This Magecart skimmer has been redesigned for mobile

Phone malware
(Image credit: Shutterstock)

Magecart operators have modified a popular credit card skimmer to only target mobile users as consumers are doing more of their online shopping from their smartphones as opposed to their computers.

According to a new report from RiskIQ, the Inter Skimmer kit is one of the most common digital skimming solutions worldwide. Several different groups of cybercriminals have used the Inter kit since late 2018 to steal payment data and it affects thousands of sites and consumers worldwide.

In March of last year, a new modified version of Inter appeared online. However, Magecart operators have altered it even more to create MobileInter which focuses solely on mobile users and targets both their login credentials and payment data.

While the first iteration of MobileInter downloaded exfiltration URLs hidden in images from GitHub repositories, the new version contains the exfiltration URLs within the skimmer code itself and uses WebSockets for data exfiltration. MobileInter also abuses Google tracking services and domains that mimic the search giant to disguise itself and its infrastructure.

MobileInter

Since MobileInter solely targets mobile users, the redesigned skimmer performs a variety of checks to ensure it is skimming a transaction made on a mobile device.

The skimmer first performs a regex check against the window location to determine if it is on a checkout page but this kind of check can also find out if a user's userAgent is set to one of several mobile browsers. MobileInter also checks the dimensions of a browser window to see if they are a size associated with a mobile browser.

After these checks have passed, the skimmer executes its data skimming and exfiltration using several other functions. Some of these functions are given names that could be mistaken for legitimate services in order to avoid detection. For example, a function called 'rumbleSpeed' is used to determine how often data exfiltration is attempted though it is meant to blend in with the jRumble plugin for jQuery, which “rumbles” elements of a webpage to make a user focus on them.

RiskIQ has also identified MobileInter disguising its operations in other ways. Since the firm began tracking Magecart, it has observed threat actors disguising their domains as legitimate services. While RiskIQ's list of domains related to MobileInter is extensive, many mimic Alibaba, Amazon and jQuery.

Although credit card skimmers first appeared in the real world at gas stations and other places where users would swipe to pay, they soon found their way online and have now established a foothold on mobile.

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
A person holding a credit card in one hand while typing on a laptop keyboard with the other.
Google system abused by hackers to hijack ecommerce stores
Malware worm
Coordinated global mobile malware campaign targets banking apps and cryptocurrency platforms
A person holding a credit card in one hand while typing on a laptop keyboard with the other.
WordPress users targeted by devious new credit card skimmer malware
mobile phone
Forget phishing, now "mishing" is the new security threat to worry about
Casio logo
Casio’s online store hit by bogus credit card stealing checkout form
An iPhone sitting on a wooden table
Millions at risk as malicious PDF files designed to steal your data are flooding SMS inboxes - how to stay safe
Latest in Security
cybersecurity
Chinese government hackers allegedly spent years undetected in foreign phone networks
Data leak
A major Keenetic router data leak could put a million households at risk
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple routers hit by new critical severity remote command injection vulnerability, with no fix in sight
Code Skull
This dangerous new ransomware is hitting Windows, ARM, ESXi systems
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring