Zscaler ThreatLabz observed a seasonal spike in web skimming and phishing campaigns targeting Black Friday and Cyber Monday shoppers. The Grelos skimmer group injected obfuscated JavaScript into e-commerce sites (both Magento and WooCommerce) to capture payment card data, using cookies for staging and base64 encoding for exfiltration disguised as benign traffic. Attackers also compromised legitimate deal websites to redirect users to malicious domains, and numerous newly registered holiday-themed domains were observed.
Magecart skimming
1 post
Cyberattacks once again Trap Black Friday Shoppers | Zscaler