By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Cybercriminals Use Unicode to Hide Mongolian Skimmer in E-Commerce Platforms
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Cybercriminals Use Unicode to Hide Mongolian Skimmer in E-Commerce Platforms
Tech News

Cybercriminals Use Unicode to Hide Mongolian Skimmer in E-Commerce Platforms

By Viral Trending Content 4 Min Read
Share
SHARE

Oct 10, 2024Ravie LakshmananCybercrime / Malware

Mongolian Skimmer

Cybersecurity researchers have shed light on a new digital skimmer campaign that leverages Unicode obfuscation techniques to conceal a skimmer dubbed Mongolian Skimmer.

“At first glance, the thing that stood out was the script’s obfuscation, which seemed a bit bizarre because of all the accented characters,” Jscrambler researchers said in an analysis. “The heavy use of Unicode characters, many of them invisible, does make the code very hard to read for humans.”

The script, at its core, has been found to leverage JavaScript’s capability to use any Unicode character in identifiers to hide the malicious functionality.

Cybersecurity

The end goal of the malware is to steal sensitive data entered on e-commerce checkout or admin pages, including financial information, which are then exfiltrated to an attacker-controlled server.

The skimmer, which typically manifests in the form of an inline script on compromised sites that fetches the actual payload from an external server, also attempts to evade analysis and debugging efforts by disabling certain functions when a web browser’s developer tools is opened.

“The skimmer uses well-known techniques to ensure compatibility across different browsers by employing both modern and legacy event-handling techniques,” Jscrambler’s Pedro Fortuna said. “This guarantees it can target a wide range of users, regardless of their browser version.”

Mongolian Skimmer

The client-side protection and compliance company said it also observed what it described as an “unusual” loader variant that loads the skimmer script only in instances where user interaction events such as scrolling, mouse movements, and touchstart are detected.

This technique, it added, could serve both as an effective anti-bot measure and a way to ensure that the loading of the skimmer is not causing performance bottlenecks.

One of the Magento sites compromised to deliver the Mongolian skimmer is also said to have targeted by a separate skimmer actor, with the two activity clusters leveraging source code comments to interact with each other and divide the profits.

Cybersecurity

“50/50 maybe?,” remarked one of the threat actors on September 24, 2024. Three days later, the other group responded: “I agree 50/50, you can add your code :)”

Then on September 30, the first threat actor replied back, stating “Alright ) so how can I contact you though? U have acc on exploit? [sic],” likely referring to the Exploit cybercrime forum.

It’s currently not known as to how the skimmer malware is delivered to target websites, although it’s believed that the attackers are setting their sights on misconfigured or vulnerable Magento or Opencart instances.

“We have multiple victim websites, which might have been breached using different methods,” Fortuna told The Hacker News. “We don’t know exactly how they got there and were able to inject the web skimmer, but all signs point to compromised Magento or Opencart instances, either because they were poorly configured or because they had vulnerable components that the attackers exploited to get in.”

“The obfuscation techniques found on this skimmer may have looked to the untrained eye as a new obfuscation method, but that was not the case,” Fortuna noted. “It used old techniques to appear more obfuscated, but they are just as easy to reverse.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

New Apple TV Expected Summer 2026 With Apple Intelligence

Microsoft releases Windows 10 KB5087544 extended security update

When it comes to academic authorship, are women at a disadvantage?

Microsoft’s MDASH AI System Finds 16 Windows Flaws Fixed in Patch Tuesday

Honor 600 Review: The Android iPhone

TAGGED: #E-Commerce, browser security, Cyber Security, Cybercrime, Cybersecurity, data breach, Internet, JavaScript, Malware, Threat Intelligence
Share This Article
Facebook Twitter Copy Link
Previous Article Week ahead in the markets: ECB interest rate decision takes centre stage
Next Article International investors descend on London as Labour tries to woo new business to Britain
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

HDFC Mutual Fund withdraws NFO of Gold-Silver FoF
Business
Pi Network (PI) faces mild bearish pressure: Check forecast
Crypto
New Apple TV Expected Summer 2026 With Apple Intelligence
Tech News
Microsoft releases Windows 10 KB5087544 extended security update
Tech News
Key points on why Chelsea want Xabi Alonso this summer – opinion
Sports
Syria needs ‘comprehensive security agreement’ with Israel, foreign minister tells Euronews
World News
Iran’s Hidden Crypto Trails Exposed As Arkham Publishes Public Wallet Map
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?