Zscaler ThreatLabz observed a seasonal spike in web skimming and phishing campaigns targeting Black Friday and Cyber Monday shoppers. The Grelos skimmer group injected obfuscated JavaScript into e-commerce sites (both Magento and WooCommerce) to capture payment card data, using cookies for staging and base64 encoding for exfiltration disguised as benign traffic. Attackers also compromised legitimate deal websites to redirect users to malicious domains, and numerous newly registered holiday-themed domains were observed.
Black Friday phishing
1 post
Cyberattacks once again Trap Black Friday Shoppers | Zscaler