Magento Sites Targeted with Sneaky Credit Card Skimmer via Swap Files

Share:

Threat actors have been observed using swap files in compromised websites to conceal a persistent credit card skimmer and harvest payment information.

The sneaky technique, observed by Sucuri on a Magento e-commerce site’s checkout page, allowed the malware to survive multiple cleanup attempts, the company said.

The skimmer is designed to capture all the data into the credit card form on the website and exfiltrate the details to an attacker-controlled domain named “amazon-analytic[.]com,” which was registered in February 2024.

“Note the use of the brand name; this tactic of leveraging popular products and services in domain names is often used by bad actors in an attempt to evade detection,” security researcher Matt Morrow said.

Cybersecurity
This is just one of many defense evasion methods employed by the threat actor, which also includes the use of swap files (“bootstrap.php-swapme”) to load the malicious code while keeping the original file (“bootstrap.php”) intact and free of malware.

“When files are edited directly via SSH the server will create a temporary ‘swap’ version in case the editor crashes, which prevents the entire contents from being lost,” Morrow explained.

“It became evident that the attackers were leveraging a swap file to keep the malware present on the server and evade normal methods of detection.”

Although it’s currently not clear how the initial access was obtained in this case, it’s suspected to have involved the use of SSH or some other terminal session.

The disclosure arrives as compromised administrator user accounts on WordPress sites are being used to install a malicious plugin that masquerades as the legitimate Wordfence plugin, but comes with capabilities to create rogue admin users and disable Wordfence while giving a false impression that everything is working as expected.

“In order for the malicious plugin to have been placed on the website in the first place, the website would have already had to have been compromised — but this malware could definitely serve as a reinfection vector,” security researcher Ben Martin said.

Cybersecurity
“The malicious code only works on pages of WordPress admin interface whose URL contains the word ‘Wordfence’ in them (Wordfence plugin configuration pages).”

Site owners are advised to restrict the use of common protocols like FTP, sFTP, and SSH to trusted IP addresses, as well as ensure that the content management systems and plugins are up-to-date.

Users are also recommended to enable two-factor authentication (2FA), use a firewall to block bots, and enforce additional wp-config.php security implementations such as DISALLOW_FILE_EDIT and DISALLOW_FILE_MODS.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
12:24 pm, Jun 27, 2025
weather icon 25°C
L: 23° | H: 26°
broken clouds
Humidity: 53 %
Pressure: 1020 mb
Wind: 10 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 56%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:45 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
23° | 26°°C 0 mm 0% 13 mph 68 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 29°°C 0 mm 0% 11 mph 91 % 1025 mb 0 mm/h
Sun Jun 29 10:00 pm
weather icon
19° | 31°°C 0 mm 0% 8 mph 76 % 1025 mb 0 mm/h
Mon Jun 30 10:00 pm
weather icon
21° | 34°°C 0.2 mm 20% 8 mph 64 % 1021 mb 0 mm/h
Tue Jul 01 10:00 pm
weather icon
21° | 33°°C 0 mm 0% 11 mph 68 % 1016 mb 0 mm/h
Today 1:00 pm
weather icon
24° | 24°°C 0 mm 0% 12 mph 55 % 1020 mb 0 mm/h
Today 4:00 pm
weather icon
25° | 26°°C 0 mm 0% 13 mph 51 % 1020 mb 0 mm/h
Today 7:00 pm
weather icon
26° | 26°°C 0 mm 0% 13 mph 44 % 1019 mb 0 mm/h
Today 10:00 pm
weather icon
21° | 21°°C 0 mm 0% 11 mph 68 % 1021 mb 0 mm/h
Tomorrow 1:00 am
weather icon
20° | 20°°C 0 mm 0% 9 mph 85 % 1021 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 18°°C 0 mm 0% 9 mph 91 % 1022 mb 0 mm/h
Tomorrow 7:00 am
weather icon
20° | 20°°C 0 mm 0% 8 mph 82 % 1023 mb 0 mm/h
Tomorrow 10:00 am
weather icon
25° | 25°°C 0 mm 0% 11 mph 61 % 1023 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,537.08
-0.33%
Ethereum(ETH)
€2,094.66
-0.14%
Tether(USDT)
€0.86
-0.01%
XRP(XRP)
€1.79
-3.82%
Solana(SOL)
€121.54
-1.05%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.137678
-0.63%
Shiba Inu(SHIB)
€0.000009
-2.35%
Pepe(PEPE)
€0.000008
-1.08%
Scroll to Top