E-commerce sites around the world could be at risk from this major threat

Ecommerce
(Image credit: StockSnap / Pixabay)

Security researchers have discovered a criminal group utilizing a credit card skimmer that piggybacks on top of a pre-existing well-known exploit. 

The new method of attack builds on the Magento 1 campaign already known to be affecting large numbers of e-commerce sites. In late 2020, Malwarebytes identified numerous Magento 1 website being hacked, largely because Adobe had recently decided to stop supporting the platform. 

Often they were injected with a credit card skimmer, which Malwarebytes found is being used to develop further exploits.

“While monitoring activities tied to this Magento 1 campaign, we identified an e-commerce shop that had been targeted twice by skimmers. This in itself is not unusual, multiple infections on the same site are common,” Jérôme Segura, head of threat intelligence at Malwarebytes, said. “However this case was different. The threat actors devised a version of their script that is aware of sites already injected with a Magento 1 skimmer. That second skimmer will simply harvest credit card details from the already existing fake form injected by the previous attackers.”

Criminals in competition

The discovery of the secondary exploit is interesting as it sets criminal groups up against one another. In some of the examples found by Malwarebytes, threat actors place their own alternate version of the original skimmer on a site in the event of administrators removing the original malicious script.  

Alternatively, the secondary skimmer may simply reflect that different code injections have different levels of access. In this case, the second group of criminals simply takes credentials from the first group’s fake forms.

Malwarebytes has informed the relevant e-commerce sites when it has discovered credit card skimmers in place. E-commerce sites are advised to install the latest web protection software to prevent cybercriminals from implementing these types of exploits.

Given that credit card details are one of the most valuable pieces of information that can be stolen from a site, it is hardly surprising that threat actors are starting to compete with one another for victims' credentials.

TOPICS
Barclay Ballard

Barclay has been writing about technology for a decade, starting out as a freelancer with ITProPortal covering everything from London’s start-up scene to comparisons of the best cloud storage services.  After that, he spent some time as the managing editor of an online outlet focusing on cloud computing, furthering his interest in virtualization, Big Data, and the Internet of Things. 

Latest in Security
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Latest in News
Microsoft Surface Laptop and Surface Pro devices on a table.
Hate Windows 11’s search? Microsoft is fixing it with AI, and that almost makes me want to buy a Copilot+ PC
Oura Ring 4
Activity tracking on Oura Ring is about to get a whole lot better, but I've got bad news about your step count
Google Pixel Buds Pro 2
Cleaned your Pixel Buds Pro 2 recently? If not, you might be getting worse sound
Google Maps on a phone being held in someone's hand
Google Maps is getting two key upgrades, for easier route planning and quicker access to Gemini AI
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Gemini on a smartphone.
Gemini 2.5 is now available for Advanced users and it seriously improves Google’s AI reasoning