logo

Tech-support Scams and Credit Card Hijacking

ID: 83d7454d-ca96-54c7-8657-cb8191d4a096

STIX ID: report--83d7454d-ca96-54c7-8657-cb8191d4a096

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ reports active campaigns abusing compromised DotNetNuke and Magento sites: obfuscated JavaScript injections on DNN pages trigger tech-support scareware popups (including audio and calls to paid support) while injected scripts on Magento checkouts inject fake payment forms that exfiltrate credit card data. The report documents attack chains, redirection behavior, code obfuscation, estimated scale (≈2,000 affected DNN pages and ≈400 Magento domains over three months), and provides lists of compromised sites for remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.