Categories: Ad Guardian PlusNews

Skimming attack with phishing techniques

A new digital skimming attack borrows phishing techniques and steals card data from fake payments page. Attackers used the secure payment pages, from third-party payment service providers, and inserted digital skimming code. They used fake Google Analytics library (ga.js), according to Malwarebytes.

Director of threat intelligence, Jérôme Segura, discovered a fake payment-mastercard[.]com domain. This was “hosting a completely different kind of skimmer that at first resembled a phishing site.”

This skimmer is interesting because it looks like a phishing page copied from an official template for CommWeb, a payments acceptance service offered by Australia’s Commonwealth Bank,” he explained. “The attackers have crafted it specifically for an Australian store running the PrestaShop Content Management System (CMS), exploiting the fact that it accepts payments via the Commonwealth Bank.”

Moreover, the fake payments page even alerts users if any fields they fill in are invalid.

After steeling victim’s details, they land on the real payment processor. The real Australian Commonwealth Bank site displayed along with the correct total amount due for purchase. This is possible by creating a unique session ID and reading browser cookies, Segura explained.

Externalizing payments shifts the burden and risk to the payment company such that even if a merchant site were hacked, online shoppers would be redirected to a different site (i.e. Paypal, MasterCard, Visa gateways) where they could enter their payment details securely,” he concluded.

Unfortunately, fraudsters are becoming incredibly creative in order to defeat those security defenses. By combining phishing-like techniques and inserting themselves in the middle, they can fool everyone.”

How the skimming attack works

The skimming attack is, thus, more dangerous than the previous ones. Here is the method it uses:  

  • The fake page collects the credit card data filled in by the victim. Then, it steals the data via the payment-mastercard rcard[.]com/ga.php?analytic={based64} URL.
  • Afterwards, the victim lands on the real payment processor.
  • In the end, the legitimate site for Australia’s Commonwealth Bank loads and displays the total amount due for the purchase.
Laurentiu Titei

View Comments

Recent Posts

Top 5 Free Desktop Publishing Software of 2025

A page layout or desktop publishing software helps you create appealing visuals for your on-screen…

20 hours ago

DriverPack Solution: Review, Download Link & its Alternatives

It won’t be an exaggeration to say that updating drivers is crucial for smooth computer…

2 days ago

How to Fix the Most Common Printer Issues, Like the Printer Not Working, Printer Not Working, and More

If you are looking for a guide that addresses the common printer issues and solutions,…

3 days ago

Acer Drivers Download and update for Windows 11 and 10

Acer computers are generally good performers with excellent battery life, fast speed, and features that…

5 days ago

Lenovo T460 Drivers Download for Windows 11/10

Lenovo T460 is a notebook PC that is well-received by customers for its functionality, fast…

5 days ago

How to Update and Install Drivers in Windows 11 and 10 (Manually and Automatically)

No wonder many computers show sluggish performance after a few years of purchase. What may…

6 days ago