Four JavaScript Sniffers Lurking in Online Stores

Four JavaScript Sniffers Lurking in Online Stores

Practically every one of us uses online shopping services, which means sooner or later we risk becoming victims of JavaScript sniffers — special code that attackers embed on websites to steal credit card data, addresses, usernames, and passwords from users.

Nearly 400,000 users of the British Airways website and mobile app have already fallen victim to sniffers, as well as visitors to the British sports giant FILA’s website and the American ticket distributor Ticketmaster. Payment systems such as PayPal, Chase Paymenttech, USAePay, and Moneris have been compromised.

Victor Okorokov, an analyst at Threat Intelligence Group-IB, discusses how sniffers infiltrate website code to steal payment information and which CRMs they target.

Four JavaScript Sniffers Lurking in Online Stores

The Hidden Threat

It so happened that for a long time JS sniffers remained off the radar of antivirus analysts, and banks and payment systems did not perceive them as a serious threat. And that was completely unjustified. Experts from Group-IB analyzed 2,440 infected online stores, with a total of about 1.5 million visitors per day, were at risk of compromise. The victims include not only users but also online stores, payment systems, and banks that issued compromised cards.

Report Group-IB became the first to investigate the darknet market for sniffers, their infrastructure, and monetization methods, generating millions of dollars for their creators. We identified 38 families of sniffers, of which only 12 had been previously known to researchers.

Let's take a closer look at four families of sniffers studied during the research.

ReactGet Family

ReactGet family sniffers are used to steal credit card data on online store websites. A sniffer can work with a large number of different payment systems used on the site: one parameter value corresponds to one payment system, and individual detected versions of the sniffer can be used to steal credentials as well as to steal credit card data from payment forms of several payment systems simultaneously, as a so-called universal sniffer. It has been established that in some cases attackers carry out phishing attacks on online store administrators to gain access to the site's administrative panel.

The campaign using this family of sniffers began in May 2017, targeting sites managed by CMS and platforms like Magento, Bigcommerce, and Shopify.

How ReactGet is embedded in the online store code

In addition to the "classic" script injection via link, operators of the ReactGet family sniffers use a special technique: JavaScript code checks whether the current address in which the user is located meets certain criteria. The malicious code will only be executed if the current URL contains the substring checkout or onestepcheckout, onepage/, out/onepag, checkout/one, ckout/one. Thus, the sniffer code will execute precisely at the moment the user proceeds to checkout and enters payment information into the form on the site.

Four JavaScript Sniffers Lurking in Online Stores
This sniffer uses a non-standard technique. The victim's payment and personal data are collected together, encoded using base64, and then the resulting string is used as a parameter to send a request to the attackers' site. Most often, the path to the gate mimics a JavaScript file, for example, resp.js, data.js and so on, but links to image files are also used, GIF and JPG. The feature is that the sniffer creates a 1 by 1 pixel image object and uses the previously obtained link as a parameter. src images. This means that for the user, such a request in traffic will appear as a request for a regular image. A similar technique was used in the sniffers of the ImageID family. Additionally, the technique of using an image sized 1 by 1 pixel is employed by many legitimate online analytics scripts, which can also mislead the user.

Four JavaScript Sniffers Lurking in Online Stores

Version analysis

Analysis of the active domains used by ReactGet sniffers has revealed many different versions of this family of sniffers. The versions differ in whether or not they include obfuscation, and furthermore, each sniffer is designed for a specific payment system that processes bank card payments for online stores. By varying the parameter corresponding to the version number, experts at Group-IB compiled a complete list of available sniffer variations, and by examining the names of the form fields each sniffer searches for in the page's code, they identified the payment systems targeted by the sniffer.

List of sniffers and their corresponding payment systems

Sniffer URLPayment system
reactjsapi.com/react.js Authorize.Net
ajaxstatic.com/api.js?v=2.1.1 Cardsave
ajaxstatic.com/api.js?v=2.1.2 Authorize.Net
ajaxstatic.com/api.js?v=2.1.3 Authorize.Net
ajaxstatic.com/api.js?v=2.1.4eWAY Rapid
ajaxstatic.com/api.js?v=2.1.5 Authorize.Net
ajaxstatic.com/api.js?v=2.1.6 Adyen
ajaxstatic.com/api.js?v=2.1.7USAePay
ajaxstatic.com/api.js?v=2.1.9 Authorize.Net
apitstatus.com/api.js?v=2.1.1 USAePay
apitstatus.com/api.js?v=2.1.2 Authorize.Net
apitstatus.com/api.js?v=2.1.3Moneris
apitstatus.com/api.js?v=2.1.5 USAePay
apitstatus.com/api.js?v=2.1.6PayPal
apitstatus.com/api.js?v=2.1.7Sage Pay
apitstatus.com/api.js?v=2.1.8Verisign
apitstatus.com/api.js?v=2.1.9PayPal
apitstatus.com/api.js?v=2.3.0Stripe
apitstatus.com/api.js?v=3.0.2Realex
apitstatus.com/api.js?v=3.0.3PayPal
apitstatus.com/api.js?v=3.0.4 LinkPoint
apitstatus.com/api.js?v=3.0.5 PayPal
apitstatus.com/api.js?v=3.0.7 PayPal
apitstatus.com/api.js?v=3.0.8DataCash
apitstatus.com/api.js?v=3.0.9 PayPal
asianfoodgracer.com/footer.js Authorize.Net
billgetstatus.com/api.js?v=1.2 Authorize.Net
billgetstatus.com/api.js?v=1.3Authorize.Net
billgetstatus.com/api.js?v=1.4 Authorize.Net
billgetstatus.com/api.js?v=1.5Verisign
billgetstatus.com/api.js?v=1.6 Authorize.Net
billgetstatus.com/api.js?v=1.7 Moneris
billgetstatus.com/api.js?v=1.8 Sage Pay
billgetstatus.com/api.js?v=2.0 USAePay
billgetstatus.com/react.jsAuthorize.Net
cloudodesc.com/gtm.js?v=1.2 Authorize.Net
cloudodesc.com/gtm.js?v=1.3ANZ eGate
cloudodesc.com/gtm.js?v=2.3Authorize.Net
cloudodesc.com/gtm.js?v=2.4 Moneris
cloudodesc.com/gtm.js?v=2.6 Sage Pay
cloudodesc.com/gtm.js?v=2.7 Sage Pay
cloudodesc.com/gtm.js?v=2.8 Chase Paymentech
cloudodesc.com/gtm.js?v=2.9Authorize.Net
cloudodesc.com/gtm.js?v=2.91 Adyen
cloudodesc.com/gtm.js?v=2.92 PsiGate
cloudodesc.com/gtm.js?v=2.93CyberSource
cloudodesc.com/gtm.js?v=2.95 ANZ eGate
cloudodesc.com/gtm.js?v=2.97Realex
geisseie.com/gs.js USAePay
gtmproc.com/age.jsAuthorize.Net
gtmproc.com/gtm.js?v=1.2 Authorize.Net
gtmproc.com/gtm.js?v=1.3 ANZ eGate
gtmproc.com/gtm.js?v=1.5PayPal
gtmproc.com/gtm.js?v=1.6 PayPal
gtmproc.com/gtm.js?v=1.7 Realex
livecheckpay.com/api.js?v=2.0 Sage Pay
livecheckpay.com/api.js?v=2.1 PayPal
livecheckpay.com/api.js?v=2.2 Verisign
livecheckpay.com/api.js?v=2.3Authorize.Net
livecheckpay.com/api.js?v=2.4Verisign
livecheckpay.com/react.jsAuthorize.Net
livegetpay.com/pay.js?v=2.1.2 ANZ eGate
livegetpay.com/pay.js?v=2.1.3 PayPal
livegetpay.com/pay.js?v=2.1.5CyberSource
livegetpay.com/pay.js?v=2.1.7 Authorize.Net
livegetpay.com/pay.js?v=2.1.8 Sage Pay
livegetpay.com/pay.js?v=2.1.9 Realex
livegetpay.com/pay.js?v=2.2.0 CyberSource
livegetpay.com/pay.js?v=2.2.1PayPal
livegetpay.com/pay.js?v=2.2.2 PayPal
livegetpay.com/pay.js?v=2.2.3 PayPal
livegetpay.com/pay.js?v=2.2.4 Verisign
livegetpay.com/pay.js?v=2.2.5 eWAY Rapid
livegetpay.com/pay.js?v=2.2.7 Sage Pay
livegetpay.com/pay.js?v=2.2.8 Sage Pay
livegetpay.com/pay.js?v=2.2.9Verisign
livegetpay.com/pay.js?v=2.3.0 Authorize.Net
livegetpay.com/pay.js?v=2.3.1Authorize.Net
livegetpay.com/pay.js?v=2.3.2First Data Global Gateway
livegetpay.com/pay.js?v=2.3.3 Authorize.Net
livegetpay.com/pay.js?v=2.3.4Authorize.Net
livegetpay.com/pay.js?v=2.3.5 Moneris
livegetpay.com/pay.js?v=2.3.6 Authorize.Net
livegetpay.com/pay.js?v=2.3.8 PayPal
livegetpay.com/pay.js?v=2.4.0Verisign
maxstatics.com/site.js USAePay
mediapack.info/track.js?d=funlove.com USAePay
mediapack.info/track.js?d=qbedding.comAuthorize.Net
mediapack.info/track.js?d=vseyewear.com Verisign
mxcounter.com/c.js?v=1.2 PayPal
mxcounter.com/c.js?v=1.3 Authorize.Net
mxcounter.com/c.js?v=1.4 Stripe
mxcounter.com/c.js?v=1.6 Authorize.Net
mxcounter.com/c.js?v=1.7eWAY Rapid
mxcounter.com/c.js?v=1.8 Sage Pay
mxcounter.com/c.js?v=2.0 Authorize.Net
mxcounter.com/c.js?v=2.1Braintree
mxcounter.com/c.js?v=2.10 Braintree
mxcounter.com/c.js?v=2.2 PayPal
mxcounter.com/c.js?v=2.3 Sage Pay
mxcounter.com/c.js?v=2.31 Sage Pay
mxcounter.com/c.js?v=2.32 Authorize.Net
mxcounter.com/c.js?v=2.33PayPal
mxcounter.com/c.js?v=2.34Authorize.Net
mxcounter.com/c.js?v=2.35 Verisign
mxcounter.com/click.js?v=1.2 PayPal
mxcounter.com/click.js?v=1.3 Authorize.Net
mxcounter.com/click.js?v=1.4 Stripe
mxcounter.com/click.js?v=1.6 Authorize.Net
mxcounter.com/click.js?v=1.7 eWAY Rapid
mxcounter.com/click.js?v=1.8Sage Pay
mxcounter.com/click.js?v=2.0Authorize.Net
mxcounter.com/click.js?v=2.1 Braintree
mxcounter.com/click.js?v=2.2PayPal
mxcounter.com/click.js?v=2.3 Sage Pay
mxcounter.com/click.js?v=2.31Sage Pay
mxcounter.com/click.js?v=2.32Authorize.Net
mxcounter.com/click.js?v=2.33PayPal
mxcounter.com/click.js?v=2.34 Authorize.Net
mxcounter.com/click.js?v=2.35 Verisign
mxcounter.com/cnt.jsAuthorize.Net
mxcounter.com/j.jsAuthorize.Net
newrelicnet.com/api.js?v=1.2Authorize.Net
newrelicnet.com/api.js?v=1.4 Authorize.Net
newrelicnet.com/api.js?v=1.8 Sage Pay
newrelicnet.com/api.js?v=4.5 Sage Pay
newrelicnet.com/api.js?v=4.6 Westpac PayWay
nr-public.com/api.js?v=2.0PayFort
nr-public.com/api.js?v=2.1 PayPal
nr-public.com/api.js?v=2.2 Authorize.Net
nr-public.com/api.js?v=2.3Stripe
nr-public.com/api.js?v=2.4First Data Global Gateway
nr-public.com/api.js?v=2.5 PsiGate
nr-public.com/api.js?v=2.6 Authorize.Net
nr-public.com/api.js?v=2.7Authorize.Net
nr-public.com/api.js?v=2.8 Moneris
nr-public.com/api.js?v=2.9 Authorize.Net
nr-public.com/api.js?v=3.1 Sage Pay
nr-public.com/api.js?v=3.2 Verisign
nr-public.com/api.js?v=3.3Moneris
nr-public.com/api.js?v=3.5 PayPal
nr-public.com/api.js?v=3.6 LinkPoint
nr-public.com/api.js?v=3.7Westpac PayWay
nr-public.com/api.js?v=3.8 Authorize.Net
nr-public.com/api.js?v=4.0Moneris
nr-public.com/api.js?v=4.0.2 PayPal
nr-public.com/api.js?v=4.0.3 Adyen
nr-public.com/api.js?v=4.0.4PayPal
nr-public.com/api.js?v=4.0.5Authorize.Net
nr-public.com/api.js?v=4.0.6USAePay
nr-public.com/api.js?v=4.0.7 EBizCharge
nr-public.com/api.js?v=4.0.8 Authorize.Net
nr-public.com/api.js?v=4.0.9 Verisign
nr-public.com/api.js?v=4.1.2 Verisign
ordercheckpays.com/api.js?v=2.11Authorize.Net
ordercheckpays.com/api.js?v=2.12 PayPal
ordercheckpays.com/api.js?v=2.13Moneris
ordercheckpays.com/api.js?v=2.14Authorize.Net
ordercheckpays.com/api.js?v=2.15PayPal
ordercheckpays.com/api.js?v=2.16PayPal
ordercheckpays.com/api.js?v=2.17Westpac PayWay
ordercheckpays.com/api.js?v=2.18 Authorize.Net
ordercheckpays.com/api.js?v=2.19 Authorize.Net
ordercheckpays.com/api.js?v=2.21 Sage Pay
ordercheckpays.com/api.js?v=2.22 Verisign
ordercheckpays.com/api.js?v=2.23Authorize.Net
ordercheckpays.com/api.js?v=2.24 PayPal
ordercheckpays.com/api.js?v=2.25 PayFort
ordercheckpays.com/api.js?v=2.29 CyberSource
ordercheckpays.com/api.js?v=2.4 PayPal Payflow Pro
ordercheckpays.com/api.js?v=2.7Authorize.Net
ordercheckpays.com/api.js?v=2.8 Authorize.Net
ordercheckpays.com/api.js?v=2.9 Verisign
ordercheckpays.com/api.js?v=3.1 Authorize.Net
ordercheckpays.com/api.js?v=3.2 Authorize.Net
ordercheckpays.com/api.js?v=3.3Sage Pay
ordercheckpays.com/api.js?v=3.4 Authorize.Net
ordercheckpays.com/api.js?v=3.5Stripe
ordercheckpays.com/api.js?v=3.6Authorize.Net
ordercheckpays.com/api.js?v=3.7 Authorize.Net
ordercheckpays.com/api.js?v=3.8 Verisign
ordercheckpays.com/api.js?v=3.9PayPal
ordercheckpays.com/api.js?v=4.0 Authorize.Net
ordercheckpays.com/api.js?v=4.1Authorize.Net
ordercheckpays.com/api.js?v=4.2 Sage Pay
ordercheckpays.com/api.js?v=4.3Authorize.Net
reactjsapi.com/api.js?v=0.1.0 Authorize.Net
reactjsapi.com/api.js?v=0.1.1PayPal
reactjsapi.com/api.js?v=4.1.2 Flint
reactjsapi.com/api.js?v=4.1.4PayPal
reactjsapi.com/api.js?v=4.1.5Sage Pay
reactjsapi.com/api.js?v=4.1.51 Verisign
reactjsapi.com/api.js?v=4.1.6Authorize.Net
reactjsapi.com/api.js?v=4.1.7Authorize.Net
reactjsapi.com/api.js?v=4.1.8 Stripe
reactjsapi.com/api.js?v=4.1.9 Fat Zebra
reactjsapi.com/api.js?v=4.2.0Sage Pay
reactjsapi.com/api.js?v=4.2.1 Authorize.Net
reactjsapi.com/api.js?v=4.2.2 First Data Global Gateway
reactjsapi.com/api.js?v=4.2.3 Authorize.Net
reactjsapi.com/api.js?v=4.2.4 eWAY Rapid
reactjsapi.com/api.js?v=4.2.5 Adyen
reactjsapi.com/api.js?v=4.2.7PayPal
reactjsapi.com/api.js?v=4.2.8 QuickBooks Merchant Services
reactjsapi.com/api.js?v=4.2.9Verisign
reactjsapi.com/api.js?v=4.2.91 Sage Pay
reactjsapi.com/api.js?v=4.2.92Verisign
reactjsapi.com/api.js?v=4.2.94Authorize.Net
reactjsapi.com/api.js?v=4.3.97Authorize.Net
reactjsapi.com/api.js?v=4.5Sage Pay
reactjsapi.com/react.jsAuthorize.Net
sydneysalonsupplies.com/gtm.jseWAY Rapid
tagsmediaget.com/react.jsAuthorize.Net
tagstracking.com/tag.js?v=2.1.2ANZ eGate
tagstracking.com/tag.js?v=2.1.3PayPal
tagstracking.com/tag.js?v=2.1.5CyberSource
tagstracking.com/tag.js?v=2.1.7Authorize.Net
tagstracking.com/tag.js?v=2.1.8Sage Pay
tagstracking.com/tag.js?v=2.1.9Realex
tagstracking.com/tag.js?v=2.2.0CyberSource
tagstracking.com/tag.js?v=2.2.1 PayPal
tagstracking.com/tag.js?v=2.2.2PayPal
tagstracking.com/tag.js?v=2.2.3PayPal
tagstracking.com/tag.js?v=2.2.4Verisign
tagstracking.com/tag.js?v=2.2.5eWAY Rapid
tagstracking.com/tag.js?v=2.2.7Sage Pay
tagstracking.com/tag.js?v=2.2.8Sage Pay
tagstracking.com/tag.js?v=2.2.9Verisign
tagstracking.com/tag.js?v=2.3.0Authorize.Net
tagstracking.com/tag.js?v=2.3.1Authorize.Net
tagstracking.com/tag.js?v=2.3.2First Data Global Gateway
tagstracking.com/tag.js?v=2.3.3Authorize.Net
tagstracking.com/tag.js?v=2.3.4Authorize.Net
tagstracking.com/tag.js?v=2.3.5Moneris
tagstracking.com/tag.js?v=2.3.6Authorize.Net
tagstracking.com/tag.js?v=2.3.8PayPal

Password sniffer

One of the advantages of JavaScript sniffers operating on the client side of the website is their versatility: the malicious code embedded on the site can steal data of any kind, whether it is payment information or login and password of a user account. Group-IB experts discovered a sample of a sniffer belonging to the ReactGet family designed to steal email addresses and passwords of website users.

Four JavaScript Sniffers Lurking in Online Stores

Intersection with ImageID sniffer

During the analysis of one of the infected stores, it was found that its website had been infected twice: in addition to the malicious code of the ReactGet family sniffer, code from the ImageID family sniffer was also discovered. This intersection may indicate that the operators behind the use of both sniffers employ similar techniques for injecting malicious code.

Four JavaScript Sniffers Lurking in Online Stores

Universal sniffer

During the analysis of one of the domain names associated with the ReactGet sniffers' infrastructure, it was found that the same user registered three other domain names. These three domains imitated the domains of real existing sites and had previously been used to host sniffers. Analyzing the code of three legitimate sites revealed an unknown sniffer, and further analysis indicated that it was an upgraded version of the ReactGet sniffer. All previously tracked versions of sniffers from this family targeted a specific payment system, meaning a special version of the sniffer was required for each payment system. However, in this case, a universal version of the sniffer was discovered, capable of stealing information from forms related to 15 different payment systems and ecommerce site modules for conducting online payments.

At the beginning of its operation, the sniffer searched for basic form fields containing the victim's personal information: full name, physical address, phone number.

Four JavaScript Sniffers Lurking in Online Stores
The sniffer then searched through more than 15 different prefixes corresponding to various payment systems and modules for online payments.

Four JavaScript Sniffers Lurking in Online Stores
Next, the victim's personal data and payment information were consolidated and sent to a site controlled by the attacker: in this specific case, two versions of the universal ReactGet sniffer were found on two different hacked sites. However, both versions sent the stolen data to the same hacked site. zoobashop.com.

Four JavaScript Sniffers Lurking in Online Stores
Analyzing the prefixes used by the sniffer to search for fields containing the victim's payment information revealed that this sniffer sample targeted the following payment systems:

  • Authorize.Net
  • Verisign
  • First Data
  • USAePay
  • Stripe
  • PayPal
  • ANZ eGate
  • Braintree
  • DataCash (MasterCard)
  • Realex Payments
  • PsiGate
  • Heartland Payment Systems

What tools are used to steal payment information

The first tool discovered during the analysis of the attackers' infrastructure is used to obfuscate malicious scripts responsible for stealing credit card information. A bash script was found on one of the attackers' hosts that utilizes the CLI of the project javascript-obfuscator to automate the obfuscation of sniffer code.

Four JavaScript Sniffers Lurking in Online Stores
The second detected tool is designed to generate code responsible for loading the main sniffer. This tool generates JavaScript code that checks if the user is on the payment page by searching the current user's address for string checkout, cart , and so on. If the result is positive, the code loads the main sniffer from the attacker's server. To conceal malicious activity, all strings, including test strings for identifying the payment page and the link to the sniffer, are encoded using base64.

Four JavaScript Sniffers Lurking in Online Stores

Phishing attacks

During the analysis of the attackers' network infrastructure, it was established that often, to gain access to the administrative panel of the target online store, the criminal group uses phishing. The attackers register a domain visually similar to the store's domain and then deploy a fake login form for the administrative panel of Magento. If successful, the attackers will gain access to the CMS Magento administrative panel, allowing them to edit site components and inject a sniffer to steal credit card data.

Four JavaScript Sniffers Lurking in Online Stores
Infrastructure

DomainDate of discovery/appearance
mediapack.info04.05.2017
adsgetapi.com15.06.2017
simcounter.com14.08.2017
mageanalytics.com22.12.2017
maxstatics.com16.01.2018
reactjsapi.com19.01.2018
mxcounter.com02.02.2018
apitstatus.com01.03.2018
orderracker.com20.04.2018
tagstracking.com25.06.2018
adsapigate.com12.07.2018
trust-tracker.com15.07.2018
fbstatspartner.com02.10.2018
billgetstatus.com12.10.2018
aldenmlilhouse.com20.10.2018
balletbeautlful.com20.10.2018
bargalnjunkie.com20.10.2018
payselector.com21.10.2018
tagsmediaget.com02.11.2018
hs-payments.com16.11.2018
ordercheckpays.com19.11.2018
geisseie.com24.11.2018
gtmproc.com29.11.2018
livegetpay.com18.12.2018
sydneysalonsupplies.com18.12.2018
newrelicnet.com19.12.2018
nr-public.com03.01.2019
cloudodesc.com04.01.2019
ajaxstatic.com11.01.2019
livecheckpay.com21.01.2019
asianfoodgracer.com25.01.2019

G-Analytics Family

This family of sniffers is used to steal customer cards from online stores. The first domain name used by the group was registered in April 2016, which may indicate the start of the group's activity in mid-2016.

In the current campaign, the group is using domain names that imitate real services, such as Google Analytics and jQuery, masking sniffer activity with legitimate scripts and names that resemble legitimate domains. The attacked sites are managed by the CMS Magento.

How G-Analytics is integrated into the online store's code

A distinguishing feature of this family is the use of various methods to steal the user's payment information. In addition to the classic injection of JavaScript code into the client part of the site, the criminal group also employed the technique of injecting code into the server part of the site, namely PHP scripts that process user-entered data. This technique is dangerous because it complicates the detection of malicious code by third-party researchers. Specialists from Group-IB discovered a version of the sniffer injected into the website's PHP code, using the domain dittm.org.

Four JavaScript Sniffers Lurking in Online Stores
An earlier version of the sniffer was also found, using the same domain to collect stolen data dittm.org, but this version was already intended for installation on the client side of the online store.

Four JavaScript Sniffers Lurking in Online Stores
Later, the group changed its tactics and began to focus more on concealing malicious activity and camouflage.

In early 2017, the group started using the domain jquery-js.com, masquerading as a CDN for jQuery: when users visit the attackers' site, they are redirected to a legitimate site jquery.com.

And in mid-2018, the group adopted the domain name g-analytics.com and started disguising the sniffer's activity as a legitimate Google Analytics service.

Four JavaScript Sniffers Lurking in Online Stores
Four JavaScript Sniffers Lurking in Online Stores

Version analysis

During the analysis of the domains used to store the sniffer code, it was found that the site contained a large number of versions that differed in the presence of obfuscation, as well as the presence or absence of unreachable code added to the file to distract attention and conceal malicious code.

A total of six versions of sniffers were identified on the site. jquery-js.com These sniffers send stolen data to an address located on the same site as the sniffer: hxxps://jquery-js[.]com/latest/jquery.min.js:

  • hxxps://jquery-js[.]com/jquery.min.js
  • hxxps://jquery-js[.]com/jquery.2.2.4.min.js
  • hxxps://jquery-js[.]com/jquery.1.8.3.min.js
  • hxxps://jquery-js[.]com/jquery.1.6.4.min.js
  • hxxps://jquery-js[.]com/jquery.1.4.4.min.js
  • hxxps://jquery-js[.]com/jquery.1.12.4.min.js

A later domain g-analytics.com, used by the group in attacks since mid-2018, serves as a repository for a greater number of sniffers. A total of 16 different versions of the sniffer were discovered. In this case, the gate for sending stolen data was disguised as a link to an image in the format of GIF: hxxp://g-analytics[.]com/__utm.gif?v=1&_v=j68&a=98811130&t=pageview&_s=1&sd=24-bit&sr=2560×1440&vp=2145×371&je=0&_u=AACAAEAB~&jid=1841704724&gjid=877686936&cid
=1283183910.1527732071
:

  • hxxps://g-analytics[.]com/libs/1.0.1/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.10/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.11/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.12/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.13/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.14/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.15/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.16/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.3/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.4/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.5/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.6/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.7/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.8/analytics.js
  • hxxps://g-analytics[.]com/libs/1.0.9/analytics.js
  • hxxps://g-analytics[.]com/libs/analytics.js

Monetization of stolen data

The criminal group monetizes the stolen data by selling cards through a specially created underground store that provides services to carders. An analysis of the domains used by the attackers allowed for the identification that google-analytics.cm was registered by the same user as the domain cardz.vc. The domain cardz.vc is associated with the store selling stolen bank cards Cardsurfs (Flysurfs), which gained popularity during the active days of the underground marketplace AlphaBay as a retailer of bank cards stolen via sniffers.

Four JavaScript Sniffers Lurking in Online Stores
Analyzing the domain analytic.is, located on the same server as the domains used by sniffers to collect stolen data, specialists from Group-IB discovered a file containing logs of a cookie stealer that seemingly was later abandoned by the developer. One entry in the log contained the domain iozoz.com, which was previously used in one of the sniffers active in 2016. Presumably, this domain was once used by a malicious actor to collect cards stolen via sniffers. This domain was registered to the email address kts241@gmail.com, which was also used to register the domains cardz.su and cardz.vc, relating to the carding store Cardsurfs.

Based on the obtained data, one can speculate that the G-Analytics family of sniffers and the underground bank card store Cardsurfs are managed by the same individuals, with the store being used for the sale of bank cards stolen via sniffers.

Infrastructure

DomainDate of discovery/appearance
iozoz.com08.04.2016
dittm.org10.09.2016
jquery-js.com02.01.2017
g-analytics.com31.05.2018
google-analytics.is21.11.2018
analytic.to04.12.2018
google-analytics.to06.12.2018
google-analytics.cm28.12.2018
analytic.is28.12.2018
googlc-analytics.cm17.01.2019

Illum Family

Illum is a family of sniffers employed in attacks on online stores running on the Magento CMS. In addition to injecting malicious code, the operators of this sniffer also use full-fledged fake payment forms that send data to the malicious gates under their control.

Upon analyzing the network infrastructure utilized by this sniffer's operators, a significant number of malicious scripts, exploits, fake payment forms, as well as a collection of examples from competing malicious sniffers were noted. Based on the information regarding the registration dates of the domain names used by the group, it can be inferred that the campaign began in late 2016.

How Illum is injected into the online store's code

The first detected versions of the sniffer were injected directly into the code of the compromised site. Stolen data was sent to cdn.illum[.]pw/records.php, with the gate being encoded using base64.

Four JavaScript Sniffers Lurking in Online Stores
Later, a packaged version of the sniffer was found using a different gate — records.nstatistics[.]com/records.php.

Four JavaScript Sniffers Lurking in Online Stores
According to report Willem de Groot, the same host was used in the sniffer that was injected into the store's website, owned by the German political party CSU.

Analysis of the attackers' website

Group-IB specialists discovered and analyzed a website used by this criminal group to store tools and collect stolen information.

Four JavaScript Sniffers Lurking in Online Stores
Among the tools found on the attackers' server were scripts and exploits for privilege escalation in Linux OS: for example, the Linux Privilege Escalation Check Script, developed by Mike Czumak, as well as an exploit for CVE-2009-1185.

Specifically for attacks on online stores, the attackers used two exploits: the first able to inject malicious code into core_config_data by exploiting CVE-2016-4010, the second exploits an RCE vulnerability in plugins for the Magento CMS, allowing arbitrary code execution on the vulnerable web server.

Four JavaScript Sniffers Lurking in Online Stores
Also, during the server analysis, various samples of sniffers and fake payment forms used by the attackers to collect payment information from hacked sites were found. As can be seen from the list below, some scripts were created specifically for each hacked site, while universal solutions were used for certain CMS and payment gateways. For example, scripts segapay_standart.js and segapay_onpage.js are designed for injection into sites using the Sage Pay payment gateway.

List of scripts for various payment gateways

ScriptPayment Gateway
sr.illum[.]pw/mjs_special/visiondirect.co.uk.js//request.payrightnow[.]cf/checkpayment.php
sr.illum[.]pw/mjs_special/topdierenshop.nl.js//request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs_special/tiendalenovo.es.js//request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs_special/pro-bolt.com.js//request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs_special/plae.co.js//request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs_special/ottolenghi.co.uk.js//request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs_special/oldtimecandy.com.js//request.payrightnow[.]cf/checkpayment.php
sr.illum[.]pw/mjs_special/mylook.ee.js//cdn.illum[.]pw/records.php
sr.illum[.]pw/mjs_special/luluandsky.com.js//request.payrightnow[.]cf/checkpayment.php
sr.illum[.]pw/mjs_special/julep.com.js//cdn.illum[.]pw/records.php
sr.illum[.]pw/mjs_special/gymcompany.es.js//request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs_special/grotekadoshop.nl.js//request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs_special/fushi.co.uk.js//request.payrightnow[.]cf/checkpayment.php
sr.illum[.]pw/mjs_special/fareastflora.com.js//request.payrightnow[.]cf/checkpayment.php
sr.illum[.]pw/mjs_special/compuindia.com.js//request.payrightnow[.]cf/alldata.php
sr.illum[.]pw/mjs/segapay_standart.js//cdn.illum[.]pw/records.php
sr.illum[.]pw/mjs/segapay_onpage.js//cdn.illum[.]pw/records.php
sr.illum[.]pw/mjs/replace_standart.js//request.payrightnow[.]cf/checkpayment.php
sr.illum[.]pw/mjs/all_inputs.js//cdn.illum[.]pw/records.php
sr.illum[.]pw/mjs/add_inputs_standart.js//request.payrightnow[.]cf/checkpayment.php
sr.illum[.]pw/magento/payment_standart.js//cdn.illum[.]pw/records.php
sr.illum[.]pw/magento/payment_redirect.js//payrightnow[.]cf/?payment=
sr.illum[.]pw/magento/payment_redcrypt.js//payrightnow[.]cf/?payment=
sr.illum[.]pw/magento/payment_forminsite.js//paymentnow[.]tk/?payment=

Host paymentnow[.]tk, used as a gate in the script payment_forminsite.js, was discovered as subjectAltName in several certificates related to the CloudFlare service. Additionally, the host contained a script evil.js. Judging by the script's name, it could have been used in the exploitation of CVE-2016-4010, which could allow the injection of malicious code into the footer of a site running on the Magento CMS. As a gate, this script applied host request.requestnet[.]tk, using the same certificate as host paymentnow[.]tk.

Fake Payment Forms

Below is an example of a form for entering card details. This form was used for injection into the online store's website to steal card data.

Four JavaScript Sniffers Lurking in Online Stores
The following illustration shows an example of a fake PayPal payment form used by attackers to inject into websites with this payment method.
Four JavaScript Sniffers Lurking in Online Stores
Infrastructure

DomainDate of discovery/appearance
cdn.illum.pw27/11/2016
records.nstatistics.com06/09/2018
request.payrightnow.cf25/05/2018
paymentnow.tk16/07/2017
payment-line.tk01/03/2018
paymentpal.cf04/09/2017
requestnet.tk28/06/2017

CoffeMokko Family

The CoffeMokko family of sniffers, designed to steal users' credit card information from online stores, has been in use at least since May 2017. It is believed that the operators of this sniffer family are a criminal group known as Group 1, described by RiskIQ specialists in 2016. The attacks targeted websites managed by CMS platforms like Magento, OpenCart, WordPress, osCommerce, and Shopify.

How CoffeMokko Injects Into Online Store Code

Operators of this family create unique sniffers for each infection: the sniffer file is located in the directory src or js on the attackers' server. The injection into the website code is done via a direct link to the sniffer.

Four JavaScript Sniffers Lurking in Online Stores
The sniffer's code hard-codes the names of the form fields from which data needs to be stolen. It also checks if the user is on the payment page by comparing a list of keywords with the user's current address.

Four JavaScript Sniffers Lurking in Online Stores
Some detected versions of the sniffer were obfuscated and contained an encrypted string that held the main resource array: this array included the names of form fields for various payment systems, as well as the address of the gateway to which the stolen data needed to be sent.

Four JavaScript Sniffers Lurking in Online Stores
The stolen payment information was sent to a script on the attacker's server via the path /savePayment/index.php или /tr/index.php. It is believed that this script serves to transmit data from the gateway to the main server that consolidates data from all the sniffers. To obscure the transmitted data, all the victim's payment information is encoded using base64, followed by several character replacements:

  • the character 'e' is replaced with ':'
  • the character 'w' is replaced with '+'
  • the character 'o' is replaced with '%'
  • the character 'd' is replaced with '#'
  • the character 'a' is replaced with '-'
  • the character '7' is replaced with '^'
  • the character 'h' is replaced with '_'
  • the character 'T' is replaced with '@'
  • the character '0' is replaced with '/'
  • the character 'Y' is replaced with '*'

As a result of the character replacements, data encoded using base64 cannot be decoded without performing the reverse transformation.

This is how a snippet of unobfuscated sniffer code looks:

Four JavaScript Sniffers Lurking in Online Stores

Infrastructure Analysis

In earlier campaigns, attackers registered domain names that were similar to the domains of legitimate online store websites. Their domain could differ from the legitimate one by just one character or another TLD. These registered domains were used to host sniffer code, which was injected into the store's code.

This group also used domain names resembling the names of popular jQuery plugins (slickjs[.]org for sites using the plugin slick.js), payment gateways (sagecdn[.]org for sites using the Sage Pay payment system).

Later, the group began to create domains whose names had nothing to do with either the store domain or the store's theme.

Four JavaScript Sniffers Lurking in Online Stores
Each domain corresponded to a site where a directory was created /js or /src. This directory stored sniffer scripts: one sniffer for each new infection. The sniffer was injected into the site's code via a direct link, but in rare cases, the attackers modified one of the site files and added malicious code to it.

Code Analysis

First Obfuscation Algorithm

In some detected samples of sniffer from this family, the code was obfuscated and contained encrypted data necessary for the sniffer's operation: in particular, the sniffer gateway address, the list of payment form fields, and in some cases — the code for a fake payment form. In the code within the function, resources were encrypted using XOR with a key passed as an argument to that same function.

Four JavaScript Sniffers Lurking in Online Stores
By decrypting the string with the corresponding key unique to each sample, it is possible to obtain a string containing all the strings from the sniffer's code separated by a delimiter.

Four JavaScript Sniffers Lurking in Online Stores

Second Obfuscation Algorithm

In later samples of sniffer from this family, another obfuscation mechanism was used: in this case, the data was encrypted using a custom-written algorithm. The string containing the encrypted data necessary for the sniffer's operation was passed as an argument to the decryption function.

Four JavaScript Sniffers Lurking in Online Stores
Using the browser console, it is possible to decrypt the encrypted data and obtain an array containing the sniffer's resources.

Four JavaScript Sniffers Lurking in Online Stores

Connection to Early MageCart Attacks

During the analysis of one of the domains used by the group as a gate for collecting stolen data, it was found that this domain had infrastructure set up for credit card theft, identical to that used by Group 1 — one of the first groups, identified by RiskIQ specialists.

On the host of the CoffeMokko sniffer family, two files were discovered:

  • mage.js — a file containing the code of the Group 1 sniffer with the gate address js-cdn.link
  • mag.php — a PHP script responsible for collecting data stolen by the sniffer

Содержимое файла mage.js Four JavaScript Sniffers Lurking in Online Stores
It was also established that the earliest domains used by the group behind the CoffeMokko sniffer family were registered on May 17, 2017:

  • link-js[.]link
  • info-js[.]link
  • track-js[.]link
  • map-js[.]link
  • smart-js[.]link

The format of these domain names matches the domain names used by Group 1 in the attacks of 2016.

Based on the findings, one can speculate that there is a connection between the operators of the CoffeMokko sniffers and the criminal group Group 1. It is presumed that the operators of CoffeMokko may have borrowed tools and software for card theft from their predecessors. However, it is more likely that the criminal group behind the use of the CoffeMokko sniffers consists of the same individuals who carried out attacks as part of Group 1's activities. After the first report on the criminal group's activities was published, all their domain names were blocked, and the tools were thoroughly examined and documented. The group was forced to take a break to revise their internal tools and rewrite the sniffer code to continue their attacks unnoticed.

Infrastructure

DomainDate of discovery/appearance
link-js.link17.05.2017
info-js.link17.05.2017
track-js.link17.05.2017
map-js.link17.05.2017
smart-js.link17.05.2017
adorebeauty.org03.09.2017
security-payment.su03.09.2017
braincdn.org04.09.2017
sagecdn.org04.09.2017
slickjs.org04.09.2017
oakandfort.org10.09.2017
citywlnery.org15.09.2017
dobell.su04.10.2017
childsplayclothing.org31.10.2017
jewsondirect.com05.11.2017
shop-rnib.org15.11.2017
closetlondon.org16.11.2017
misshaus.org28.11.2017
battery-force.org01.12.2017
kik-vape.org01.12.2017
greatfurnituretradingco.org02.12.2017
etradesupply.org04.12.2017
replacemyremote.org04.12.2017
all-about-sneakers.org05.12.2017
mage-checkout.org05.12.2017
nililotan.org07.12.2017
lamoodbighats.net08.12.2017
walletgear.org10.12.2017
dahlie.org12.12.2017
davidsfootwear.org20.12.2017
blackriverimaging.org23.12.2017
exrpesso.org02.01.2018
parks.su09.01.2018
pmtonline.su12.01.2018
ottocap.org15.01.2018
christohperward.org27.01.2018
coffetea.org31.01.2018
energycoffe.org31.01.2018
energytea.org31.01.2018
teacoffe.net31.01.2018
adaptivecss.org01.03.2018
coffemokko.com01.03.2018
londontea.net01.03.2018
ukcoffe.com01.03.2018
labbe.biz20.03.2018
batterynart.com03.04.2018
btosports.net09.04.2018
chicksaddlery.net16.04.2018
paypaypay.org11.05.2018
ar500arnor.com26.05.2018
authorizecdn.com28.05.2018
slickmin.com28.05.2018
bannerbuzz.info03.06.2018
kandypens.net08.06.2018
mylrendyphone.com15.06.2018
freshchat.info01.07.2018
3lift.org02.07.2018
abtasty.net02.07.2018
mechat.info02.07.2018
zoplm.com02.07.2018
zapaljs.com02.09.2018
foodandcot.com15.09.2018
freshdepor.com15.09.2018
swappastore.com15.09.2018
verywellfitnesse.com15.09.2018
elegrina.com18.11.2018
majsurplus.com19.11.2018
top5value.com19.11.2018

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster