Silent Skimmer Attacks Exploiting Telerik UI to Steal Payment Data (Campaign)
ID: 92a19f06-a703-5ddb-bf7f-f573838fa648
STIX ID: report--92a19f06-a703-5ddb-bf7f-f573838fa648
Feed Name: Wiz Cloud Threat Landscape
Threat Score
Date Published: 2024-11-07
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
...
...
In May 2024, the Silent Skimmer actor exploited legacy Telerik UI vulnerabilities (CVE-2017-11317, CVE-2019-18935) to gain RCE against a multinational organization's payment systems, deploying web shells, reverse shells/proxies, and loaders to evade detection and exfiltrate payment data (saved to CSV) using compiled Python and tunneling tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
