Remove eCommerce Remove Information Security Remove Malware
article thumbnail

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 45

Security Affairs

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape iClicker site hack targeted students with malware via fake CAPTCHA New Noodlophile Stealer Distributes Via Fake AI Video Generation Platforms Backdoor found in popular ecommerce components Stealthy Linux backdoor leveraging (..)

Malware 97
article thumbnail

Crooks use Google Tag Manager skimmer to steal credit card data from a Magento-based e-stores

Security Affairs

Sucuri researchers found threat actors using Google Tag Manager (GTM) to deploy e-skimmer malware on a Magento eCommerce site. This isn’t the first time that Sucuri documented the use of GTM to deploy e-skimmer on e-store, in 2024, the experts detailed how Magecart veteran ATMZOW was using Google Tag Manager to deliver malware.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Visa warns of new sophisticated credit card skimmer dubbed Baka

Security Affairs

Baka is a sophisticated e-skimmer developed by a skilled malware developer that implements a unique obfuscation method and loader. The skimmer loads dynamically to avoid static malware scanners and uses unique encryption parameters for each victim to obfuscate the malicious code.” ” reads the alert published by VISA.

eCommerce 144
article thumbnail

NginRAT – A stealth malware targets e-store hiding on Nginx servers

Security Affairs

Threat actors are targeting e-stores with remote access malware, dubbed NginRAT, that hides on Nginx servers bypassing security solutions. Researchers from security firm Sansec recently discovered a new Linux remote access trojan (RAT), tracked as CronRAT , that hides in the Linux task scheduling system (cron) on February 31st.

Malware 142
article thumbnail

AkiraBot: AI-Powered spam bot evades CAPTCHA to target 80,000+ websites

Security Affairs

“These technologies are primarily used by small- to medium-sized businesses for their ease in enabling website development with integrations for eCommerce, website content management, and business service offerings.” .” reads the report published by SentinelOne.

eCommerce 130
article thumbnail

Sansec uncovered a supply chain attack via 21 backdoored Magento extensions

Security Affairs

“Hundreds of stores, including a $40 billion multinational, are running backdoored versions of popular ecommerce software. We found that the backdoor is actively used since at least April 20th. Sansec identified these backdoors in the following packages which were published between 2019 and 2022.”

article thumbnail

A new e-skimmer found on WordPress site using the WooCommerce plugin

Security Affairs

Experts from security firm Sucuri discovered a new e-skimmer software that is different from similar malware used in Magecart attacks. The e-skimmer doesn’t just intercept payment information provided by the users into the fields on a check-out page. reads the analysis published by Sucuri. “For It’s not so easy to see.

eCommerce 145