North Korean hackers are skimming US and European shoppers
2020-07-06 • Sansec •
Sansec attributed a set of Magecart-style digital skimming operations against US and European online stores to HIDDEN COBRA based on reused infrastructure and distinctive malware code patterns tied to prior North Korean activity. The actor gained unauthorized access to store code, injected checkout-page skimmers, and exfiltrated payment data to compromised collector sites such as luxmodelagency.com, signedbooksandcollectibles.com, stefanoturco.com, technokain.com, darvishkhan.net, and areac-agr.com. The report describes one campaign using a double-Base64 “clientToken” GET parameter and another using brand-lookalike domains and an “__preloader” image-based exfiltration technique. The activity matters because it extends North Korean cyber operations from banks and cryptocurrency targets into profit-driven card skimming.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | signedbooksandcollectibles.com | 2020-07-06 | 2021-04-14 |
| DOMAIN | technokain.com | 2020-07-06 | 2021-04-14 |
| DOMAIN | stefanoturco.com | 2020-07-06 | 2021-04-14 |
| DOMAIN | luxmodelagency.com | 2020-07-06 | 2021-04-14 |
| DOMAIN | areac-agr.com | 2019-12-17 | 2021-04-14 |
| DOMAIN | darvishkhan.net | 2019-07-02 | 2021-04-14 |
| IPv4 | 23.81.246.179 | 2019-12-17 | 2021-03-23 |
| HASH | 9fe97ae18c45e22fe76b8bd5165d0e1… | 2020-07-06 | 2020-07-06 |
| URL | https://technokain.com/vendor/j… | 2020-07-06 | 2020-07-06 |
| URL | https://technokain.com/ads/adsh… | 2020-07-06 | 2020-07-06 |
| URL | https://www.areac-agr.com/cms/w… | 2020-07-06 | 2020-07-06 |
| URL | https://www.luxmodelagency.com/… | 2020-07-06 | 2020-07-06 |
| URL | https://darvishkhan.net/wp-incl… | 2020-07-06 | 2020-07-06 |
| URL | https://darvishkhan.net/wp-incl… | 2020-07-06 | 2020-07-06 |
| URL | https://www.forbes.com/sites/ja… | 2020-07-06 | 2020-07-06 |
| URL | https://www.areac-agr.com/cms/w… | 2020-07-06 | 2020-07-06 |
| URL | https://www.signedbooksandcolle… | 2020-07-06 | 2020-07-06 |
| DOMAIN | papers0urce.com | 2020-07-06 | 2020-07-06 |
| DOMAIN | claires-assets.com | 2020-07-06 | 2020-07-06 |
| DOMAIN | focuscamere.com | 2020-07-06 | 2020-07-06 |
| URL | http://www.areac-agr.com/cms/wp… | 2019-12-17 | 2020-07-06 |
| URL | https://darvishkhan.net/wp-cont… | 2019-07-02 | 2020-07-06 |