North Korean hackers are skimming US and European shoppers

2020-07-06 Sansec

https://sansec.io/research/north-korea-magecart

Thumbnail for North Korean hackers are skimming US and European shoppers

Sansec attributed a set of Magecart-style digital skimming operations against US and European online stores to HIDDEN COBRA based on reused infrastructure and distinctive malware code patterns tied to prior North Korean activity. The actor gained unauthorized access to store code, injected checkout-page skimmers, and exfiltrated payment data to compromised collector sites such as luxmodelagency.com, signedbooksandcollectibles.com, stefanoturco.com, technokain.com, darvishkhan.net, and areac-agr.com. The report describes one campaign using a double-Base64 “clientToken” GET parameter and another using brand-lookalike domains and an “__preloader” image-based exfiltration technique. The activity matters because it extends North Korean cyber operations from banks and cryptocurrency targets into profit-driven card skimming.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN signedbooksandcollectibles.com 2020-07-06 2021-04-14
DOMAIN technokain.com 2020-07-06 2021-04-14
DOMAIN stefanoturco.com 2020-07-06 2021-04-14
DOMAIN luxmodelagency.com 2020-07-06 2021-04-14
DOMAIN areac-agr.com 2019-12-17 2021-04-14
DOMAIN darvishkhan.net 2019-07-02 2021-04-14
IPv4 23.81.246.179 2019-12-17 2021-03-23
HASH 9fe97ae18c45e22fe76b8bd5165d0e1… 2020-07-06 2020-07-06
URL https://technokain.com/vendor/j… 2020-07-06 2020-07-06
URL https://technokain.com/ads/adsh… 2020-07-06 2020-07-06
URL https://www.areac-agr.com/cms/w… 2020-07-06 2020-07-06
URL https://www.luxmodelagency.com/… 2020-07-06 2020-07-06
URL https://darvishkhan.net/wp-incl… 2020-07-06 2020-07-06
URL https://darvishkhan.net/wp-incl… 2020-07-06 2020-07-06
URL https://www.forbes.com/sites/ja… 2020-07-06 2020-07-06
URL https://www.areac-agr.com/cms/w… 2020-07-06 2020-07-06
URL https://www.signedbooksandcolle… 2020-07-06 2020-07-06
DOMAIN papers0urce.com 2020-07-06 2020-07-06
DOMAIN claires-assets.com 2020-07-06 2020-07-06
DOMAIN focuscamere.com 2020-07-06 2020-07-06
URL http://www.areac-agr.com/cms/wp… 2019-12-17 2020-07-06
URL https://darvishkhan.net/wp-cont… 2019-07-02 2020-07-06

Related Reports

« Back