HomeSecurityMagecart attack: Hackers attacked the site of the gun manufacturer Smith & Wesson

Magecart attack: Hackers attacked the site of gun manufacturer Smith & Wesson

American gun manufacturer Smith & Wesson was the victim of a hacking attack late last month. Specifically, it was a Magecart attack , where attackers introduced a malicious skimmer software onto website . the company's The hackers' goal was to steal customers' financial information (from payment cards).Magecart

The Magecart attack was discovered by security researcher Willem de Groot of Sanguine Security. The researcher found that the attackers introduced the skimmer on the Smith & Wesson website on November 27.

The compromised Smith & Wesson online store is loading malicious code from a domain created by the hackers . The malicious code is designed to steal personal and financial informationthat users provide when making online purchases.

The Magecart attack is ongoing, as the skimmer is still active in the online store:

live.sequracdn [.] net / storage / modrrnize.js

Magecart attack: Hackers attacked the site of gun manufacturer Smith & Wesson

The script changes depending on the section of the site that users visit.

“This script is not easy to detect as it will load either a non- malicious or a malicious script depending on the visitor and the section of the site they are visiting,” BleepingComputer reported.

“In most sections of the site, the loaded JavaScript file looks like a normal non-malicious 11KB script. However, if you use a US IP address and non-Linux browsers, the script changes from 11KB to 20KB.”

The Smith & Wesson online store runs Magento. According to the researcher, the attackers likely exploited a vulnerability in the system to inject the malicious code and carry out the Magecart attack.

In November, Magento software was found to have a remote code execution. The vulnerability was named CVE-2019-8144. Hackers could exploit the vulnerability to deliver malicious payloads to vulnerable systems.

Users who have recently made purchases on smith-wesson.com should contact bank and check their credit cards to see if any suspicious activity has occurred.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS