Sell Links Worldwide Telecom and IT News Updates, Reviews, Trends, Analysis, PR RiskIQ Researchers Track E-commerce Threat Magecart Part II, Discover Network of Threat Actors Physically Reshipping Items Purchased with Stolen Cards via U.S. Mules | Worldwide Telecom and IT News Updates, Reviews, Trends, Analysis, PR

RiskIQ Researchers Track E-commerce Threat Magecart Part II, Discover Network of Threat Actors Physically Reshipping Items Purchased with Stolen Cards via U.S. Mules

RiskIQ Researchers Track E-commerce Threat Magecart Part II, Discover Network of Threat Actors Physically Reshipping Items Purchased with Stolen Cards via U.S. Mules

No Comments on RiskIQ Researchers Track E-commerce Threat Magecart Part II, Discover Network of Threat Actors Physically Reshipping Items Purchased with Stolen Cards via U.S. Mules

New report uncovers a direct link to the outcome of stolen credit cards, offering rare insight into the physical world operations of actors tied to digital threats

LONDON, UK – July 12, 2017 – In October of last year, the RiskIQ Threat Research team released “Compromised E-commerce Sites Lead to ‘Magecart,” a report profiling the e-commerce threat they discovered and dubbed ‘Magecart,’ which injects JavaScript code into e-commerce sites running outdated and unpatched versions of shopping cart software from Magento, Powerfront, and OpenCart. By logging consumer keystrokes, these attackers capture large quantities of payment card information.

RiskIQ logo
RiskIQ logo

Now, by following a new strain of Magecart, the team has discovered a direct link to the outcome of the stolen credit cards for threat actors, offering rare insight into the physical world operations of actors tied to digital threats.

The Report, “Magecart Part II: From Javascript Injects to Reshipping for Financial Gain,” highlights how threat actors targeting e-commerce sites cash out by reshipping items purchased with stolen cards via a physical reshipping company, operating with mules in the U.S.

In light of the recent Krebs on Security blog post, which ties Magecart infrastructure listed in our original report to a credit card dumps website known as “Trump’s Dumps,” it’s clear that these actors have a diversified portfolio of rackets for monetising their plunder.

“Magecart activity is still going strong, affecting new sites and continuing to register new domains to host the injected web skimmer scripts,” said Yonathan Klijnsma, threat researcher at RiskIQ. “New insight into the sophisticated way these actors are monetising their activities in the physical world shows the broadness of their scope of operations.”

By pivoting on a domain related to known Magecart activity in RiskIQ PassiveTotal, the team found that the server behind its IP address, currently used for the injects of the Magecart script, also links to a reshipping company website falsely advertised as a freight/logistics provider.

Via false employment ads on Russian job websites for U.S.-based job seekers, mules are recruited under the pretence of “transport agents,” tasked with receiving shipments of electronics and other goods bought with stolen credit cards to ship to an address in Eastern Europe. This technique is similar to more traditional schemes involving money mules, but rather than a direct transfer of funds, the actors behind Magecart transfer funds into higher-priced goods, which can be shipped across borders without suspicion then sold for a hefty profit.

Magecart Part II: From Javascript Injects to Reshipping for Financial Gain’ takes a deep dive into:

  • The evolution of payment card theft
  • Magecart infrastructure: what it looks like, how to detect it, and how it’s evolving
  • Why e-commerce sites and consumers are at risk
  • The Magecart operators’ offline rackets and why they work
  • Guidance for e-commerce site owners and why having a dynamic view of their digital footprint is key to defending themselves

To conduct this and other web research, RiskIQ applies its proprietary virtual user web crawling technology. This advanced internet reconnaissance acts like a user would, thoroughly interrogating websites and web apps, as well as respective browser session communications. It processes more than 2 billion HTTP requests per day to surface, identify, and connect internet elements to malicious campaigns.

RiskIQ sees what appears on social media pages, websites, and mobile sites – just as it appears in users’ browsers. RiskIQ virtual users capture the DOM and find the dynamic links and changes made by JavaScript that could signify a potential attack.

“This new report shows how Magecart is an effective and lucrative operation for these actors,” Klijnsma said. “It may well indicate a burgeoning trend of keylogging threats affecting e-commerce sites.”


About RiskIQ
RiskIQ is the leader in digital threat management, providing the most comprehensive discovery, intelligence, and mitigation of threats associated with an organization’s digital presence. With more than 80 percent of attacks originating outside the firewall, RiskIQ allows enterprises to gain unified insight and control over web, social, and mobile exposures. Trusted by thousands of security analysts, RiskIQ’s platform combines advanced internet data reconnaissance and analytics to expedite investigations, understand digital attack surfaces, assess risk, and take action to protect business, brand, and customers. Based in San Francisco, the company is backed by Summit Partners, Battery Ventures, Georgian Partners, and MassMutual Ventures. Visit RiskIQ.com or follow us on Twitter.

Try RiskIQ Community Edition for free by visiting https://www.riskiq.com/community/

To learn more about RiskIQ, visit www.riskiq.com.

###

Media Relations
Anna May
Atomic PR
riskiq@atomicpr.com
020 3861 3901

About the author:

Related Posts

Leave a comment

Lastest Posts

RSS Latest Technology News World "Touch With Us"

  • Qualcomm Extends Cash Tender Offer for All Outstanding Shares of NXP
    SEP 22, 2017SAN DIEGO Qualcomm Incorporated (NASDAQ: QCOM) today announced that Qualcomm River Holdings B.V., an indirect wholly owned subsidiary of Qualcomm, has extended the offering period of its previously announced cash tender offer to purchase all of the outstanding common shares of NXP Semiconductors N.V. (NASDAQ: NXPI). The tender offer is being made pursuant...
  • With focus on photos, ASUS announces new ZenFone 4 smartphones powered by Snapdragon
    SEP 22, 2017 Qualcomm products mentioned within this post are offered by Qualcomm Technologies, Inc. and/or its subsidiaries. Last month ASUS announced the latest iteration of the ZenFone series, the ASUS ZenFone 4 and the ASUS ZenFone 4 Pro, marking an exciting advancement in mobile photography. The ASUS ZenFone 4 Pro features the Qualcomm Snapdragon 835 Mobile Platform, and the ASUS ZenFone...
  • Qualcomm Snapdragon Supports Breakthrough Gigabit Connectivity in the Asus ZenFone 4 Pro
    World’s First Commercial Smartphone to Have Gigabit LTE and 802.11ad Multi-gigabit Wi-Fi Technologies Qualcomm Technologies, Inc., a subsidiary of Qualcomm Incorporated (NASDAQ: QCOM), today announced that its Qualcomm® Snapdragon™ Mobile Platforms will power the ASUS ZenFone 4 Pro with gigabit connectivity. The world’s first commercial smartphone to feature Gigabit LTE and 802.11ad multi-gigabit Wi-Fi technologies,...
  • MWC Americas: EVP Cristiano Amon discusses Gigabit LTE and 5G in the digital economy
    Mobile, the largest technology platform in human history, directly impacts the digital economy. As connectivity evolves and we move toward 5G, an already-expansive mobile ecosystem will extend to new industries, enabling new services and powering new devices. This was the crux of EVP of Qualcomm Technologies, Inc. and President of Qualcomm CDMA Technologies Cristiano Amon’s keynote...
  • MaidSafe launches SAFE Network Alpha 2 – The Authenticator Release
    The world’s first and only autonomous data network underlines its superiority for protecting data. Troon, SCOTLAND, September 22nd, 2017 – Today MaidSafe, developer of the world’s first and only autonomous data network, is announcing the Authenticator Release of the SAFE Network. This Alpha 2 release includes a new mechanism for access control (the Authenticator) that integrates...

Connect with Us

About us

TechRecur.com is one of the leading publishing company in Telecom, Media and Technology (TMT) industry. We have been publishing news, research, press releases, reviews, interviews, etc. for the last 10 years. We have been established to meet day-to-day requirements of senior executives regarding information and research on TMT. TechRecur.com also provides platform to decision makers to meet, discuss and network. TechRecur.com provides advice on market analysis and service opportunities in TMT Industry globally. Leveraging our relationships with leading players of the telecom industry we provide strategic advice across technology verticals and functional areas. EMAIL: INFO[at]TECHRECUR.COM | Web: www.techrecur.com

Back to Top