Threat actors load credit card skimmers using a known phishing technique called homoglyph attacks. A threat actor is using this technique on several domain names to load the popular Inter skimming kit inside of a favicon file. It may not be their first rodeo either as some ties point to an existing Magecart group. Several domains have been registered recently with the same technique, including a fourth domain for zoploploply.com, but that is quite different from the one involved.”]
Source: https://blog.malwarebytes.com/threat-analysis/2020/08/inter-skimming-kit-used-in-homoglyph-attacks/

