• Categories
    Category
  • Categories
    Category
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
News Comments FAQ Related Articles

Magecart Targets OpenCart Websites Payment Information

5548

Opencart based online stores are now under the radar of Magecart group, a notorious group which is known for performing credit card skimming attacks.

The latest string of attacks from the group came into light after Yonathan Klijnsma of RiskIQ reported them after finding Group 12 of Magecart with skimmers on OpenCart sites similar to the ones used to target Magento-based sites. According to the report, the skimmers made use of a domain name called ‘batbing[.]com’ in the exploits.

Klijnsma observed that Group 12 used a JavaScript code known as ‘pre-filter’ to decide if they wanted to inject skimmers on the site.The script searched for the word ‘checkout’ in the URL visited by shoppers and then proceeded with inserting the skimmer. Following this, the credit card information entered by users would be stolen.

A replica of Bing's search engine script was also found on the checkout page.Earlier, a French advertising company named Adverline was a victim of the groups' multiple credit card skimming attacks.

Apart from that, it has also compromised numerous e-commerce sites running on Magento, OpenCart, and OSCommerce, and also several other Wordpress sites.Their attacks are carried out by injecting skimming code in JavaScript libraries used in these sites. Unpatched platforms are a major issue.

“Major online stores running these platforms are usually victimized when a platform-wide vulnerability comes out that requires immediate patching. But the majority of outdated platforms run on smaller, mostly unknown stores. Attackers target plugins installed on these platforms, which are often vulnerable because their developers write code for functionality over security,” Klijnsma wrote on his blog explaining the reason for the attack.

Tags:
muhammad
Author: 

Comments ( 0 )

No comments available

Add a comment

Frequently asked questions ( 0 )

No questions available

Related Tutorials in Magecart Targets OpenCart Websites Payment Information

Related Tutorials in Magecart Targets OpenCart Websites Payment Information

How to Install Opencart on Ubuntu 19.04
How to Install Opencart on Ubuntu 19.04
Jun 7, 2019
How to install Opencart – 3.0.2 on CentOS – 7
How to install Opencart – 3.0.2 on CentOS – 7
May 9, 2018
How to install Opencart on Ubuntu 18.04
How to install Opencart on Ubuntu 18.04
Jun 21, 2018
How to Install Opencart on Linuxmint 19
How to Install Opencart on Linuxmint 19
Jul 15, 2019
How to install OpenCart on CentOS 7.6
How to install OpenCart on CentOS 7.6
Jun 15, 2019
How to install  opencart 3.0.2 cms on linuxmint 18.03
How to install  opencart 3.0.2 cms on linuxmint 18.03
Jun 21, 2018
How to Create Own Online Shopping Store - OpenCart
How to Create Own Online Shopping Store - OpenCart
Jun 4, 2016

Related News in Magecart Targets OpenCart Websites Payment Information

Related News in Magecart Targets OpenCart Websites Payment Information

CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
CryptoMix Clop Ransomware Variant Targets Not Individual Machines But Whole Networks
Mar 12, 2019
URL Attacks and The Ways to Stay Away from Them!
URL Attacks and The Ways to Stay Away from Them!
Mar 19, 2019
ATM Skimming Attack With Hijacked ATM Security Camera to Steal User’s PIN
ATM Skimming Attack With Hijacked ATM Security Camera to Steal User’s PIN
Mar 13, 2019
Nine Popular WordPress plugins affected with critical SQL injection vulnerabilities
Nine Popular WordPress plugins affected with critical SQL injection vulnerabilities
Sep 7, 2019
Magecart Targets OpenCart Websites Payment Information
Magecart Targets OpenCart Websites Payment Information
May 17, 2019
WordPress 5.1.1 fixes a threatening XSS vulnerability
WordPress 5.1.1 fixes a threatening XSS vulnerability
Mar 22, 2019
Major Security Flaw Found in Cisco Routers
Major Security Flaw Found in Cisco Routers
Oct 2, 2019
New backdoor SLUB uses watering hole attack to target victims
New backdoor SLUB uses watering hole attack to target victims
Mar 13, 2019
Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help Isaiah ?
What is the use of SUID & SGID commands

How to set the special permissions to the files and folders using SUID and SGID commands...

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.