惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Cisco Talos Blog
Cisco Talos Blog
Cyberwarzone
Cyberwarzone
T
Tenable Blog
Security Latest
Security Latest
NISL@THU
NISL@THU
V
Vulnerabilities – Threatpost
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
W
WeLiveSecurity
罗磊的独立博客
Stack Overflow Blog
Stack Overflow Blog
云风的 BLOG
云风的 BLOG
Martin Fowler
Martin Fowler
Engineering at Meta
Engineering at Meta
T
Tor Project blog
H
Heimdal Security Blog
Microsoft Security Blog
Microsoft Security Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
雷峰网
雷峰网
L
LINUX DO - 热门话题
The GitHub Blog
The GitHub Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Recorded Future
Recorded Future
Hugging Face - Blog
Hugging Face - Blog
P
Privacy & Cybersecurity Law Blog
F
Full Disclosure
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
PCI Perspectives
PCI Perspectives
MyScale Blog
MyScale Blog
B
Blog RSS Feed
www.infosecurity-magazine.com
www.infosecurity-magazine.com
K
Kaspersky official blog
Attack and Defense Labs
Attack and Defense Labs
H
Hackread – Cybersecurity News, Data Breaches, AI and More
有赞技术团队
有赞技术团队
Know Your Adversary
Know Your Adversary
Hacker News - Newest:
Hacker News - Newest: "LLM"
Scott Helme
Scott Helme
The Last Watchdog
The Last Watchdog
博客园 - 【当耐特】
S
Security Affairs
The Cloudflare Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
N
News and Events Feed by Topic
AI
AI
H
Help Net Security
美团技术团队
T
Threatpost
Project Zero
Project Zero

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus How card fraud is powered by underground card checkers Tracking down The Com Turning Chaos into Clarity: The Next Phase of Intel 471’s Geopolitical Intelligence Solution The FBI’s Group 78: Covertly fighting ransomware? How threat actors bypass multifactor authentication Crimson Collective In a digital age, US paper check fraud flourishes How you can defend against AI-driven fraud and phishing Detecting cybercriminal activity on Telegram NPM - Shai-Hulud Worm Threat hunting case study: ToolShell AMOS Stealer How AI can (and can’t) help in threat hunting The Phrack leak: Examining an APT’s workstation How initial access offers power intrusions and ransomware Drawing value from cyber threat intelligence “Pig-Butchering” Scams: The Dark Side of Social Engineering and Why Terminology Matters After disruption, XSS cybercrime forum faces loss of trust Update: Salt Typhoon Bridging the CTI Gap: New Exposure Modules on Verity471 Deliver Market-Disrupting Views of Threats Introducing Verity471: Cyber Threat Intelligence Ready to Operationalize FileFix Social Engineering Technique Guided Threat Hunts Takes Your Behavioral Threat Hunting to the Next Level Defending against doxing CVE-2025-53770 - Microsoft Sharepoint Mass Exploitation (ToolShell) Threat hunting case study: Lumma infostealer Pro-Russian hacktivism: Shifting alliances, new groups and risks mommy Access Broker NATO summit commences in tandem with tense cyber, kinetic conflict A look at ‘Tinker,’ Black Basta’s phishing fixer, negotiator Threat hunting case study: DragonForce Two critical challenges facing CTI teams and how to overcome them: Intel 471’s additional insights into the SANS 2025 CTI Survey Android malware trends: Stealthier, easier-to-use Fingerprinting threat actors by their anonymity techniques DanaBot malware disrupted, threat actors named Intel 471 brings HUNTER behavioral threat hunts to Google Security Operations SANS 2025 CTI Survey: It’s Business Time for Cyber Risk How an alleged Russian hacker slipped away Threat hunting case study: Medusa ransomware CVE-2025-31324 - SAP NetWeaver Vulnerability DragonForce Ransomware Managing a cyber crisis LabHost: A defunct but potent phishing service Understanding and threat hunting for RMM software misuse Threat-hunting case study: Windows Management Instrumentation abuse VanHelsing Ransomware An in-depth look at Black Basta's TTPs Six Key Takeaways From the SANS 2025 Threat Hunting Survey Update: Medusa Ransomware Writing high-quality IDS detection rules Threat hunting case study: RMM software Update: LockBit Ransomware Zservers: Bulletproof hosting for online crime Update: Black Basta Ransomware and Threat Group Black Basta exposed: A look at a cybercrime data leak BadPilot Campaign The evolution of Russian cybercrime Android trojan TgToxic updates its capabilities Threat hunting case study: SocGholish DeepSeek AI poses cybersecurity risks Law enforcement hammered cybercrime in 2024. Is it working? Remote Monitoring and Management (RMM) Abuse How threat actors are using artificial intelligence Threat hunting case study: PsExec How ransomware may trend in 2025 What 2025 May Hold for Cybersecurity Bring Your Own Hunts to HUNTER ‘Tis the Season to Be Alert for Cyber Threats: 5 Unjoyful Holiday Tactics Collecting Useful CTI from Underground Markets Expanding source coverage: adding Signal chats to threat intelligence
An Overview of the Actors Behind the Largest MageCart Attack (So Far!)
Intel 471 · 2020-09-26 · via Intel 471 Blog

A truism is that where there is money, there is crime — it applies in every corner of society, from street markets to financial markets, and everything in between. In the realm of cyber security, however, it is often truer than many would believe. State-sponsored and sanctioned cyber threat actors have routinely targeted large financial industries, often leveraging the Society for Worldwide Interbank Financial Telecommunication (SWIFT) network. Other large actors have targeted stock exchanges or even the emerging cryptocurrency markets, while still many more smaller actors have targeted retail finance, and even ATMs, and a growing segment of these attacks have also turned to target eCommerce platforms and online retailers.

It should then come as no surprise that especially with the COVID-19 pandemic, as more people than ever have turned to eCommerce platforms to supply themselves or eke out a living, that threat actors would seek to target these platforms. However, over the last two weeks, an unknown group has, according to a report released by Sansec, carried out the largest ever Magecart-style attack against retailers running the eCommerce platform Magento (version 1), affecting at least 2,806 stores.

The targeting of the v1 platform is significant because as of June 2020 the platform has been designated End of Life (EOL). This designation is important, as it means these stores will no longer receive updates — especially security updates — from Adobe, which acquired the platform in 2018, and some estimates have suggested there may be “tens of thousands” of v1 stores operating globally. This means that vulnerabilities found by researchers and threat actors will remain unpatched.

The Initial Attack

Sansec reported that the initial attack appears to have begun on or around 11 September 2020, with the attacker targeting only a handful of online retailers. Sansec provided a handful of indicators related the compromise, which allowed us to begin our search. We mapped out the indicators in King & Union’s intelligence and link analysis platform Avalon with enrichment provided by Cyborg Security’s SIGNS threat data feed.

[Image: Image for post]

Figure 1 — Initial Indicators of Compromise


The starting point allowed us to recover some of the initial artifacts from the attack, including the attacker’s obfuscated Javascript hosted at https[:]//mcdnn[.]me/121192/assets/js/jet[.]js and https[:]//mcdnn[.]me/121082/assets/js/jet[.]js. From this data we were able to recover other artifacts which appear related to the actors which identify that their domain had been used previously for a nearly identical Magecart-style attack, dating back to at least 02 August 2020 — a month prior to the so-called ‘Cardbleed’ attack. These artifacts appear to target the OnePage, OneStepCheckout, and FireCheckout plugins for various eCommerce Platforms (including Magento).

[Image: Image for post]

Figure 2 — Obfuscated jet.js from mcdnn[.]me

[Image: Image for post]

Figure 3 — Recovered file dating back to 02 August 2020

We were also able to identify dozens of modified prototype.js files — a legitimate component of the Magento eCommerce platform — all of which had been modified and which pointed to the “widget.js” web Skimmer hosted on the attacker-controlled mcdnn[.]net domain. Again, note the similarities to the recovered file above.

[Image: Image for post]

Figure 4 — Sample code snippet from modified prototype.js files

We then began the initial enrichment process, in order to identify the attack’s infrastructure. We noted that the attacker’s infrastructure was, largely, hosted on IPs in close proximity to one another, from the same provider, located in Moscow, Russia. We also noted that the actors have a tendency to reuse domains between campaigns, which can be considered odd given the highly temporal nature of Magecart-style attacks.

This basic enrichment allowed us to then collate and correlate the attacker’s infrastructure with Cyborg Security’s SIGNS threat feed, which identified significant overlap between this current activity group, and activity that Cyborg Security has previously observed earlier in the year.

Based on the significant overlap in infrastructure and some of the observed TTPs it is highly probable that these attacks were carried out by the same actors responsible for the so-called Ant and Cockroach web skimmer.

We were also able to identify several domains which had been registered in the same period, but which appeared to be inactive. It is likely that the attackers will use this additional infrastructure in future campaigns, or as a fall back in the event their current infrastructure is blocked.

[Image: Image for post]

Figure 5 — Enrichment from Cyborg Security’s SIGNS threat feed

From the Cyborg Security SIGNS threat feed, we were also able to quickly identify previous targeting and tactics, techniques, and procedures which led to some interesting overlaps.

  • Previous activity identified that the actors, who appear to be primarily financially motivated, have largely targeted the Magento platform in the past, with some specific targeting of the “v1” version, specifically.
  • Previous eCommerce attacks by the actors appear to target two languages exclusively for the checkout pages: English and Portuguese.
  • Some of their infrastructure has previously been tied to the Brazilian-focused Lampion banking trojan, further reinforcing an interest in the LATAM market.
  • Infrastructure re-use (IPs and Domains) across campaigns.
  • The actors frequently employ homoglyph-style attacks, mimicking various protocols or legitimate web services for their domains.

The “Cardbleed” Exploit Connection

Another element mentioned in the Sansec story was the possible connection to a post by an actor referred to as “z3r0day” in a popular Russian deep web forum.

We retrieved the post, which was authored on 15 August 2020, and it is presented below in its original Russian, and translated to English.

[Image: Image for post]

Figure 6 — Original post by ‘z3r0day’ dated 15 August 2020

[Image: Image for post]

Figure 7 — Translation of ‘z3r0day’ post, courtesy Google Translate

In the post, the actor describes an alleged 0-day vulnerability affecting all Magento v1 stores.

The seller also says they will include additional 1-day vulnerabilities that can use used to target Magento v1, as well as documentation and even a training video to guide would-be purchasers through the exploitation process. As Sansec noted, the provider is also committing to only sell 10 copies of the exploit, likely in an effort to ensure that exploitation of the vulnerability remains somewhat covert. As of 21 September 2020, 7 copies of the exploit have been sold.

[Image: Image for post]

Figure 8 — An update given from the seller ‘z3r0day’

We were able to gather additional details on the seller by leveraging our threat actor profiles, which allowed us to map out the actor’s previous activity, as well as known contact information.

An interesting point is that the seller had authored a second post on the same day that he offered the 0-day vulnerability, looking for partnership opportunities with individuals who actively target “popular” CMS platforms (with the actor listing OpenCart and Magento specifically, but indicating other platforms would be acceptable as well).

[Image: Image for post]

Figure 9 — A previous post from actor ‘z3r0day’ on the same date as his post regarding a Magento 0-day

[Image: Image for post]

Figure 10 — Previous Activity by actor ‘z3r0day’

One point to note regarding ‘z3r0day’ is that while he stipulates that he will not work with those targeting CIS countries (a relatively common practice for those operating on the Russian underground, otherwise referred to as the RuNet), he has also previously expressed that he will also not work with those targeting India, a practice that is much less common. It is unclear at this time why he has this limitation.

The actor also appears to be affiliated with the well-known ‘Allsafe’ VPS service which provides threat actors with a hosting provider which not only permits malicious activity but will also provide pre-configured servers for various malicious activity.

Intelligence Gaps

Currently, there exist a few intelligence gaps regarding the reporting surrounding the recent wave of Magecart-style attacks which have appeared to have targeted the Magento version 1 platform.

  • While the targeting of the end-of-life Magento platform appears intentional, is this because the attacker has access to a specific and novel capability (i.e. the ‘Cardbleed’ 0-day attack), or were these platforms previously compromised by the attackers (or perhaps purchased from actors who cultivate network access)?
  • Presently, there are no direct operational linkages which connect the actors conducting the attacks with the seller ‘z3r0day’ and the alleged ‘Cardbleed’ exploit.
  • The actors responsible for the attacks appear to have been carrying out similar attacks prior to 15 August 2020, when the ‘Cardbleed’ exploit was offered for sale.
  • The attacker has previously been shown to reuse specific TTPs and infrastructure, however it is reasonable that an attacker gaining a significant advantage would want to avoid detection as long as possible.
  • The attacker may have felt compelled to act quickly and operate using infrastructure that they deemed reliable.

Conclusion

While it remains unclear how the actors have gained access to the targeted Magento v1 platforms, that the scope of the attack is unprecedented is without doubt. However, such radical escalation on the part of the attackers is unsurprising given the continued growth in online retailing, especially with the continued reliance on it by many as a result of the COVID-19 pandemic.

However, perhaps more important is the fact that with Magento version 1 being rendered obsolete, any vulnerabilities discovered in the platform will remain unpatched. This is further complicated by the extremely large base of legacy users who remain on the EOL version for various reasons.

As a result, it is highly likely that some exploit developers and attackers will focus their efforts on the EOL version specifically. This will result in companies which choose to operate on the legacy version exposing themselves to increased targeting by financially motivated threat actors, and potentially exposing their clients to increased risk of fraud.

Clients of King & Union will find all of our research available in the Avalon platform in the Cyborg Security group!