HomeSecurityMagecart attacks - online stores: Hackers use 404 error pages and steal...

Magecart attacks – online stores: Hackers use 404 error pages and steal data

A new Magecart interferes with the 404 error pages of online shopping sites and hides malicious code designed to steal customers' personal information and card details.

This technique is one of three variations observed by researchers from Akamai.

404 error pages

Akamai says the attack is targeting Magento and WooCommerce, with some victims linked to well-known companies in the food and retail sectors.

Abuse of 404 error pages

All sites display a “404 error” page when visitors try to access a web page that does not exist, has moved, or has a “broken” link.

In this campaign, attackers are exploiting the default '404 Not Found' page to hide and load the malicious phishing card. This is a new infection method that we have not encountered before. This shows once again that hackers are constantly evolving their methods to carry out their malicious activities without being noticed.

See also: Balada Injector attacks: 17,000 WordPress sites compromised

The skimmer loader is either disguised as a Meta Pixel code snippet or hidden within random inline scripts, already present on the compromised fund website.

The loader initiates a fetch request to a relative path named 'icons', but since this path does not exist on the website, we end up with a “404 Not Found” error page.

According to Akamai researchers, the loader contained an expression match that looked for a specific string in the returned HTML of the 404 page. When Akamai located the string on the page, it found a base64-encoded string hidden in a comment. Decoding this string revealed the JavaScript skimmer, which is hidden in the 404 error pages of online stores.

“We simulated additional requests to non-existent paths and all returned the same 404 error page, which contained the comment with the malicious code,” Akamai explains.

“These checks confirm that the attacker successfully changed the default error page for the entire website and hid the malicious code within it!“.

Because the request is submitted over a first-party path, most security tools that monitor suspicious network requests on the checkout page willignore it.

See also: Citrix NetScaler: Hackers steal credentials from its login pages

Magecart attacks - online stores: Hackers use 404 error pages and steal data
Magecart attacks – online stores: Hackers use 404 error pages and steal data

Card information theft

The skimmer code displays a fake formthat website visitors must fill out. In this form, they must add informationsuch as their credit card number, expiration date, and security code.

After entering the details, the victim receives a fake “session expired” message.

The information is sent to the attackers encrypted.

The abuse of 404 error pages, identified in this campaign, demonstrates the evolving tactics and flexibility of attackers, which are making it increasingly difficult for website administrators to detect malicious code on compromised websites.

E-commerce and hackers

Alarm bells have been raised in the e-commerce world as more and more stores fall victim to Magecart attacks. However, there are steps that can be taken to detect and prevent attacks .

Detecting Magecart Attacks 

Many times, Magecart attacks seem extremely sophisticated. And the truth is that with the use of new techniques (such as abusing 404 pages), their detection becomes difficult. However, by checking for certain elements, such as changes in the appearance or responsiveness of your website, you can realize that something is suspicious.

See also: Israel: RedAlert app breached by hackers

Magecart
Magecart attacks – online stores: Hackers use 404 error pages and steal data

Preventing Magecart Attacks 

If we want to prevent Magecart attacks, we should implement multi-layered strategies for website security, monitoring page activity, auditing and verifying external vendors, and implementing the latest security. 

  • Multi-layered website security: This means that your line of defense should not be based on just one point. Instead, techniques should extend across all layers of the website's infrastructure, protecting servers, content management systems (CMS), and all sensitive elements.
  • Page activity monitoring: Enrich the crawling process by constantly monitoring pagination and code execution attempts.
  • Check and verify external vendors: Don't take anything for granted. Check and verify the security of third-party providers you work with.
  • Implement the latest security standards: Implement security standards against Magecart attacks and update them if they change.

E-commerce security is not a simple technical puzzle, of course. It is an ongoing challenge that requires all the tools, techniques, and strategies at our disposal. But with persistence, understanding the risks, and taking protective measures, you can stand up to hackers and keep your customers’ information safe.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS