Case Study

The Latest eCommerce ThreatScape Reports

ECOMMERCE THREATSCAPE - A YEAR IN REVIEW

We monitor the security status of over 16 million websites worldwide.

Threats are evolving. Hacked eCommerce numbers are growing. We, as an industry, also need to evolve to win.
Here's our report on what we've seen and learned in 2024.

Top 5 Loader Malware Detected:

  • JS_loader_parrot (linked to Parrot TDS malware) targeting Wordpress, Joomla, Drupal, Magento 1, Magento 2, OpenCart
  • JS_loader_firstkiss (targets checkout page) targeting Magento 2, BigCommerce, Magento
  • JS_loader_injector_google_ads (mimics Google Analytics script) targeting Wordpress, Magento 2, OpenCart, Magento 1, Joomla
  • JS_loader_cloudsonicwave (targets Wordpress Popup Builder) targeting Wordpress, PHP
  • JS_loader_kritec (loader associated with Magecart) targeting Magento 2, Wordpress, Prestashop, OpenCart, Magento 1, OpenMage.

Top 5 Skimmer Malware Detected:

  • JS_skimmer_z3r0day (part of the Cardbleed family) targeting Magento 1, Magento 2, Wordpress, Squarespace
  • JS_Skimmer_Gclon targeting Magento 1, Magento 2
  • JS_skimmer_united81 (considered part of Magecart family) targeting Magento 1, Magento 2, Wordpress, Drupal
  • JS_skimmer_dedwards_packed targeting Wordpress, OpenCart, Magento 1, Magento 2, Joomla
  • JS_skimmer_google_ads (mimics Google Analytics script) targeting Wordpress, OpenCart, Magento 1, Magento 2

New Malware Identified Through Forensic Investigations

New Malware / IOCS / Legit files used maliciously identified through forensic investigations in the last month.

  • SVG OnLoad
  • SVG Script
  • Statnestt Loader
  • Zheng Webshell
  • foobarloader backdoor
  • favico uploader
  • tmpname5 uploader
  • migk loader
  • charLoader
  • SharPyShell Webshell
  • LummaStealer Dropper
  • JS_skimmer_checksum_obfuscated
Hand pointing forward with digital lock icon and text reading 'Website Security' on a dark background.
Abstract blue circular gradient with bright outer edge fading inward on black background.

The latest global eCommerce ThreatScape Report highlights the threats, trends and developments across the eCommerce Industry.

Download Latest ThreatScape Report
Abstract circular glow with purple and blue gradient fading outward on a white background.

What you need to know to protect your business.

Man in white shirt looking shocked at dual computer monitors displaying 'System Hacked' warning messages.

Digital Skimmers & Loaders

Over the last 7 years, Digital Skimmers have been the most widely used malware for payment data theft. That trend has however, been slowly changing until early 2024 when Digital Loaders became more prevalent than Digital Skimmers.

This is a significant​ point in the fight against cyber crime in the eCommerce world as it shows that technologies like ThreatView have become so good at detecting Digital Skimmers that we are disrupting the criminal process. The next stage of their attack is to use Digital Loaders.

What is a Digital Loader?

A Digital Loader is usually a small script that tells a website visitor's browser to fetch a piece of code from another website. It effectively LOADS the code into the visitor's browser to do whatever it is designed to do. Most loaders in the eCommerce world are designed to covertly load Digital Skimmers into a visitor's browser, capturing any relevant payment data before it even reaches the website.

Digital loaders are a challenge to detect without appropriate technology and we're constantly seeing them evolve and develop as the cyber security world adapts.

Digital globe with interconnected padlock icons symbolizing cybersecurity and data protection.
Close-up of a woman holding a magnifying glass that enlarges her left eye.

What Else to Consider

A Digital Loader or Digital Skimmer is the final step in the attack and it is the part that does the theft of your customer data. Leading up to that point, the criminals will need to have found a way to break in, a backdoor/webshell to enable them to break back in and re-establish their attack should their user access be detected and shut down, and they may have made other changes to the site.

Our recommendation is if you detect a Digital Skimmer or Loader, you should do a full threat sweep of your eCommerce infrastructure to make sure there isn't some other nasty hidden code within your site.​

Naturally, this is what we can help you with. To help you get proactive. Stay ahead of the criminals, detect their movements and shut down any future attacks.

Check Your Website Security

Digital Skimmers - Magecart and Others

A digital skimmer refers to malicious code inserted into the checkout pages of online stores. This code operates by capturing credit card details entered by customers during the checkout process and transmitting this sensitive information to a server controlled by the attacker.

Due to the stealthy nature of this attack and the utilisation of advanced concealment techniques, digital skimmers can remain undetected for extended periods, potentially accumulating vast amounts of credit card data over time. Well known names of malware in this category are Magecart, FakeGA, FirstKiss, R3nin.

Digital circuit board with glowing red warning triangle and exclamation mark labeled MALWARE.
Miniature shopping cart filled with small boxes is placed on a laptop keyboard next to two credit cards.

Notably, digital skimmers have been implicated in several prominent security breaches involving well-known companies such as Ticketmaster, Tupperware, and British Airways. Additionally, they have been utilized in extensive automated attacks targeting eCommerce platforms like Magento, Wordpress, Magecart, OpenMage, Drupal, Joomla and others.

Whether overseeing security for a large corporation or managing a small online business, it is essential to comprehend the methods employed by digital skimmers to safeguard both your enterprise and its clientele.

Check Your Website Security
Blue circular gradient with pixelated texture fading to black on the right side.

Be the first to receive the latest news from Turaco Labs.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Purple light flare with a gradient glow effect on a dark background.
Proudly, designed, developed and maintained by Tecbot.