HomeSecurityHackers abuse Google Tag Manager to deliver credit card skimmer

Hackers abuse Google Tag Manager to deliver credit card skimmer

Hackers are abusing Google Tag Manager (GTM) to deliver credit card skimmer malware, targeting Magento-based e-commerce sites.

credit card skimmer malware Google Tag Manager

Security firm Sucuri said the malicious code appears to be a typical GTM and Google Analytics script used for advertising and analytics purposes. In fact, it contains an obfuscated backdoor that gives attackers permanent access.

At least three sites appear to have been infected with the GTM identifier in question (GTM-MLHK2N68). The GTM identifier refers to a container that includes various tracking codes (e.g. Google Analytics, Facebook Pixel) and rules that should be triggered when certain conditions are met.

See also: WordPress Skimmers Steal Credit Cards Through Malicious JavaScript

Further analysis by the researchers revealed that the malware is loaded from the Magento database table “cms_block.content”, with the GTM tag containing an encoded JavaScript payload that acts as a credit card skimmer.

This script collects sensitive data entered by users during the checkout process. Specifically, the credit card skimmer malware steals credit card information and personal details, which are sent to a remote server controlled by the attackers.

This isn't the first time Google Tag Manager has been used by cybercriminals for malicious purposes. In 2018, Sucuri revealed that the tool had been used in a malvertising campaign.

See also: Microsoft: Hackers deploy malware via ASP.NET keys

Protection from credit card skimmers

Store owners can protect themselves from credit card skimmers by regularly updating their software. Platforms like WordPress, Magento, and OpenCart frequently release security that fix known vulnerabilities. It is critical to install these updates promptly to reduce the likelihood of an attack.

Hackers abuse Google Tag Manager to deliver credit card skimmer
Hackers abuse Google Tag Manager to deliver credit card skimmer

Using strong and unique passwords for all administrator and user accounts is also essential. Passwords should include a combination of letters, numbers, and special characters to make them more difficult to crack.

See also: Fake Google Chrome sites distribute ValleyRAT malware

Regularly monitoring website logs can help identify suspicious activity. Store owners should check logs for unusual or unauthorized actions that may indicate an attack.

Finally, regular backups of your website and data are essential. In the event of an attack, backups can help restore your website and minimize data loss.

Source: thehackernews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS