A relatively unknown group of Vietnamese hackers calling themselves “XE Group” has been linked to eight years of for-profit hacking and credit card skimming.

See also: Nobelium hacking group uses new Ceeloader malware
Threat actors are believed to be responsible for stealing thousands of credit cards per day, primarily from restaurants, non-profits, arts, and travel platforms.
Hackers use publicly available exploits to compromise externally-facing services, primarily Telerik UI flaws, to install credential and payment information-stealing malware.
A 2020 Malwarebytes report initially outlined the group's activities, but a more in-depth analysis of recent breaches attributed to it was published yesterday by Volexity.
More details emerge
Volexity was able to map the infrastructure that XE Group has been using for the past three years and shared all the technical details and IOCs on GitHub.
Researchers were able to find multiple infected sites carrying the same skimmer thanks to a common technique for loading malicious JavaScript snippets.
See also: WIRTE hacking group targets governments in the Middle East
"The code used to load the malicious JavaScript from this page reveals that the attacker uses an interesting technique: the JavaScript keyword 'object' is used to populate the domain value," the researchers said in the Volexity report.

These types of breaches are categorized as “Magecart” attacks, which is when a threat actor hacks an eCommerce website to add malicious JavaScript that collects customer and payment information as it is submitted. This stolen information is then uploaded to a remote server for the attackers to harvest.
The long-term success of these attacks depends on how well they can remain hidden on a website without being detected by security products.
See also: Docker servers targeted by hacking group TeamTNT
Uploading this skimmer sample to VirusTotal returns a detection score of 0/57, meaning that JavaScript is very stealthy against AV detection.
Volexity attributes XE Group's activity to Vietnamese threat actors, as many of the domain names used for command and control servers are registered to an individual in Vietnam.
Information source: bleepingcomputer.com
