logo

The Stealth Skimmer: How Hackers Weaponized WebRTC to Bypass PCI Security and Siphon Credit Cards

ID: db8acc20-b389-5216-9a73-868cc5045750

STIX ID: report--db8acc20-b389-5216-9a73-868cc5045750

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-03-30

Date Updated: 2026-04-23

Author: Ddos

...
...

Sansec has identified a novel and active WebRTC-based web skimming campaign that weaponizes the WebRTC DataChannel to exfiltrate credit card data from e-commerce checkout pages, evading CSP and HTTP-focused network defenses. The attackers use ephemeral JavaScript loaders (reusing script nonces or exploiting unsafe directives), deferred execution (requestIdleCallback), and encrypted UDP transmissions to send stolen payment data; initial access is likely linked to the PolyShell vulnerability in Adobe Commerce/Magento, and several multinational organizations including a major U.S. bank and an automotive giant were reported affected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.