No Cookies for CartThief, a New Magecart Variant
#1
Quote:A new variant of the Magecart attacks has been targeting smaller e-commerce operations, according to The Media Trust’s digital security and operations (DSO) team.
Researchers found a new type of malware that targets payment pages on legitimate Magento-hosted retail sites. Dubbed CartThief, the malware’s behavior is similar to that of the current iteration of the Magecart malware.

As soon as credit card information is entered into a checkout page and a payment is submitted, the malware collects, encrypts and sends personally identifiable (PII) and financial information to the malicious actors’ command-and-control server.
What sets this malware apart is the method used to encode or obfuscate the malicious domain and the PII data collection activity. To avoid arousing suspicion and sneak past many blocking technologies, there are no user-identifying cookies or source codes to set off alarms for users. The absence of cookies is one feature that differentiates CartThief from other Magecart variants.

Source: https://www.infosecurity-magazine.com/ne...ief-a-new/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
CrystalDiskInfo 9.9.0 [2026/05/18]
CrystalDiskInfo 9....harlan4096 — 06:43
Adobe Acrobat Reader DC 2026.001.21563
Adobe Acrobat Read...harlan4096 — 06:42
FastCopy 5.11.3
FastCopy 5.11.3: ...harlan4096 — 06:40
QOwnNotes
26.5.12 Added a n...Kool — 03:51
AnyViewer 3.6.0 for macOS
AnyViewer 3.6.0 fo...harlan4096 — 10:44

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)axuben
avatar (40)ihijudu
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
leemaek's profile leemaek

>