New Credit Card Skimmer Targets WordPress, Magento, and OpenCart Sites
ID: 94ea5f4f-2b02-5870-b98e-07e6bb7e5147
STIX ID: report--94ea5f4f-2b02-5870-b98e-07e6bb7e5147
Feed Name: The Hacker News
Multiple CMS platforms including WordPress (WooCommerce), Magento, and OpenCart are being targeted by the "Caesar Cipher Skimmer," a credit-card web skimmer that injects obfuscated PHP/JS (masquerading as style sheets and as Google Analytics/Tag Manager) to harvest payment data. The campaign uses a Caesar-cipher-like encoding to conceal payload domains, loads a second-layer script via WebSocket to fetch the skimmer, and persists through modified checkout files, WPCode plugin abuse, and database injections; Russian-language comments suggest Russian-speaking operators. Site owners are advised to keep CMS and plugins up to date, enforce strong passwords, and audit administrator accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
