Blog | G5 Cyber Security

Wave of MageCart attacks target hundreds of outdated Magento sites

Analysts have found the source of a mass breach of over 500 e-commerce stores running the Magento 1 platform. The attack involves a single domain loading a credit card skimmer on all of them. The goal of the threat actors was to steal the credit card information of customers on the targeted online stores. The attackers abused a known vulnerability in the Quickview plugin to inject rogue Magento admin users that could then run code with the highest privileges. Sansec points out that in an extreme case, the adversaries injected as many as 19 backdoors on a single Magento platform.”]

Source: https://www.bleepingcomputer.com/news/security/wave-of-magecart-attacks-target-hundreds-of-outdated-magento-sites/

Exit mobile version