216.73.216.6

Silent Credit Card Thief Uncovered

· Published 04/04/2025 11:47 · Modified 04/04/2025 17:32

Export JSON

Essential information

Published
04/04/2025 11:47
Modified
04/04/2025 17:32
Tags
2025-04-04 browser extensions bulgaria credit card skimming evasion techniques financial data theft lnk file obfuscated scripts persistence rolandskimmer
Related entities
1 intrusion sets (apt), 19 techniques (mitre), 1 malware, 1 others

Description

A sophisticated campaign dubbed '' has been discovered, targeting users in . The attack utilizes malicious across Chrome, Edge, and Firefox, initiated through a deceptive . The malware employs to establish persistent access, harvesting and exfiltrating sensitive financial data. The attack workflow involves system reconnaissance, downloading additional malicious files, and injecting scripts into web pages. The threat actor uses unique identifiers to track victims and employs sophisticated techniques to evade detection. The campaign demonstrates the evolving nature of web-based threats, highlighting the need for enhanced security measures against LNK-based attacks and unverified .

External references