惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
Docker
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Last Week in AI
Last Week in AI
博客园_首页
Microsoft Security Blog
Microsoft Security Blog
Blog — PlanetScale
Blog — PlanetScale
M
MIT News - Artificial intelligence
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
A
About on SuperTechFans
aimingoo的专栏
aimingoo的专栏
V
Visual Studio Blog
Jina AI
Jina AI
N
Netflix TechBlog - Medium
量子位
博客园 - 三生石上(FineUI控件)
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
I
InfoQ
J
Java Code Geeks
T
Tailwind CSS Blog
博客园 - 司徒正美
Stack Overflow Blog
Stack Overflow Blog
阮一峰的网络日志
阮一峰的网络日志
Engineering at Meta
Engineering at Meta
腾讯CDC

Sansec - experts in eCommerce security

GorgonAgora: 4,800+ fake storefronts skim cards across hundreds of impersonated brands Sansec adds support for Sylius 1 & 2 Critical vulnerability in Mirasvit Cache Warmer for Magento Critical FunnelKit vulnerability threatens 40,000+ WooCommerce checkouts Composer vulnerability leaks GitHub tokens, threatens PHP supply chain Over 200 PrestaShop stores expose installer, allowing full takeover ClickFix malware hits DoD cybersecurity vendor homepage SVG Onload Tag Hides Magecart Skimmer on 99 Stores Mass PolyShell attack wave hits 471 stores in one hour Novel WebRTC skimmer bypasses security controls at $100+ billion car maker PolyShell: unrestricted file upload in Magento and Adobe Commerce Digital skimmer hits global supermarket chain Building a faster YARA engine in pure Go Magento Developers Impersonated in Targeted GitHub Malware Operation Claude finds 353 zero-days on Packagist The billion-dollar security.txt problem Keylogger targets 200,000+ employees at major US bank ConnectPOS leaked Github secrets for years Critical backdoor found in MGT Varnish extension SessionReaper attacks have started, 3 in 5 stores still vulnerable SessionReaper, unauthenticated RCE in Magento & Adobe Commerce (CVE-2025-54236) Adobe patches critical Magento admin takeover via menu injection Backdoor found in popular ecommerce components Found defunct.dat on your site? You've got a problem. You have 2 weeks left to set up CSP for your store Merchants left guessing at last-minute PCI-DSS u-turn Magento Security Release APSB25-08 [Impact Analysis] Sorry, client-side security does not work Google services abused in skimming campaigns Thousands of Adobe Commerce stores hacked in competing CosmicSting campaigns
Adobe Commerce merchants to be hit with TrojanOrders this...
Sansec Forensics Team · 2022-11-15 · via Sansec - experts in eCommerce security

After a quiet summer, the number of attacks targeting the mail template vulnerability in Magento 2 and Adobe Commerce is rising fast. Merchants and developers should be on the lookout for TrojanOrders: orders that exploit a critical vulnerability in Magento stores. The trend in recent weeks paints a grim picture for ecommerce DevOps teams worldwide for the coming weeks.

Rise of TrojanOrders in November

TrojanOrder attacks are surging

November is on track to see more Magento 2 template attack probes than the previous ten months combined. There is a big uptick in attacks using the mail template vulnerability in Magento 2 from February 2022 (CVE-2022-24086). Sansec estimates that at least a third of all Magento and Adobe Commerce stores have not been patched so far.

The attack consists of a few steps. A probe means “trying to trigger the system to send an email, with the exploit code in one of the fields.” An email is, among others, triggered by placing an order; that is why we call this attack TrojanOrder. Other triggers are “sign up as customer” or “share a wishlist.” A successful probe means the attacker can take over the website.

After gaining access to the website, the first order of business is installing a Remote Access Trojan, giving easy and permanent access to the website, often even after patching or upgrading the system. In the attacks we investigated, this backdoor is often, but not always, hidden in the file health_check.php, normally a legitimate Magento component.

Seven attack groups

Aggregating data from TrojanOrder incident cases at Sansec in the last weeks shows seven different attack vectors at the time of writing (November 2022). Seven attack vectors means at least seven Magecart groups now actively trying TrojanOrders on Magento 2 websites. Developing an attack route is difficult and expensive. Once a group has a working exploit (attack vector), they keep on using it unless it ceases to be effective.

There is a big increase of active scanning for the file that contains the backdoor (health_check.php). This is a sign of attacker groups are trying to take over infected sites from other groups.

What is behind this rise in attacks?

It is hard to pinpoint a single reason for the increase because the attack patterns are diffuse and successful attacks are mostly not detectable from the outside. But there are several reasons to contemplate.

Exploit kits for sale

A driving factor behind TrojanOrders is the availability of several low-cost exploit kits, easily acquired on hacking forums. This is an example from the popular exploit.in forum, but there are at least three others.

Exploit for TrojanOrder / CVE-2022-24086 for sale 1-3

This particular exploit kit was basic but included an instruction video. Quickly, more advanced exploit kits were offered, some even claiming a 56% success rate.

Exploit for TrojanOrder / CVE-2022-24086 for sale 2-3

Exploit for TrojanOrder / CVE-2022-24086 for sale 3-3

💡 How does this work? It is not always trivial to benefit from a vulnerability like CVE-2022-240486. Whenever such a vulnerability is published, attackers start with small-scale, interactive attacks. The goal is to achieve a repeatable process, also known as an exploit. Depending on the complexity of the vulnerability, this process can take hours or months. And when an exploit has finally been developed, it is either used for internal monetization or sold as a ready-to-use exploit kit to others.

The Magento exploits offered for sale were initially priced between $20k and $30k. However, as more exploit kits became available, the price has now dropped to 0.15 BTC, which means that it is now available to practically everyone.

Successful attacks lead to more attacks

If a group becomes more successful, the number of attacks will start to rise. Every extra website hacked brings in extra credit cards, extra payments, or extra private data.

It’s likely that it took a while for groups to find good attack vectors for this vulnerability. Now that the attack vectors have matured, the number of attacks is rising fast.

Perfect timing

November is the perfect attack month, ecommerce websites are (1) very busy with preparations for Black Friday and Cyber Monday and have a code freeze in place; (2) the number of orders is growing; and (3) the expected gains are bigger.

October, November, and December are, for most ecommerce websites, the most important months with regard to revenue. All focus is on sales and scaling, not on distractions such as patches and upgrades.

The more orders, the easier it is to overlook a TrojanOrder. Some merchants may get alerted by a strange order in their sales panel, but most staff will ignore it. November is the perfect month to execute this attack because of the high volume of transactions.

And, related, these months are also the best for harvesting customer and payment data from ecommerce websites. More transactions lead to more data. More transactions lead to slower detection, as card owners and issuers have more transactions to monitor.

You are patched, but are you secure?

Most Magento and Adobe Commerce websites were exposed to this vulnerability.

There is a chance you have already been attacked before applying one of the patches, and a backdoor was installed on your system. It is hard to estimate the probability of successful attacks because these backdoors are well-hidden on the server and can only be detected with a backend malware scanner like eComscan.

How can you see if you are being probed?

The first visible sign is a suspicious new customer record or transaction. Seeing customers pop up with names or addresses like “system” or “pwd”? Orders made by jarhovichbig@protonmail.com? Most likely, this is a TrojanOrder, and Sansec recommends inspecting your system as soon as possible.

TrojanOrder probe

The best way to ensure your store is clean, is to use a backend malware scanner. Scan your store this month for free with eComscan using the coupon TROJANORDER.

The official Magento Security Scan can't find these TrojanOrders, because it is only scans from the outside (frontend malware scanner).

Emergency fix

We strongly recommend to upgrade to a support version of Magento or Adobe Commerce. If that is not immediately viable, you could consider implementing the following emergency patch to the top of app/bootstrap.php, which will block most attacks:

if(preg_match('/addafterfiltercallback/si', preg_replace("/[^A-Za-z]/", '', urldecode(urldecode(file_get_contents("php://input")))))) {
    header('HTTP/1.1 503 Service Temporarily Unavailable');
    header('Status: 503 Service Temporarily Unavailable');
    exit;
}

NB. This emergency patch comes without any warranty.

Read more