2021-06-28
:: Luke
#MAGECART GROUP 12
#toolser.pw
#pathc.space
#skimmer
#ecommerce
#magento
#PHP
#website malware
This PHP code injection is used to selectively inject the JavaScript skimmer that is loaded from toolser.pw
(recently had been using pathc.space
).
2021-06-13
:: Luke
#hotjar.info
#wss
#skimmer
#ecommerce
#magento
#JavaScript
#website malware
A twist on the old ‘analytics code’ camouflage used by some skimmers to evade detection.
2021-06-03
:: Luke
#analiticsweb.site
#zulhqmnr@netmail.tk
#skimmer
#ecommerce
#magento
#JavaScript
#website malware
A JavaScript skimmer that loads from analiticsweb[.]site/analytics.js - and opsec failure leads to discovery of more malicious domains.
2021-05-08
:: Luke
#lolzilla
#portzilla
#skimmer
#ecommerce
#magento
#JavaScript
#PHP
#website malware
lolzilla skimmer analyzes a visitor’s HTTP request to determine whether it can capture the visitor’s payment data using a PHP skimmer or if it should deploy a JavaScript skimmer onto the checkout page to capture the data.
2021-04-25
:: Luke
#secure-authorize.net
#php://input
#skimmer
#fraud
#magento
#ecommerce
#PHP
#website malware
A PHP skimmer that exfiltrates the stolen payment data to a fake DLL file on the malicious domain secure-authorize.net.