Emerging MakeFrame Skimmer from Magecart Sets Sights on SMBs
#1
Information 
Quote:Researchers have observed a new skimmer from the prolific Magecart Group that has been actively harvesting payment-card data from 19 different victim websites, mainly belonging to small- and medium-sized businesses (SMBs), for several months.
 
RiskIQ researchers first discovered the skimmer, dubbed MakeFrame for its use of iframes to skim data, on Jan. 24. Since then, they’ve captured several different versions of the skimmer with “various levels of obfuscation,” researchers Jordan Herman and Mia Ihm wrote in a blog post published Thursday.
 
The versions range from from development versions in clear code to finalized versions using encrypted obfuscation, they wrote.
 
“This version of the skimmer is the classic Magecart blob of hex-encoded terms and obfuscated code,” Herman and Ihn wrote. “It is nestled in amongst benign code to blend in and avoid detection.”
MakeFrame also leeches off the compromised site for its functionality, a technique that in particular alerted researchers that MakeFrame is most likely the work of Magecart Group 7. And, targeting SMB sites, as MakeFrame does, also is indicative of Magecart Group 7 activity, researchers said.
 
“In some cases, we’ve seen MakeFrame using compromised sites for all three of its functions — hosting the skimming code itself, loading the skimmer on other compromised websites and exfiltrating the stolen data,” Herman and Ihm wrote.

Read more: https://threatpost.com/emerging-makefram...bs/154374/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
XYplorer
What's new in Rele...Kool — 15:21
Free Download Manager 6.30.0.6459
Changes in 6.30.0....harlan4096 — 13:51
AMD introduces Ryzen PRO 9000 series, Ry...
AMD launches first...harlan4096 — 13:49
Ashampoo Home Design 10 FREE!
Jaki jest kodCygi — 09:31
AMD launches EPYC 4005 Embedded, Zen5 CP...
AMD has new EPYC 4...harlan4096 — 08:54

[-]
Birthdays
Today's Birthdays
avatar (45)ThomasLYDAY
avatar (40)upakoExapy
Upcoming Birthdays
avatar (38)fapedDow
avatar (48)pohudidere
avatar (38)eqiduseb
avatar (49)skepwHug
avatar (38)RicardoGoase
avatar (43)Denpokhew
avatar (35)azidony
avatar (40)maskbSleew

[-]
Online Staff
There are no staff members currently online.

>