Attention online shoppers: beware of Magecart!


Magecart is a cybercrime group that uses online skimming techniques to steal personal data from websites, most commonly customer details and payment information.

The latest iteration, observed by Malwarebytes on a Parisian travel accessory store, involves the injection of a skimmer called Kritec to intercept the checkout process and display a fake payment dialog to victims.

The skimmer is complex and heavily obfuscated, and the threat actors behind the operation are targeting different online stores with custom modals.

Discerning whether an online store is trustworthy has become very difficult.

