
North Korean government-sponsored hacking groups are infiltrating online stores to insert malicious code that can steal details customers' payment card when they visit the checkout page and fill out payment forms . The recent web skimming attacks on online stores have been going on since May 2019, according to Dutch security firm SanSec .
The most well-known victim of this series of attacks is the accessories chain Claire’s, which was breached in April and June.
These types of attacks are called “web skimming”, “e-skimming” or “Magecart attack”. The latter name comes from the name of the first group that engaged in this tactic.
Web skimming attacks are simple, although they require advanced technical skills to execute. Attackers attempt to gain access to an online store's backend server, related resources, or third-party widgets, in order to execute malicious code on the store's frontend.
The code is loaded only on the checkout page and secretly captures payment card detailswhen customers fill out the payment form. This data is then transferred to a remote server, from where the hackers collect it and sell it on underground marketplaces.
Web skimming attacks typically require hackers to use large infrastructure to host the malicious code.
SanSec has managed to link domains and server IP addresses used in recent web skimming attacksNorth Korean hackers government-sponsored
SanSec founder Willem de Groot said the evidence points to the hacking group Hidden Cobra (or Lazarus Group), the code name given by the US to Pyongyang hackers.

“The way HIDDEN COBRA gained access is not yet known, but attackers often use spear phishing attacks to obtain the passwords of retail staff,” de Groot said today.
The web skimming attacks discovered by SanSec provide a glimpse into the hacking operations funded by the North Korean state. In most cases, state-run hacking groups are used to spy on other governments. In the case of North Korea, however, they are also used to raise funds for the government, which is invested in weapons and missiles.
Pyongyang hackers have been linked to online bank robberies around the world, ATM robberies, cryptocurrency scams, and the hacking of cryptocurrency exchanges, and have also been accused of creating the infamous WannaCry ransomware.
