Cyberkriminelle verwenden Unicode, um mongolische Skimmer in E-Commerce-Plattformen zu verstecken

Teilen:

Cybersecurity researchers have shed light on a new digital skimmer campaign that leverages Unicode obfuscation techniques to conceal a skimmer dubbed Mongolian Skimmer.

“At first glance, the thing that stood out was the script’s obfuscation, which seemed a bit bizarre because of all the accented characters,” Jscrambler researchers said in an analysis. “The heavy use of Unicode characters, many of them invisible, does make the code very hard to read for humans.”

The script, at its core, has been found to leverage JavaScript’s capability to use any Unicode character in identifiers to hide the malicious functionality.

The end goal of the malware is to steal sensitive data entered on e-commerce checkout or admin pages, including financial information, which are then exfiltrated to an attacker-controlled server.

The skimmer, which typically manifests in the form of an inline script on compromised sites that fetches the actual payload from an external server, also attempts to evade analysis and debugging efforts by disabling certain functions when a web browser’s developer tools is opened.

“The skimmer uses well-known techniques to ensure compatibility across different browsers by employing both modern and legacy event-handling techniques,” Jscrambler’s Pedro Fortuna said. “This guarantees it can target a wide range of users, regardless of their browser version.”

Mongolian Skimmer

The client-side protection and compliance company said it also observed what it described as an “unusual” loader variant that loads the skimmer script only in instances where user interaction events such as scrolling, mouse movements, and touchstart are detected.

This technique, it added, could serve both as an effective anti-bot measure and a way to ensure that the loading of the skimmer is not causing performance bottlenecks.

One of the Magento sites compromised to deliver the Mongolian skimmer is also said to have targeted by a separate skimmer actor, with the two activity clusters leveraging source code comments to interact with each other and divide the profits.

“50/50 maybe?,” remarked one of the threat actors on September 24, 2024. Three days later, the other group responded: “I agree 50/50, you can add your code :)”

Then on September 30, the first threat actor replied back, stating “Alright ) so how can I contact you though? U have acc on exploit? [sic],” likely referring to the Exploit cybercrime forum.

It’s currently not known as to how the skimmer malware is delivered to target websites, although it’s believed that the attackers are setting their sights on misconfigured or vulnerable Magento or Opencart instances.

“We have multiple victim websites, which might have been breached using different methods,” Fortuna told The Hacker News. “We don’t know exactly how they got there and were able to inject the web skimmer, but all signs point to compromised Magento or Opencart instances, either because they were poorly configured or because they had vulnerable components that the attackers exploited to get in.”

“The obfuscation techniques found on this skimmer may have looked to the untrained eye as a new obfuscation method, but that was not the case,” Fortuna noted. “It used old techniques to appear more obfuscated, but they are just as easy to reverse.”

Ravie Lakshmanan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
6:00 am, Juli 1, 2025
Wetter-Symbol 22°C
L: 20° | H: 23°
wenige Wolken
Luftfeuchtigkeit: 78 %
Druck: 1014 mb
Wind: 3 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 20%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:47 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
20° | 23°°C 0 mm 0% 11 mph 78 % 1015 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
19° | 24°°C 0.2 mm 20% 12 mph 76 % 1024 mb 0 mm/h
Do. Juli 03 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 8 mph 52 % 1029 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
16° | 29°°C 0 mm 0% 10 mph 48 % 1027 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
17° | 22°°C 0.2 mm 20% 13 mph 81 % 1019 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 3 mph 78 % 1014 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
24° | 27°°C 0 mm 0% 2 mph 69 % 1014 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
28° | 31°°C 0 mm 0% 7 mph 46 % 1013 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
32° | 32°°C 0 mm 0% 9 mph 25 % 1012 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
28° | 28°°C 0 mm 0% 11 mph 31 % 1013 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 8 mph 48 % 1015 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 6 mph 65 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 6 mph 76 % 1016 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€90,751.15
-1.30%
Ethereum(ETH)
€2,096.53
-1.07%
Fesseln(USDT)
€0.85
0.01%
XRP(XRP)
€1.88
1.55%
Solana(SOL)
€129.53
0.97%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.138905
-1.91%
Shiba Inu(SHIB)
€0.000009
-1.93%
Pepe(PEPE)
€0.000008
-4.35%
Nach oben scrollen