Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

5/19/2020
05:10 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Magecart Plants Card Skimmers via Old Magento Plug-in Flaw

The FBI has warned ecommerce sites about attacks targeting a more than three-year-old flaw in the Magmi mass importer.

Cybercriminals operating under the Magecart umbrella group are exploiting an old vulnerability in a Magento plugin to insert credit card data-skimming malware on sites built on the ecommerce platform.

In an alert earlier this month, the FBI described the latest attacks as involving CVE-2017-7391, a three-year old—and long since patched—cross-site scripting vulnerability in the Magmi 0.7.22 mass importer for Magento.

According to the FBI, the attackers breached a US Magento e-commerce site via the vulnerable plugin and placed malicious JavaScript code on checkout pages where users submit payment card data and personal information. The attackers also retrieved administrator credentials and downloaded web shells that allowed them to install other malware and maintain a persistent presence on the site.

The malware allowed the attackers to gather payment-card data and other information belonging to cardholders such as their names, email addresses, physical addresses, and phone numbers. The criminals encrypted the stolen data and stored it in a JPEG dump file they had created. They later used the web shell to extract the dump file using HTTP GET requests, the FBI said.

The alert provided indicators of compromise that organizations running Magento could use to protect their site against the Magecart attacks.

Pervasive Threat

Magecart is an umbrella term for a collection of at least seven separate groups that have been placing online card skimmers on hundreds of thousands of e-commerce sites worldwide over the last few years. Some estimates have pegged the number of sites that Magecart actors have comprised at more than two million.

In many cases, the skimmers have been comprised of very small pieces of JavaScript code injected into vulnerable plugins and other third-party components on e-commerce sites. Typically, the malware has worked by capturing payment card data and other PII that users enter into checkout pages and then transmitting the data to remote, attacker-controlled systems.

Hank Schless, senior manager of security solutions at Lookout, says the card-skimming malware Magecart injects into websites can be hard to spot. "Much like a Trojanized version of a legitimate mobile app appearing on an app store or a text supposedly from your bank with a normal-looking URL, malicious actors always look for ways to throw as few red flags as possible," he says. 

With a majority of people working from home and conducting a lot more transactions online than before because of the COVID-19 pandemic, expect bad actors like Magecart to ramp up their malicious activity, Schless says.

"Magecart is a perfect example of threat actors exploiting a changing risk landscape that IT and security teams have been forced to protect against," he says. The environment makes it necessary for organizations to lock down every extension of the corporate network - from payment platforms to employee mobile devices, Schless says.

Alex Guirakhoo, threat research team lead at Digital Shadows, says the surge in online activity as a result of COVID-19 has given attackers a larger attack surface. According to Guirakhoo, cybercriminals in underground forums have been actively discussing ways to take advantage of increased consumer traffic on ecommerce sites to hide their malicious activity.

"To mitigate against code-injection attacks, organizations should ensure that they monitor for any unauthorized code changes, particularly on checkout pages of e-commerce platforms," Guirakhoo notes. "Organizations should also monitor for any publicly disclosed vulnerabilities affecting any of their third-party e-commerce platforms."

Related Content:

A listing of free products and services compiled for Dark Reading by Omdia analysts to help meet the challenges of COVID-19. 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
COVID-19: Latest Security News & Commentary
Dark Reading Staff 11/19/2020
New Proposed DNS Security Features Released
Kelly Jackson Higgins, Executive Editor at Dark Reading,  11/19/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: He hits the gong anytime he sees someone click on an email link.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-29070
PUBLISHED: 2020-11-25
osCommerce 2.3.4.1 has XSS vulnerability via the authenticated user entering the XSS payload into the title section of newsletters.
CVE-2020-26212
PUBLISHED: 2020-11-25
GLPI stands for Gestionnaire Libre de Parc Informatique and it is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. In GLPI before version 9.5.3, any authenticated user has read-only permissions to the planning of ever...
CVE-2020-26243
PUBLISHED: 2020-11-25
Nanopb is a small code-size Protocol Buffers implementation. In Nanopb before versions 0.4.4 and 0.3.9.7, decoding specifically formed message can leak memory if dynamic allocation is enabled and an oneof field contains a static submessage that contains a dynamic field, and the message being decoded...
CVE-2020-25650
PUBLISHED: 2020-11-25
A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service fo...
CVE-2020-29071
PUBLISHED: 2020-11-25
An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the platform as attachments, when the -htmlview URL is directly accessed. The impact ranges from executing commands as root on the server to retrieving se...