{"id":16708,"date":"2019-10-28T10:52:16","date_gmt":"2019-10-28T18:52:16","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/10\/28\/news-10447\/"},"modified":"2019-10-28T10:52:16","modified_gmt":"2019-10-28T18:52:16","slug":"news-10447","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/10\/28\/news-10447\/","title":{"rendered":"VB2019 paper: Inside Magecart: the history behind the covert card-skimming assault on the e-commerce industry"},"content":{"rendered":"<p>Magecart is an umbrella-term for various groups that engage in placing JavaScript code on e-commerce sites to steal credit card info. Magecart attacks go back almost a decade but it became an infosec household name following some prominent breaches in 2018.<\/p>\n<p>Magecart is getting a lot of attention from security researchers, and <em>RiskIQ<\/em>&#8216;s Yonathan Klijnsma is probably the most prolific among them. He was one of the authors of a 2018 <a href=\"https:\/\/www.riskiq.com\/blog\/external-threat-management\/magecart-growing-threat\/\" target=\"_blank\">report <\/a>that detailed the modi operandi of the various Magecart groups.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" style=\"display: block; margin-left: auto; margin-right: auto;\" src=\"https:\/\/www.virusbulletin.com\/files\/cache\/74be1b594787c8156478cce59664dde1_f3852.png\" alt=\"ecosystem_image1.png\" width=\"650\" height=\"330\" \/><span class=\"centered-caption\">A rich underground economy exists around all the different steps needed to monetize a breach.<\/span><\/p>\n<p>At VB2019 in London earlier this month, Yonathan also presented a paper on Magecart in which he looked at some of the more interesting groups and the latest Magecart trends.<\/p>\n<p>Today we publish Yonathan&#8217;s paper in both <a title=\"VB2019 paper: Inside Magecart: the history behind the covert card-skimming assault on the e-Commerce industry\" href=\"https:\/\/www.virusbulletin.com\/virusbulletin\/2019\/10\/vb2019-paper-inside-magecart-history-behind-covert-card-skimming-assault-e-commerce-industry\/\">HTML<\/a> and <a href=\"https:\/\/www.virusbulletin.com\/uploads\/pdf\/magazine\/2019\/VB2019-Klijnsma.pdf\" target=\"_blank\">PDF <\/a>format. We have also uploaded the video of his VB2019 presentation to our <em>YouTube<\/em> channel.<\/p>\n<p>\u00a0<\/p>\n<p>\u00a0<\/p>\n<p style=\"text-align: center;\" width=\"100%\" height=\"420\"><iframe loading=\"lazy\" src=\"https:\/\/www.youtube.com\/embed\/YeAIxAeKSYU\" frameborder=\"0\" width=\"100%\" height=\"420\" style=\"\"> <\/iframe><\/p>\n<p>\u00a0<\/p>\n<p>outertext<br \/><a href=\"https:\/\/www.virusbulletin.com\/blog\/2019\/10\/vb2019-paper-inside-magecart-history-behind-covert-card-skimming-assault-e-commerce-industry\/\" target=\"bwo\" >https:\/\/www.virusbulletin.com\/rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.virusbulletin.com\/files\/cache\/74be1b594787c8156478cce59664dde1_f3852.png\"\/><br \/>                                 Today we publish the VB2019 paper by RiskIQ researcher Yonathan Klijnsma, who looked at the Magecart web-skimming attacks.                <\/p>\n<p>                 <a href=\"https:\/\/www.virusbulletin.com\/blog\/2019\/10\/vb2019-paper-inside-magecart-history-behind-covert-card-skimming-assault-e-commerce-industry\/\">Read more<\/a>                                <\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[23177,10378,23176],"tags":[],"class_list":["post-16708","post","type-post","status-publish","format-standard","hentry","category-magazine","category-security","category-virusbulletin"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=16708"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16708\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=16708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=16708"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=16708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}