
Practically every one of us uses online shopping services, which means sooner or later we risk becoming victims of JavaScript sniffers — special code that attackers embed on websites to steal credit card data, addresses, usernames, and passwords from users.
Nearly 400,000 users of the British Airways website and mobile app have already fallen victim to sniffers, as well as visitors to the British sports giant FILA’s website and the American ticket distributor Ticketmaster. Payment systems such as PayPal, Chase Paymenttech, USAePay, and Moneris have been compromised.
Victor Okorokov, an analyst at Threat Intelligence Group-IB, discusses how sniffers infiltrate website code to steal payment information and which CRMs they target.

The Hidden Threat
It so happened that for a long time JS sniffers remained off the radar of antivirus analysts, and banks and payment systems did not perceive them as a serious threat. And that was completely unjustified. Experts from Group-IB 2,440 infected online stores, with a total of about 1.5 million visitors per day, were at risk of compromise. The victims include not only users but also online stores, payment systems, and banks that issued compromised cards.
Group-IB became the first to investigate the darknet market for sniffers, their infrastructure, and monetization methods, generating millions of dollars for their creators. We identified 38 families of sniffers, of which only 12 had been previously known to researchers.
Let's take a closer look at four families of sniffers studied during the research.
ReactGet Family
ReactGet family sniffers are used to steal credit card data on online store websites. A sniffer can work with a large number of different payment systems used on the site: one parameter value corresponds to one payment system, and individual detected versions of the sniffer can be used to steal credentials as well as to steal credit card data from payment forms of several payment systems simultaneously, as a so-called universal sniffer. It has been established that in some cases attackers carry out phishing attacks on online store administrators to gain access to the site's administrative panel.
The campaign using this family of sniffers began in May 2017, targeting sites managed by CMS and platforms like Magento, Bigcommerce, and Shopify.
How ReactGet is embedded in the online store code
In addition to the "classic" script injection via link, operators of the ReactGet family sniffers use a special technique: JavaScript code checks whether the current address in which the user is located meets certain criteria. The malicious code will only be executed if the current URL contains the substring checkout or onestepcheckout, onepage/, out/onepag, checkout/one, ckout/one. Thus, the sniffer code will execute precisely at the moment the user proceeds to checkout and enters payment information into the form on the site.

This sniffer uses a non-standard technique. The victim's payment and personal data are collected together, encoded using base64, and then the resulting string is used as a parameter to send a request to the attackers' site. Most often, the path to the gate mimics a JavaScript file, for example, resp.js, data.js and so on, but links to image files are also used, GIF and JPG. The feature is that the sniffer creates a 1 by 1 pixel image object and uses the previously obtained link as a parameter. src images. This means that for the user, such a request in traffic will appear as a request for a regular image. A similar technique was used in the sniffers of the ImageID family. Additionally, the technique of using an image sized 1 by 1 pixel is employed by many legitimate online analytics scripts, which can also mislead the user.

Version analysis
Analysis of the active domains used by ReactGet sniffers has revealed many different versions of this family of sniffers. The versions differ in whether or not they include obfuscation, and furthermore, each sniffer is designed for a specific payment system that processes bank card payments for online stores. By varying the parameter corresponding to the version number, experts at Group-IB compiled a complete list of available sniffer variations, and by examining the names of the form fields each sniffer searches for in the page's code, they identified the payment systems targeted by the sniffer.
List of sniffers and their corresponding payment systems
| Sniffer URL | Payment system |
|---|---|
| Authorize.Net | |
| Cardsave | |
| Authorize.Net | |
| Authorize.Net | |
| eWAY Rapid | |
| Authorize.Net | |
| Adyen | |
| USAePay | |
| Authorize.Net | |
| USAePay | |
| Authorize.Net | |
| Moneris | |
| USAePay | |
| PayPal | |
| Sage Pay | |
| Verisign | |
| PayPal | |
| Stripe | |
| Realex | |
| PayPal | |
| LinkPoint | |
| PayPal | |
| PayPal | |
| DataCash | |
| PayPal | |
| Authorize.Net | |
| Authorize.Net | |
| Authorize.Net | |
| Authorize.Net | |
| Verisign | |
| Authorize.Net | |
| Moneris | |
| Sage Pay | |
| USAePay | |
| Authorize.Net | |
| Authorize.Net | |
| ANZ eGate | |
| Authorize.Net | |
| Moneris | |
| Sage Pay | |
| Sage Pay | |
| Chase Paymentech | |
| Authorize.Net | |
| Adyen | |
| PsiGate | |
| CyberSource | |
| ANZ eGate | |
| Realex | |
| USAePay | |
| Authorize.Net | |
| Authorize.Net | |
| ANZ eGate | |
| PayPal | |
| PayPal | |
| Realex | |
| Sage Pay | |
| PayPal | |
| Verisign | |
| Authorize.Net | |
| Verisign | |
| Authorize.Net | |
| ANZ eGate | |
| PayPal | |
| CyberSource | |
| Authorize.Net | |
| Sage Pay | |
| Realex | |
| CyberSource | |
| PayPal | |
| PayPal | |
| PayPal | |
| Verisign | |
| eWAY Rapid | |
| Sage Pay | |
| Sage Pay | |
| Verisign | |
| Authorize.Net | |
| Authorize.Net | |
| First Data Global Gateway | |
| Authorize.Net | |
| Authorize.Net | |
| Moneris | |
| Authorize.Net | |
| PayPal | |
| Verisign | |
| USAePay | |
| USAePay | |
| Authorize.Net | |
| Verisign | |
| PayPal | |
| Authorize.Net | |
| Stripe | |
| Authorize.Net | |
| eWAY Rapid | |
| Sage Pay | |
| Authorize.Net | |
| Braintree | |
| Braintree | |
| PayPal | |
| Sage Pay | |
| Sage Pay | |
| Authorize.Net | |
| PayPal | |
| Authorize.Net | |
| Verisign | |
| PayPal | |
| Authorize.Net | |
| Stripe | |
| Authorize.Net | |
| eWAY Rapid | |
| Sage Pay | |
| Authorize.Net | |
| Braintree | |
| PayPal | |
| Sage Pay | |
| Sage Pay | |
| Authorize.Net | |
| PayPal | |
| Authorize.Net | |
| Verisign | |
| Authorize.Net | |
| Authorize.Net | |
| Authorize.Net | |
| Authorize.Net | |
| Sage Pay | |
| Sage Pay | |
| Westpac PayWay | |
| PayFort | |
| PayPal | |
| Authorize.Net | |
| Stripe | |
| First Data Global Gateway | |
| PsiGate | |
| Authorize.Net | |
| Authorize.Net | |
| Moneris | |
| Authorize.Net | |
| Sage Pay | |
| Verisign | |
| Moneris | |
| PayPal | |
| LinkPoint | |
| Westpac PayWay | |
| Authorize.Net | |
| Moneris | |
| PayPal | |
| Adyen | |
| PayPal | |
| Authorize.Net | |
| USAePay | |
| EBizCharge | |
| Authorize.Net | |
| Verisign | |
| Verisign | |
| Authorize.Net | |
| PayPal | |
| Moneris | |
| Authorize.Net | |
| PayPal | |
| PayPal | |
| Westpac PayWay | |
| Authorize.Net | |
| Authorize.Net | |
| Sage Pay | |
| Verisign | |
| Authorize.Net | |
| PayPal | |
| PayFort | |
| CyberSource | |
| PayPal Payflow Pro | |
| Authorize.Net | |
| Authorize.Net | |
| Verisign | |
| Authorize.Net | |
| Authorize.Net | |
| Sage Pay | |
| Authorize.Net | |
| Stripe | |
| Authorize.Net | |
| Authorize.Net | |
| Verisign | |
| PayPal | |
| Authorize.Net | |
| Authorize.Net | |
| Sage Pay | |
| Authorize.Net | |
| Authorize.Net | |
| PayPal | |
| Flint | |
| PayPal | |
| Sage Pay | |
| Verisign | |
| Authorize.Net | |
| Authorize.Net | |
| Stripe | |
| Fat Zebra | |
| Sage Pay | |
| Authorize.Net | |
| First Data Global Gateway | |
| Authorize.Net | |
| eWAY Rapid | |
| Adyen | |
| PayPal | |
| QuickBooks Merchant Services | |
| Verisign | |
| Sage Pay | |
| Verisign | |
| Authorize.Net | |
| Authorize.Net | |
| Sage Pay | |
| Authorize.Net | |
| eWAY Rapid | |
| Authorize.Net | |
| ANZ eGate | |
| PayPal | |
| CyberSource | |
| Authorize.Net | |
| Sage Pay | |
| Realex | |
| CyberSource | |
| PayPal | |
| PayPal | |
| PayPal | |
| Verisign | |
| eWAY Rapid | |
| Sage Pay | |
| Sage Pay | |
| Verisign | |
| Authorize.Net | |
| Authorize.Net | |
| First Data Global Gateway | |
| Authorize.Net | |
| Authorize.Net | |
| Moneris | |
| Authorize.Net | |
| PayPal |
Password sniffer
One of the advantages of JavaScript sniffers operating on the client side of the website is their versatility: the malicious code embedded on the site can steal data of any kind, whether it is payment information or login and password of a user account. Group-IB experts discovered a sample of a sniffer belonging to the ReactGet family designed to steal email addresses and passwords of website users.

Intersection with ImageID sniffer
During the analysis of one of the infected stores, it was found that its website had been infected twice: in addition to the malicious code of the ReactGet family sniffer, code from the ImageID family sniffer was also discovered. This intersection may indicate that the operators behind the use of both sniffers employ similar techniques for injecting malicious code.

Universal sniffer
During the analysis of one of the domain names associated with the ReactGet sniffers' infrastructure, it was found that the same user registered three other domain names. These three domains imitated the domains of real existing sites and had previously been used to host sniffers. Analyzing the code of three legitimate sites revealed an unknown sniffer, and further analysis indicated that it was an upgraded version of the ReactGet sniffer. All previously tracked versions of sniffers from this family targeted a specific payment system, meaning a special version of the sniffer was required for each payment system. However, in this case, a universal version of the sniffer was discovered, capable of stealing information from forms related to 15 different payment systems and ecommerce site modules for conducting online payments.
At the beginning of its operation, the sniffer searched for basic form fields containing the victim's personal information: full name, physical address, phone number.

The sniffer then searched through more than 15 different prefixes corresponding to various payment systems and modules for online payments.

Next, the victim's personal data and payment information were consolidated and sent to a site controlled by the attacker: in this specific case, two versions of the universal ReactGet sniffer were found on two different hacked sites. However, both versions sent the stolen data to the same hacked site. zoobashop.com.

Analyzing the prefixes used by the sniffer to search for fields containing the victim's payment information revealed that this sniffer sample targeted the following payment systems:
- Authorize.Net
- Verisign
- First Data
- USAePay
- Stripe
- PayPal
- ANZ eGate
- Braintree
- DataCash (MasterCard)
- Realex Payments
- PsiGate
- Heartland Payment Systems
What tools are used to steal payment information
The first tool discovered during the analysis of the attackers' infrastructure is used to obfuscate malicious scripts responsible for stealing credit card information. A bash script was found on one of the attackers' hosts that utilizes the CLI of the project to automate the obfuscation of sniffer code.
![]()
The second detected tool is designed to generate code responsible for loading the main sniffer. This tool generates JavaScript code that checks if the user is on the payment page by searching the current user's address for string checkout, cart , and so on. If the result is positive, the code loads the main sniffer from the attacker's server. To conceal malicious activity, all strings, including test strings for identifying the payment page and the link to the sniffer, are encoded using base64.

Phishing attacks
During the analysis of the attackers' network infrastructure, it was established that often, to gain access to the administrative panel of the target online store, the criminal group uses phishing. The attackers register a domain visually similar to the store's domain and then deploy a fake login form for the administrative panel of Magento. If successful, the attackers will gain access to the CMS Magento administrative panel, allowing them to edit site components and inject a sniffer to steal credit card data.

Infrastructure
| Domain | Date of discovery/appearance |
|---|---|
| mediapack.info | 04.05.2017 |
| adsgetapi.com | 15.06.2017 |
| simcounter.com | 14.08.2017 |
| mageanalytics.com | 22.12.2017 |
| maxstatics.com | 16.01.2018 |
| reactjsapi.com | 19.01.2018 |
| mxcounter.com | 02.02.2018 |
| apitstatus.com | 01.03.2018 |
| orderracker.com | 20.04.2018 |
| tagstracking.com | 25.06.2018 |
| adsapigate.com | 12.07.2018 |
| trust-tracker.com | 15.07.2018 |
| fbstatspartner.com | 02.10.2018 |
| billgetstatus.com | 12.10.2018 |
| aldenmlilhouse.com | 20.10.2018 |
| balletbeautlful.com | 20.10.2018 |
| bargalnjunkie.com | 20.10.2018 |
| payselector.com | 21.10.2018 |
| tagsmediaget.com | 02.11.2018 |
| hs-payments.com | 16.11.2018 |
| ordercheckpays.com | 19.11.2018 |
| geisseie.com | 24.11.2018 |
| gtmproc.com | 29.11.2018 |
| livegetpay.com | 18.12.2018 |
| sydneysalonsupplies.com | 18.12.2018 |
| newrelicnet.com | 19.12.2018 |
| nr-public.com | 03.01.2019 |
| cloudodesc.com | 04.01.2019 |
| ajaxstatic.com | 11.01.2019 |
| livecheckpay.com | 21.01.2019 |
| asianfoodgracer.com | 25.01.2019 |
G-Analytics Family
This family of sniffers is used to steal customer cards from online stores. The first domain name used by the group was registered in April 2016, which may indicate the start of the group's activity in mid-2016.
In the current campaign, the group is using domain names that imitate real services, such as Google Analytics and jQuery, masking sniffer activity with legitimate scripts and names that resemble legitimate domains. The attacked sites are managed by the CMS Magento.
How G-Analytics is integrated into the online store's code
A distinguishing feature of this family is the use of various methods to steal the user's payment information. In addition to the classic injection of JavaScript code into the client part of the site, the criminal group also employed the technique of injecting code into the server part of the site, namely PHP scripts that process user-entered data. This technique is dangerous because it complicates the detection of malicious code by third-party researchers. Specialists from Group-IB discovered a version of the sniffer injected into the website's PHP code, using the domain dittm.org.

An earlier version of the sniffer was also found, using the same domain to collect stolen data dittm.org, but this version was already intended for installation on the client side of the online store.

Later, the group changed its tactics and began to focus more on concealing malicious activity and camouflage.
In early 2017, the group started using the domain jquery-js.com, masquerading as a CDN for jQuery: when users visit the attackers' site, they are redirected to a legitimate site jquery.com.
And in mid-2018, the group adopted the domain name g-analytics.com and started disguising the sniffer's activity as a legitimate Google Analytics service.


Version analysis
During the analysis of the domains used to store the sniffer code, it was found that the site contained a large number of versions that differed in the presence of obfuscation, as well as the presence or absence of unreachable code added to the file to distract attention and conceal malicious code.
A total of six versions of sniffers were identified on the site. jquery-js.com These sniffers send stolen data to an address located on the same site as the sniffer: hxxps://jquery-js[.]com/latest/jquery.min.js:
- hxxps://jquery-js[.]com/jquery.min.js
- hxxps://jquery-js[.]com/jquery.2.2.4.min.js
- hxxps://jquery-js[.]com/jquery.1.8.3.min.js
- hxxps://jquery-js[.]com/jquery.1.6.4.min.js
- hxxps://jquery-js[.]com/jquery.1.4.4.min.js
- hxxps://jquery-js[.]com/jquery.1.12.4.min.js
A later domain g-analytics.com, used by the group in attacks since mid-2018, serves as a repository for a greater number of sniffers. A total of 16 different versions of the sniffer were discovered. In this case, the gate for sending stolen data was disguised as a link to an image in the format of GIF: hxxp://g-analytics[.]com/__utm.gif?v=1&_v=j68&a=98811130&t=pageview&_s=1&sd=24-bit&sr=2560×1440&vp=2145×371&je=0&_u=AACAAEAB~&jid=1841704724&gjid=877686936&cid
=1283183910.1527732071:
- hxxps://g-analytics[.]com/libs/1.0.1/analytics.js
- hxxps://g-analytics[.]com/libs/1.0.10/analytics.js
- hxxps://g-analytics[.]com/libs/1.0.11/analytics.js
- hxxps://g-analytics[.]com/libs/1.0.12/analytics.js
- hxxps://g-analytics[.]com/libs/1.0.13/analytics.js
- hxxps://g-analytics[.]com/libs/1.0.14/analytics.js
- hxxps://g-analytics[.]com/libs/1.0.15/analytics.js
- hxxps://g-analytics[.]com/libs/1.0.16/analytics.js
- hxxps://g-analytics[.]com/libs/1.0.3/analytics.js
- hxxps://g-analytics[.]com/libs/1.0.4/analytics.js
- hxxps://g-analytics[.]com/libs/1.0.5/analytics.js
- hxxps://g-analytics[.]com/libs/1.0.6/analytics.js
- hxxps://g-analytics[.]com/libs/1.0.7/analytics.js
- hxxps://g-analytics[.]com/libs/1.0.8/analytics.js
- hxxps://g-analytics[.]com/libs/1.0.9/analytics.js
- hxxps://g-analytics[.]com/libs/analytics.js
Monetization of stolen data
The criminal group monetizes the stolen data by selling cards through a specially created underground store that provides services to carders. An analysis of the domains used by the attackers allowed for the identification that google-analytics.cm was registered by the same user as the domain cardz.vc. The domain cardz.vc is associated with the store selling stolen bank cards Cardsurfs (Flysurfs), which gained popularity during the active days of the underground marketplace AlphaBay as a retailer of bank cards stolen via sniffers.

Analyzing the domain analytic.is, located on the same server as the domains used by sniffers to collect stolen data, specialists from Group-IB discovered a file containing logs of a cookie stealer that seemingly was later abandoned by the developer. One entry in the log contained the domain iozoz.com, which was previously used in one of the sniffers active in 2016. Presumably, this domain was once used by a malicious actor to collect cards stolen via sniffers. This domain was registered to the email address kts241@gmail.com, which was also used to register the domains cardz.su and cardz.vc, relating to the carding store Cardsurfs.
Based on the obtained data, one can speculate that the G-Analytics family of sniffers and the underground bank card store Cardsurfs are managed by the same individuals, with the store being used for the sale of bank cards stolen via sniffers.
Infrastructure
| Domain | Date of discovery/appearance |
|---|---|
| iozoz.com | 08.04.2016 |
| dittm.org | 10.09.2016 |
| jquery-js.com | 02.01.2017 |
| g-analytics.com | 31.05.2018 |
| google-analytics.is | 21.11.2018 |
| analytic.to | 04.12.2018 |
| google-analytics.to | 06.12.2018 |
| google-analytics.cm | 28.12.2018 |
| analytic.is | 28.12.2018 |
| googlc-analytics.cm | 17.01.2019 |
Illum Family
Illum is a family of sniffers employed in attacks on online stores running on the Magento CMS. In addition to injecting malicious code, the operators of this sniffer also use full-fledged fake payment forms that send data to the malicious gates under their control.
Upon analyzing the network infrastructure utilized by this sniffer's operators, a significant number of malicious scripts, exploits, fake payment forms, as well as a collection of examples from competing malicious sniffers were noted. Based on the information regarding the registration dates of the domain names used by the group, it can be inferred that the campaign began in late 2016.
How Illum is injected into the online store's code
The first detected versions of the sniffer were injected directly into the code of the compromised site. Stolen data was sent to cdn.illum[.]pw/records.php, with the gate being encoded using base64.

Later, a packaged version of the sniffer was found using a different gate — records.nstatistics[.]com/records.php.

According to Willem de Groot, the same host was used in the sniffer that was injected into , owned by the German political party CSU.
Analysis of the attackers' website
Group-IB specialists discovered and analyzed a website used by this criminal group to store tools and collect stolen information.

Among the tools found on the attackers' server were scripts and exploits for privilege escalation in Linux OS: for example, the Linux Privilege Escalation Check Script, developed by Mike Czumak, as well as an exploit for CVE-2009-1185.
Specifically for attacks on online stores, the attackers used two exploits: able to inject malicious code into core_config_data by exploiting CVE-2016-4010, exploits an RCE vulnerability in plugins for the Magento CMS, allowing arbitrary code execution on the vulnerable web server.

Also, during the server analysis, various samples of sniffers and fake payment forms used by the attackers to collect payment information from hacked sites were found. As can be seen from the list below, some scripts were created specifically for each hacked site, while universal solutions were used for certain CMS and payment gateways. For example, scripts segapay_standart.js and segapay_onpage.js are designed for injection into sites using the Sage Pay payment gateway.
List of scripts for various payment gateways
| Script | Payment Gateway |
|---|---|
| [.]pw/mjs_special/visiondirect.co.uk.js | //request.payrightnow[.]cf/checkpayment.php |
| [.]pw/mjs_special/topdierenshop.nl.js | //request.payrightnow[.]cf/alldata.php |
| [.]pw/mjs_special/tiendalenovo.es.js | //request.payrightnow[.]cf/alldata.php |
| [.]pw/mjs_special/pro-bolt.com.js | //request.payrightnow[.]cf/alldata.php |
| [.]pw/mjs_special/plae.co.js | //request.payrightnow[.]cf/alldata.php |
| [.]pw/mjs_special/ottolenghi.co.uk.js | //request.payrightnow[.]cf/alldata.php |
| [.]pw/mjs_special/oldtimecandy.com.js | //request.payrightnow[.]cf/checkpayment.php |
| [.]pw/mjs_special/mylook.ee.js | //cdn.illum[.]pw/records.php |
| [.]pw/mjs_special/luluandsky.com.js | //request.payrightnow[.]cf/checkpayment.php |
| [.]pw/mjs_special/julep.com.js | //cdn.illum[.]pw/records.php |
| [.]pw/mjs_special/gymcompany.es.js | //request.payrightnow[.]cf/alldata.php |
| [.]pw/mjs_special/grotekadoshop.nl.js | //request.payrightnow[.]cf/alldata.php |
| [.]pw/mjs_special/fushi.co.uk.js | //request.payrightnow[.]cf/checkpayment.php |
| [.]pw/mjs_special/fareastflora.com.js | //request.payrightnow[.]cf/checkpayment.php |
| [.]pw/mjs_special/compuindia.com.js | //request.payrightnow[.]cf/alldata.php |
| [.]pw/mjs/segapay_standart.js | //cdn.illum[.]pw/records.php |
| [.]pw/mjs/segapay_onpage.js | //cdn.illum[.]pw/records.php |
| [.]pw/mjs/replace_standart.js | //request.payrightnow[.]cf/checkpayment.php |
| [.]pw/mjs/all_inputs.js | //cdn.illum[.]pw/records.php |
| [.]pw/mjs/add_inputs_standart.js | //request.payrightnow[.]cf/checkpayment.php |
| [.]pw/magento/payment_standart.js | //cdn.illum[.]pw/records.php |
| [.]pw/magento/payment_redirect.js | //payrightnow[.]cf/?payment= |
| [.]pw/magento/payment_redcrypt.js | //payrightnow[.]cf/?payment= |
| [.]pw/magento/payment_forminsite.js | //paymentnow[.]tk/?payment= |
Host paymentnow[.]tk, used as a gate in the script payment_forminsite.js, was discovered as subjectAltName in several certificates related to the CloudFlare service. Additionally, the host contained a script evil.js. Judging by the script's name, it could have been used in the exploitation of CVE-2016-4010, which could allow the injection of malicious code into the footer of a site running on the Magento CMS. As a gate, this script applied host request.requestnet[.]tk, using the same certificate as host paymentnow[.]tk.
Fake Payment Forms
Below is an example of a form for entering card details. This form was used for injection into the online store's website to steal card data.

The following illustration shows an example of a fake PayPal payment form used by attackers to inject into websites with this payment method.

Infrastructure
| Domain | Date of discovery/appearance |
|---|---|
| cdn.illum.pw | 27/11/2016 |
| records.nstatistics.com | 06/09/2018 |
| request.payrightnow.cf | 25/05/2018 |
| paymentnow.tk | 16/07/2017 |
| payment-line.tk | 01/03/2018 |
| paymentpal.cf | 04/09/2017 |
| requestnet.tk | 28/06/2017 |
CoffeMokko Family
The CoffeMokko family of sniffers, designed to steal users' credit card information from online stores, has been in use at least since May 2017. It is believed that the operators of this sniffer family are a criminal group known as Group 1, described by RiskIQ specialists in 2016. The attacks targeted websites managed by CMS platforms like Magento, OpenCart, WordPress, osCommerce, and Shopify.
How CoffeMokko Injects Into Online Store Code
Operators of this family create unique sniffers for each infection: the sniffer file is located in the directory src or js on the attackers' server. The injection into the website code is done via a direct link to the sniffer.

The sniffer's code hard-codes the names of the form fields from which data needs to be stolen. It also checks if the user is on the payment page by comparing a list of keywords with the user's current address.

Some detected versions of the sniffer were obfuscated and contained an encrypted string that held the main resource array: this array included the names of form fields for various payment systems, as well as the address of the gateway to which the stolen data needed to be sent.

The stolen payment information was sent to a script on the attacker's server via the path /savePayment/index.php или /tr/index.php. It is believed that this script serves to transmit data from the gateway to the main server that consolidates data from all the sniffers. To obscure the transmitted data, all the victim's payment information is encoded using base64, followed by several character replacements:
- the character 'e' is replaced with ':'
- the character 'w' is replaced with '+'
- the character 'o' is replaced with '%'
- the character 'd' is replaced with '#'
- the character 'a' is replaced with '-'
- the character '7' is replaced with '^'
- the character 'h' is replaced with '_'
- the character 'T' is replaced with '@'
- the character '0' is replaced with '/'
- the character 'Y' is replaced with '*'
As a result of the character replacements, data encoded using base64 cannot be decoded without performing the reverse transformation.
This is how a snippet of unobfuscated sniffer code looks:

Infrastructure Analysis
In earlier campaigns, attackers registered domain names that were similar to the domains of legitimate online store websites. Their domain could differ from the legitimate one by just one character or another TLD. These registered domains were used to host sniffer code, which was injected into the store's code.
This group also used domain names resembling the names of popular jQuery plugins (slickjs[.]org for sites using the plugin slick.js), payment gateways (sagecdn[.]org for sites using the Sage Pay payment system).
Later, the group began to create domains whose names had nothing to do with either the store domain or the store's theme.

Each domain corresponded to a site where a directory was created /js or /src. This directory stored sniffer scripts: one sniffer for each new infection. The sniffer was injected into the site's code via a direct link, but in rare cases, the attackers modified one of the site files and added malicious code to it.
Code Analysis
First Obfuscation Algorithm
In some detected samples of sniffer from this family, the code was obfuscated and contained encrypted data necessary for the sniffer's operation: in particular, the sniffer gateway address, the list of payment form fields, and in some cases — the code for a fake payment form. In the code within the function, resources were encrypted using XOR with a key passed as an argument to that same function.

By decrypting the string with the corresponding key unique to each sample, it is possible to obtain a string containing all the strings from the sniffer's code separated by a delimiter.

Second Obfuscation Algorithm
In later samples of sniffer from this family, another obfuscation mechanism was used: in this case, the data was encrypted using a custom-written algorithm. The string containing the encrypted data necessary for the sniffer's operation was passed as an argument to the decryption function.

Using the browser console, it is possible to decrypt the encrypted data and obtain an array containing the sniffer's resources.

Connection to Early MageCart Attacks
During the analysis of one of the domains used by the group as a gate for collecting stolen data, it was found that this domain had infrastructure set up for credit card theft, identical to that used by Group 1 — one of the first groups, by RiskIQ specialists.
On the host of the CoffeMokko sniffer family, two files were discovered:
- mage.js — a file containing the code of the Group 1 sniffer with the gate address js-cdn.link
- mag.php — a PHP script responsible for collecting data stolen by the sniffer
Содержимое файла mage.js 
It was also established that the earliest domains used by the group behind the CoffeMokko sniffer family were registered on May 17, 2017:
- link-js[.]link
- info-js[.]link
- track-js[.]link
- map-js[.]link
- smart-js[.]link
The format of these domain names matches the domain names used by Group 1 in the attacks of 2016.
Based on the findings, one can speculate that there is a connection between the operators of the CoffeMokko sniffers and the criminal group Group 1. It is presumed that the operators of CoffeMokko may have borrowed tools and software for card theft from their predecessors. However, it is more likely that the criminal group behind the use of the CoffeMokko sniffers consists of the same individuals who carried out attacks as part of Group 1's activities. After the first report on the criminal group's activities was published, all their domain names were blocked, and the tools were thoroughly examined and documented. The group was forced to take a break to revise their internal tools and rewrite the sniffer code to continue their attacks unnoticed.
Infrastructure
| Domain | Date of discovery/appearance |
|---|---|
| link-js.link | 17.05.2017 |
| info-js.link | 17.05.2017 |
| track-js.link | 17.05.2017 |
| map-js.link | 17.05.2017 |
| smart-js.link | 17.05.2017 |
| adorebeauty.org | 03.09.2017 |
| security-payment.su | 03.09.2017 |
| braincdn.org | 04.09.2017 |
| sagecdn.org | 04.09.2017 |
| slickjs.org | 04.09.2017 |
| oakandfort.org | 10.09.2017 |
| citywlnery.org | 15.09.2017 |
| dobell.su | 04.10.2017 |
| childsplayclothing.org | 31.10.2017 |
| jewsondirect.com | 05.11.2017 |
| shop-rnib.org | 15.11.2017 |
| closetlondon.org | 16.11.2017 |
| misshaus.org | 28.11.2017 |
| battery-force.org | 01.12.2017 |
| kik-vape.org | 01.12.2017 |
| greatfurnituretradingco.org | 02.12.2017 |
| etradesupply.org | 04.12.2017 |
| replacemyremote.org | 04.12.2017 |
| all-about-sneakers.org | 05.12.2017 |
| mage-checkout.org | 05.12.2017 |
| nililotan.org | 07.12.2017 |
| lamoodbighats.net | 08.12.2017 |
| walletgear.org | 10.12.2017 |
| dahlie.org | 12.12.2017 |
| davidsfootwear.org | 20.12.2017 |
| blackriverimaging.org | 23.12.2017 |
| exrpesso.org | 02.01.2018 |
| parks.su | 09.01.2018 |
| pmtonline.su | 12.01.2018 |
| ottocap.org | 15.01.2018 |
| christohperward.org | 27.01.2018 |
| coffetea.org | 31.01.2018 |
| energycoffe.org | 31.01.2018 |
| energytea.org | 31.01.2018 |
| teacoffe.net | 31.01.2018 |
| adaptivecss.org | 01.03.2018 |
| coffemokko.com | 01.03.2018 |
| londontea.net | 01.03.2018 |
| ukcoffe.com | 01.03.2018 |
| labbe.biz | 20.03.2018 |
| batterynart.com | 03.04.2018 |
| btosports.net | 09.04.2018 |
| chicksaddlery.net | 16.04.2018 |
| paypaypay.org | 11.05.2018 |
| ar500arnor.com | 26.05.2018 |
| authorizecdn.com | 28.05.2018 |
| slickmin.com | 28.05.2018 |
| bannerbuzz.info | 03.06.2018 |
| kandypens.net | 08.06.2018 |
| mylrendyphone.com | 15.06.2018 |
| freshchat.info | 01.07.2018 |
| 3lift.org | 02.07.2018 |
| abtasty.net | 02.07.2018 |
| mechat.info | 02.07.2018 |
| zoplm.com | 02.07.2018 |
| zapaljs.com | 02.09.2018 |
| foodandcot.com | 15.09.2018 |
| freshdepor.com | 15.09.2018 |
| swappastore.com | 15.09.2018 |
| verywellfitnesse.com | 15.09.2018 |
| elegrina.com | 18.11.2018 |
| majsurplus.com | 19.11.2018 |
| top5value.com | 19.11.2018 |
Source: habr.com
