Emerging MakeFrame Skimmer from Magecart Sets Sights on SMBs
#1
Information 
Quote:Researchers have observed a new skimmer from the prolific Magecart Group that has been actively harvesting payment-card data from 19 different victim websites, mainly belonging to small- and medium-sized businesses (SMBs), for several months.
 
RiskIQ researchers first discovered the skimmer, dubbed MakeFrame for its use of iframes to skim data, on Jan. 24. Since then, they’ve captured several different versions of the skimmer with “various levels of obfuscation,” researchers Jordan Herman and Mia Ihm wrote in a blog post published Thursday.
 
The versions range from from development versions in clear code to finalized versions using encrypted obfuscation, they wrote.
 
“This version of the skimmer is the classic Magecart blob of hex-encoded terms and obfuscated code,” Herman and Ihn wrote. “It is nestled in amongst benign code to blend in and avoid detection.”
MakeFrame also leeches off the compromised site for its functionality, a technique that in particular alerted researchers that MakeFrame is most likely the work of Magecart Group 7. And, targeting SMB sites, as MakeFrame does, also is indicative of Magecart Group 7 activity, researchers said.
 
“In some cases, we’ve seen MakeFrame using compromised sites for all three of its functions — hosting the skimming code itself, loading the skimmer on other compromised websites and exfiltrating the stolen data,” Herman and Ihm wrote.

Read more: https://threatpost.com/emerging-makefram...bs/154374/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Forced bios update
Hey! I’ve run into s...BrynnD — 10:03
Surfshark VPN : Award-winning VPN servi...
Surfshark Apps Ver...jasonX — 07:34
Surfshark VPN : Award-winning VPN servi...
How to unblock block...jasonX — 07:11
K-Lite Codec Pack 19.6.8 / 19.6.8 Update
Changes in 19.6.8:...harlan4096 — 07:02
AdGuard for Windows 7.22.7
AdGuard for Window...harlan4096 — 07:01

[-]
Birthdays
Today's Birthdays
avatar (45)wapedDow
Upcoming Birthdays
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)Toligo

[-]
Online Staff
There are no staff members currently online.

>