Browser Extensions Abused in New Credit Card Skimming Attack to Steal Financial Data
ID: 8bacd832-24e0-511e-8c2d-498c473f5953
STIX ID: report--8bacd832-24e0-511e-8c2d-498c473f5953
Feed Name: Cyber Press
FortiGuard Labs uncovered "RolandSkimmer," a malicious campaign that distributes a ZIP containing a shortcut (LNK) which executes an obfuscated VBScript via mshta.exe to deploy browser extensions (malicious or mimicking legitimate ones) across Chrome, Edge, and Firefox. The extensions intercept network requests and form submissions to exfiltrate credit card data, while persistence is achieved by modifying browser shortcuts and preconfiguring Firefox profiles; the report includes domains, file names, and other IoCs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
