logo

Silent Skimmer: Online Payment Scraping Campaign Shifts Targets From APAC to NALA

ID: c5311950-8aee-50b9-8e67-86f42da2b9f7

STIX ID: report--c5311950-8aee-50b9-8e67-86f42da2b9f7

Feed Name: Arctic Wolf Blog

Threat Score
75/100

Date Published: 2023-09-18

Date Updated: 2026-04-27

...
...

Arctic Wolf Labs describes the "Silent Skimmer" campaign: an active, financially motivated operation that exploits vulnerable IIS/ASP.NET web applications (notably via CVE‑2019‑18935) to deploy Godzilla webshells, PowerShell RATs, and privilege‑escalation tools, then injects obfuscated JavaScript into checkout pages to scrape and exfiltrate payment data; the report includes TTP mapping (MITRE ATT&CK), network infrastructure details, IOCs (file hashes, domains, IPs), and attribution indicators pointing to Chinese‑language tooling and APAC‑based C2 infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.