The Stealth Skimmer: How Hackers Weaponized WebRTC to Bypass PCI Security and Siphon Credit Cards
ID: db8acc20-b389-5216-9a73-868cc5045750
STIX ID: report--db8acc20-b389-5216-9a73-868cc5045750
Feed Name: securityonline.info
Sansec has identified a novel and active WebRTC-based web skimming campaign that weaponizes the WebRTC DataChannel to exfiltrate credit card data from e-commerce checkout pages, evading CSP and HTTP-focused network defenses. The attackers use ephemeral JavaScript loaders (reusing script nonces or exploiting unsafe directives), deferred execution (requestIdleCallback), and encrypted UDP transmissions to send stolen payment data; initial access is likely linked to the PolyShell vulnerability in Adobe Commerce/Magento, and several multinational organizations including a major U.S. bank and an automotive giant were reported affected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
