Keylogger Found Harvesting Credentials on Top US Bank’s Employee Store
ID: 3b51e510-082d-50e6-ad76-ec47773505f1
STIX ID: report--3b51e510-082d-50e6-ad76-ec47773505f1
Feed Name: securityonline.info
Threat Score
Sansec discovered an active two-stage keylogger on a top-3 U.S. bank's employee merchandise site that harvested form inputs (credentials, payment card data, PII) for ~18 hours by loading an external script (js-csp.com/getInjector/) and exfiltrating data via an image beacon; the campaign is linked to prior getInjector campaigns, affected up to ~200,000 employees, and had very low detection by security vendors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
