Magecart hackers target popular poker software

(Image credit: Shutterstock.com)

Magecart credit card skimmers typically target users through their web browser when shopping online but new research from Malwarebytes has discovered that cybercriminals were able to compromise poker software to do so as well.

Poker Tracker is a software suite used by online poker enthusiasts to improve their chances of winning by making decision using statistics compiled from the gameplay of their opponents. Malwarebytes first began its investigation into Poker Tracker when its anti-malware blocked the software from connecting to a domain known to host credit card skimmers.

The firm's security researchers installed and ran the software at which time they discovered it was connecting to ajsaxclick[.]com and retrieving a malicious JavaScript file. At first Malwarebytes believed that the application had been compromised but this would be quite unusual as credit card skimmers have only been observed on websites.

Upon closer inspection though, the researchers found that the software can load and display web pages from PokerTracker's subdomain 'pt4.pokertracker.com'. The cybercriminals hacked both Poker Tracker's software and its website and injected them with malicious code that the software loaded every time it launched. This led any payment made through the software or its website to copy the attacker with the payment details.

CMS issue

The cybercriminals that compromised PokerTracker's website were able to do so because the site was running an outdated version of Drupal CMS. The site was running Drupal 6.3.x while the latest release is 8.6.17 and in that time, many known vulnerabilities have been patched.

However, Malwarebytes security researcher Jérôme Segura noted that it was unusual to see credit card skimmers targeting Drupal since they typically are found on ecommerce platforms with Magento being the most popular target. 

The cybersecurity firm informed PokerTracker regarding the issue and it has since been fixed but Segura explained in a blog post that we should expect to find credit card skimmers in unexpected locations going forward, saying:

“What this incident tells us is that users might encounter web skimmers in unexpected locations—and not just in online shopping checkout pages. At the end of the day, anything that will load unvalidated JavaScript code is susceptible to being caught in the crosshairs. As a result, the Magecart robbers have a nice, wide playing field in front of them.”

Via Bleeping Computer

Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 9 (game #1140)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Sunday, March 9 (game #371)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Sunday, March 9 (game #637)
WhatsApp
WhatsApp just made its AI impossible to avoid – but at least you can turn it off