Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Cybercriminals use Unicode to hide Mongolian skimmer on e-commerce platforms
Global Security

Cybercriminals use Unicode to hide Mongolian skimmer on e-commerce platforms

AdminBy AdminOctober 10, 2024No Comments3 Mins Read
Mongolian Skimmer
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


October 10, 2024Ravi LakshmananCybercrime / Malware

Mongolian skimmer

Cybersecurity researchers have shed light on a new digital skimmer campaign that uses Unicode obfuscation techniques to hide a skimmer called the Mongolian Skimmer.

“At first glance, what caught my eye was the obfuscation of the script, which seemed a bit odd because of all the accented characters,” Jscrambler researchers said in the analysis. “The heavy use of Unicode characters, many of them invisible, makes the code very difficult for humans to read.”

The script, at its core, was set to leverage JavaScript enabled use any Unicode character in the identifier to hide the malicious functionality.

Cyber ​​security

The ultimate goal of the malware is to steal sensitive data entered on e-commerce checkout or admin pages, including financial information, which is then transmitted to a server controlled by the attacker.

The skimmer, which usually appears as an embedded script on hacked sites that receives the actual payload from an external server, also tries to avoid analysis and debugging by disabling certain features when a web browser developer tools open

“The skimmer uses well-known techniques to ensure cross-browser compatibility, using both modern and legacy event handling techniques,” said Jscrambler’s Pedro Fortuna. “This ensures that it can target a wide range of users, regardless of their browser version.”

Mongolian skimmer

The client-side security and compliance company said it also observed what it called an “unusual” variant of the loader that only loads the skimmer script when user interaction events such as scrolling, mouse movements and touch start are revealed.

This technique, it added, can serve as both an effective anti-bot measure and a way to ensure that loading the skimmer does not cause performance degradation.

One of the Magento sites hacked to deliver the Mongolian skimmer is said to have also been targeted individual skimmer actorwith two clusters of activities using source code comments to interact with each other and share profits.

Cyber ​​security

“Maybe 50/50?”, one of the threat actors remarked on September 24, 2024. Three days later, another group replied: “I agree 50/50, you can add your code :)”

Then on September 30th, the first threat responded, saying, “Ok, how can I contact you? Do you have an exploit account? (sic),” likely referring to the Exploit cybercrime forum.

“The obfuscation techniques found on this skimmer might look to the untrained eye like a new obfuscation technique, but they are not,” Fortuna noted. “They used old methods to look more complicated, but they’re just as easy to change.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025

Pragmatic approach to NHI stocks

June 30, 2025

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025

Pragmatic approach to NHI stocks

June 30, 2025

FBI warns about expanded spider attacks on airline using social engineering

June 28, 2025

The new AI Facebook tool asks for upload your photos for plot ideas, causing privacy trouble

June 28, 2025

From the theft of the browser to the intelligence collection instrument

June 28, 2025

More than 1000 SOHO devices hacked in China associated with cyber-science associated with cyber

June 27, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025

Europol demonstrates $ 540 million in cryptocurrency fraud, arrests five suspects

June 30, 2025

Slide

June 30, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.