.threatstream.com/attackpattern/9598" target="_blank">[MITRE ATT&amp;CK] T1036.001 - Masquerading: Invalid Code Signature</a> | <a href="https://ui.threatstream.com/attackpattern/9872" target="_blank">[MITRE ATT&amp;CK] T1027.001 - Obfuscated Files or Information: Binary Padding</a> | <a href="https://ui.threatstream.com/attackpattern/9721" target="_blank">[MITRE ATT&amp;CK] T1102 - Web Service</a><br><b>Tags:</b> Polyglot file, file-type:JAR, file-type:MSI, MSI+JAR polyglot, ZIP file, file-type:CAB, CAB+JAR polyglot, BelCloud LTD, detection:StrRAT, detection:Ratty, malware-type:RAT</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://decoded.avast.io/martinchlumecky/ddosia-project/" target="_blank">DDosia Project: Volunteers Carrying out NoName(057)16’s Dirty Work</a></h3>

<p>(published: January 11, 2023)</p>

<p>A pro-Russian DDoS group called <i>NoName057(16)</i> has been targeting Poland, Latvia, Lithuania, and Ukraine (in the order of intensity). In September 2022, the group relied on a botnet of infected machines. After it was taken down, <i>NoName057(16)</i> started building a volunteer hacktivist DDoS collective. Their Python-based DDoS tool named DDosia has Linux/macOS and Windows versions. Avast researchers detected 2,200 DDoS targets and estimated the overall success rate at 13% and increasing. To incentivise its followers, the group regularly announces cryptocurrency payments to its top performers in the amount of several hundred US dollars.<br><b>Analyst Comment:</b> The current DDosia’s capability is relatively low, but it can be enough to take down web services that do not expect heavier network traffic. Hacktivist groups tend to utilize DDoS attacks as their main vector to affect businesses and government entities that they are not happy with. Denial-of-service attacks can potentially cost your company loss in revenue because severe attacks can shut down online services for extended periods of time. Organizations should implement DDoS protection measures and put in place a business continuity plan in the unfortunate case that your company is the target of a significant DDoS attack.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/attackpattern/9990" target="_blank">[MITRE ATT&amp;CK] T1498 - Network Denial Of Service</a> | <a href="https://ui.threatstream.com/attackpattern/9591" target="_blank">[MITRE ATT&amp;CK] T1027 - Obfuscated Files Or Information</a><br><b>Tags:</b> detection:DDosia, actor:NoName(057)16, Hacktivism, malware-type:DDoS, Russia, source-country:RU, target-region:Europe, Poland, target-country:PL, Latvia, target-country:LT, Lithuania, target-country:LV, Ukraine, target-country:UA</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.welivesecurity.com/2023/01/10/strongpity-espionage-campaign-targeting-android-users/" target="_blank">StrongPity Espionage Campaign Targeting Android Users</a></h3>

<p>(published: January 10, 2023)</p>

<p>ESET researchers identified a new campaign attributed to the Turkey-sponsored Promethium (StrongPity) APT. The attackers copied a video-chat service website and offered to download an Android app that actually is a trojanized version of the Telegram messenger. An installation leads to modular, fully-functional spyware, similar to the Android spyware used by Promethium in a previous campaign targeting Syria. If a targeted user gives the trojanized app accessibility services permission, it can expand its information-gathering to exfiltrate communication from 17 apps such as Gmail, Messenger, Skype, Tinder, and Viber.<br><b>Analyst Comment:</b> Always use the Google Play Store to obtain your software, and avoid downloading applications, even if they appear legitimate, from third-party stores. Accessibility services and other excessive permission requests from an app should raise concern. Install anti-virus software for your mobile device. Note that rooting your device lowers its protections against malware such as Android/StrongPity.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/attackpattern/17768" target="_blank">[MITRE ATT&amp;CK] T1398 - Modify Os Kernel Or Boot Partition</a> | <a href="https://ui.threatstream.com/attackpattern/18652" target="_blank">[MITRE ATT&amp;CK] T1624.001 - Event Triggered Execution: Broadcast Receivers</a> | <a href="https://ui.threatstream.com/attackpattern/17814" target="_blank">[MITRE ATT&amp;CK] T1407 - Download New Code At Runtime</a> | <a href="https://ui.threatstream.com/attackpattern/17807" target="_blank">[MITRE ATT&amp;CK] T1406 - Obfuscated Files Or Information</a> | <a href="https://ui.threatstream.com/attackpattern/18650" target="_blank">[MITRE ATT&amp;CK] T1628.002 - Hide Artifacts: User Evasion</a> | <a href="https://ui.threatstream.com/attackpattern/18613" target="_blank">[MITRE ATT&amp;CK] T1629.003 - Impair Defenses: Disable Or Modify Tools</a> | <a href="https://ui.threatstream.com/attackpattern/17765" target="_blank">[MITRE ATT&amp;CK] T1420 - File And Directory Discovery</a> | <a href="https://ui.threatstream.com/attackpattern/12247" target="_blank">[MITRE ATT&amp;CK] T1418 - Application Discovery</a> | <a href="https://ui.threatstream.com/attackpattern/17834" target="_blank">[MITRE ATT&amp;CK] T1422 - System Network Configuration Discovery</a> | <a href="https://ui.threatstream.com/attackpattern/17824" target="_blank">[MITRE ATT&amp;CK] T1426 - System Information Discovery</a> | <a href="https://ui.threatstream.com/attackpattern/18653" target="_blank">[MITRE ATT&amp;CK] T1417.001 - Input Capture: Keylogging</a> | <a href="https://ui.threatstream.com/attackpattern/17840" target="_blank">[MITRE ATT&amp;CK] T1517 - Access Notifications</a> | <a href="https://ui.threatstream.com/attackpattern/17816" target="_blank">[MITRE ATT&amp;CK] T1532 - Data Encrypted</a> | <a href="https://ui.threatstream.com/attackpattern/17820" target="_blank">[MITRE ATT&amp;CK] T1430 - Location Tracking</a> | <a href="https://ui.threatstream.com/attackpattern/17806" target="_blank">[MITRE ATT&amp;CK] T1429 - Capture Audio</a> | <a href="https://ui.threatstream.com/attackpattern/17836" target="_blank">[MITRE ATT&amp;CK] T1513 - Screen Capture</a> | <a href="https://ui.threatstream.com/attackpattern/18665" target="_blank">[MITRE ATT&amp;CK] T1636.002 - Protected User Data: Call Log</a> | <a href="https://ui.threatstream.com/attackpattern/18648" target="_blank">[MITRE ATT&amp;CK] T1636.003 - Protected User Data: Contact List</a> | <a href="https://ui.threatstream.com/attackpattern/18649" target="_blank">[MITRE ATT&amp;CK] T1636.004 - Protected User Data: Sms Messages</a> | <a href="https://ui.threatstream.com/attackpattern/18625" target="_blank">[MITRE ATT&amp;CK] T1437.001 - Application Layer Protocol: Web Protocols</a> | <a href="https://ui.threatstream.com/attackpattern/18622" target="_blank">[MITRE ATT&amp;CK] T1521.001 - Encrypted Channel: Symmetric Cryptography</a> | <a href="https://ui.threatstream.com/attackpattern/18640" target="_blank">[MITRE ATT&amp;CK] T1646 - Exfiltration Over C2 Channel</a><br><b>Tags:</b> mitre-group:Promethium, actor:StrongPity, detection:Android/StrongPity, APT, Cyberespionage, Mobile, malware-type:Backdoor, malware-type:Spyware, Modular malware, Trojanized app, Accessibility services, HTTrack, Turkey, source-country:TR, Telegram, Shagle, Android</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.grc.com/sn/sn-905-notes.pdf" target="_blank">Security Now! #905: 1</a></h3>

<p>(published: January 10, 2023)</p>

<p>The LastPass password manager uses Password-based Key Derivation Function 2 (PBKDF2) to store user passwords. In January 2023, Security Now research community revealed that some user vaults in LastPass had PBKDF2 iteration count set to 5000, 500, or just 1. It makes brute-force attacks on the hashed memorized secrets practical, and these numbers are significantly lower than recommendations from OWASP (310,000 iterations for PBKDF2-HMAC-SHA256) and NIST (as large as verification server performance will allow, typically at least 10,000 iterations). Another concern around the previously-disclosed LastPass breach is unencrypted “LastTouch” field containing a time code that shows when the last logon at each stored domain occurred.<br><b>Analyst Comment:</b> Over the years, threat actors have the ability to accumulate more brute-forcing power through advances in technology and cloud abuse. It is important to follow the current best practices for password storing. If your passwords and secrets were potentially exposed in a breach while not hashed securely according to the modern day standards, it is safe to assume them compromised and change the passwords as soon as possible.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/attackpattern/9858" target="_blank">[MITRE ATT&amp;CK] T1110.002 - Brute Force: Password Cracking</a><br><b>Tags:</b> LastPass, PBKDF2, Iteration count, Brute force, Data breach</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.malwarebytes.com/blog/threat-intelligence/2023/01/crypto-inspired-magecart-skimmer-surfaces-via-digital-crime-haven" target="_blank">Crypto-Inspired Magecart Skimmer Surfaces via Digital Crime Haven</a></h3>

<p>(published: January 9, 2023)</p>

<p>A new skimming campaign using the Mr.SNIFFA framework was detected by Malwarebytes researchers. For its domains, the campaign utilizes the theme of cryptocurrency and public figures known in the cryptocurrency industry. Judging from the domain naming and hosting information, the same actor may be involved in crypto giveaway scams. Russian-based hosting provider DDoS-Guard hosts these domains together with other threats including Bitcoin mixers, carding and crimeware sites, fake e-commerce shops, and malware distribution sites.<br><b>Analyst Comment:</b> Site administrators should be aware of supply-chain dependencies and remove ones that are unsupported and/or abandoned. Keep your systems updated and secure the administrator panel with two-factor authentication or other access restrictions. If your site was infected, perform a core file integrity check, query for any files containing the same injection, and check any recently modified or added files. All known network indicators associated with this campaign are available in the Anomali platform and customers are advised to block these on their infrastructure.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/attackpattern/9591" target="_blank">[MITRE ATT&amp;CK] T1027 - Obfuscated Files Or Information</a> | <a href="https://ui.threatstream.com/attackpattern/9638" target="_blank">[MITRE ATT&amp;CK] T1105 - Ingress Tool Transfer</a><br><b>Tags:</b> Magecart, malware-type:Skimmer, Cryptocurrency, Mr.SNIFFA, target-industry:E-commerce, Credit card data, DDoS-Guard</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacker stole credit cards from the website of Canada’s largest alcohol retailer LCBO]]></title>
<description><![CDATA[The Canadian Liquor Control Board of Ontario (LCBO), the largest beverage alcohol retailer in the country, disclosed Magecart attack. Canadian Liquor Control Board of Ontario (LCBO), the largest beverage alcohol retailer in the country, disclosed a Magecart attack on January 10, 2023. Threat acto...]]></description>
<link>https://tsecurity.de/de/1770230/hacking/hacker-stole-credit-cards-from-the-website-of-canadas-largest-alcohol-retailer-lcbo/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1770230/hacking/hacker-stole-credit-cards-from-the-website-of-canadas-largest-alcohol-retailer-lcbo/</guid>
<pubDate>Sun, 15 Jan 2023 17:16:21 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The Canadian Liquor Control Board of Ontario (LCBO), the largest beverage alcohol retailer in the country, disclosed Magecart attack. Canadian Liquor Control Board of Ontario (LCBO), the largest beverage alcohol retailer in the country, disclosed a Magecart attack on January 10, 2023. Threat actors compromised the Canadian Liquor Control Board of Ontario’s website and injected […]</p>
<p>The post <a rel="nofollow" href="https://securityaffairs.com/140823/data-breach/lcbo-magecart-attack.html">Hacker stole credit cards from the website of Canada’s largest alcohol retailer LCBO</a> appeared first on <a rel="nofollow" href="https://securityaffairs.com/">Security Affairs</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researchers Find 'Digital Crime Haven' While Investigating Magecart Activity]]></title>
<description><![CDATA[A security vendor's investigation of infrastructure associated with a new, crypto-focused Magecart skimmer leads to discovery of cryptoscam sites, malware distribution marketplace, Bitcoin mixers, and more.]]></description>
<link>https://tsecurity.de/de/1767434/it-security-nachrichten/researchers-find-digital-crime-haven-while-investigating-magecart-activity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1767434/it-security-nachrichten/researchers-find-digital-crime-haven-while-investigating-magecart-activity/</guid>
<pubDate>Fri, 13 Jan 2023 00:45:58 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A security vendor's investigation of infrastructure associated with a new, crypto-focused Magecart skimmer leads to discovery of cryptoscam sites, malware distribution marketplace, Bitcoin mixers, and more.]]></content:encoded>
</item>
<item>
<title><![CDATA[Neues digitales Verbrecherparadies entdeckt]]></title>
<description><![CDATA[Das Threat Intelligence Team von Malwarebytes hat einen Magecart-Skimmer identifiziert, der das mr.SNIFFA-Toolkit nutzt und auf E-Commerce-Webseiten und deren Kunden abzielt.

Tags: #Cyber Crime | #Malware | #Skimmer]]></description>
<link>https://tsecurity.de/de/1763018/it-security-nachrichten/neues-digitales-verbrecherparadies-entdeckt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1763018/it-security-nachrichten/neues-digitales-verbrecherparadies-entdeckt/</guid>
<pubDate>Tue, 10 Jan 2023 13:16:16 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2023/01/Kreditkarten-Shutterstock-64083652-1920.jpg" class="attachment-full size-full wp-post-image" alt="Kreditkartendiebstahl" decoding="async" loading="lazy" srcset="https://www.it-daily.net/wp-content/uploads/2023/01/Kreditkarten-Shutterstock-64083652-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2023/01/Kreditkarten-Shutterstock-64083652-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2023/01/Kreditkarten-Shutterstock-64083652-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2023/01/Kreditkarten-Shutterstock-64083652-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2023/01/Kreditkarten-Shutterstock-64083652-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Neues digitales Verbrecherparadies entdeckt 3"></p>
    Das Threat Intelligence Team von Malwarebytes hat einen Magecart-Skimmer identifiziert, der das mr.SNIFFA-Toolkit nutzt und auf E-Commerce-Webseiten und deren Kunden abzielt.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-crime">#Cyber Crime</a> | <a href="https://www.it-daily.net/thema/malware">#Malware</a> | <a href="https://www.it-daily.net/thema/skimmer">#Skimmer</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Weihnachtszeit - Angriffszeit: Cyberschutz für Einzelhändler - stores+shops]]></title>
<description><![CDATA[Mitarbeitende und Kund:innen über gängige Cybersecurity-Praktiken informieren und zum Melden verdächtiger Aktivitäten motivieren. Magecart-Attacken.]]></description>
<link>https://tsecurity.de/de/1742504/it-security-nachrichten/weihnachtszeit-angriffszeit-cyberschutz-fuer-einzelhaendler-stores-shops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1742504/it-security-nachrichten/weihnachtszeit-angriffszeit-cyberschutz-fuer-einzelhaendler-stores-shops/</guid>
<pubDate>Thu, 22 Dec 2022 01:46:13 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mitarbeitende und Kund:innen über gängige Cybersecurity-Praktiken informieren und zum Melden verdächtiger Aktivitäten motivieren. Magecart-Attacken.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anomali Cyber Watch: MuddyWater Hides Behind Legitimate Remote Administration Tools, Vice Society Tops Ransomware Threats to Education, Abandoned JavaScript Library Domain Pushes Web-Skimmers]]></title>
<description><![CDATA[The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: APT, Compromised websites, Education, Healthcare, Iran, Phishing, Ransomware, and Supply chain. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used ...]]></description>
<link>https://tsecurity.de/de/1731039/it-security-nachrichten/anomali-cyber-watch-muddywater-hides-behind-legitimate-remote-administration-tools-vice-society-tops-ransomware-threats-to-education-abandoned-javascript-library-domain-pushes-web-skimmers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1731039/it-security-nachrichten/anomali-cyber-watch-muddywater-hides-behind-legitimate-remote-administration-tools-vice-society-tops-ransomware-threats-to-education-abandoned-javascript-library-domain-pushes-web-skimmers/</guid>
<pubDate>Tue, 13 Dec 2022 17:31:16 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: <b>APT, Compromised websites, Education, Healthcare, Iran, Phishing, Ransomware,</b> and <b>Supply chain</b>. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.</p>

<p><img src="https://www.anomali.com/images/uploads/blog/acw-121322.png"><br><b>Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.</b></p>

<h2>Trending Cyber News and Threat Intelligence</h2>

<div class="trending-threat-article">
<h3><a href="https://www.deepinstinct.com/blog/new-muddywater-threat-old-kitten-new-tricks" target="_blank">New MuddyWater Threat: Old Kitten; New Tricks</a></h3>

<p>(published: December 8, 2022)</p>

<p>In 2020-2022, Iran-sponsored MuddyWater (Static Kitten, Mercury) group went through abusing several legitimate remote administration tools: RemoteUtilities, followed by ScreenConnect and then Atera Agent. Since September 2022, a new campaign attributed to MuddyWater uses spearphishing to deliver links to archived MSI files with yet another remote administration tool: Syncro. Deep Instinct researchers observed the targeting of Armenia, Azerbaijan, Egypt, Iraq, Israel, Jordan, Oman, Qatar, Tajikistan, and United Arab Emirates.<br><b>Analyst Comment:</b> Network defenders are advised to establish a baseline for typical running processes and monitor for remote desktop solutions that are not common in the organization.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/ttp/3905074" target="_blank">[MITRE ATT&amp;CK] Phishing - T1566</a> | <a href="https://ui.threatstream.com/ttp/947139" target="_blank">[MITRE ATT&amp;CK] Remote Access Tools - T1219</a><br><b>Tags:</b> mitre-group:MuddyWater, actor:Static Kitten, actor:Mercury, Iran, source-country:IR, APT, Cyberespionage, Ministry of Intelligence and Security, detection:Syncro, malware-type:RAT, file-type:MSI, file-type:ZIP, OneHub, Windows</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://blog.morphisec.com/babuk-ransomware-variant-major-attack" target="_blank">Babuk Ransomware Variant in Major New Attack</a></h3>

<p>(published: December 7, 2022)</p>

<p>In November 2022, Morphisec researchers identified a new ransomware variant based on the Babuk source code that was leaked in 2021. One modification is lowering detection by abusing the legitimate Microsoft signed process: DLL side-loading into NTSD.exe — a Symbolic Debugger tool for Windows. The mechanism to remove the available Shadow Copies was changed to using Component Object Model objects that execute Windows Management Instrumentation queries. This sample was detected in a large, unnamed manufacturing company where attackers had network access and were gathering information for two weeks. They have compromised the company’s domain controller and used it to distribute ransomware to all devices within the organization through Group Policy Object. The delivered BAT script bypasses User Account Control and executes a malicious MSI file that contains files for DLL side-loading and an open-source-based reflective loader (OCS files).<br><b>Analyst Comment:</b> The attackers strive to improve their evasion techniques, their malware on certain steps hides behind Microsoft-signed processes and exists primarily in device memory. It increases the need for the defense-in-depth approach and robust monitoring of your organization domain.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/ttp/2402531" target="_blank">[MITRE ATT&amp;CK] Data Encrypted for Impact - T1486</a> | <a href="https://ui.threatstream.com/ttp/3906164" target="_blank">[MITRE ATT&amp;CK] Abuse Elevation Control Mechanism - T1548</a> | <a href="https://ui.threatstream.com/ttp/3905764" target="_blank">[MITRE ATT&amp;CK] Hijack Execution Flow - T1574</a> | <a href="https://ui.threatstream.com/ttp/2402538" target="_blank">[MITRE ATT&amp;CK] Group Policy Modification - T1484</a> | <a href="https://ui.threatstream.com/ttp/3905778" target="_blank">[MITRE ATT&amp;CK] Impair Defenses - T1562</a> | <a href="https://ui.threatstream.com/ttp/947136" target="_blank">[MITRE ATT&amp;CK] Deobfuscate/Decode Files or Information - T1140</a> | <a href="https://ui.threatstream.com/ttp/2402535" target="_blank">[MITRE ATT&amp;CK] Service Stop - T1489</a> | <a href="https://ui.threatstream.com/ttp/2402534" target="_blank">[MITRE ATT&amp;CK] Inhibit System Recovery - T1490</a> | <a href="https://ui.threatstream.com/ttp/3905086" target="_blank">[MITRE ATT&amp;CK] Inter-Process Communication - T1559</a><br><b>Tags:</b> detection:Babuk, malware-type:Ransomware, Leaked source code, Russian-speaking, target-industry:Manufacturing, UAC bypass, COM objects, WMI queries, DLL side-loading, file-type:BAT, file-type:MSI, file-type:DLL, file-type:OCS, Windows</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.microsoft.com/en-us/security/blog/2022/12/06/dev-0139-launches-targeted-attacks-against-the-cryptocurrency-industry/" target="_blank">DEV-0139 Launches Targeted Attacks Against the Cryptocurrency Industry</a></h3>

<p>(published: December 6, 2022)</p>

<p>DEV-0139, a suspected state-sponsored group, has been involved in sophisticated targeting of the cryptocurrency investment industry. The social engineering phase of the attack started in October 2022. The attackers showed a deep knowledge of the targeted industry; they communicated with targets both in existing and in newly-created, attacker-controlled Telegram groups. After gaining initial trust, DEV-0139 delivers malicious macros in an XLS spearphishing attachment (alternative infection chain starts with a malicious MSI file). The attackers rely on DLL side-loading to execute the final payload, the Wolfic implant.<br><b>Analyst Comment:</b> Attackers go to a great length in their social engineering attacks and are creating fake professional profiles and groups. It’s important to combine anti-phishing awareness with system hardening. Do not disable runtime macro scanning by Antimalware Scan Interface. Implement rules to block Office applications from creating executable content, block Office communication application from creating child processes, and block Win32 API calls from Office macros.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/ttp/947205" target="_blank">[MITRE ATT&amp;CK] User Execution - T1204</a> | <a href="https://ui.threatstream.com/ttp/3904527" target="_blank">[MITRE ATT&amp;CK] Ingress Tool Transfer - T1105</a> | <a href="https://ui.threatstream.com/ttp/3904523" target="_blank">[MITRE ATT&amp;CK] Rogue Domain Controller - T1207</a> | <a href="https://ui.threatstream.com/ttp/947136" target="_blank">[MITRE ATT&amp;CK] Deobfuscate/Decode Files or Information - T1140</a> | <a href="https://ui.threatstream.com/ttp/3905074" target="_blank">[MITRE ATT&amp;CK] Phishing - T1566</a> | <a href="https://ui.threatstream.com/ttp/3906161" target="_blank">[MITRE ATT&amp;CK] Command and Scripting Interpreter - T1059</a> | <a href="https://ui.threatstream.com/ttp/3905769" target="_blank">[MITRE ATT&amp;CK] Native API - T1106</a> | <a href="https://ui.threatstream.com/ttp/947141" target="_blank">[MITRE ATT&amp;CK] Masquerading - T1036</a> | <a href="https://ui.threatstream.com/ttp/3905071" target="_blank">[MITRE ATT&amp;CK] Application Layer Protocol - T1071</a> | <a href="https://ui.threatstream.com/ttp/947259" target="_blank">[MITRE ATT&amp;CK] Data Encoding - T1132</a> | <a href="https://ui.threatstream.com/ttp/3904494" target="_blank">[MITRE ATT&amp;CK] Exfiltration Over C2 Channel - T1041</a><br><b>Tags:</b> actor:DEV-0139, target-industry:Cryptocurrency, Social engineering, Telegram, Cryptocurrency exchange, OKX Binance, Huobi, file-type:XLS, file-type:PNG, file-type:TMP, file-type:MSI, OpenDrive, detection:Wolfic</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://unit42.paloaltonetworks.com/vice-society-targets-education-sector/" target="_blank">Vice Society: Profiling a Persistent Threat to the Education Sector</a></h3>

<p>(published: December 6, 2022)</p>

<p>Among ransomware groups targeting the education sector in 2022, Vice Society was the most impactful with at least 33 educational institutions having been listed on the group’s data leak site. Other Vice Society’s common victims include healthcare and regional governments, followed by 15 other targeted industries. The group targeted 29 countries with approximately half of the cases being in the US and the UK. In their attacks, Vice Society uses commodity ransomware families such as the Linux-targeting variant of HelloKitty (FiveHands) and Zeppelin ransomware targeting Windows.<br><b>Analyst Comment:</b> Ransomware is an evolving threat that requires a defense-in-depth approach. For backups, follow the 3-2-1 rule: 3 copies, 2 devices, and 1 stored in a secure location. Data loss is manageable through segmentation, off-line storage, encrypting data at rest, and limiting the storage of personal and sensitive data.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/ttp/2402531" target="_blank">[MITRE ATT&amp;CK] Data Encrypted for Impact - T1486</a> | <a href="https://ui.threatstream.com/ttp/3905074" target="_blank">[MITRE ATT&amp;CK] Phishing - T1566</a> | <a href="https://ui.threatstream.com/ttp/947231" target="_blank">[MITRE ATT&amp;CK] Valid Accounts - T1078</a> | <a href="https://ui.threatstream.com/ttp/947138" target="_blank">[MITRE ATT&amp;CK] Exploit Public-Facing Application - T1190</a> | <a href="https://ui.threatstream.com/ttp/947077" target="_blank">[MITRE ATT&amp;CK] Windows Management Instrumentation - T1047</a> | <a href="https://ui.threatstream.com/ttp/947127" target="_blank">[MITRE ATT&amp;CK] Scheduled Task - T1053</a> | <a href="https://ui.threatstream.com/ttp/3906161" target="_blank">[MITRE ATT&amp;CK] Command and Scripting Interpreter - T1059</a> | <a href="https://ui.threatstream.com/ttp/3905040" target="_blank">[MITRE ATT&amp;CK] Create or Modify System Process - T1543</a> | <a href="https://ui.threatstream.com/ttp/3905768" target="_blank">[MITRE ATT&amp;CK] Boot or Logon Autostart Execution - T1547</a> | <a href="https://ui.threatstream.com/ttp/3905764" target="_blank">[MITRE ATT&amp;CK] Hijack Execution Flow - T1574</a> | <a href="https://ui.threatstream.com/ttp/947233" target="_blank">[MITRE ATT&amp;CK] Exploitation for Privilege Escalation - T1068</a> | <a href="https://ui.threatstream.com/ttp/947141" target="_blank">[MITRE ATT&amp;CK] Masquerading - T1036</a> | <a href="https://ui.threatstream.com/ttp/947142" target="_blank">[MITRE ATT&amp;CK] Process Injection - T1055</a> | <a href="https://ui.threatstream.com/ttp/947194" target="_blank">[MITRE ATT&amp;CK] Indicator Removal on Host - T1070</a> | <a href="https://ui.threatstream.com/ttp/947166" target="_blank">[MITRE ATT&amp;CK] Modify Registry - T1112</a> | <a href="https://ui.threatstream.com/ttp/2402543" target="_blank">[MITRE ATT&amp;CK] Virtualization/Sandbox Evasion - T1497</a> | <a href="https://ui.threatstream.com/ttp/3905778" target="_blank">[MITRE ATT&amp;CK] Impair Defenses - T1562</a> | <a href="https://ui.threatstream.com/ttp/3905348" target="_blank">[MITRE ATT&amp;CK] OS Credential Dumping - T1003</a> | <a href="https://ui.threatstream.com/ttp/947276" target="_blank">[MITRE ATT&amp;CK] Network Service Scanning - T1046</a> | <a href="https://ui.threatstream.com/ttp/2402537" target="_blank">[MITRE ATT&amp;CK] Domain Trust Discovery - T1482</a> | <a href="https://ui.threatstream.com/ttp/947162" target="_blank">[MITRE ATT&amp;CK] Remote Services - T1021</a> | <a href="https://ui.threatstream.com/ttp/947110" target="_blank">[MITRE ATT&amp;CK] Taint Shared Content - T1080</a> | <a href="https://ui.threatstream.com/ttp/3904544" target="_blank">[MITRE ATT&amp;CK] Lateral Tool Transfer - T1570</a> | <a href="https://ui.threatstream.com/ttp/947193" target="_blank">[MITRE ATT&amp;CK] Automated Exfiltration - T1020</a> | <a href="https://ui.threatstream.com/ttp/3904494" target="_blank">[MITRE ATT&amp;CK] Exfiltration Over C2 Channel - T1041</a> | <a href="https://ui.threatstream.com/ttp/947224" target="_blank">[MITRE ATT&amp;CK] Exfiltration Over Alternative Protocol - T1048</a> | <a href="https://ui.threatstream.com/ttp/3905082" target="_blank">[MITRE ATT&amp;CK] Exfiltration Over Web Service - T1567</a> | <a href="https://ui.threatstream.com/ttp/947139" target="_blank">[MITRE ATT&amp;CK] Remote Access Tools - T1219</a> | <a href="https://ui.threatstream.com/ttp/3297598" target="_blank">[MITRE ATT&amp;CK] Account Access Removal - T1531</a><br><b>Tags:</b> actor:Vice Society, malware-type:Ransomware, target-industry:Education, target-industry:Healthcare, detection:HelloKitty, file-type:ELF, Linux, detection:Zeppelin, Windows, PrintNightmare, CVE-2021-1675, CVE-2021-34527, target-country:US, target-country:UK</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://blog.sucuri.net/2022/12/infected-wordpress-plugins-redirect-to-push-notification-scam.html" target="_blank">Infected WordPress Plugins Redirect to Push Notification Scam</a></h3>

<p>(published: December 6, 2022)</p>

<p>A new malicious campaign targeting WordPress websites adds a listener to the whole page’s onclick event causing fraudulent redirects whenever a site visitor clicks on any link. Sucuri researchers discovered that the malicious script avoids detection by using obfuscation followed by unusual hexadecimal encoding of the binary string. Additionally this script detects open Developer Tools using multiple alternative methods, including checks for the following functions: checkByImageMethod, checkDevByScreenResize, detectDevByKeyboard, checkByFirebugMethod, and checkByProfileMethod.<br><b>Analyst Comment:</b> Website owners should pay attention to the feedback from website visitors as some malicious activity can be seen only by those who match certain profiling (such as the absence of dev tools). Update and patch your content management system, plugins, themes, and other extensible components.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a><br><b>Tags:</b> Redirect, WordPress, WordPress Plugin, Scam, Obfuscation, hex2dec, Compromised website</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://blog.jscrambler.com/defcon-skimming-a-new-batch-of-web-skimming-attacks" target="_blank">Defcon Skimming: A New Batch of Web Skimming Attacks</a></h3>

<p>(published: December 5, 2022)</p>

<p>Jscrambler researchers analyzed three new web-skimming clusters (categorized under Magecart umbrella term) dubbed Group X, Group Y, and Group Z. All three were disguising their malicious Javascript as Google code (Google Tag Manager or Google Analytics). Common tactics included code obfuscation, and referrer fingerprinting. Group X was able to mass-inject their code by exploiting a free, third-party JavaScript library that was discontinued in December 2014. They re-registered the abandoned domain name and used it to serve their skimming scripts via the URL that the old library was hosted at.<br><b>Analyst Comment:</b> Site administrators should be aware of supply-chain dependencies and remove ones that are unsupported and/or abandoned. Keep their systems updated and secure the administrator panel with two-factor authentication or other access restrictions. If your site was infected, perform a core file integrity check, query for any files containing the same injection, and check any recently modified or added files. All known network indicators associated with this campaign are available in the Anomali platform and customers are advised to block these on their infrastructure.<br><b>MITRE ATT&amp;CK:</b> <a href="https://ui.threatstream.com/ttp/947137" target="_blank">[MITRE ATT&amp;CK] Supply Chain Compromise - T1195</a> | <a href="https://ui.threatstream.com/ttp/947259" target="_blank">[MITRE ATT&amp;CK] Data Encoding - T1132</a> | <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a><br><b>Tags:</b> Supply chain, Web skimming, Cockpit, target-industry:E-commerce, Payment Card Industry, Credit card data, Google Analytics, JavaScript</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Where Baby Chips Come From, Proot, Magecart, Lockbit, Scattered Spider, & PhilTel - SWN #260]]></title>
<description><![CDATA[$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('YkQnSjpu1EA');
									});]]></description>
<link>https://tsecurity.de/de/1722757/it-security-video/where-baby-chips-come-from-proot-magecart-lockbit-scattered-spider-philtel-swn-260/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1722757/it-security-video/where-baby-chips-come-from-proot-magecart-lockbit-scattered-spider-philtel-swn-260/</guid>
<pubDate>Wed, 07 Dec 2022 00:16:18 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/YkQnSjpu1EA/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<div id="ytplayer_YkQnSjpu1EA"></div>

					<script>
									$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('YkQnSjpu1EA');
									}); 
									</script>]]></content:encoded>
</item>
<item>
<title><![CDATA[PhilTel | Baby Chips | Magecart | LockBit | Scattered Spider | & More – SWN260]]></title>
<description><![CDATA[$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('oOKtRp6QAaQ');
									});]]></description>
<link>https://tsecurity.de/de/1722517/it-security-video/philtel-baby-chips-magecart-lockbit-scattered-spider-more-swn260/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1722517/it-security-video/philtel-baby-chips-magecart-lockbit-scattered-spider-more-swn260/</guid>
<pubDate>Tue, 06 Dec 2022 20:31:22 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/oOKtRp6QAaQ/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<div id="ytplayer_oOKtRp6QAaQ"></div>

					<script>
									$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('oOKtRp6QAaQ');
									}); 
									</script>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Threat Actors Using Highly Evasive Skimmer to Steal Credit Card Data]]></title>
<description><![CDATA[Cybersecurity researchers at Cyble Research & Intelligence Labs have identified a tweet with a JavaScript skimmer that is mentioned by a security analyst on Twitter.  The Magecart threat group has created this skimmer that mainly steals data related to payments from the Magento website, which is ...]]></description>
<link>https://tsecurity.de/de/1621252/hacking/magecart-threat-actors-using-highly-evasive-skimmer-to-steal-credit-card-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1621252/hacking/magecart-threat-actors-using-highly-evasive-skimmer-to-steal-credit-card-data/</guid>
<pubDate>Mon, 05 Sep 2022 14:13:48 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="300" height="300" src="https://i1.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiE4XjUvePbnSXj248lRQdM7f-Rn6ECO8WPr_TQiIoKQRelpPXJOBpGPmxvNRvTyiWRuhq_kw7am8eJ6_XnEofQ0mvLO-ooPwYaJIXUcj1LpjIDKDkGi-yGlB1Dl0h3yIQguQIYc4DMX4ER_cDTKM1GnJfr1LGgc8WgHqA4ZvM6OaKibB-Iki9lo9bWSw/s16000/Magecart%20Threat%20Actors%20Using%20Highly%20Evasive%20Skimmer.png?fit=300%2C300&amp;ssl=1" class="webfeedsFeaturedVisual wp-post-image" alt="Magecart Threat Actors Using Highly Evasive Skimmer to Steal Credit Card Data" link_thumbnail=""><p>Cybersecurity researchers at Cyble Research &amp; Intelligence Labs have identified a tweet with a JavaScript skimmer that is mentioned by a security analyst on Twitter.  The Magecart threat group has created this skimmer that mainly steals data related to payments from the Magento website, which is an e-commerce platform. By exploiting the security flaws in […]</p>
<p>The post <a rel="nofollow" href="https://gbhackers.com/magecart-threat-actors-using-highly-evasive-skimmer/">Magecart Threat Actors Using Highly Evasive Skimmer to Steal Credit Card Data</a> appeared first on <a rel="nofollow" href="https://gbhackers.com/">GBHackers On Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Researchers analyzed a new JavaScript skimmer used by Magecart threat actors]]></title>
<description><![CDATA[Researchers from Cyble analyzed a new, highly evasive JavaScript skimmer used by Magecart threat actors. Cyble Research & Intelligence Labs started its investigation after seeing a post on Twitter a new JavaScript skimmer developed by the Magecart threat group used to target Magento e-commerce we...]]></description>
<link>https://tsecurity.de/de/1618733/hacking/researchers-analyzed-a-new-javascript-skimmer-used-by-magecart-threat-actors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1618733/hacking/researchers-analyzed-a-new-javascript-skimmer-used-by-magecart-threat-actors/</guid>
<pubDate>Thu, 01 Sep 2022 23:15:19 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Researchers from Cyble analyzed a new, highly evasive JavaScript skimmer used by Magecart threat actors. Cyble Research &amp; Intelligence Labs started its investigation after seeing a post on Twitter a new JavaScript skimmer developed by the Magecart threat group used to target Magento e-commerce websites. In Magecart attacks against Magento e-stores, attackers attempt to exploit vulnerabilities […]</p>
<p>The post <a rel="nofollow" href="https://securityaffairs.co/wordpress/135177/cyber-crime/javascript-skimmer-magecart.html">Researchers analyzed a new JavaScript skimmer used by Magecart threat actors</a> appeared first on <a rel="nofollow" href="https://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lean security 101: 3 tips for building your framework]]></title>
<description><![CDATA[Cobalt, Lazarus, MageCart, Evil, Revil — cybercrime syndicates spring up so fast it’s hard to keep track. Until they infiltrate your system. But you know what’s even more overwhelming than rampant cybercrime? Building your organization’s security framework. CIS, NIST, PCI DSS, HIPAA, HITrust, and...]]></description>
<link>https://tsecurity.de/de/1609820/it-security-nachrichten/lean-security-101-3-tips-for-building-your-framework/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1609820/it-security-nachrichten/lean-security-101-3-tips-for-building-your-framework/</guid>
<pubDate>Wed, 24 Aug 2022 05:33:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cobalt, Lazarus, MageCart, Evil, Revil — cybercrime syndicates spring up so fast it’s hard to keep track. Until they infiltrate your system. But you know what’s even more overwhelming than rampant cybercrime? Building your organization’s security framework. CIS, NIST, PCI DSS, HIPAA, HITrust, and the list goes on. Even if you had the resources to implement every relevant industry standard and control to a tee, you still couldn’t keep your company from getting caught up … <a href="https://www.helpnetsecurity.com/2022/08/24/lean-security-101-3-tips-for-building-your-framework/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a rel="nofollow" href="https://www.helpnetsecurity.com/2022/08/24/lean-security-101-3-tips-for-building-your-framework/">Lean security 101: 3 tips for building your framework</a> appeared first on <a rel="nofollow" href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How merchants can defend themselves against Magecart attacks]]></title>
<description><![CDATA[In this Help Net Security video, Angel Grant, VP of Security, F5, explains what Magecart attacks are and how they have evolved over the years. Grant illustrates how cybercriminals are leveraging such attacks, and offers defense tips.
The post How merchants can defend themselves against Magecart a...]]></description>
<link>https://tsecurity.de/de/1605758/it-security-nachrichten/how-merchants-can-defend-themselves-against-magecart-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1605758/it-security-nachrichten/how-merchants-can-defend-themselves-against-magecart-attacks/</guid>
<pubDate>Fri, 19 Aug 2022 06:03:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>In this Help Net Security video, Angel Grant, VP of Security, F5, explains what Magecart attacks are and how they have evolved over the years. Grant illustrates how cybercriminals are leveraging such attacks, and offers defense tips.</p>
<p>The post <a rel="nofollow" href="https://www.helpnetsecurity.com/2022/08/19/how-merchants-can-defend-themselves-against-magecart-attacks-video/">How merchants can defend themselves against Magecart attacks</a> appeared first on <a rel="nofollow" href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Lean Security 101: 3 Tips for Building Your Framework]]></title>
<description><![CDATA[Cobalt, Lazarus, MageCart, Evil, Revil — cybercrime syndicates spring up so fast it's hard to keep track. Until…they infiltrate your system. But you know what's even more overwhelming than rampant cybercrime?
Building your organization's security framework. 
CIS, NIST, PCI DSS, HIPAA, HITrust, an...]]></description>
<link>https://tsecurity.de/de/1603858/it-security-nachrichten/lean-security-101-3-tips-for-building-your-framework/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1603858/it-security-nachrichten/lean-security-101-3-tips-for-building-your-framework/</guid>
<pubDate>Wed, 17 Aug 2022 14:03:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cobalt, Lazarus, MageCart, Evil, Revil — cybercrime syndicates spring up so fast it's hard to keep track. Until…they infiltrate your system. But you know what's even more overwhelming than rampant cybercrime?
Building your organization's security framework. 
CIS, NIST, PCI DSS, HIPAA, HITrust, and the list goes on. Even if you had the resources to implement every relevant industry standard and]]></content:encoded>
</item>
<item>
<title><![CDATA[Restaurant Ordering Platforms Targeted By Hackers]]></title>
<description><![CDATA[Secure your business with CyberHoot Today!!! Sign Up Now Customers from over 300 restaurants’ had payment card details stolen in web-skimming campaigns targeting three online ordering platforms. Web-skimmers, or Magecart ...]]></description>
<link>https://tsecurity.de/de/1582650/it-security-nachrichten/restaurant-ordering-platforms-targeted-by-hackers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1582650/it-security-nachrichten/restaurant-ordering-platforms-targeted-by-hackers/</guid>
<pubDate>Tue, 26 Jul 2022 16:18:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Secure your business with CyberHoot Today!!! Sign Up Now Customers from over 300 restaurants’ had payment card details stolen in web-skimming campaigns targeting three online ordering platforms. Web-skimmers, or Magecart ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Hacks Food Ordering Systems to Steal Payment Data from Over 300 Restaurants]]></title>
<description><![CDATA[Three restaurant ordering platforms MenuDrive, Harbortouch, and InTouchPOS were the target of two Magecart skimming campaigns that resulted in the compromise of at least 311 restaurants.
The trio of breaches has led to the theft of more than 50,000 payment card records from these infected restaur...]]></description>
<link>https://tsecurity.de/de/1581267/it-security-nachrichten/magecart-hacks-food-ordering-systems-to-steal-payment-data-from-over-300-restaurants/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1581267/it-security-nachrichten/magecart-hacks-food-ordering-systems-to-steal-payment-data-from-over-300-restaurants/</guid>
<pubDate>Mon, 25 Jul 2022 13:01:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Three restaurant ordering platforms MenuDrive, Harbortouch, and InTouchPOS were the target of two Magecart skimming campaigns that resulted in the compromise of at least 311 restaurants.
The trio of breaches has led to the theft of more than 50,000 payment card records from these infected restaurants and posted for sale on the dark web.
"The online ordering platforms MenuDrive and Harbortouch]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Card Skimmers Hitting Restaurant-Ordering Systems – Expert Comments]]></title>
<description><![CDATA[A new Recorded Future threat analysis reveals that  300 restaurants and at least 50,000 payment cards have been compromised by two separate campaigns against MenuDrive, Harbortouch and InTouchPOS services. “The online ordering platforms MenuDrive and Harbortouch were targeted by the same Magecart...]]></description>
<link>https://tsecurity.de/de/1578750/it-security-nachrichten/magecart-card-skimmers-hitting-restaurant-ordering-systems-expert-comments/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1578750/it-security-nachrichten/magecart-card-skimmers-hitting-restaurant-ordering-systems-expert-comments/</guid>
<pubDate>Thu, 21 Jul 2022 17:33:43 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new Recorded Future threat analysis reveals that  300 restaurants and at least 50,000 payment cards have been compromised by two separate campaigns against MenuDrive, Harbortouch and InTouchPOS services. “The online ordering platforms MenuDrive and Harbortouch were targeted by the same Magecart campaign, resulting in e-skimmer infections on 80 restaurants using MenuDrive and 74 using […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Supply Chain Attacks Hit Hundreds of Restaurants]]></title>
<description><![CDATA[Tens of thousands of card details swiped from online users]]></description>
<link>https://tsecurity.de/de/1577948/it-security-nachrichten/magecart-supply-chain-attacks-hit-hundreds-of-restaurants/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1577948/it-security-nachrichten/magecart-supply-chain-attacks-hit-hundreds-of-restaurants/</guid>
<pubDate>Thu, 21 Jul 2022 09:16:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Tens of thousands of card details swiped from online users]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Serves Up Card Skimmers on Restaurant-Ordering Systems]]></title>
<description><![CDATA[300 restaurants and at least 50,000 payment cards compromised by two separate campaigns against MenuDrive, Harbortouch and InTouchPOS services.]]></description>
<link>https://tsecurity.de/de/1577004/it-security-nachrichten/magecart-serves-up-card-skimmers-on-restaurant-ordering-systems/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1577004/it-security-nachrichten/magecart-serves-up-card-skimmers-on-restaurant-ordering-systems/</guid>
<pubDate>Wed, 20 Jul 2022 12:48:18 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[300 restaurants and at least 50,000 payment cards compromised by two separate campaigns against MenuDrive, Harbortouch and InTouchPOS services.]]></content:encoded>
</item>
<item>
<title><![CDATA[Roaming Mantis, FBI, MageCart, CloudMensis, FreePBX, & Rich Mogull - SWN #224]]></title>
<description><![CDATA[$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('JdGCwgkp8Uo');
									});]]></description>
<link>https://tsecurity.de/de/1576244/it-security-video/roaming-mantis-fbi-magecart-cloudmensis-freepbx-rich-mogull-swn-224/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1576244/it-security-video/roaming-mantis-fbi-magecart-cloudmensis-freepbx-rich-mogull-swn-224/</guid>
<pubDate>Tue, 19 Jul 2022 21:33:42 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/JdGCwgkp8Uo/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<div id="ytplayer_JdGCwgkp8Uo"></div>

					<script>
									$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('JdGCwgkp8Uo');
									}); 
									</script>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ongoing Magecart Campaign Targets Online Ordering at Local Restaurants]]></title>
<description><![CDATA[More than 311 local eateries have been breached through online ordering platforms MenuDrive, Harbortouch, and InTouchPOS, impacting 50K records — and counting.]]></description>
<link>https://tsecurity.de/de/1576220/it-security-nachrichten/ongoing-magecart-campaign-targets-online-ordering-at-local-restaurants/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1576220/it-security-nachrichten/ongoing-magecart-campaign-targets-online-ordering-at-local-restaurants/</guid>
<pubDate>Tue, 19 Jul 2022 21:33:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[More than 311 local eateries have been breached through online ordering platforms MenuDrive, Harbortouch, and InTouchPOS, impacting 50K records — and counting.]]></content:encoded>
</item>
<item>
<title><![CDATA[Anomali Cyber Watch: API Hammering Confuses Sandboxes, Pirate Panda Wrote in Nim, Magecart Obfuscates Variable Names, and More]]></title>
<description><![CDATA[The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: API hammering, APT, China, Phishing, Ransomware, Russia, and Vulnerabilities. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs...]]></description>
<link>https://tsecurity.de/de/1554930/it-security-nachrichten/anomali-cyber-watch-api-hammering-confuses-sandboxes-pirate-panda-wrote-in-nim-magecart-obfuscates-variable-names-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1554930/it-security-nachrichten/anomali-cyber-watch-api-hammering-confuses-sandboxes-pirate-panda-wrote-in-nim-magecart-obfuscates-variable-names-and-more/</guid>
<pubDate>Tue, 28 Jun 2022 19:16:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: <b>API hammering, APT, China, Phishing, Ransomware, Russia,</b> and <b>Vulnerabilities</b>. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.</p>

<p><img src="https://www.anomali.com/images/uploads/blog/acw-062822.png"><br><b>Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.</b></p>

<h2>Trending Cyber News and Threat Intelligence</h2>

<div class="trending-threat-article">
<h3><a href="https://asec.ahnlab.com/en/35822/" target="_blank">Lockbit Ransomware Disguised as Copyright Claim E-mail Being Distributed</a></h3>

<p>(published: June 24, 2022)</p>

<p>ASEC researchers have released their analysis of a recent phishing campaign, active since February 2022. The campaign aims to infect users with Lockbit ransomware, using the pretense of a copyright claim as the phishing lure. The phishing email directs the recipient to open the attached zip file which contains a pdf of the infringed material. In reality, the pdf is a disguised NSIS executable which downloads and installs Lockbit. The ransomware is installed onto the desktop for persistence through desktop change or reboot. Prior to data encryption, Lockbit will delete the volume shadow copy to prevent data recovery, in addition to terminating a variety of services and processes to avoid detection.<br><b>Analyst Comment:</b> Never click on suspicious attachments or run any executables from suspicious emails. Copyright infringement emails are a common phishing lure. Such emails will be straight forward to rectify if legitimate. If a copyright email is attempting to coerce you into opening attachments, such emails should be treated with extreme caution.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3905074" target="_blank">[MITRE ATT&amp;CK] Phishing - T1566</a> | <a href="https://ui.threatstream.com/ttp/2402531" target="_blank">[MITRE ATT&amp;CK] Data Encrypted for Impact - T1486</a> | <a href="https://ui.threatstream.com/ttp/3905778" target="_blank">[MITRE ATT&amp;CK] Impair Defenses - T1562</a><br><b>Tags:</b> malware:Phishing, malware:Lockbit, Lockbit, Copyright, Ransomware</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://unit42.paloaltonetworks.com/api-hammering-malware-families/" target="_blank">There is More Than One Way To Sleep: Deep Dive into the Implementations of API Hammering by Various Malware Families</a></h3>

<p>(published: June 24, 2022)</p>

<p>Researchers at Palo Alto Networks have released their analysis of new BazarLoader and Zloader samples that utilize API Hammering as a technique to evade sandbox detection. API Hammering makes use of a large volume of Windows API calls to delay the execution of malicious activity to trick sandboxes into thinking the malware is benign. Whilst BazarLoader has utilized the technique in the past, this new variant creates large loops of benign API using a new process. Encoded registry keys within the malware are used for the calls and the large loop count is created from the offset of the first null byte of the first file in System32 directory. Zloader uses a different form of API Hammering to evade sandbox detection. Hardcoded within Zloader are four large functions with many smaller functions within. Each function makes an input/output (I/O) call to mimic the behavior of many legitimate processes.<br><b>Analyst Comment:</b> Defense in depth is the best defense against sophisticated malware. The Anomali Platform can assist in detection of malware and Match anomalous activity from all telemetry sources to provide the complete picture of adversary activity within your network.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/2402543" target="_blank">[MITRE ATT&amp;CK] Virtualization/Sandbox Evasion - T1497</a><br><b>Tags:</b> malware:BazarLoader, malware:Zloader, BazarLoader, Zloader, API Hammering</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.cisa.gov/uscert/ncas/analysis-reports/ar22-174a" target="_blank">Malware Analysis Report (AR22-174A)</a></h3>

<p>(published: June 23, 2022)</p>

<p>The Cybersecurity and Infrastructure Security Agency (CISA) have released a new malware analysis report on a malicious version of XMRIG Cryptominer which functions as a remote access trojan (RAT). The loader for the malware is only decrypted during execution, and is only executed within memory. C2 instructions for the RAT are received from a hardcoded ip address and always on port 443. Functionality for the RAT includes data exfiltration, desktop monitoring, keylogging, lateral movement and reverse shell access.<br><b>Analyst Comment:</b> Malware signatures are provided within the report; an up to date antivirus solution is a critical component of a robust defense in depth protection policy.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3904494" target="_blank">[MITRE ATT&amp;CK] Exfiltration Over C2 Channel - T1041</a> | <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a> | <a href="https://ui.threatstream.com/ttp/947243" target="_blank">[MITRE ATT&amp;CK] Input Capture - T1056</a> | <a href="https://ui.threatstream.com/ttp/947162" target="_blank">[MITRE ATT&amp;CK] Remote Services - T1021</a><br><b>Tags:</b> malware:XMRIG, XMRIG Cryptominer, XMRIG, RAT, CISA</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.rapid7.com/blog/post/2022/06/23/cve-2022-31749-watchguard-authenticated-arbitrary-file-read-write-fixed/" target="_blank">CVE-2022-31749: WatchGuard Authenticated Arbitrary File Read/Write (Fixed)</a></h3>

<p>(published: June 23, 2022)</p>

<p>Researchers at Rapid7 have reported that as of 23rd of June, a patch had been released for an exploit they discovered, recorded as CVE-2022-31749. The vulnerability allows users of a low privilege level of Watchguard Firebox or XTM users to read system files arbitrarily via argument injection if using SSH. If using the diagnose or import pac commands, arguments can be passed to ftpput and ftpget commands bypassing credential authentication. Whilst it is still unconfirmed if remote code execution (RCE) is possible with this vulnerability, proof of concept exploitations have shown that the configd-hash.xml file can be exfiltrated, containing user password hashes.<br><b>Analyst Comment:</b> A patch management policy will ensure that critical systems and vulnerabilities are patched in a timely manner with minimal downtime. Always change standard passwords, as they are weak and their hashes can be reversed into usable passwords by threat actors easily if they are stolen.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3906161" target="_blank">[MITRE ATT&amp;CK] Command and Scripting Interpreter - T1059</a> | <a href="https://ui.threatstream.com/ttp/3906164" target="_blank">[MITRE ATT&amp;CK] Abuse Elevation Control Mechanism - T1548</a> | <a href="https://ui.threatstream.com/ttp/947135" target="_blank">[MITRE ATT&amp;CK] Data from Local System - T1005</a> | <a href="https://ui.threatstream.com/ttp/947233" target="_blank">[MITRE ATT&amp;CK] Exploitation for Privilege Escalation - T1068</a><br><b>Tags:</b> vulnerability:CVE-2021-26855, Watchguard, XTM, CVE-2021-26855, ssh</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://research.checkpoint.com/2022/chinese-actor-takes-aim-armed-with-nim-language-and-bizarro-aes/" target="_blank">Chinese Actor Takes Aim, Armed with Nim Language and Bizzaro AES</a></h3>

<p>(published: June 22, 2022)</p>

<p>Checkpoint Researchers have identified a campaign of activity by a Chinese-speaking actor that is likely closely linked to the threat actor Tropic Trooper (PIRATE PANDA, APT23). Whilst the initial infection vector the group employs is unknown, the dropper being used after infection in this campaign is written in Nim and executes 2 instructions. The first is to download a Mandarin based app named SMS Bomber, used to conduct DDOS attacks on phones, but additionally it injects some Shellcode into a notepad.exe process, effectively making SMS Bomber a trojanized app. The Shellcode contacts an obfuscated IP before downloading the Yahoyah trojan and TClient backdoor, both previously used by Tropic Trooper. To disrupt analysis, strings that are usually encrypted with AES are instead encrypted with an inverted sequence of AES operations, resulting in an increase to researcher time to deobfuscate.<br><b>Analyst Comment:</b> A defense in depth approach to security is the best defense against APT groups. The Anomali Platform can assist in detecting APT activity within your networks, correlating your logs against global intelligence to detect malicious activity and launch investigations.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3904523" target="_blank">[MITRE ATT&amp;CK] Rogue Domain Controller - T1207</a> | <a href="https://ui.threatstream.com/ttp/947142" target="_blank">[MITRE ATT&amp;CK] Process Injection - T1055</a> | <a href="https://ui.threatstream.com/ttp/947259" target="_blank">[MITRE ATT&amp;CK] Data Encoding - T1132</a> | <a href="https://ui.threatstream.com/ttp/3906161" target="_blank">[MITRE ATT&amp;CK] Command and Scripting Interpreter - T1059</a><br><b>Tags:</b> actor:Tropic Trooper, actor:PIRATE PANDA, mitre-group:APT23, Tropic Trooper, PIRATE PANDA, APT23, malware:Yahoyah, malware:TClient, Yahoyah, TClient, AES, DDOS, SMS Bomber, Shellcode</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://blog.talosintelligence.com/2022/06/avoslocker-new-arsenal.html" target="_blank">Avos Ransomware Group Expands with New Attack Arsenal</a></h3>

<p>(published: June 21, 2022)</p>

<p>Cisco Talos researchers have documented the recent activity of Avos, a threat actor who is typically involved in Ransomware as a Service (RaaS) activities. The threat actor maintains AvosLocker as the ransomware of choice. Whilst spam campaigns are often the initial infection vector, from late 2021 onward Avos was seen exploiting Log4j vulnerabilities for arbitrary code injection, specifically CVE-2021-44228, CVE-2021-45046, CVE-2021-45105, CVE-2021-44832. Once the threat actors gain access to the victim’s machine, an encoded Powershell script is used to download AvosLocker. As of publication date, Avos is still operating on a RaaS model of operations.<br><b>Analyst Comment:</b> Critical vulnerabilities should be patched at the earliest possible opportunity to reduce the risk of exploitation. A patch management process should facilitate and oversee patch deployment to minimize downtime for vulnerable systems.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3905074" target="_blank">[MITRE ATT&amp;CK] Phishing - T1566</a> | <a href="https://ui.threatstream.com/ttp/947233" target="_blank">[MITRE ATT&amp;CK] Exploitation for Privilege Escalation - T1068</a> | <a href="https://ui.threatstream.com/ttp/3906161" target="_blank">[MITRE ATT&amp;CK] Command and Scripting Interpreter - T1059</a> | <a href="https://ui.threatstream.com/ttp/2402531" target="_blank">[MITRE ATT&amp;CK] Data Encrypted for Impact - T1486</a><br><b>Tags:</b> actor:Avos, Avos, AvosLocker, malware:AvosLocker, Powershell, Log4j, RaaS, Spam</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://securelist.com/toddycat/106799/" target="_blank">Unveiling an Unknown APT Actor Attacking High-Profile Entities in Europe and Asia</a></h3>

<p>(published: June 21, 2022)</p>

<p>Kaspersky researchers have released their analysis of a new APT group dubbed ToddyCat. Active since December 2020, ToddyCat has been linked to multiple campaigns exploiting ProxyLogon (CVE-2021-26855) to compromise Microsoft Exchange servers initially in Taiwan and Vietnam. New countries they have targeted include Afghanistan, India, Indonesia, Iran, Kyrgyzstan, Malaysia, Pakistan, Russia, Slovakia, Thailand, United Kingdom and Uzbekistan. Additionally, ToddyCat utilizes two unique, custom malware; a backdoor named Samurai and a trojan named Ninja. Samurai is a sophisticated backdoor operated on ports 80 and 443 and it allows for the deployment of additional malware (mostly Ninja) and lateral movement. It features anti-analysis functionality, being heavily encrypted and using complicated switch cases to confuse instruction flow. Ninja is a powerful trojan that boasts functionality including file system management, process enumeration, multiple reverse shell sessions and arbitrary code injection.<br><b>Analyst Comment:</b> Patch management policies should be enforced to ensure that critical vulnerabilities are patched as soon as possible. The Anomali platform can help identify malicious Indicators of Compromise within your system and provide insight into the threat actors targeting you.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3904549" target="_blank">[MITRE ATT&amp;CK] Remote Service Session Hijacking - T1563</a> | <a href="https://ui.threatstream.com/ttp/947138" target="_blank">[MITRE ATT&amp;CK] Exploit Public-Facing Application - T1190</a> | <a href="https://ui.threatstream.com/ttp/947276" target="_blank">[MITRE ATT&amp;CK] Network Service Scanning - T1046</a> | <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a> | <a href="https://ui.threatstream.com/ttp/947244" target="_blank">[MITRE ATT&amp;CK] Exploitation for Client Execution - T1203</a><br><b>Tags:</b> actor:ToddyCat, vulnerability:CVE-2021-26855, Samurai, Ninja, ToddyCat, ProxyLogon, target-region:Asia, target-region:Europe, malware:Samurai, malware:Ninja</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://blog.malwarebytes.com/threat-intelligence/2022/06/russias-apt28-uses-fear-of-nuclear-war-to-spread-follina-docs-in-ukraine/" target="_blank">Russia’s APT28 Uses Fear of Nuclear War to Spread Follina Docs in Ukraine</a></h3>

<p>(published: June 21, 2022)</p>

<p>Malwarebytes researchers have documented a new campaign by Russia-sponsored threat actor APT28 (Fancy Bear), utilizing Follina (CVE-2022-30190), a remote code execution vulnerability affecting Microsoft Support Diagnostic Tool (MSDT) to steal information. Phishing emails were distributed that contain a Microsoft Word document whose contents were copied from an Atlantic Council article. The document contained an embedded Document.xml.rels to retrieve a HTML file which, in turn, executes an encoded Powershell Script. Once executed, a custom stealer is installed which targets usernames, passwords and urls on Chrome and Edge, and cookie data on Firefox. Stolen data is exfiltrated to a C2 domain using IMAP email protocol.<br><b>Analyst Comment:</b> Never open documents from suspicious emails. Fear is a common tactic to pressure victims into making a hasty decision, thus scare attempts to open attachments should be treated with a high degree of caution.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947224" target="_blank">[MITRE ATT&amp;CK] Exfiltration Over Alternative Protocol - T1048</a> | <a href="https://ui.threatstream.com/ttp/3905074" target="_blank">[MITRE ATT&amp;CK] Phishing - T1566</a> | <a href="https://ui.threatstream.com/ttp/947259" target="_blank">[MITRE ATT&amp;CK] Data Encoding - T1132</a> | <a href="https://ui.threatstream.com/ttp/947216" target="_blank">[MITRE ATT&amp;CK] Exploitation for Credential Access - T1212</a> | <a href="https://ui.threatstream.com/ttp/3906161" target="_blank">[MITRE ATT&amp;CK] Command and Scripting Interpreter - T1059</a> | <a href="https://ui.threatstream.com/ttp/3297610" target="_blank">[MITRE ATT&amp;CK] Steal Web Session Cookie - T1539</a><br><b>Tags:</b> mitre-group:APT28, Fancy Bear, vulnerability:CVE-2022-30190, Atlantic Council, Russia, Follina, Powershell, Chrome, Edge, Firefox</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://blog.malwarebytes.com/threat-intelligence/2022/06/client-side-magecart-attacks-still-around-but-more-covert/" target="_blank">Client-Side Magecart Attacks Still Around, but More Covert </a></h3>

<p>(published: June 20, 2022)</p>

<p>Research from Malwarebytes has detected a new wave of Magecart skimmers, which have been active since November 2021. These still function client side, but come with additional functionality. Variable names, once in plain text with names reflecting the data they contained, are now obfuscated to make analysis more difficult. Additionally, the skimmers check for the presence of a VM, stopping their execution if they detect a sandbox.<br><b>Analyst Comment:</b> Ensure endpoint security is up to date and security patches are installed in a timely manner to minimize the risk of skimmer injection. Monitor network traffic for strange behavior to detect possible C2 activity.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947243" target="_blank">[MITRE ATT&amp;CK] Input Capture - T1056</a> | <a href="https://ui.threatstream.com/ttp/3904494" target="_blank">[MITRE ATT&amp;CK] Exfiltration Over C2 Channel - T1041</a> | <a href="https://ui.threatstream.com/ttp/2402543" target="_blank">[MITRE ATT&amp;CK] Virtualization/Sandbox Evasion - T1497</a><br><b>Tags:</b> Magecart, skimmers, credential theft, sandbox evasion</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.bleepingcomputer.com/news/security/microsoft-365-credentials-targeted-in-new-fake-voicemail-campaign/" target="_blank">Microsoft 365 Credentials Targeted in New Fake Voicemail Campaign</a></h3>

<p>(published: June 20, 2022)</p>

<p>ZScaler researchers have discovered a new phishing campaign targeting organizations within the US, specifically those within the Healthcare, Manufacturing, Military and Security Software industries. The emails are routed through Japanese email services to spoof targeted organizations. Each phishing email contains a HTML attachment with a musical note inside the file text to masquerade as a voice note file. When opened, embedded Javascript within the file triggers, redirecting victims to a phishing site with a CAPTCHA security to feign legitimacy. Following this, a fake Microsoft login portal is presented that will steal any credentials entered.<br><b>Analyst Comment:</b> Never click on attachments from suspicious emails. Education is the best defense against phishing attacks. Always check the domain and url are correct before entering in any private or personal information. If you are logged in already, and you are asked to log in an additional time, it is a possible indicator that the website is illegitimate.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3905074" target="_blank">[MITRE ATT&amp;CK] Phishing - T1566</a> | <a href="https://ui.threatstream.com/ttp/947243" target="_blank">[MITRE ATT&amp;CK] Input Capture - T1056</a> | <a href="https://ui.threatstream.com/ttp/947205" target="_blank">[MITRE ATT&amp;CK] User Execution - T1204</a><br><b>Tags:</b> Phishing, Healthcare, Manufacturing, Military,Security Software, HTML, CAPTCHA, Microsoft, Javascript</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fresh Magecart Skimmer Attack Infrastructure Flagged by Analysts]]></title>
<description><![CDATA[Don't sleep on Magecart attacks, which security teams could miss by relying solely on automated crawlers and sandboxes, experts warn.]]></description>
<link>https://tsecurity.de/de/1549211/it-security-nachrichten/fresh-magecart-skimmer-attack-infrastructure-flagged-by-analysts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1549211/it-security-nachrichten/fresh-magecart-skimmer-attack-infrastructure-flagged-by-analysts/</guid>
<pubDate>Wed, 22 Jun 2022 18:33:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Don't sleep on Magecart attacks, which security teams could miss by relying solely on automated crawlers and sandboxes, experts warn.]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart attacks are still around but are more difficult to detect]]></title>
<description><![CDATA[Researchers from Malwarebytes warns that the Magecart skimming campaign is active, but the attacks are more covert. Magecart threat actors have switched most of their operations server-side to avoid detection of security firms. However, Malwarebytes researchers warn that the Client-side Magecart ...]]></description>
<link>https://tsecurity.de/de/1548947/hacking/magecart-attacks-are-still-around-but-are-more-difficult-to-detect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1548947/hacking/magecart-attacks-are-still-around-but-are-more-difficult-to-detect/</guid>
<pubDate>Wed, 22 Jun 2022 14:01:08 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Researchers from Malwarebytes warns that the Magecart skimming campaign is active, but the attacks are more covert. Magecart threat actors have switched most of their operations server-side to avoid detection of security firms. However, Malwarebytes researchers warn that the Client-side Magecart attacks are still targeting organizations, but are more covert. The researchers recently uncovered two […]</p>
<p>The post <a rel="nofollow" href="https://securityaffairs.co/wordpress/132512/cyber-crime/magecart-attacks-difficult-detect.html">Magecart attacks are still around but are more difficult to detect</a> appeared first on <a rel="nofollow" href="https://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Newly Discovered Magecart Infrastructure Reveals the Scale of Ongoing Campaign]]></title>
<description><![CDATA[A newly discovered Magecart skimming campaign has its roots in a previous attack activity going all the way back to November 2021.
To that end, it has come to light that two malware domains identified as hosting credit card skimmer code — "scanalytic[.]org" and "js.staticounter[.]net" — are part ...]]></description>
<link>https://tsecurity.de/de/1548631/it-security-nachrichten/newly-discovered-magecart-infrastructure-reveals-the-scale-of-ongoing-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1548631/it-security-nachrichten/newly-discovered-magecart-infrastructure-reveals-the-scale-of-ongoing-campaign/</guid>
<pubDate>Wed, 22 Jun 2022 10:18:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A newly discovered Magecart skimming campaign has its roots in a previous attack activity going all the way back to November 2021.
To that end, it has come to light that two malware domains identified as hosting credit card skimmer code — "scanalytic[.]org" and "js.staticounter[.]net" — are part of a broader infrastructure used to carry out the intrusions, Malwarebytes said in a Tuesday analysis]]></content:encoded>
</item>
<item>
<title><![CDATA[6/21/2022]]></title>
<description><![CDATA[Biden Signs Cyber Bills Into Law Former NSA Chief Warns of Russian Cyberattacks Against U.S. Financial SectorRussian Gov’t Hackers Hit Ukraine With Cobalt Strike, CredoMap MalwareKazakhstan Gov’t Used Spyware Against ProtestersReport: Daycare Monitoring Apps Are ‘Dangerously Insecure’ Magecart At...]]></description>
<link>https://tsecurity.de/de/1548346/it-security-nachrichten/6212022/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1548346/it-security-nachrichten/6212022/</guid>
<pubDate>Wed, 22 Jun 2022 05:18:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Biden Signs Cyber Bills Into Law Former NSA Chief Warns of Russian Cyberattacks Against U.S. Financial SectorRussian Gov’t Hackers Hit Ukraine With Cobalt Strike, CredoMap MalwareKazakhstan Gov’t Used Spyware Against ProtestersReport: Daycare Monitoring Apps Are ‘Dangerously Insecure’ Magecart Attacks Are Still Around: And They Are Becoming More StealthyHPE Tackles Cyber Skills Shortage with Hands-On ExperiencePhishing … <a href="https://thecyberbeat.com/2022/06/22/6-21-2022/" class="more-link">Continue reading <span class="screen-reader-text">6/21/2022</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart tarnt sich besser | ZDNet.de]]></title>
<description><![CDATA[... Website eingebettet ist, fängt dann die vom Kunden eingegebenen Kartendaten ab und sendet sie an einen vom Angreifer kontrollierten Server.]]></description>
<link>https://tsecurity.de/de/1547745/windows-server/magecart-tarnt-sich-besser-zdnetde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1547745/windows-server/magecart-tarnt-sich-besser-zdnetde/</guid>
<pubDate>Tue, 21 Jun 2022 15:05:32 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[... Website eingebettet ist, fängt dann die vom Kunden eingegebenen Kartendaten ab und sendet sie an einen vom Angreifer kontrollierten <b>Server</b>.]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart tarnt sich besser]]></title>
<description><![CDATA[Magecart-Angriffe gibt es immer noch. Und sie werden immer unauffälliger. Sie sind vielleicht nicht mehr das heißeste Thema im Bereich der Cybersicherheit, aber sie sind immer noch ein Problem.]]></description>
<link>https://tsecurity.de/de/1547570/it-nachrichten/magecart-tarnt-sich-besser/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1547570/it-nachrichten/magecart-tarnt-sich-besser/</guid>
<pubDate>Tue, 21 Jun 2022 13:05:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Magecart-Angriffe gibt es immer noch. Und sie werden immer unauffälliger. Sie sind vielleicht nicht mehr das heißeste Thema im Bereich der Cybersicherheit, aber sie sind immer noch ein Problem.]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart attacks are still around. And they are becoming more stealthy]]></title>
<description><![CDATA[They might not be the hottest topics in the cybersecurity realm anymore, but they are still a problem.]]></description>
<link>https://tsecurity.de/de/1547469/it-security-nachrichten/magecart-attacks-are-still-around-and-they-are-becoming-more-stealthy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1547469/it-security-nachrichten/magecart-attacks-are-still-around-and-they-are-becoming-more-stealthy/</guid>
<pubDate>Tue, 21 Jun 2022 11:48:38 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[They might not be the hottest topics in the cybersecurity realm anymore, but they are still a problem.]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart - The Rising Threat to e-commerce Websites - Shrutirupa Banerjiee]]></title>
<description><![CDATA[$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('ECzjTctzWzA');
									});]]></description>
<link>https://tsecurity.de/de/1530730/it-security-video/magecart-the-rising-threat-to-e-commerce-websites-shrutirupa-banerjiee/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1530730/it-security-video/magecart-the-rising-threat-to-e-commerce-websites-shrutirupa-banerjiee/</guid>
<pubDate>Sat, 04 Jun 2022 18:34:44 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/ECzjTctzWzA/hqdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<div id="ytplayer_ECzjTctzWzA"></div>

					<script>
									$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('ECzjTctzWzA');
									}); 
									</script>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Bad Guys Win – Analysis of 10,000 Magecart Vulnerabilities]]></title>
<description><![CDATA[$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('Knk_iPrNSsk');
									});]]></description>
<link>https://tsecurity.de/de/1530706/it-security-video/the-bad-guys-win-analysis-of-10000-magecart-vulnerabilities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1530706/it-security-video/the-bad-guys-win-analysis-of-10000-magecart-vulnerabilities/</guid>
<pubDate>Sat, 04 Jun 2022 18:34:43 +0200</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/Knk_iPrNSsk/hqdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<div id="ytplayer_Knk_iPrNSsk"></div>

					<script>
									$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('Knk_iPrNSsk');
									}); 
									</script>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anomali Cyber Watch: TURLA’s New Phishing-Based Reconnaissance Campaign in Eastern Europe, Unknown APT Group Has Targeted Russia Repeatedly Since Ukraine Invasion and More]]></title>
<description><![CDATA[The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: Chromeloader, Goodwill, MageCart, Saitama, Turla and Yashma. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential ma...]]></description>
<link>https://tsecurity.de/de/1528421/it-security-nachrichten/anomali-cyber-watch-turlas-new-phishing-based-reconnaissance-campaign-in-eastern-europe-unknown-apt-group-has-targeted-russia-repeatedly-since-ukraine-invasion-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1528421/it-security-nachrichten/anomali-cyber-watch-turlas-new-phishing-based-reconnaissance-campaign-in-eastern-europe-unknown-apt-group-has-targeted-russia-repeatedly-since-ukraine-invasion-and-more/</guid>
<pubDate>Sat, 04 Jun 2022 07:04:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: <b>Chromeloader, Goodwill, MageCart, Saitama, Turla</b> and <b>Yashma</b>. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.</p>

<p><img src="https://www.anomali.com/images/uploads/blog/acw-060122.png"><br><b>Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.</b></p>

<h2>Trending Cyber News and Threat Intelligence</h2>

<div class="trending-threat-article">
<h3><a href="https://blog.sucuri.net/2022/05/credit-card-stealer-targets-psigate-payment-gateway-software.html" target="_blank">Credit Card Stealer Targets PsiGate Payment Gateway Software</a></h3>

<p>(published: May 25, 2022)</p>

<p>Sucuri Researchers have detailed their findings on a MageCart skimmer that had been discovered within the Magento payment portal. Embedded within the core_config_data table of Magento’s database, the skimmer was obfuscated and encoded with CharCode. Once deobfuscated, a JavaScript credit card stealer was revealed. The stealer is able to acquire text and fields that are submitted to the payment page, including credit card numbers and expiry dates. Once stolen, a synchronous AJAX is used to exfiltrate the data.<br><b>Analyst Comment:</b> Harden endpoint security and utilize firewalls to block suspicious activity to help mitigate against skimmer injection. Monitor network traffic to identify anomalous behavior that may indicate C2 activity.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3904494" target="_blank">[MITRE ATT&amp;CK] Exfiltration Over C2 Channel - T1041</a> | <a href="https://ui.threatstream.com/ttp/947259" target="_blank">[MITRE ATT&amp;CK] Data Encoding - T1132</a> | <a href="https://ui.threatstream.com/ttp/947243" target="_blank">[MITRE ATT&amp;CK] Input Capture - T1056</a><br><b>Tags:</b> MageCart, skimmer, JavaScript Magento, PsiGate, AJAX</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://blog.malwarebytes.com/threat-intelligence/2022/05/how-the-saitama-backdoor-uses-dns-tunnelling/" target="_blank">How the Saitama Backdoor uses DNS Tunneling</a></h3>

<p>(published: May 25, 2022)</p>

<p>MalwareBytes Researchers have released their report detailing the process behind which the Saitama backdoor utilizes DNS tunneling to stealthy communicate with command and control (C2) infrastructure. DNS tunneling is an effective way to hide C2 communication as DNS traffic serves a vital function in modern day internet communications thus blocking DNS traffic is almost never done. Saitama formats its DNS lookups with the structure of a domain consisting of message, counter . root domain. Data is encoded utilizing a hardcoded base36 alphabet. There are four types of messages that Saitama can send using this method: Make Contact to establish communication with a C2 domain, Ask For Command to get the expected size of the payload to be delivered, Get A Command in which Saitama will make Receive requests to retrieve payloads and instructions and finally Run The Command in which Saitama runs the instructions or executes the payload and sends the results to the established C2.<br><b>Analyst Comment:</b> Implement an effective DNS filtering system to block malicious queries. Furthermore, maintaining a whitelist of allowed applications for installation will assist in preventing malware like Saitama from being installed.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947259" target="_blank">[MITRE ATT&amp;CK] Data Encoding - T1132</a> | <a href="https://ui.threatstream.com/ttp/3904494" target="_blank">[MITRE ATT&amp;CK] Exfiltration Over C2 Channel - T1041</a><br><b>Tags:</b> C2, DNS, Saitama, backdoor, base36, DNS tunneling</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.trendmicro.com/en_us/research/22/e/new-linux-based-ransomware-cheerscrypt-targets-exsi-devices.html" target="_blank">New Linux-Based Ransomware Cheerscrypt Targets ESXi Devices</a></h3>

<p>(published: May 25, 2022)</p>

<p>A new ransomware named Cheers (Cheerscrypt) has been targeting vulnerable VMware ESXi servers since March 2022. It uses SOSEMANUK stream cipher to encrypt files and ECDH to generate the SOSEMANUK key. Cheers targets its victims with double extortion for decryption and for keeping the stolen data private.<br><b>Analyst Comment:</b> Server virtualization systems are heavily targeted and require protection and disaster recovery planning. Backup important information, and keep your systems updated and securely configured.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/2402531" target="_blank">[MITRE ATT&amp;CK] Data Encrypted for Impact - T1486</a> | <a href="https://ui.threatstream.com/ttp/2402535" target="_blank">[MITRE ATT&amp;CK] Service Stop - T1489</a><br><b>Tags:</b> Cheerscrypt, Cheers, Ransomware, Double extortion, VMware ESXi, Linux</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://redcanary.com/blog/chromeloader/" target="_blank">ChromeLoader: a Pushy Malvertiser</a></h3>

<p>(published: May 25, 2022)</p>

<p>Red Canary researchers monitored the ChromeLoader browser hijacker since February 2022 and noticed an increase in its activity in May 2022. Under the pretense of a cracked video game or pirated movie or TV show, the user is enticed to open an ISO file and launch the ChromeLoader executable inside. For persistence through a scheduled task, it bypasses the Windows Task Scheduler (schtasks.exe) by loading the Task Scheduler COM API, along with a cross-process injection into Service Host Process (svchost.exe). ChromeLoader uses PowerShell to inject itself into the Chrome browser in the form of a malicious extension. ChromeLoader version targeting MacOS drops payloads for either Chrome or Safari.<br><b>Analyst Comment:</b> Check application reviews, developer information, and scan a downloaded file before making use of it. Defenders can monitor for PowerShell spawning chrome.exe containing load-extension and AppData\Local as a parameter.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947129" target="_blank">[MITRE ATT&amp;CK] Browser Extensions - T1176</a> | <a href="https://ui.threatstream.com/ttp/947127" target="_blank">[MITRE ATT&amp;CK] Scheduled Task - T1053</a> | <a href="https://ui.threatstream.com/ttp/3906161" target="_blank">[MITRE ATT&amp;CK] Command and Scripting Interpreter - T1059</a> | <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a> | <a href="https://ui.threatstream.com/ttp/947136" target="_blank">[MITRE ATT&amp;CK] Deobfuscate/Decode Files or Information - T1140</a><br><b>Tags:</b> ChromeLoader, Browser hijacker, Loader, PowerShell, Chrome, Windows, Safari, MacOS</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.crowdstrike.com/blog/how-to-hunt-for-decisivearchitect-and-justforfun-implant/" target="_blank">Hunting a Global Telecommunications Threat: DecisiveArchitect and Its Custom Implant JustForFun</a></h3>

<p>(published: May 25, 2022)</p>

<p>CrowdStrike researchers analyze the BPFDoor (JustForFun) implant used by threat group Red Menshen (DecisiveArchitect). They observe activity dating back to 2019 targeting logistic and telecommunication companies to steal targeted information such as call detail records (CDRs) or information relating to specific phone numbers. The actors do interact with Windows systems in initial stages and use Windows post-exploitation tools after moving laterally later, but their main tool is the BFDoor implant that achieves stealthy persistence on Linux and Oracle Solaris systems.<br><b>Analyst Comment:</b> To look for a BPFDoor infection on Linux, start with identifying a spoofed command line and associated open files. On Solaris, look for process strings indicating a process running with a packet filter, and processes that loaded the libpcap library. Check for typical Red Menshen file paths provided by CrowdStrike.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3905776" target="_blank">[MITRE ATT&amp;CK] Hide Artifacts - T1564</a> | <a href="https://ui.threatstream.com/ttp/3905040" target="_blank">[MITRE ATT&amp;CK] Create or Modify System Process - T1543</a> | <a href="https://ui.threatstream.com/ttp/947081" target="_blank">[MITRE ATT&amp;CK] Logon Scripts - T1037</a><br><b>Tags:</b> BPFDoor, Telecommunications, Logistics, DecisiveArchitect, Red Menshen, JustForFun, CVE-2019-3010, China, Windows, ldapdomaindump, Impacket, Solaris, Linux</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://blogs.blackberry.com/en/2022/05/yashma-ransomware-tracing-the-chaos-family-tree" target="_blank">Yashma Ransomware, Tracing the Chaos Family Tree</a></h3>

<p>(published: May 24, 2022)</p>

<p>The Blackberry Research and Intelligence Team have released their research tracing and documenting the evolution of the Chaos ransomware family tree. There are currently six versions of Chaos, with Chaos v1.0 being a rebrand of the .NET version of Ryuk and the latest Chaos v6.0 being named Yashma. Chaos has ties to the Onyx ransomware as well, with the creator of Chaos claiming the Onyx was developed using Chaos v4.0 as a base. Blackberry researchers document the change to the ransomware’s functionality over its iterations, with early versions only destroying data, essentially making it a wiper. Later versions of Chaos were able to encrypt data, with Chaos v5.0 overcoming the v4.0 limitation of only encrypting files less than 2MB. The current version, Yashma, now includes functionality to detect the victim’s country and prevent itself from running if it detects specific languages and the ability to stop various services on the victim machine.<br><b>Analyst Comment:</b> Ransomware is a threat that is always evolving. Maintain a defense in depth security posture to maximize your protection against malware. Enforce a backup policy to ensure that you are able to recover quickly from possible attacks and minimize downtime. Check to see if there are any decryptors available before considering paying ransom.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/2402541" target="_blank">[MITRE ATT&amp;CK] Data Destruction - T1485</a> | <a href="https://ui.threatstream.com/ttp/2402531" target="_blank">[MITRE ATT&amp;CK] Data Encrypted for Impact - T1486</a> | <a href="https://ui.threatstream.com/ttp/3905778" target="_blank">[MITRE ATT&amp;CK] Impair Defenses - T1562</a><br><b>Tags:</b> Yashma, Onyx, Ryuk, ransomware, Chaos, wiper</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://cloudsek.com/threatintelligence/goodwill-ransomware-forces-victims-to-donate-to-the-poor-and-provides-financial-assistance-to-patients-in-need/" target="_blank">Unknown APT Group Has Targeted Russia Repeatedly Since Ukraine Invasion</a></h3>

<p>(published: May 24, 2022)</p>

<p>Malwarebytes researchers discovered an unknown Advanced Persistent Threat (APT) group (possibly China-sponsored) targeting Russian government entities. At least four spearphishing campaigns have been recorded since late February 2022, covering various topics for the lures: Cybersecurity instructions, Interactive map of Ukraine, and even job vacancy at Saudi Aramco. The final payload, a novel remote access trojan (RAT) employs a number of anti-analysis techniques. Those are control flow flattening, using XOR for string obfuscation, implementing command-and-control (C2) HTTPS over raw sockets, and using the WolfSSL library to implement SSL itself. The last two measures cause Any.run and Fiddler to fail to capture the HTTPS requests made by the malware.<br><b>Analyst Comment:</b> Defenders should teach their users to avoid unwarranted emails and be suspicious when an attachment asks to enable editing. Analysts dealing with a sample with control code flattening can deobfuscate with the D810 plugin for IDA.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947250" target="_blank">[MITRE ATT&amp;CK] Standard Non-Application Layer Protocol - T1095</a> | <a href="https://ui.threatstream.com/ttp/2336976" target="_blank">[MITRE ATT&amp;CK] Template Injection - T1221</a> | <a href="https://ui.threatstream.com/ttp/3905074" target="_blank">[MITRE ATT&amp;CK] Phishing - T1566</a> | <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a> | <a href="https://ui.threatstream.com/ttp/947136" target="_blank">[MITRE ATT&amp;CK] Deobfuscate/Decode Files or Information - T1140</a> | <a href="https://ui.threatstream.com/ttp/3904527" target="_blank">[MITRE ATT&amp;CK] Ingress Tool Transfer - T1105</a> | <a href="https://ui.threatstream.com/ttp/947082" target="_blank">[MITRE ATT&amp;CK] System Owner/User Discovery - T1033</a> | <a href="https://ui.threatstream.com/ttp/947195" target="_blank">[MITRE ATT&amp;CK] File and Directory Discovery - T1083</a> | <a href="https://ui.threatstream.com/ttp/947145" target="_blank">[MITRE ATT&amp;CK] Signed Binary Proxy Execution - T1218</a><br><b>Tags:</b> APT, Russia, target-country:RU, Cyberespionage, Spearphishing, RAT, Typosquatting, Deep Panda, Windows, VBS, DLL, OLLVM, Control flow flattening, Blake2b-256, WolfSSL, Rostec, Government, Defense, Military, China, Ukraine</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://cloudsek.com/threatintelligence/goodwill-ransomware-forces-victims-to-donate-to-the-poor-and-provides-financial-assistance-to-patients-in-need/" target="_blank">GoodWill Ransomware Forces Victims to Donate to the Poor and Provides Financial Assistance to Patients in Need</a></h3>

<p>(published: May 24, 2022)</p>

<p>GoodWill Ransomware was first identified in March 2022. It is attributed to an India-based actor based on its infrastructure, email provided, and an error comment string in Hindi. Instead of demanding a monetary payment from a victim whose files were encrypted, it makes three demands to help people in need. It demands new clothes/blankets for the homeless, to take five poor children to Dominos, KFC, or Pizza Hut, and to pay a hospital bill for somebody who cannot afford it.<br><b>Analyst Comment:</b> There are no known victims of the GoodWill ransomware. Despite its “good” intentions, file encryptions can cause shutdown of the targeted company's operations and accompanied revenue loss. Organizations should enforce data protection, backup, and recovery measures.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/2402531" target="_blank">[MITRE ATT&amp;CK] Data Encrypted for Impact - T1486</a> | <a href="https://ui.threatstream.com/ttp/2402543" target="_blank">[MITRE ATT&amp;CK] Virtualization/Sandbox Evasion - T1497</a><br><b>Tags:</b> GoodWill, Ransomware, Hindi, Hacktivism, India, source-country:IN</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://blog.sekoia.io/turla-new-phishing-campaign-eastern-europe/" target="_blank">TURLA’s New Phishing-Based Reconnaissance Campaign in Eastern Europe</a></h3>

<p>(published: May 23, 2022)</p>

<p>Sekoia researchers expanded on indicators shared by Google and discovered a new campaign by Russia-sponsored group Turla. Threat actors use typosquatted domains to host documents that are used for reconnaissance. Embedded external PNG file is being requested from an attacker-controlled server via the HTTP protocol. It allows the attackers to collect the victim's IP address and the Word application version and type. Phishing documents were themed around topics of war and sanctions on Russia and targeting included Austrian Federal Economic Chamber, Baltic Defence College, and NATO Joint Advanced Distributed Learning.<br><b>Analyst Comment:</b> It’s important to keep a watchful eye on suspicious domain registration activity related to your brand and companies from your supply chain. Anomali Targeted Threat Monitoring service can help you detect and block such suspicious domain registrations.<br><b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/3905074" target="_blank">[MITRE ATT&amp;CK] Phishing - T1566</a><br><b>Tags:</b> Turla, Reconnaissance, Phishing, Typosquatting, Russia, source-country:RU, FSB</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart hackers hide stolen credit card data into images and bogus CSS files]]></title>
<description><![CDATA[Magecart hackers continuously improve their exfiltration techniques to evade detection, they are hiding stolen credit card data into images. Magecart hackers have devised a new technique to obfuscating the malware within comment blocks and hide stolen credit card data into images evading detectio...]]></description>
<link>https://tsecurity.de/de/1513216/hacking/magecart-hackers-hide-stolen-credit-card-data-into-images-and-bogus-css-files/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1513216/hacking/magecart-hackers-hide-stolen-credit-card-data-into-images-and-bogus-css-files/</guid>
<pubDate>Mon, 12 Jul 2021 09:45:42 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Magecart hackers continuously improve their exfiltration techniques to evade detection, they are hiding stolen credit card data into images. Magecart hackers have devised a new technique to obfuscating the malware within comment blocks and hide stolen credit card data into images evading detection. Hacker groups under the Magecart umbrella continue to target e-stores to steal payment card data with […]</p>
<p>The post <a rel="nofollow" href="https://securityaffairs.co/wordpress/119975/cyber-crime/magecart-hides-data-into-images.html">Magecart hackers hide stolen credit card data into images and bogus CSS files</a> appeared first on <a rel="nofollow" href="https://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Hackers Hide Stolen Credit Card Data Into Images & Selling It in DarkWeb]]></title>
<description><![CDATA[A brand-new technique has been used by the hackers of the Magecart threat group recently to hide stolen credit card data in the images.  In general, the threat actors of Magecart target the e-commerce websites, as their main motive is to steal credit card details. Once they are done with the stea...]]></description>
<link>https://tsecurity.de/de/1513148/hacking/magecart-hackers-hide-stolen-credit-card-data-into-images-selling-it-in-darkweb/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1513148/hacking/magecart-hackers-hide-stolen-credit-card-data-into-images-selling-it-in-darkweb/</guid>
<pubDate>Sun, 11 Jul 2021 08:15:39 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="300" height="300" src="https://i0.wp.com/1.bp.blogspot.com/-uebz8ZrJuhE/YOqAG_V4OlI/AAAAAAAAN8c/rvGRBurlv8kg9y1YP0EGphthw5gR_XtQgCLcBGAsYHQ/s16000/Magecart%2BHackers.png?fit=300%2C300&amp;ssl=1" class="webfeedsFeaturedVisual wp-post-image" alt="Magecart" link_thumbnail=""><p>A brand-new technique has been used by the hackers of the Magecart threat group recently to hide stolen credit card data in the images.  In general, the threat actors of Magecart target the e-commerce websites, as their main motive is to steal credit card details. Once they are done with the stealing process, the threat […]</p>
<p>The post <a rel="nofollow" href="https://gbhackers.com/magecart-hackers/">Magecart Hackers Hide Stolen Credit Card Data Into Images &amp; Selling It in DarkWeb</a> appeared first on <a rel="nofollow" href="https://gbhackers.com/">GBHackers On Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Now Hides Malicious PHP Web Shells In Website Favicons]]></title>
<description><![CDATA[Once again, the Magecart gang has made it to the news owing to a unique…
Magecart Now Hides Malicious PHP Web Shells In Website Favicons on Latest Hacking News.]]></description>
<link>https://tsecurity.de/de/1478707/it-security-nachrichten/magecart-now-hides-malicious-php-web-shells-in-website-favicons/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1478707/it-security-nachrichten/magecart-now-hides-malicious-php-web-shells-in-website-favicons/</guid>
<pubDate>Thu, 20 May 2021 20:15:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Once again, the Magecart gang has made it to the news owing to a unique…</p>
<p><a rel="nofollow" href="https://latesthackingnews.com/2021/05/20/magecart-now-hides-malicious-php-web-shells-in-website-favicons/">Magecart Now Hides Malicious PHP Web Shells In Website Favicons</a> on <a rel="nofollow" href="https://latesthackingnews.com/">Latest Hacking News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Goes Server-Side in Latest Tactics Changeup]]></title>
<description><![CDATA[The latest Magecart iteration is finding success with a new PHP web shell skimmer.]]></description>
<link>https://tsecurity.de/de/1474736/it-security-nachrichten/magecart-goes-server-side-in-latest-tactics-changeup/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1474736/it-security-nachrichten/magecart-goes-server-side-in-latest-tactics-changeup/</guid>
<pubDate>Tue, 18 May 2021 01:00:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The latest Magecart iteration is finding success with a new PHP web shell skimmer.]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Group 12 Hackers Distributed New PHP based Web Skimmer to Steal Credit Cards Data]]></title>
<description><![CDATA[Researchers observed a new wave of PHP-based Web Skimmer by Magecart group 12 threat actors to steal card details from Magento 1 websites. Magento eCommerce platform is written by PHP, and acquired by Adobe. also frequently targeted by the threat actors specifically from the Magecart group, who h...]]></description>
<link>https://tsecurity.de/de/1474218/hacking/magecart-group-12-hackers-distributed-new-php-based-web-skimmer-to-steal-credit-cards-data/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1474218/hacking/magecart-group-12-hackers-distributed-new-php-based-web-skimmer-to-steal-credit-cards-data/</guid>
<pubDate>Mon, 17 May 2021 16:01:05 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="300" height="300" src="https://i1.wp.com/1.bp.blogspot.com/-KriAKkgMv08/YKJwyy9lKmI/AAAAAAAANJM/G5z1iNmPoJEPO8iKqrY0AKSMungnE8A0gCLcBGAsYHQ/s16000/web%2Bshell.png?fit=300%2C300&amp;ssl=1" class="webfeedsFeaturedVisual wp-post-image" alt="Web Skimmer" link_thumbnail=""><p>Researchers observed a new wave of PHP-based Web Skimmer by Magecart group 12 threat actors to steal card details from Magento 1 websites. Magento eCommerce platform is written by PHP, and acquired by Adobe. also frequently targeted by the threat actors specifically from the Magecart group, who have very active to attack vulnerable e-commerce platforms. […]</p>
<p>The post <a rel="nofollow" href="https://gbhackers.com/php-based-web-skimmer/">Magecart Group 12 Hackers Distributed New PHP based Web Skimmer to Steal Credit Cards Data</a> appeared first on <a rel="nofollow" href="https://gbhackers.com/">GBHackers On Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart gang hides PHP-based web shells in favicons]]></title>
<description><![CDATA[Magecart cybercrime gang is using favicon to hide malicious PHP web shells used to maintain remote access to inject JavaScript skimmers into online stores. Magecart hackers are distributing malicious PHP web shells hidden in website favicon to inject JavaScript e-skimmers into online stores and s...]]></description>
<link>https://tsecurity.de/de/1472136/hacking/magecart-gang-hides-php-based-web-shells-in-favicons/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1472136/hacking/magecart-gang-hides-php-based-web-shells-in-favicons/</guid>
<pubDate>Fri, 14 May 2021 16:45:43 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Magecart cybercrime gang is using favicon to hide malicious PHP web shells used to maintain remote access to inject JavaScript skimmers into online stores. Magecart hackers are distributing malicious PHP web shells hidden in website favicon to inject JavaScript e-skimmers into online stores and steal payment information. Researchers from Malwarebytes observed threat actors, likely Magecart […]</p>
<p>The post <a rel="nofollow" href="https://securityaffairs.co/wordpress/117909/cyber-crime/magecart-web-shells.html">Magecart gang hides PHP-based web shells in favicons</a> appeared first on <a rel="nofollow" href="https://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Hackers Now hide PHP-Based Backdoor In Website Favicons]]></title>
<description><![CDATA[Cybercrime groups are distributing malicious PHP web shells disguised as a favicon to maintain remote access to the compromised servers and inject JavaScript skimmers into online shopping platforms with an aim to steal financial information from their users.
"These web shells known as Smilodon or...]]></description>
<link>https://tsecurity.de/de/1471839/it-security-nachrichten/magecart-hackers-now-hide-php-based-backdoor-in-website-favicons/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1471839/it-security-nachrichten/magecart-hackers-now-hide-php-based-backdoor-in-website-favicons/</guid>
<pubDate>Fri, 14 May 2021 13:15:32 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybercrime groups are distributing malicious PHP web shells disguised as a favicon to maintain remote access to the compromised servers and inject JavaScript skimmers into online shopping platforms with an aim to steal financial information from their users.
"These web shells known as Smilodon or Megalodon are used to dynamically load JavaScript skimming code via server-side requests into online<img src="http://feeds.feedburner.com/~r/TheHackersNews/~4/nFK0H3Q2zss" height="1" width="1" alt="">]]></content:encoded>
</item>
<item>
<title><![CDATA[Anomali Cyber Watch:&nbsp; APT, Malware, Vulnerabilities and More.]]></title>
<description><![CDATA[The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: BlackRock, CopperStealer, Go, Lazarus, Mirai, Mustang Panda, Rust, Tax Season, and Vulnerabilities. The IOCs related to these stories are attached to Anomali Cyber Watch and can be u...]]></description>
<link>https://tsecurity.de/de/1451624/it-security-nachrichten/anomali-cyber-watchnbsp-apt-malware-vulnerabilities-and-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1451624/it-security-nachrichten/anomali-cyber-watchnbsp-apt-malware-vulnerabilities-and-more/</guid>
<pubDate>Mon, 26 Apr 2021 05:52:26 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: <b>BlackRock, CopperStealer, Go, Lazarus, Mirai, Mustang Panda, Rust, Tax Season,</b> and <b>Vulnerabilities</b>. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.</p>

<p><img src="https://www.anomali.com/images/uploads/blog/acw-032321.png"><br>
<em>Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.</em></p>

<h2>Trending Cyber News and Threat Intelligence</h2>

<div class="trending-threat-article">
<h3><a href="https://blog.eset.ie/2021/03/19/beware-android-trojan-posing-as-clubhouse-app/" target="_blank">Bogus Android Clubhouse App Drops Credential-Swiping Malware</a></h3>

<p>(published: March 19, 2021)</p>

<p>Researchers are warning of a fake version of the popular audio chat app Clubhouse, which delivers malware that steals login credentials for more than 450 apps. Clubhouse has burst on the social media scene over the past few months, gaining hype through its audio-chat rooms where participants can discuss anything from politics to relationships. Despite being invite-only, and only being around for a year, the app is closing in on 13 million downloads. The app is only available on Apple's App Store mobile application marketplace - though plans are in the works to develop one.<br>
<b>Analyst Comment:</b> Use only the official stores to download apps to your devices. Be wary of what kinds of permissions you grant to applications. Before downloading an app, do some research.<br>
<b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947278" target="_blank">[MITRE ATT&amp;CK] Remote File Copy - T1105</a><br>
<b>Tags:</b> LokiBot, BlackRock, Banking, Android, Clubhouse</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://labs.sentinelone.com/new-macos-malware-xcodespy-targets-xcode-developers-with-eggshell-backdoor/" target="_blank">Trojanized Xcode Project Slips XcodeSpy Malware to Apple Developers</a></h3>

<p>(published: March 18, 2021)</p>

<p>Researchers from cybersecurity firm SentinelOne have discovered a malicious version of the legitimate iOS TabBarInteraction Xcode project being distributed in a supply-chain attack. The malware, dubbed XcodeSpy, targets Xcode, an integrated development environment (IDE) used in macOS for developing Apple software and applications. The malicious project is a ripped version of TabBarInteraction, a legitimate project that has not been compromised. Malicious Xcode projects are being used to hijack developer systems and spread custom EggShell backdoors.<br>
<b>Analyst Comment:</b> Researchers attribute this new targeting of Apple developers to North Korea and Lazarus group: similar TTPs of compromising developer supply chain were discovered in January 2021 when North Korean APT was using a malicious Visual Studio project. Moreover, one of the victims of XcodeSpy is a Japanese organization regularly targeted by North Korea. A behavioral detection solution is required to fully detect the presence of XcodeSpy payloads.<br>
<b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947278" target="_blank">[MITRE ATT&amp;CK] Remote File Copy - T1105</a> | <a href="https://ui.threatstream.com/ttp/947109" target="_blank">[MITRE ATT&amp;CK] Security Software Discovery - T1063</a> | <a href="https://ui.threatstream.com/ttp/947235" target="_blank">[MITRE ATT&amp;CK] Obfuscated Files or Information - T1027</a><br>
<b>Tags:</b> Lazarus, XcodeSpy, North Korea, EggShell, Xcode, Apple</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.cybereason.com/blog/cybereason-exposes-malware-targeting-us-taxpayers" target="_blank">Cybereason Exposes Campaign Targeting US Taxpayers with NetWire and Remcos Malware</a></h3>

<p>(published: March 18, 2021)</p>

<p>Cybereason detected a new campaign targeting US taxpayers with documents that purport to contain tax-related content, ultimately delivering NetWire and Remcos - two powerful and popular RATs (remote access trojans) which can allow attackers to take control of the victims’ machines and steal sensitive information. The attackers dwarf heuristic detection by using unusually large files, they further conceal payloads by using a combination of steganography and public cloud services.<br>
<b>Analyst Comment:</b> Social engineering via phishing emails continues to be the preferred infection method among actors targeting US taxpayers. Despite various anti-detection tactics, these attacks can be stopped both by better detection and by teaching users of the dangers of enabling macros in a suspicious document.<br>
<b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947109" target="_blank">[MITRE ATT&amp;CK] Security Software Discovery - T1063</a> | <a href="https://ui.threatstream.com/ttp/947139" target="_blank">[MITRE ATT&amp;CK] Remote Access Tools - T1219</a> | <a href="https://ui.threatstream.com/ttp/947180" target="_blank">[MITRE ATT&amp;CK] Spearphishing Attachment - T1193</a><br>
<b>Tags:</b> Remcos, NetWire, Banking, Finance</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://securelist.com/convuster-macos-adware-in-rust/101258/" target="_blank">Convuster: MacOS Adware Now in Rust and Swift</a></h3>

<p>(published: March 18, 2021)</p>

<p>Convuster is a new adware program targeting the macOS platform. Two kinds of Convuster samples were found: those written in Rust and written in Swift. Rust samples could be recognized from the frequent use of the language's standard library, as well as several code lines containing paths to files with the .rs extension. From the victim’s point of view the Convuster installer mimics a Flash Player update.<br>
<b>Analyst Comment:</b> Actors have been paying increased attention to new programming languages, seemingly in the hope that such code will be more opaque to virus analysts who have little or no experience with the newer languages. It is interesting to note that Convuster would instal even if the user tries to refuse the fake Flash installation prompt.<br>
<b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947141" target="_blank">[MITRE ATT&amp;CK] Masquerading - T1036</a> | <a href="https://ui.threatstream.com/ttp/947125" target="_blank">[MITRE ATT&amp;CK] System Information Discovery - T1082</a><br>
<b>Tags:</b> Convuster, macOS, adware, Rust, Swift, fake-Flash</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.proofpoint.com/us/blog/threat-insight/now-you-see-it-now-you-dont-copperstealer-performs-widespread-theft" target="_blank">New CopperStealer Malware Steals Google, Apple, Facebook Accounts</a></h3>

<p>(published: March 18, 2021)</p>

<p>The malware, dubbed CopperStealer by Proofpoint researchers, is an actively developed password and cookie stealer with a downloader feature. The malware is being distributed via fake software crack sites. The malware attempts to steal the account passwords to Facebook, Instagram, Google, and other major service providers. The stolen passwords are used to run malicious ads for profit and spread more malware such as Smokeloader. The earliest discovered samples date back to July 2019, after which CopperStealer was developing with increased speed totaling in 80 currently known versions.<br>
<b>Analyst Comment:</b> CopperStealer’s active development and use of DGA based C2 servers demonstrates operational maturity as well as redundancy. Proofpoint, Facebook, Cloudflare, and others, used sinkholing to disrupt CopperStealers current activities, but we will likely see new versions in the wild soon.<br>
<b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947278" target="_blank">[MITRE ATT&amp;CK] Remote File Copy - T1105</a> | <a href="https://ui.threatstream.com/ttp/947269" target="_blank">[MITRE ATT&amp;CK] Access Token Manipulation - T1134</a> | <a href="https://ui.threatstream.com/ttp/947189" target="_blank">[MITRE ATT&amp;CK] Account Discovery - T1087</a> | <a href="https://ui.threatstream.com/ttp/947207" target="_blank">[MITRE ATT&amp;CK] Process Discovery - T1057</a> | <a href="https://ui.threatstream.com/ttp/947126" target="_blank">[MITRE ATT&amp;CK] Standard Application Layer Protocol - T1071</a> | <a href="https://ui.threatstream.com/ttp/947187" target="_blank">[MITRE ATT&amp;CK] System Network Configuration Discovery - T1016</a><br>
<b>Tags:</b> CopperStealer, Smokeloader, DGA, Social-Media, Facebook, sinkhole, PUA</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-defenders-blog-operation-dianxun/" target="_blank">Operation Dianxun</a></h3>

<p>(published: March 16, 2021)</p>

<p>McAfee ATR disclosed an espionage campaign named Operation Dianxun. The tactics, techniques and procedures used in the attack are similar to those observed in earlier campaigns which were publicly attributed to the threat actors RedDelta and Mustang Panda. Users are targeted with fake Flash phishing with DotNet downloader, that installs Cobalt Strike Beacon. Most probably this threat is targeting people working in the telecommunications industry and has been used for espionage purposes to spy on companies related to 5G technology.<br>
<b>Analyst Comment:</b> Companies dealing with sensitive telecommunication technologies should be able to block these attacks based on the malware samples and malicious domains identified. Furthermore, they should monitor their networks for a more general Cobalt Strike and DotNet malware activities.<br>
<b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947106" target="_blank">[MITRE ATT&amp;CK] Spearphishing Link - T1192</a> | <a href="https://ui.threatstream.com/ttp/947205" target="_blank">[MITRE ATT&amp;CK] User Execution - T1204</a> | <a href="https://ui.threatstream.com/ttp/947127" target="_blank">[MITRE ATT&amp;CK] Scheduled Task - T1053</a> | <a href="https://ui.threatstream.com/ttp/947142" target="_blank">[MITRE ATT&amp;CK] Process Injection - T1055</a><br>
<b>Tags:</b> Dianxun, Operation-Dianxun, DotNet payload, DotNet, Cobalt-Strike</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://www.bleepingcomputer.com/news/security/hackers-hide-credit-card-data-from-compromised-stores-in-jpg-file/" target="_blank">Hackers Hide Credit Card Data From Compromised Stores in JPG File</a></h3>

<p>(published: March 16, 2021)</p>

<p>Researchers at website security company Sucuri found the new exfiltration technique when investigating a compromised online shop running version 2 of the open-source Magento e-commerce platform. Instead of sending the card info to a server they control, hackers hide it in a JPG image and store it on the infected website. These incidents are also known as Magecart attacks and have started years ago.<br>
<b>Analyst Comment:</b> As these actors hide their exfiltration traffic in a benign-looking image file, the malicious activity might be hard to detect. A complex system doing integrity checks and monitoring new file creation might be necessarily.<br>
<b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947141" target="_blank">[MITRE ATT&amp;CK] Masquerading - T1036</a> | <a href="https://ui.threatstream.com/ttp/947136" target="_blank">[MITRE ATT&amp;CK] Deobfuscate/Decode Files or Information - T1140</a> | <a href="https://ui.threatstream.com/ttp/947278" target="_blank">[MITRE ATT&amp;CK] Remote File Copy - T1105</a><br>
<b>Tags:</b> Magecart, Magento, Skimming, Skimmer</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://msrc-blog.microsoft.com/2021/03/15/one-click-microsoft-exchange-on-premises-mitigation-tool-march-2021/" target="_blank">One-Click Microsoft Exchange On-Premises Mitigation Tool</a></h3>

<p>(published: March 15, 2021)</p>

<p>This month, Microsoft disclosed that four zero-day vulnerabilities were being actively used in attacks against Microsoft Exchange. These vulnerabilities are collectively known as ProxyLogon and are being used by threat actors to drop web shells, cryptominers, and more recently, the DearCry ransomware on exploited servers. On March 15, 2021, Microsoft released the EOMT one-click PowerShell script so that small business owners can get further help securing their Microsoft Exchange servers.<br>
<b>Analyst Comment:</b> This tool should only be used as a temporary mitigation until your Exchange servers can be fully updated as outlined in our previous guidance.<br>
<b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947247" target="_blank">[MITRE ATT&amp;CK] Web Shell - T1100</a><br>
<b>Tags:</b> ProxyLogon, DearCry, CVE-2021-26855, Microsoft-Exchange</p>
</div>

<div class="trending-threat-article">
<h3><a href="https://unit42.paloaltonetworks.com/mirai-variant-iot-vulnerabilities/" target="_blank">New Mirai Variant Targeting Network Security Devices</a></h3>

<p>(published: March 15, 2021)</p>

<p>Palo Alto Unit 42 security researchers have discovered a Mirai variant campaign that was quickly evolving to include additional vulnerabilities. Five known vulnerabilities and three unknown vulnerabilities were exploited in this attack. Among the targets were SonicWall, D-Link, Yealink, Netgear, and is likely to include other unknown devices. After getting the initial foothold the malware installs GoLang v1.9.4 and downloads binaries written in that language.<br>
<b>Analyst Comment:</b> We recommend patching your IoT devices, filtering malicious domains, using next-generation firewalls. More research is needed regarding unknown and unidentified vulnerabilities used by this Mirai variant.<br>
<b>MITRE ATT&amp;CK: </b> <a href="https://ui.threatstream.com/ttp/947201" target="_blank">[MITRE ATT&amp;CK] Scripting - T1064</a> | <a href="https://ui.threatstream.com/ttp/947191" target="_blank">[MITRE ATT&amp;CK] Command-Line Interface - T1059</a> | <a href="https://ui.threatstream.com/ttp/947233" target="_blank">[MITRE ATT&amp;CK] Exploitation for Privilege Escalation - T1068</a> | <a href="https://ui.threatstream.com/ttp/947210" target="_blank">[MITRE ATT&amp;CK] Exfiltration Over Command and Control Channel - T1041</a> | <a href="https://ui.threatstream.com/ttp/947278" target="_blank">[MITRE ATT&amp;CK] Remote File Copy - T1105</a> | <a href="https://ui.threatstream.com/ttp/947187" target="_blank">[MITRE ATT&amp;CK] System Network Configuration Discovery - T1016</a><br>
<b>Tags:</b> Mirai, IoT, GoLangC, VisualDoor, CVE-2019-19356, CVE-2021-22502, CVE-2021-27562, CVE-2021-27561, CVE-2021-25502, CVE-2020-25506, CVE-2020-26919</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Source Defense colloborate with Prevalent to mitigate third-party risks to client-side web applications]]></title>
<description><![CDATA[Source Defense announced its partnership with Prevalent to identify threats and protect online businesses against automated and client-side attacks exploiting third-party code and website access. Prevalent and Source Defense’s joint solution offers deeper visibility on the true array of code and ...]]></description>
<link>https://tsecurity.de/de/1447024/it-security-nachrichten/source-defense-colloborate-with-prevalent-to-mitigate-third-party-risks-to-client-side-web-applications/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1447024/it-security-nachrichten/source-defense-colloborate-with-prevalent-to-mitigate-third-party-risks-to-client-side-web-applications/</guid>
<pubDate>Thu, 22 Apr 2021 01:30:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Source Defense announced its partnership with Prevalent to identify threats and protect online businesses against automated and client-side attacks exploiting third-party code and website access. Prevalent and Source Defense’s joint solution offers deeper visibility on the true array of code and vendor relationships powering websites, with automated policy enforcement and remediation features to defeat malicious activity and prove regulatory compliance. As client-side threats such as Magecart and formjacking attacks continue to victimize websites across industries, … <a href="https://www.helpnetsecurity.com/2021/04/22/source-defense-prevalent/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a rel="nofollow" href="https://www.helpnetsecurity.com/2021/04/22/source-defense-prevalent/">Source Defense colloborate with Prevalent to mitigate third-party risks to client-side web applications</a> appeared first on <a rel="nofollow" href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[93% of consumers concerned about data security when filling out online forms]]></title>
<description><![CDATA[Source Defense provides in-depth analysis of the client-side threat landscape and specific attacks like formjacking, Magecart and web browser threats. The research offers a rare window on web security sentiments for a population relying almost exclusively on websites for all manner of shopping, h...]]></description>
<link>https://tsecurity.de/de/1424346/it-security-nachrichten/93-of-consumers-concerned-about-data-security-when-filling-out-online-forms/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1424346/it-security-nachrichten/93-of-consumers-concerned-about-data-security-when-filling-out-online-forms/</guid>
<pubDate>Tue, 30 Mar 2021 04:45:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Source Defense provides in-depth analysis of the client-side threat landscape and specific attacks like formjacking, Magecart and web browser threats. The research offers a rare window on web security sentiments for a population relying almost exclusively on websites for all manner of shopping, healthcare, financial services and other essential needs during the pandemic. Key findings 93% of consumers are concerned about data security when filling out online forms 91% said that brands requiring consumers to … <a href="https://www.helpnetsecurity.com/2021/03/30/data-security-online-forms/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a rel="nofollow" href="https://www.helpnetsecurity.com/2021/03/30/data-security-online-forms/">93% of consumers concerned about data security when filling out online forms</a> appeared first on <a rel="nofollow" href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare Page Shield: Early warning system for malicious scripts]]></title>
<description><![CDATA[Cloudflare has released a new feature that aims to protect websites from Magecart and other malicious JavaScript-based attacks. [...]]]></description>
<link>https://tsecurity.de/de/1421098/it-security-nachrichten/cloudflare-page-shield-early-warning-system-for-malicious-scripts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1421098/it-security-nachrichten/cloudflare-page-shield-early-warning-system-for-malicious-scripts/</guid>
<pubDate>Thu, 25 Mar 2021 22:45:13 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cloudflare has released a new feature that aims to protect websites from Magecart and other malicious JavaScript-based attacks. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Cloudflare launches Page Shield to thwart Magecart card skimming attacks]]></title>
<description><![CDATA[Magecart attacks remain a prolific threat to the security of our financial data.]]></description>
<link>https://tsecurity.de/de/1420504/hacking/cloudflare-launches-page-shield-to-thwart-magecart-card-skimming-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1420504/hacking/cloudflare-launches-page-shield-to-thwart-magecart-card-skimming-attacks/</guid>
<pubDate>Thu, 25 Mar 2021 14:00:50 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Magecart attacks remain a prolific threat to the security of our financial data.]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Skimmer Attacks Sites Whilst Hiding Stolen Data In JPG Files]]></title>
<description><![CDATA[Continuing with their invasive strategies, the e-commerce predator Magecart has developed another malicious feature. As…
Magecart Skimmer Attacks Sites Whilst Hiding Stolen Data In JPG Files on Latest Hacking News.]]></description>
<link>https://tsecurity.de/de/1416190/it-security-nachrichten/magecart-skimmer-attacks-sites-whilst-hiding-stolen-data-in-jpg-files/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1416190/it-security-nachrichten/magecart-skimmer-attacks-sites-whilst-hiding-stolen-data-in-jpg-files/</guid>
<pubDate>Mon, 22 Mar 2021 10:00:13 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Continuing with their invasive strategies, the e-commerce predator Magecart has developed another malicious feature. As…</p>
<p><a rel="nofollow" href="https://latesthackingnews.com/2021/03/22/magecart-skimmer-attacks-sites-whilst-hiding-stolen-data-in-jpg-files/">Magecart Skimmer Attacks Sites Whilst Hiding Stolen Data In JPG Files</a> on <a rel="nofollow" href="https://latesthackingnews.com/">Latest Hacking News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Attackers Save Stolen Credit-Card Data in .JPG File]]></title>
<description><![CDATA[Researchers from Sucuri discovered the tactic, which creatively hides malicious activity until the info can be retrieved, during an investigation into a compromised Magento 2 e-commerce site.]]></description>
<link>https://tsecurity.de/de/1410837/it-security-nachrichten/magecart-attackers-save-stolen-credit-card-data-in-jpg-file/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1410837/it-security-nachrichten/magecart-attackers-save-stolen-credit-card-data-in-jpg-file/</guid>
<pubDate>Tue, 16 Mar 2021 17:30:28 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researchers from Sucuri discovered the tactic, which creatively hides malicious activity until the info can be retrieved, during an investigation into a compromised Magento 2 e-commerce site.]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart hackers hide captured credit card data in JPG file]]></title>
<description><![CDATA[Crooks devised a new method to hide credit card data siphoned from compromised e-stores, experts observed hackers hiding data in JPG files. Cybercriminals have devised a new method to hide credit card data siphoned from compromised online stores, experts from Sucuri observed Magecart hackers hidi...]]></description>
<link>https://tsecurity.de/de/1410828/hacking/magecart-hackers-hide-captured-credit-card-data-in-jpg-file/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1410828/hacking/magecart-hackers-hide-captured-credit-card-data-in-jpg-file/</guid>
<pubDate>Tue, 16 Mar 2021 17:15:34 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Crooks devised a new method to hide credit card data siphoned from compromised e-stores, experts observed hackers hiding data in JPG files. Cybercriminals have devised a new method to hide credit card data siphoned from compromised online stores, experts from Sucuri observed Magecart hackers hiding data in JPG files to avoid detection and storing them […]</p>
<p>The post <a rel="nofollow" href="https://securityaffairs.co/wordpress/115655/hacking/magecart-credit-card-jpg.html">Magecart hackers hide captured credit card data in JPG file</a> appeared first on <a rel="nofollow" href="https://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers steal credit card data abusing Google’s Apps Script]]></title>
<description><![CDATA[Hackers abuse Google Apps Script to steal credit cards, bypass CSP Attackers are abusing Google’s Apps Script business application development platform to steal payment card information from e-stores. Sansec researchers reported that threat actors are abusing Google’s Apps Script business applica...]]></description>
<link>https://tsecurity.de/de/1385038/hacking/hackers-steal-credit-card-data-abusing-googles-apps-script/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1385038/hacking/hackers-steal-credit-card-data-abusing-googles-apps-script/</guid>
<pubDate>Fri, 19 Feb 2021 10:00:50 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Hackers abuse Google Apps Script to steal credit cards, bypass CSP Attackers are abusing Google’s Apps Script business application development platform to steal payment card information from e-stores. Sansec researchers reported that threat actors are abusing Google’s Apps Script business application development platform to steal credit card data provided by customers of e-commerce websites. “Attackers use […]</p>
<p>The post <a rel="nofollow" href="https://securityaffairs.co/wordpress/114750/cyber-crime/googles-apps-script-magecart.html">Hackers steal credit card data abusing Google’s Apps Script</a> appeared first on <a rel="nofollow" href="https://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Outdated Magneto 1 Witnessed Credit Card Skimming Threats]]></title>
<description><![CDATA[ Magento is an open-source code e-commerce site that supplies online traders with a scalable shopping cart system, and managing their online store's layout, content, and features. Lately, threat actors began leveraging a flaw in the ‘Magento 1’ branch that has not been managed any longer in the f...]]></description>
<link>https://tsecurity.de/de/1370081/hacking/outdated-magneto-1-witnessed-credit-card-skimming-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1370081/hacking/outdated-magneto-1-witnessed-credit-card-skimming-threats/</guid>
<pubDate>Thu, 04 Feb 2021 12:45:45 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p> </p><div class="separator"><a href="https://1.bp.blogspot.com/-YrSTYHSzyuA/YBvFj-ffagI/AAAAAAAAJcA/Cpct-b7UAuYJi-nwz8S7ONlANF3g_KGxQCLcBGAsYHQ/s1920/security-4700815_1920.jpg"><img alt="" border="0" data-original-height="1280" data-original-width="1920" src="https://1.bp.blogspot.com/-YrSTYHSzyuA/YBvFj-ffagI/AAAAAAAAJcA/Cpct-b7UAuYJi-nwz8S7ONlANF3g_KGxQCLcBGAsYHQ/s600/security-4700815_1920.jpg" width="600"></a></div>Magento is an open-source code e-commerce site that supplies online traders with a scalable shopping cart system, and managing their online store's layout, content, and features. Lately, threat actors began leveraging a flaw in the ‘Magento 1’ branch that has not been managed any longer in the fall of 2020. <div><br></div><div>Thousands of retailers worldwide on the platform are encouraged to upgrade the mobile version to ‘Magento 2’, as thousands of e-commerce shops were hacked with the credit card skimming code infecting all of them. During the tracking of events related to the ‘Magento 1’ initiative, observably, an e-commerce shop was attacked twice by skimmers. </div><div><br><div>In this particular incident, the threat actors devised a copy of their writings that is well-known to places that were already injected by the Magento 1 skimmer. The second skimmer will now actually collect the credit card data from the pre-existing fake form which were previously injected by the actors.</div><div><br></div><div>"A large number of Magento 1 sites have been hacked but yet are not necessarily being monetized,” as stated by the researcher at Malwarebytes. He further added that “Other threat actors that want access will undoubtedly attempt to inject their own malicious code. When that happens, we see criminals trying to access the same resources and sometimes fighting with one another.” </div><div><br></div><div>The end-of-life of Magento 1, paired with a famous feat, was an immense blessing for the actors at risk. Many pages were indiscriminately compromised merely because they were weak. RiskIQ has allocated these cases to Magecart Group 12, which uses diverse tactics including chain threats with a long history of web skimming.</div><div><br></div><div>On the payment websites of Costway, one of the leading retailers in North America and Europe, two web skimmers have been found selling appliances, furniture, etc. The skimmers seek to provide payment information with consumers' credit card. “Our crawlers identified that the websites for Costway France, U.K., Germany, and Spain, which run the Magento 1 software, had been compromised around the same time frame,” said researchers. </div><div><br></div><div>On the Costway check-out page, the researchers noticed  the credit card skimmer injection, which stands out in English while the majority of the platform is in French. This is no surprise considering the automated and very indiscriminate Magento 1 hacking campaign. </div><div><br></div><div>The threat to victims is huge, as scientists claim that just in December 2020, Costway's French portal (Costway[.]fr) received approximately 180K tourists. There is also a second skimmer (loaded from the securityxx[.]top externally) on the web which targets the skimmer of Magento 1. </div><div><br></div><div>Many Magento 1 websites have been compromised, but they are not monetized yet. Additional attacks would certainly continue to inject their own malicious code.  </div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The three steps required to shield your company from a Magecart attack]]></title>
<description><![CDATA[Magecart refers to a cybercrime syndicate that specializes in cyberattacks involving digital credit card theft by skimming online payment forms.]]></description>
<link>https://tsecurity.de/de/1366697/it-security-nachrichten/the-three-steps-required-to-shield-your-company-from-a-magecart-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1366697/it-security-nachrichten/the-three-steps-required-to-shield-your-company-from-a-magecart-attack/</guid>
<pubDate>Mon, 01 Feb 2021 11:16:15 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Magecart refers to a cybercrime syndicate that specializes in cyberattacks involving digital credit card theft by skimming online payment forms.]]></content:encoded>
</item>
<item>
<title><![CDATA[Multi-Platform Credit Card Skimmer Discovered- Expert Offers Perspective]]></title>
<description><![CDATA[A new Magecart card skimmer, discovered by Dutch cybersecurity company Sansec, is collecting customers payment info on dozens of stores hosted by Shopify, BigCommerce, Zencart, and Woocommerce. The skimmer works…
The ISBuzz Post: This Post Multi-Platform Credit Card Skimmer Discovered- Expert Off...]]></description>
<link>https://tsecurity.de/de/1342251/it-security-nachrichten/multi-platform-credit-card-skimmer-discovered-expert-offers-perspective/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1342251/it-security-nachrichten/multi-platform-credit-card-skimmer-discovered-expert-offers-perspective/</guid>
<pubDate>Mon, 04 Jan 2021 15:31:34 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new Magecart card skimmer, discovered by Dutch cybersecurity company Sansec, is collecting customers payment info on dozens of stores hosted by Shopify, BigCommerce, Zencart, and Woocommerce. The skimmer works…</p>
<p>The ISBuzz Post: This Post <a rel="nofollow" href="https://informationsecuritybuzz.com/expert-comments/multi-platform-credit-card-skimmer-discovered-expert-offers-perspective/" data-wpel-link="internal">Multi-Platform Credit Card Skimmer Discovered- Expert Offers Perspective</a> appeared first on <a rel="nofollow" href="https://informationsecuritybuzz.com/" data-wpel-link="internal">Information Security Buzz</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Law Enforcement Take Down Three Bulletproof VPN Providers]]></title>
<description><![CDATA[Law enforcement agencies from the US, Germany, France, Switzerland, and the Netherlands have seized this week the web domains and server infrastructure of three VPN services that provided a safe haven for cybercriminals to attack their victims. From a report: The three services were active at ins...]]></description>
<link>https://tsecurity.de/de/1335424/it-security-nachrichten/law-enforcement-take-down-three-bulletproof-vpn-providers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1335424/it-security-nachrichten/law-enforcement-take-down-three-bulletproof-vpn-providers/</guid>
<pubDate>Tue, 22 Dec 2020 18:31:24 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Law enforcement agencies from the US, Germany, France, Switzerland, and the Netherlands have seized this week the web domains and server infrastructure of three VPN services that provided a safe haven for cybercriminals to attack their victims. From a report: The three services were active at insorg.org, safe-inet.com, and safe-inet.net before the domains were seized and replaced with law enforcement banners on Monday. The services have been active for more than a decade, are believed to be operated by the same individual/group, and have been heavily advertised on both Russian and English-speaking underground cybercrime forums, where they were sold for prices ranging from $1.3/day to $190/year. According to the US Department of Justice and Europol, the three companies' servers were often used to mask the real identities of ransomware gangs, web skimmer (Magecart) groups, online phishers, and hackers involved in account takeovers, allowing them to operate from behind a proxy network up to five layers deep.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Law+Enforcement+Take+Down+Three+Bulletproof+VPN+Providers%3A+https%3A%2F%2Fbit.ly%2F3aznxDT"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F20%2F12%2F22%2F1717239%2Flaw-enforcement-take-down-three-bulletproof-vpn-providers%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/20/12/22/1717239/law-enforcement-take-down-three-bulletproof-vpn-providers?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stealthy Magecart malware mistakenly leaks list of hacked stores]]></title>
<description><![CDATA[A list of dozens of online stores hacked by a web skimming group was inadvertently leaked by a dropper used to deploy a stealthy remote access trojan (RAT) on compromised e-commerce sites. [...]]]></description>
<link>https://tsecurity.de/de/1332813/it-security-nachrichten/stealthy-magecart-malware-mistakenly-leaks-list-of-hacked-stores/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1332813/it-security-nachrichten/stealthy-magecart-malware-mistakenly-leaks-list-of-hacked-stores/</guid>
<pubDate>Fri, 18 Dec 2020 20:01:39 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A list of dozens of online stores hacked by a web skimming group was inadvertently leaked by a dropper used to deploy a stealthy remote access trojan (RAT) on compromised e-commerce sites. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Warnung vor Magecart-Angriffen zur Weihnachtszeit]]></title>
<description><![CDATA[Dies betrifft die meisten Websites von Online-Einzelhändlern. ... Darüber hinaus sollten IT-Teams regelmäßig die entsprechenden Security-Patches ...]]></description>
<link>https://tsecurity.de/de/1329331/it-security-nachrichten/warnung-vor-magecart-angriffen-zur-weihnachtszeit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1329331/it-security-nachrichten/warnung-vor-magecart-angriffen-zur-weihnachtszeit/</guid>
<pubDate>Wed, 16 Dec 2020 06:31:17 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dies betrifft die meisten Websites von <b>Online</b>-Einzelhändlern. ... Darüber hinaus sollten <b>IT</b>-Teams regelmäßig die entsprechenden <b>Security</b>-Patches ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Warnung vor Magecart-Angriffen zur Weihnachtszeit]]></title>
<description><![CDATA[E-Commerce und Einzelhändler sind in diesem Jahr einem erheblichen und erhöhten Risiko ausgesetzt. Der Übeltäter: Magecart Angriffe, die rund um die Weihnachtszeit stattfinden. Bei so genannten Magecart-Angriffen werden durch einen injizierten Schadcode, heimlich Bank- oder Kreditkartendaten von ...]]></description>
<link>https://tsecurity.de/de/1329305/it-security-nachrichten/warnung-vor-magecart-angriffen-zur-weihnachtszeit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1329305/it-security-nachrichten/warnung-vor-magecart-angriffen-zur-weihnachtszeit/</guid>
<pubDate>Wed, 16 Dec 2020 05:16:11 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div class="feed-description"><p>E-Commerce und Einzelhändler sind in diesem Jahr <a href="https://www.it-daily.net/it-sicherheit/cybercrime/26167-onlinekaeufe-zur-weihnachtszeit-sind-ein-paradies-fuer-cyber-kriminelle?highlight=Weihnachten" target="_self">einem erheblichen und erhöhten Risiko ausgesetzt</a>. Der Übeltäter: Magecart Angriffe, die rund um die Weihnachtszeit stattfinden. Bei so genannten Magecart-Angriffen werden durch einen injizierten Schadcode, heimlich Bank- oder Kreditkartendaten von Kunden gestohlen.</p></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Targets Online Stores By Hiding Behind Social Media Buttons]]></title>
<description><![CDATA[As the holiday season approaches, people need to be even more vigilant during online shopping. That too, while sharing their
Magecart Targets Online Stores By Hiding Behind Social Media Buttons on Latest Hacking News.]]></description>
<link>https://tsecurity.de/de/1323490/it-security-nachrichten/magecart-targets-online-stores-by-hiding-behind-social-media-buttons/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1323490/it-security-nachrichten/magecart-targets-online-stores-by-hiding-behind-social-media-buttons/</guid>
<pubDate>Thu, 10 Dec 2020 13:46:30 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>As the holiday season approaches, people need to be even more vigilant during online shopping. That too, while sharing their</p>
<p><a rel="nofollow" href="https://latesthackingnews.com/2020/12/10/magecart-targets-online-stores-by-hiding-behind-social-media-buttons/">Magecart Targets Online Stores By Hiding Behind Social Media Buttons</a> on <a rel="nofollow" href="https://latesthackingnews.com/">Latest Hacking News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Crooks hide software skimmer inside CSS files]]></title>
<description><![CDATA[Security researchers have uncovered a new technique to inject a software skimmer onto websites, the malware hides in CSS files. Security researchers have uncovered a new technique used by threat actors to inject a software skimmer onto websites, the attackers hide the malware in CSS files. Securi...]]></description>
<link>https://tsecurity.de/de/1322317/hacking/crooks-hide-software-skimmer-inside-css-files/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1322317/hacking/crooks-hide-software-skimmer-inside-css-files/</guid>
<pubDate>Wed, 09 Dec 2020 16:30:45 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security researchers have uncovered a new technique to inject a software skimmer onto websites, the malware hides in CSS files. Security researchers have uncovered a new technique used by threat actors to inject a software skimmer onto websites, the attackers hide the malware in CSS files. Security experts have analyzed multiple Magecart attack techniques over […]</p>
<p>The post <a rel="nofollow" href="https://securityaffairs.co/wordpress/112117/malware/skimmer-inside-css-files.html">Crooks hide software skimmer inside CSS files</a> appeared first on <a rel="nofollow" href="https://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers hide web skimmer inside a website's CSS files]]></title>
<description><![CDATA[Previously, security researchers found web skimmers (Magecart scripts) inside favicons, site logos, live chat windows, and, most recently, in social media sharing buttons.]]></description>
<link>https://tsecurity.de/de/1322100/hacking/hackers-hide-web-skimmer-inside-a-websites-css-files/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1322100/hacking/hackers-hide-web-skimmer-inside-a-websites-css-files/</guid>
<pubDate>Wed, 09 Dec 2020 14:00:45 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Previously, security researchers found web skimmers (Magecart scripts) inside favicons, site logos, live chat windows, and, most recently, in social media sharing buttons.]]></content:encoded>
</item>
<item>
<title><![CDATA[Hiding Malware in Social Media Buttons]]></title>
<description><![CDATA[Clever tactic:
This new malware was discovered by researchers at Dutch cyber-security company Sansec that focuses on defending e-commerce websites from digital skimming (also known as Magecart) attacks.
The payment skimmer malware pulls its sleight of hand trick with the help of a double payload ...]]></description>
<link>https://tsecurity.de/de/1319576/reverse-engineering/hiding-malware-in-social-media-buttons/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1319576/reverse-engineering/hiding-malware-in-social-media-buttons/</guid>
<pubDate>Mon, 07 Dec 2020 13:47:39 +0100</pubDate>
<category>🕵️ Reverse Engineering</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Clever <a href="https://www.bleepingcomputer.com/news/security/credit-card-stealing-malware-hides-in-social-media-sharing-icons/">tactic</a>:</p>
<blockquote><p>This new malware was discovered by researchers at Dutch cyber-security company Sansec that focuses on defending e-commerce websites from digital skimming (also known as Magecart) attacks.</p>
<p>The payment skimmer malware pulls its sleight of hand trick with the help of a double payload structure where the source code of the skimmer script that steals customers’ credit cards will be concealed in a social sharing icon loaded as an HTML ‘svg’ element with a ‘path’ element as a container.</p>
<p>The syntax for hiding the skimmer’s source code as a social media button perfectly mimics an ‘svg’ element named using social media platform names (e.g., facebook_full, twitter_full, instagram_full, youtube_full, pinterest_full, and google_full)...</p></blockquote>]]></content:encoded>
</item>
<item>
<title><![CDATA[Credit card stealer discovered in social media buttons]]></title>
<description><![CDATA[Web skimmer (Magecart) gangs find a new ways to attack e-commerce stores and online shoppers.]]></description>
<link>https://tsecurity.de/de/1319519/hacking/credit-card-stealer-discovered-in-social-media-buttons/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1319519/hacking/credit-card-stealer-discovered-in-social-media-buttons/</guid>
<pubDate>Mon, 07 Dec 2020 13:45:51 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Web skimmer (Magecart) gangs find a new ways to attack e-commerce stores and online shoppers.]]></content:encoded>
</item>
<item>
<title><![CDATA[New Magecart Attacks, GoDaddy DNS Attacks, & Ryan Corey - SWN #85]]></title>
<description><![CDATA[$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('LyFGmkncGcQ');
									});]]></description>
<link>https://tsecurity.de/de/1314656/it-security-video/new-magecart-attacks-godaddy-dns-attacks-ryan-corey-swn-85/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1314656/it-security-video/new-magecart-attacks-godaddy-dns-attacks-ryan-corey-swn-85/</guid>
<pubDate>Tue, 01 Dec 2020 23:01:57 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/LyFGmkncGcQ/maxresdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<div id="ytplayer_LyFGmkncGcQ"></div>

					<script>
									$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('LyFGmkncGcQ');
									}); 
									</script>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Attack Convincingly Hijacks PayPal Transactions at Checkout]]></title>
<description><![CDATA[New credit-card skimmer uses postMessage to make malicious process look authentic to victims to steal payment data.]]></description>
<link>https://tsecurity.de/de/1313982/it-security-nachrichten/magecart-attack-convincingly-hijacks-paypal-transactions-at-checkout/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1313982/it-security-nachrichten/magecart-attack-convincingly-hijacks-paypal-transactions-at-checkout/</guid>
<pubDate>Tue, 01 Dec 2020 14:01:55 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[New credit-card skimmer uses postMessage to make malicious process look authentic to victims to steal payment data.]]></content:encoded>
</item>
<item>
<title><![CDATA[2020 Black Friday/Cyber Monday – Likely Magecart Attack Increase Due To Plug-in Vulns – Experts Perspective]]></title>
<description><![CDATA[With Black Friday and Cyber Monday just a week away, an expert with Juniper Threat Labs offers insight into why Magecart attacks are likely to be on the increase for…
The ISBuzz Post: This Post 2020 Black Friday/Cyber Monday – Likely Magecart Attack Increase Due To Plug-in Vulns – Experts Perspec...]]></description>
<link>https://tsecurity.de/de/1303292/it-security-nachrichten/2020-black-fridaycyber-monday-likely-magecart-attack-increase-due-to-plug-in-vulns-experts-perspective/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1303292/it-security-nachrichten/2020-black-fridaycyber-monday-likely-magecart-attack-increase-due-to-plug-in-vulns-experts-perspective/</guid>
<pubDate>Fri, 20 Nov 2020 14:01:38 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>With Black Friday and Cyber Monday just a week away, an expert with Juniper Threat Labs offers insight into why Magecart attacks are likely to be on the increase for…</p>
<p>The ISBuzz Post: This Post <a rel="nofollow" href="https://www.informationsecuritybuzz.com/expert-comments/2020-black-friday-cyber-monday-likely-magecart-attack-increase-due-to-plug-in-vulns-experts-perspective/">2020 Black Friday/Cyber Monday – Likely Magecart Attack Increase Due To Plug-in Vulns – Experts Perspective</a> appeared first on <a rel="nofollow" href="https://www.informationsecuritybuzz.com/">Information Security Buzz</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Experts On New Grelos Skimmer Variant Reveals Overlap in Magecart Activities]]></title>
<description><![CDATA[Researchers have uncovered a new Grelos skimmer, which demonstrates increased overlaps in Magecart infrastructure and groups making it difficult to separate various campaigns and their collaboration work.
The ISBuzz Post: This Post Experts On New Grelos Skimmer Variant Reveals Overlap in Magecart...]]></description>
<link>https://tsecurity.de/de/1303204/it-security-nachrichten/experts-on-new-grelos-skimmer-variant-reveals-overlap-in-magecart-activities/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1303204/it-security-nachrichten/experts-on-new-grelos-skimmer-variant-reveals-overlap-in-magecart-activities/</guid>
<pubDate>Fri, 20 Nov 2020 12:46:25 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Researchers have uncovered a new Grelos skimmer, which demonstrates increased overlaps in Magecart infrastructure and groups making it difficult to separate various campaigns and their collaboration work.</p>
<p>The ISBuzz Post: This Post <a rel="nofollow" href="https://www.informationsecuritybuzz.com/expert-comments/experts-on-new-grelos-skimmer-variant-reveals-overlap-in-magecart-activities/">Experts On New Grelos Skimmer Variant Reveals Overlap in Magecart Activities</a> appeared first on <a rel="nofollow" href="https://www.informationsecuritybuzz.com/">Information Security Buzz</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Grelos skimmer variant reveals murkiness in tracking Magecart operations]]></title>
<description><![CDATA[Security experts from RiskIQ discovered a new variant of the Grelos skimmer that presents overlap with Magecart group operations. Researchers from RiskIQ analyzed the increased overlap of a new variant of the skimmer dubbed Grelos and the operations of the groups under the Magecart umbrella. The ...]]></description>
<link>https://tsecurity.de/de/1302038/hacking/new-grelos-skimmer-variant-reveals-murkiness-in-tracking-magecart-operations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1302038/hacking/new-grelos-skimmer-variant-reveals-murkiness-in-tracking-magecart-operations/</guid>
<pubDate>Thu, 19 Nov 2020 14:15:55 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Security experts from RiskIQ discovered a new variant of the Grelos skimmer that presents overlap with Magecart group operations. Researchers from RiskIQ analyzed the increased overlap of a new variant of the skimmer dubbed Grelos and the operations of the groups under the Magecart umbrella. The analysis demonstrates the difficulty in associating new strains of skimmer to groups […]</p>
<p>The post <a rel="nofollow" href="https://securityaffairs.co/wordpress/111165/malware/grelos-skimmer.html">New Grelos skimmer variant reveals murkiness in tracking Magecart operations</a> appeared first on <a rel="nofollow" href="https://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Grelos skimmer variant reveals overlap in Magecart group activities, malware infrastructure]]></title>
<description><![CDATA[The discovery of a new skimmer variant reveals the difficulties associated with tracking separate Magecart campaigns.]]></description>
<link>https://tsecurity.de/de/1301876/hacking/new-grelos-skimmer-variant-reveals-overlap-in-magecart-group-activities-malware-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1301876/hacking/new-grelos-skimmer-variant-reveals-overlap-in-magecart-group-activities-malware-infrastructure/</guid>
<pubDate>Thu, 19 Nov 2020 11:45:50 +0100</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The discovery of a new skimmer variant reveals the difficulties associated with tracking separate Magecart campaigns.]]></content:encoded>
</item>
<item>
<title><![CDATA[Heads up: A new strain of card-skimming Grelos malware is on the loose]]></title>
<description><![CDATA[Magecart variant has changed and you should be alert, warns RiskIQ A new offshoot of the Grelos card-skimming malware - a common Magecart variant - is doing the rounds, according to infosec biz RiskIQ.…]]></description>
<link>https://tsecurity.de/de/1301280/it-security-nachrichten/heads-up-a-new-strain-of-card-skimming-grelos-malware-is-on-the-loose/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1301280/it-security-nachrichten/heads-up-a-new-strain-of-card-skimming-grelos-malware-is-on-the-loose/</guid>
<pubDate>Wed, 18 Nov 2020 20:48:23 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Magecart variant has changed and you should be alert, warns RiskIQ</h4> <p>A new offshoot of the Grelos card-skimming malware - a common Magecart variant - is doing the rounds, according to infosec biz RiskIQ.…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ticketmaster cops £1.25m ICO fine for 2018 Magecart breach, blames someone else and vows to appeal]]></title>
<description><![CDATA[Own your screwups, growls irate watchdog The Information Commissioner’s Office has fined Ticketmaster £1.25m after the site’s operators failed to spot a Magecart card skimmer infection until after 9 million customers’ details had been slurped by criminals.…]]></description>
<link>https://tsecurity.de/de/1296363/it-security-nachrichten/ticketmaster-cops-125m-ico-fine-for-2018-magecart-breach-blames-someone-else-and-vows-to-appeal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1296363/it-security-nachrichten/ticketmaster-cops-125m-ico-fine-for-2018-magecart-breach-blames-someone-else-and-vows-to-appeal/</guid>
<pubDate>Fri, 13 Nov 2020 17:17:02 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Own your screwups, growls irate watchdog</h4> <p>The Information Commissioner’s Office has fined Ticketmaster £1.25m after the site’s operators failed to spot a Magecart card skimmer infection until after 9 million customers’ details had been slurped by criminals.…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Over 2800 e-Shops Running Outdated Magento Software Hit by Credit Card Hackers]]></title>
<description><![CDATA[A wave of cyberattacks against retailers running the Magento 1.x e-commerce platform earlier this September has been attributed to one single group, according to the latest research.
"This group has carried out a large number of diverse Magecart attacks that often compromise large numbers of webs...]]></description>
<link>https://tsecurity.de/de/1293330/it-security-nachrichten/over-2800-e-shops-running-outdated-magento-software-hit-by-credit-card-hackers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1293330/it-security-nachrichten/over-2800-e-shops-running-outdated-magento-software-hit-by-credit-card-hackers/</guid>
<pubDate>Wed, 11 Nov 2020 13:02:14 +0100</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A wave of cyberattacks against retailers running the Magento 1.x e-commerce platform earlier this September has been attributed to one single group, according to the latest research.
"This group has carried out a large number of diverse Magecart attacks that often compromise large numbers of websites at once through supply chain attacks, such as the Adverline incident, or through the use of<img src="http://feeds.feedburner.com/~r/TheHackersNews/~4/Rgjd3zFkPPs" height="1" width="1" alt="">]]></content:encoded>
</item>
<item>
<title><![CDATA[Retail Security: Magecart and the Rise of e-Commerce Threats]]></title>
<description><![CDATA[$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('PD0iHTwAd0g');
									});]]></description>
<link>https://tsecurity.de/de/1277279/it-security-video/retail-security-magecart-and-the-rise-of-e-commerce-threats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1277279/it-security-video/retail-security-magecart-and-the-rise-of-e-commerce-threats/</guid>
<pubDate>Mon, 26 Oct 2020 21:17:04 +0100</pubDate>
<category>🎥 IT Security Video</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<enclosure url="https://i.ytimg.com/vi/PD0iHTwAd0g/hqdefault.jpg" length="0" type="image/jpeg" />
<content:encoded><![CDATA[<div id="ytplayer_PD0iHTwAd0g"></div>

					<script>
									$(document).ready(function() {
										onYouTubePlayerAPIReadyByID('PD0iHTwAd0g');
									}); 
									</script>]]></content:encoded>
</item>
<item>
<title><![CDATA[CymaticONE + VADR’s new features allow customers to protect their web properties from persistent attacks]]></title>
<description><![CDATA[Cymatic unveiled exciting new features to its client-side web application firewall, CymaticONE + VADR—the only WAF solution that combines client-side WAF defenses with a proprietary vulnerability, awareness, detection, and response (VADR) engine to deliver continuous in-session intelligence and c...]]></description>
<link>https://tsecurity.de/de/1272905/it-security-nachrichten/cymaticone-vadrs-new-features-allow-customers-to-protect-their-web-properties-from-persistent-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1272905/it-security-nachrichten/cymaticone-vadrs-new-features-allow-customers-to-protect-their-web-properties-from-persistent-attacks/</guid>
<pubDate>Thu, 22 Oct 2020 03:31:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Cymatic unveiled exciting new features to its client-side web application firewall, CymaticONE + VADR—the only WAF solution that combines client-side WAF defenses with a proprietary vulnerability, awareness, detection, and response (VADR) engine to deliver continuous in-session intelligence and cyber threat defense for users and applications. Click. Click. Done. It’s that simple. CymaticONE + VADR installs at the client with a single line of JavaScript to combat modern-day cyber threats such as Magecart, cross-site scripting (XSS), … <a href="https://www.helpnetsecurity.com/2020/10/22/cymatic-cymaticone-vadr/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a rel="nofollow" href="https://www.helpnetsecurity.com/2020/10/22/cymatic-cymaticone-vadr/">CymaticONE + VADR’s new features allow customers to protect their web properties from persistent attacks</a> appeared first on <a rel="nofollow" href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[British Airways fined £20m for Magecart hack that exposed 400k folks' credit card details to crooks]]></title>
<description><![CDATA[Airline was saving domain admin creds and card details alike in plaintext British Airways is to pay a £20m data protection fine after its 2018 Magecart hack – even though the Information Commissioner’s Office discovered the airline had been saving credit card details in plain text since 2015.…]]></description>
<link>https://tsecurity.de/de/1267400/it-security-nachrichten/british-airways-fined-20m-for-magecart-hack-that-exposed-400k-folks-credit-card-details-to-crooks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1267400/it-security-nachrichten/british-airways-fined-20m-for-magecart-hack-that-exposed-400k-folks-credit-card-details-to-crooks/</guid>
<pubDate>Fri, 16 Oct 2020 14:31:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h4>Airline was saving domain admin creds and card details alike in plaintext</h4> <p>British Airways is to pay a £20m data protection fine after its 2018 Magecart hack – even though the Information Commissioner’s Office discovered the airline had been saving credit card details in plain text since 2015.…</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Boom! Mobile Customer Data Lost to Fullz House/Magecart Attack]]></title>
<description><![CDATA[The Magecart spinoff group targeted the wireless service provider in an odd choice of victim.]]></description>
<link>https://tsecurity.de/de/1258035/it-security-nachrichten/boom-mobile-customer-data-lost-to-fullz-housemagecart-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1258035/it-security-nachrichten/boom-mobile-customer-data-lost-to-fullz-housemagecart-attack/</guid>
<pubDate>Tue, 06 Oct 2020 20:46:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The Magecart spinoff group targeted the wireless service provider in an odd choice of victim.]]></content:encoded>
</item>
<item>
<title><![CDATA[Boom! Mobile falls prey to Magecart card-skimming attack]]></title>
<description><![CDATA[Researchers say the website is still compromised, placing consumers at risk.]]></description>
<link>https://tsecurity.de/de/1257384/hacking/boom-mobile-falls-prey-to-magecart-card-skimming-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1257384/hacking/boom-mobile-falls-prey-to-magecart-card-skimming-attack/</guid>
<pubDate>Tue, 06 Oct 2020 13:15:46 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researchers say the website is still compromised, placing consumers at risk.]]></content:encoded>
</item>
<item>
<title><![CDATA[Fullz House hacked the website of Boom! Mobile provider to steal credit cards]]></title>
<description><![CDATA[The credit card skimming group Fullz House has compromised the website of US mobile virtual network operator (MVNO) Boom! Mobile. The credit card skimming group Fullz House has compromised the website of US mobile virtual network operator (MVNO) Boom! Mobile in a classic MageCart attack. Boom! Mo...]]></description>
<link>https://tsecurity.de/de/1257295/hacking/fullz-house-hacked-the-website-of-boom-mobile-provider-to-steal-credit-cards/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1257295/hacking/fullz-house-hacked-the-website-of-boom-mobile-provider-to-steal-credit-cards/</guid>
<pubDate>Tue, 06 Oct 2020 12:00:49 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The credit card skimming group Fullz House has compromised the website of US mobile virtual network operator (MVNO) Boom! Mobile. The credit card skimming group Fullz House has compromised the website of US mobile virtual network operator (MVNO) Boom! Mobile in a classic MageCart attack. Boom! Mobile offers postpaid and prepaid no-contract wireless service plans to its customers that […]</p>
<p>The post <a rel="nofollow" href="https://securityaffairs.co/wordpress/109144/malware/boom-mobile-e-skimmer.html">Fullz House hacked the website of Boom! Mobile provider to steal credit cards</a> appeared first on <a rel="nofollow" href="https://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Erfolgreiche Angriffskampagne trifft Online-Shops auf Basis von Magento 1]]></title>
<description><![CDATA[Der Support für Version 1.x der Onlineshop-Software Magento endete im Juni 2020. Eine aktuelle "Magecart"-Angriffskampagne zielt nun auf veraltete Shops.]]></description>
<link>https://tsecurity.de/de/1237772/it-nachrichten/erfolgreiche-angriffskampagne-trifft-online-shops-auf-basis-von-magento-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1237772/it-nachrichten/erfolgreiche-angriffskampagne-trifft-online-shops-auf-basis-von-magento-1/</guid>
<pubDate>Tue, 15 Sep 2020 17:03:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Support für Version 1.x der Onlineshop-Software Magento endete im Juni 2020. Eine aktuelle "Magecart"-Angriffskampagne zielt nun auf veraltete Shops.]]></content:encoded>
</item>
<item>
<title><![CDATA[Erfolgreiche Angriffskampagne trifft Online-Shops auf Basis von Magento 1]]></title>
<description><![CDATA[Der Support für Version 1.x der Onlineshop-Software Magento endete im Juni 2020. Eine aktuelle "Magecart"-Angriffskampagne zielt nun auf veraltete Shops.]]></description>
<link>https://tsecurity.de/de/1237735/it-security-nachrichten/erfolgreiche-angriffskampagne-trifft-online-shops-auf-basis-von-magento-1/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1237735/it-security-nachrichten/erfolgreiche-angriffskampagne-trifft-online-shops-auf-basis-von-magento-1/</guid>
<pubDate>Tue, 15 Sep 2020 17:02:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Der Support für Version 1.x der Onlineshop-Software Magento endete im Juni 2020. Eine aktuelle "Magecart"-Angriffskampagne zielt nun auf veraltete Shops.]]></content:encoded>
</item>
<item>
<title><![CDATA[Thousands of Magento stores hacked in a few days in largest-ever skimming campaign]]></title>
<description><![CDATA[Thousands of Magento online stores have been hacked over the past few days as part of the largest ever skimming campaign. Security experts from cybersecurity firm Sansec reported that nearly 2,000 Magento online stores have been hacked over the past few days as part of the largest ever Magecart-s...]]></description>
<link>https://tsecurity.de/de/1236981/hacking/thousands-of-magento-stores-hacked-in-a-few-days-in-largest-ever-skimming-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1236981/hacking/thousands-of-magento-stores-hacked-in-a-few-days-in-largest-ever-skimming-campaign/</guid>
<pubDate>Mon, 14 Sep 2020 23:30:50 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Thousands of Magento online stores have been hacked over the past few days as part of the largest ever skimming campaign. Security experts from cybersecurity firm Sansec reported that nearly 2,000 Magento online stores have been hacked over the past few days as part of the largest ever Magecart-style campaign. Most of the hacked sites […]</p>
<p>The post <a rel="nofollow" href="https://securityaffairs.co/wordpress/108282/cyber-crime/magento-stores-skimming-campaign.html">Thousands of Magento stores hacked in a few days in largest-ever skimming campaign</a> appeared first on <a rel="nofollow" href="https://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Magecart Attack Impacts More Than 10K Online Shoppers]]></title>
<description><![CDATA[Close to 2,000 e-commerce sites were infected over the weekend with a payment-card skimmer, maybe the result of a zero-day exploit.]]></description>
<link>https://tsecurity.de/de/1236762/it-security-nachrichten/magecart-attack-impacts-more-than-10k-online-shoppers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1236762/it-security-nachrichten/magecart-attack-impacts-more-than-10k-online-shoppers/</guid>
<pubDate>Mon, 14 Sep 2020 18:46:22 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Close to 2,000 e-commerce sites were infected over the weekend with a payment-card skimmer, maybe the result of a zero-day exploit.]]></content:encoded>
</item>
<item>
<title><![CDATA[Warner Music Group online stores hit by look-like Magecart attack]]></title>
<description><![CDATA[Warner Music Group (WMG) disclosed a data breach affecting US-based e-commerce stores, the compromise appears to be a Magecart attack. Warner Music Group (WMG) is a major music company with interests in recorded music, music publishing and artist services. The company has disclosed a data breach ...]]></description>
<link>https://tsecurity.de/de/1228459/hacking/warner-music-group-online-stores-hit-by-look-like-magecart-attack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1228459/hacking/warner-music-group-online-stores-hit-by-look-like-magecart-attack/</guid>
<pubDate>Fri, 04 Sep 2020 17:45:46 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Warner Music Group (WMG) disclosed a data breach affecting US-based e-commerce stores, the compromise appears to be a Magecart attack. Warner Music Group (WMG) is a major music company with interests in recorded music, music publishing and artist services. The company has disclosed a data breach that impacted customers’ personal and financial information, the incident […]</p>
<p>The post <a rel="nofollow" href="https://securityaffairs.co/wordpress/107897/data-breach/warner-music-group-data-breach.html">Warner Music Group online stores hit by look-like Magecart attack</a> appeared first on <a rel="nofollow" href="https://securityaffairs.co/wordpress">Security Affairs</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warner Music discloses months-long web skimming incident]]></title>
<description><![CDATA[Magecart hacker gangs strike again!]]></description>
<link>https://tsecurity.de/de/1227672/hacking/warner-music-discloses-months-long-web-skimming-incident/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1227672/hacking/warner-music-discloses-months-long-web-skimming-incident/</guid>
<pubDate>Fri, 04 Sep 2020 01:45:38 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Magecart hacker gangs strike again!]]></content:encoded>
</item>
<item>
<title><![CDATA[Warner Music Group finds hackers compromised its online stores]]></title>
<description><![CDATA[Warner Music Group (WMG), the third-largest global music recording company, has disclosed a data breach affecting customers' personal and financial information after several of its US-based e-commerce stores were hacked in April 2020 in what looks like a Magecart attack. [...]]]></description>
<link>https://tsecurity.de/de/1227532/it-security-nachrichten/warner-music-group-finds-hackers-compromised-its-online-stores/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1227532/it-security-nachrichten/warner-music-group-finds-hackers-compromised-its-online-stores/</guid>
<pubDate>Thu, 03 Sep 2020 22:02:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Warner Music Group (WMG), the third-largest global music recording company, has disclosed a data breach affecting customers' personal and financial information after several of its US-based e-commerce stores were hacked in April 2020 in what looks like a Magecart attack. [...]]]></content:encoded>
</item>
<item>
<title><![CDATA[Inter: a ‘low bar’ kit for Magecart credit card skimmer attacks on e-commerce websites]]></title>
<description><![CDATA[Researchers say that any attacker with a “little cash to burn” can join the attack trend.]]></description>
<link>https://tsecurity.de/de/1226958/hacking/inter-a-low-bar-kit-for-magecart-credit-card-skimmer-attacks-on-e-commerce-websites/</link>
<guid isPermaLink="true">https://tsecurity.de/de/1226958/hacking/inter-a-low-bar-kit-for-magecart-credit-card-skimmer-attacks-on-e-commerce-websites/</guid>
<pubDate>Thu, 03 Sep 2020 13:15:40 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Researchers say that any attacker with a “little cash to burn” can join the attack trend.]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,08ms -->