logo

Browser Extensions Abused in New Credit Card Skimming Attack to Steal Financial Data

ID: 8bacd832-24e0-511e-8c2d-498c473f5953

STIX ID: report--8bacd832-24e0-511e-8c2d-498c473f5953

Feed Name: Cyber Press

Threat Score
72/100

Date Published: 2025-04-04

Date Updated: 2026-04-13

Author: Mandvi

...
...

FortiGuard Labs uncovered "RolandSkimmer," a malicious campaign that distributes a ZIP containing a shortcut (LNK) which executes an obfuscated VBScript via mshta.exe to deploy browser extensions (malicious or mimicking legitimate ones) across Chrome, Edge, and Firefox. The extensions intercept network requests and form submissions to exfiltrate credit card data, while persistence is achieved by modifying browser shortcuts and preconfiguring Firefox profiles; the report includes domains, file names, and other IoCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.