m2cmds.php: Magento 2 Dev Tool or Deceptive Hacktool?

m2cmds.php: Magento 2 Dev Tool or Deceptive Hacktool?
Is this m2cmds.php file an insecure third-party dev tool for Magento - or a malicious hacktool used by an attacker?
Read more →

Skimmer Loaded Via Image On MemberPress Checkout Form & Magento

Skimmer Loaded Via Image On MemberPress Checkout Form & Magento
A payment card skimmer hidden within an existing PNG image on an infected WordPress website that uses MemberPress and collects payment data for private membership. A variant was also found stealing payment card information on an infected Magento website.
Read more →

Trojan Malware, Recon, & BEC Attacks

Trojan Malware, Recon, & BEC Attacks
Attackers were running recon on a foreign company via trojan spyware connected to a C2 panel on a compromised web host server. Unfortunately they forgot to have their logs and screenshots automatically purged from their C2 panel, so I was able to stumble upon their mainly intact C2 panel. Let’s see what it reveals about their operation.
Read more →

Magento 2 Skimmer Uses getCredentialStorage

Magento 2 Skimmer Uses getCredentialStorage
A PHP skimmer injected into a Magento 2 core file and used to steal login data from HTTP requests.
Read more →

Recover Data From RansomWeb Malware

Recover Data From RansomWeb Malware
RansomWeb malware rewrites your file’s text to unreadable binary data and appends .xploiter to the file’s extension (e.g index.php.xploiter) - but you can use the malware against itself to revert back to your original files.
Read more →
Disclaimer: The research posted on this website is for information purposes only. Do not use it for illegal purposes.