HT TECH wants to start sending you push notifications. Click allow to subscribe

CERT-In issues warning about a credit card skimming campaign that is targeting e-commerce websites

These skimmer codes that are being injected to JavaScript libraries are designed to steal not just credit card information, but also passwords.

By: HT TECH
Updated on: Aug 20 2022, 22:01 IST
CERT-In explained in an official post that hackers are targeting websites that are hosted on Microsoft’s IIS server that is running on the ASP.NET web application framework. (Pixabay)

The Indian Computer Emergency Response Team (CERT-In) has issued a public warning about a credit card skimming campaign that is targeting sports, health and e-commerce websites. CERT-In explained in an official post that hackers are targeting websites that are hosted on Microsoft’s IIS server that is running on the ASP.NET web application framework.

The problem that these attackers are exploiting lies with version 4.0.30319 of ASP.NET which is no longer officially supported by Microsoft and contains a host of vulnerabilities which makes it easy for hackers to break in.

You may be interested in

Mobiles Tablets Laptops
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹156,900
Check details
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹107,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
41% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹52,990₹89,999
Buy now
41% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹34,490₹57,999
Buy now
40% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,350₹51,990
Buy now
35% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹25,999₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,668₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹16,998
Check details

In the advisory, CERT-In has asked these websites using ASP.NET web framework and IIS server to update to the latest version and conduct audits of web application, server and database server. CERT-In has also asked these sites to check web server directories regularly to keep an eye out for malicious web shell files and make sure they are removed before they can be exploited.

CERT-In referred to a recent Malwarebytes Labs report that discovered a known vulnerability, CVE-2017-9248, for ASP.NET that has been exploited recently to steal credit card details. Researchers at Malwarebytes Labs found over a dozen sites that have been compromised with malicious code injected into legitimate JavaScript libraries.

ASP.NET is a web application framework widely used by websites running shopping cart applications. The compromised websites found by Malwarebytes Labs all had a shopping cart feature that was exploited.

These skimmer codes that are being injected to JavaScript libraries are designed to steal not just credit card information, but also passwords. Malwarebytes Labs pointed out that this skimming campaign started sometime in April this year when online transactions and payments were at high thanks to Covid-19 lockdowns.

While CERT-IN's warning was specific to websites that were using the outdated web server framework, another instance of attackers using malware to target mobile apps to steal card details has also been spotted this year.

A cybersecurity firm called ThreatFabric recently detected a new malware called BlackRock which has targeted over 337 Android apps and is still rampant.

BlackRock uses overlays and keylogger functionality over legitimate apps to steal credit card details and get access to the apps.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 18 Jul, 18:20 IST
Tags:

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
10% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹80,990₹89,900
Buy now
38% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹24,999₹39,999
Buy now
38% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹34,000
Buy now
38% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹28,999
Buy now
25% OFF
Samsung Galaxy Tab A7 Lite
  • Silver
  • 3 GB RAM
  • 32 GB Storage
₹9,529₹12,700
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
44% OFF
HP ZBook Firefly 14 G9 7M3U0PA Laptop
  • Nouvelle Silver
  • 16 GB RAM
  • 1 TB SSD
₹79,990₹142,659
Buy now
39% OFF
HP ZBook Firefly 14 G9 7M3T2PA Laptop
  • Nouvelle Silver
  • 16 GB RAM
  • 1 TB SSD
₹98,900₹162,500
Buy now
9% OFF
Asus Vivobook K15 OLED K513EA L512TS Laptop
  • Indie Black
  • 16 GB RAM
  • 512 GB SSD
₹41,999₹45,999
Buy now
NEXT ARTICLE BEGINS