Multiple retailers hit by new North Korea cyberattack

The websites of multiple retailers in the US and Europe have been compromised by the Magecart credit card skimmer following a series of cy...

The websites of multiple retailers in the US and Europe have been compromised by the Magecart credit card skimmer following a series of cyberattacks which are believed to have been launched by the North Korean state-sponsored advanced persistent threat (APT) group Lazarus.

Up until now, North Korean hacking activity was limited to banks and South Korean cryptocurrency markets and the country's covert cyber operations have earned hackers $2bn, according to a report released last year by the UN.

As reported by Computer Weekly, Sansec researcher Willem de Groot first discovered the new campaign that has been operating for over 12 months.

De Groot believes the campaign is financially motivated as obtaining hard currency can be difficult for North Korea and its government. The stolen payment card details acquired from Magecart can be sold from between $5 and $30 on dark web forums which means that the operation has likely been quite lucrative for the Lazarus group.

Global skimming campaign

According to a blog post from Sansec, the Lazarus group used the sites of an Italian modeling agency and a vintage music store in Tehran to run its global skimming campaign.

In order to monetize its skimming operations, the group developed a global exfiltration network that utilizes compromised  websites as a disguise for its criminal activity. The network is also used to funnel the stolen assets so that they can be sold on dark web markets.

Sansec research connected the dots to lead back to the Lazarus group after it identified multiple, independent links between recent skimming activity and previously documented North Korean hacking operations. The firm believes that the group used spear phishing attacks to obtain staff passwords to online retail sites. Once inside, the hackers injected the malicious Magecart script into these store's checkout pages where the skimmer was able to collect customer's payment data.

It was first discovered that hackers had infiltrated these sites back in June of last year and Sansec has been tracking the campaign ever since through unique identifying characteristics and distinctive patterns in the skimmer's code.

Via Computer Weekly



from TechRadar - All the latest technology news https://ift.tt/2O0Dpmn
via IFTTT

COMMENTS

BLOGGER
Name

Apps,3858,Business,151,Camera,1155,Earn $$$,3,Gadgets,1741,Games,926,GTA,1,Innovations,3,Mobile,1697,Paid Promotions,5,Promotions,5,Sports,1,Technology,8106,Trailers,796,Travel,37,Trending,4,Trendly News,25335,TrendlyNews,123,Video,5,XIAOMI,13,YouTube - 9to5Google,122,
ltr
item
Trendly News | #ListenNow #Everyday #100ShortNews #TopTrendings #PopularNews #Reviews #TrendlyNews: Multiple retailers hit by new North Korea cyberattack
Multiple retailers hit by new North Korea cyberattack
Trendly News | #ListenNow #Everyday #100ShortNews #TopTrendings #PopularNews #Reviews #TrendlyNews
http://www.trendlynews.in/2020/07/multiple-retailers-hit-by-new-north.html
http://www.trendlynews.in/
http://www.trendlynews.in/
http://www.trendlynews.in/2020/07/multiple-retailers-hit-by-new-north.html
true
3372890392287038985
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share. STEP 2: Click the link you shared to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy