Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
High
A Magecart skimming campaign is found leveraging homoglyph attack techniques. The hackers targeted visitors of several sites using typo-squatted domain names, and modified favicons to inject software skimmers used to steal payment card information. Researchers identified the exfiltration gateway, which appeared to be a slight variation of a legitimate domain name based on the usage of a “q” character in place of what should have been a “p”. One of the interesting characteristics of this sample compared to other Inter skimming kits was that it was in a .ico file format instead of HTML or JavaScript. The injected favicon was a copy of the legitimate favicon. Inside the malicious file is JavaScript code identified to be Magecart skimming code that gathers credit card and billing information. Multiple other victim sites and their associated look-alike domains were identified as being tied to this campaign. Infrastructure overlaps indicate that this activity is likely tied to Magecart Group 8.