Crooks set up fraudulent infrastructure that looks like a typical content delivery network. Behind it hides a credit card skimmer injected into Magento online stores. Using lookalike domains is nothing new among malware authors. Crooks use a local web server exposed to the Internet via the free ngrok service to collect the stolen data. This combination of tricks and technologies shows us that fraudsters can devise custom schemes in an attempt to evade detection. Another reason to keep watchful eye on third-party content.”]

