Security researchers have noticed that some cybercriminals attacking online stores are using Telegram to extract information from the credit cards of customers making purchases.
This particular trick makes data exfiltration more effective and facilitates the entire management of the card skimming operation.
The new method was discovered by Affable Kraut using data from Sansec, a company that specializes in combating digital skimming. The researcher analyzed the malicious JavaScript, which includes common anti-analysis mechanisms.

In a Twitter, Kraut explains how the script works, noting that it collects data from any type of input field and sends it to a channel on Telegram.
All information is encrypted using a public key. A “Telegram bot” then posts the stolen data to a chat as a message.
Kraut notes that while this method is effective for data exfiltration, it can backfire because anyone with the token for the “Telegram bot” can take control of the process.
Jérôme Segura, Director of Threat Intelligence at Malwarebytes, also analyzed the script, saying that its author applied simple Base64 encoding to the bot ID, Telegram channel, and API request. Here's an image showing how the whole process works.

The researcher says that data exfiltration only begins “if the current browser URL contains a keyword indicative of a shopping website and when the user validates a purchase.” Payment details will then be sent to both the legitimate payment processor and the cybercriminals.
In an analysis published today, Segura points out that this mechanism eliminates the need for a data exfiltration infrastructure, which could be blocked by security solutions or dismantled by law enforcement.
Furthermore, protecting against this skimmer variant is not easy. Blocking connections on Telegram is a temporary solution since attackers could choose a different legitimate service to hide exfiltration.
Telegram has been used in the past to extract stolen data. Last year, Juniper Networks published an investigation into an “information thief” called “Masad Clipper and Stealer” who used the platform to deliver sensitive data stored in a victim’s browser (logins, addresses, credit cards) to cybercriminals.
Segura says that Malwarebytes has detected a few online stores infected with this variant of the card skimmer. However, the researcher believes that these are not the only ones and that many more have been infected.
