Analysis of a recent Magecart campaign
ID: 92dc6c9a-8f97-500d-889d-edeb70f7d10a
STIX ID: report--92dc6c9a-8f97-500d-889d-edeb70f7d10a
Feed Name: BushidoToken Blog
Threat Score
SanSec disclosed a Magecart campaign using jquerycdn.at to host JavaScript skimmers that were injected into checkout pages of at least 299 stores (predominantly Magento 1). The skimmers collect credit card data and personal details via functions such as GetCCInfo and SaveParam, base64-encode the data and exfiltrate it to jquerycdn.at/gate.php; the report includes domains, an IP (217.8.117.75), multiple file hashes, and notes the malicious infrastructure remains online.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
