Hackers used a cloud video hosting service to carry out a supply chain attack on more than a hundred real estate sites, inserting malicious scripts to steal credit card information.

These scripts are known as skimmers or formjackers and are usually inserted into compromised websites to steal sensitive information. Skimmers are commonly used on checkout pages in online stores to steal payment information.
See also: Malicious Telegram installer installs Purple Fox malware on infected machines
In the new attack, discovered by researchers at Palo Alto Networks Unit42, hackers abused a cloud video hosting feature to inject skimmer code into a video player. When a site uses that player, it also uses the malicious script, resulting in the site being infected.
Researchers found over 100 real estate sites compromised as part of this hacking campaign.
Researchers alerted the cloud video platform and helped the infected sites clean up their pages. However, this campaign is a representative example of the ingenuity and determination of cybercriminals .
With a single breach, hundreds of infections
The cloud video platform used by the hackersallows users to create video players that include custom JavaScript scripts to customize the player.
A customized video player like this, which is usually embedded in real estate sites, used a static JavaScript file that was hosted on a remote server.
See also: Broward Health: Data breach affects 1.3 million people
Unit42 researchers believe that the attackers gained access to the upstream JavaScript file and modified it to include a malicious skimmer script.
In the next update of the player, the video player began displaying the malicious script on all real estate sites that already had the player embedded. Thus, the script could steal sensitive information entered into website forms.

The code itself is highly obfuscated, making it difficult to detect by unsophisticated security tools.
Researchers discovered that the skimmer steals victims' names, email addresses, phone numbers, and credit card information. This stolen information is then sent to a server controlled by the attackers. The hackers can then use the stolen data to carry out other attacks.
See also: The Lapsus$ ransomware gang “hit” the media company Impresa
Palo Alto Networks has published a complete list of IoCs (indicators of compromise) in this GitHub repository.
A new significant threat
This hacking campaign, which abuses a cloud video hosting service to steal credit card details, uses a “polymorphic” and constantly evolving skimmer that cannot be countered by conventional methods of domain name and URL blocking.
Website administrators who embed JavaScript scripts in their sites must be careful, even if the source is considered trustworthy.
Source: Bleeping Computer
