Silent Skimmer: Online Payment Scraping Campaign Shifts Targets From APAC to NALA
ID: c5311950-8aee-50b9-8e67-86f42da2b9f7
STIX ID: report--c5311950-8aee-50b9-8e67-86f42da2b9f7
Feed Name: Arctic Wolf Blog
Arctic Wolf Labs describes the "Silent Skimmer" campaign: an active, financially motivated operation that exploits vulnerable IIS/ASP.NET web applications (notably via CVE‑2019‑18935) to deploy Godzilla webshells, PowerShell RATs, and privilege‑escalation tools, then injects obfuscated JavaScript into checkout pages to scrape and exfiltrate payment data; the report includes TTP mapping (MITRE ATT&CK), network infrastructure details, IOCs (file hashes, domains, IPs), and attribution indicators pointing to Chinese‑language tooling and APAC‑based C2 infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
