HomeSecurityBoom! Mobile: Fullz House breached the mobile phone provider's site...

Boom! Mobile: Fullz House hacked the mobile provider's site to steal credit cards

Fullz House, a hacking group known for credit card skimming , has compromised and infected the website of US mobile virtual network operator (MVNO) Boom! Mobile with a credit card stealing script. Boom! Mobile provides US-based customers with prepaid, contract-free wireless service plans that operate on the country’s major mobile networks, including AT&T, Verizon and T-Mobile. This type of breach is known as a MageCart attack , web skimming or e-skimming. These scripts are then used by hackers to steal credit card or personal information submitted by the sites’ customers in e-commerce forms.

As reported by BleepingComputer, breach is currently ongoing, with the Fullz House group's malicious credit card skimmer active on the company's shopping cart-based e-commerce platform.

Boom! Mobile-site violation

According to Malwarebytes, the hackers provided a single line of code that loads an external JavaScript library from paypal-debit[.]com/cdn/ga.js, disguised as a Google Analytics script.

The skimmer collects credit card details from the corresponding input fields whenever it detects any changes, immediately executing the collected data as a GET request with Base64 encoding.

While the exact method Fullz House used to infiltrate Boom! Mobile's site with the aim of stealing credit cards is unknown, Malwarebytes observed that the company's site is running PHP version 5.6.40, a version that stopped being supported in January of last year.

Boom! Mobile-site breach by Fullz House

Malwarebytes reported the security incident to Boom! Mobile via live chat and email, but has not yet received a response from the company. Malwarebytes added that Boom! Mobile's website remains at risk, as do its online shoppers.

Fullz House uses a hybrid skimming/ phishing, as discovered by researchers at digital threat management firm RiskIQ. The group members perform skimming and phishing attacks, targeting banking and credit card information from both payment provider customers and e-commerce platform payments. Furthermore, they attempt to develop their own web skimmers rather than relying on skimmers created by others that are camouflaged as Google Analytics scripts and loaded via a script tag within compromised online stores.

Boom! Mobile-site breach by Fullz House aimed at stealing credit cards

However, unlike modern skimmers that collect data only when customers complete the order, Fullz House's skimmer scripts work more like a keylogger that constantly checks input fields for changes.

In addition, the skimmer developed by Fullz House also functions as a phishing tool, redirecting victims who click the “Buy”from the compromised online store to fake and “fraudulent” payment sites, which are designed to “mimic” payment interfaces from legitimate financial institutions. On this page, victims are asked to enter payment details that are sent to the attackers’ servers once the “Pay”. Victims are immediately redirected to the store’s real payment processor page to complete the purchase, unaware that their credit card details have been stolen.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS