#Magecart

Malware/Tool

2020-07-06 • North Korean hackers are skimming US and European shoppers

Magecart is a broad label for digital-skimming malware and associated activity that steals payment-card data during online purchases, rather than one discrete malware family. A North Korea-linked operation modified code on compromised retail websites, including the international fashion chain Claire’s, to intercept shoppers’ transaction details. Sansec attributed the activity to HIDDEN COBRA through reused infrastructure and distinctive code patterns connecting multiple intrusions. The method used to gain access to the stores was not determined, and spear-phishing was discussed only as a common possibility rather than a confirmed delivery route.

Tagged Reports

« Back