216.73.216.6

Fake GIF Leveraged in Multi-Stage Reverse-Proxy Card Skimming Attack

· Published 26/04/2025 03:26 · Modified 28/04/2025 08:51

Export JSON

Essential information

Published
26/04/2025 03:26
Modified
28/04/2025 08:51
Tags
2025-04-26 card skimming ecommerce javascript injection magento multi-stage attack reverse proxy sessionstorage
Related entities
7 techniques (mitre), 1 others

Description

A sophisticated multi-stage carding attack on a website has been uncovered. The malware used a fake gif image file, local browser data, and a malicious reverse-proxy server to steal credit card data, login details, cookies, and other sensitive information. The attack targeted an outdated 1.9.2.4 installation, exploiting its lack of support and security vulnerabilities. The malware injected JavaScript code disguised as Bing tracking code and utilized a tampered payment file to create a user-specific attack. This advanced technique allowed the attackers to intercept and manipulate all website traffic while remaining undetected by victims and administrators.

External references