ADVERTISEMENT

Hackers target online shoppers in new Adobe e-commerce malware campaign

A new malware campaign that steals payment information from online shoppers is discovered lurking in dozens of e-commerce sites that use Adobe’s Magento platform, Malwarebytes said.

credit card online scam malware campaign

Image by Alexander56891 | Shutterstock

Stefanie Schappert
Stefanie Schappert Senior Journalist
August 22, 2024 Updated: August 22, 2024 3 min read

The skimming scam

Malwarebytes skimmer scam - beer e-commerce site
Example of code injection for the online store of a popular European beer manufacturer. Image by Malwarebytes.
Malwarebytes skimmer scam - java script
Example of compromised Canadian university website shows the hacker's remotely loaded JavaScript, which contains a simple function to retrieve information from the compromised site. The site’s domain name is being passed as a parameter (‘s’) into another URL meant to retrieve the actual full skimmer code, which consists of a huge blob of obfuscated JavaScript. Images by Malwarebytes.
ADVERTISEMENT

'Criminals piggyback on to legitimate websites'

Malwarebytes skimmer scam - payment sites replaced
During checkout, the payment flow is seamlessly altered such that a fake “Payment Method” frame is inserted within the store’s page. As payment details are entered, the data is transmitted in real-time and stored in a criminal database. image by Malwarebytes.

The compromised storefronts

Malwarebytes skimmer scam - malicious domains
List of websites compromised (L). Anti-malware program identifies the skimmer scam as a suspected phishing attack (R). Images by Malwarebytes.
ADVERTISEMENT