Massive malicious campaign by FakeSecurity JS-sniffer
ID: c63866b5-2b1c-5c92-85b9-3248a75782d2
STIX ID: report--c63866b5-2b1c-5c92-85b9-3248a75782d2
Feed Name: Group-IB Blog
Threat Score
Group-IB identified the FakeSecurity JS-sniffer campaign (Dec 2018–2019) where attackers used Mephistophilus phishing landing pages and spam to deliver Vidar password-stealer to e-commerce administrators, then leveraged stolen credentials to install JS-sniffers on Magento sites to capture customers' payment data; the report details the infection chain, associated infrastructure (domains, IPs), and file hashes for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
