Magecart malware merrily sipped card details, evaded security scans on UK e-tailer Páramo for almost 8 months
- Reference: 1589881511
- News link: https://www.theregister.co.uk/2020/05/19/paramo_hack_magecart/
- Source link:
London-based Páramo told customers last week that it had discovered a "small piece of computer code covertly installed within our website".
The warning continued: "This code copied card details entered, destined for PayPal and additionally sent them on to the attacker's server. The data transferred was name, address, card number and CVV code."
The Register confirmed with Páramo that 3,743 people's full card details – including all data points necessary to make online purchases elsewhere – had been stolen between July 2019 and March this year. In its message to customers the retailer said:
This is despite the fact that Páramo employ Security Metrics, an approved security scanning vendor, to conduct quarterly vulnerability scans on our websites for PCI DSS purposes. The coding remained undiscovered due to its sophisticated nature.
Security Metrics did not respond to The Register 's questions.
Páramo's IT director, Jason Martin, told The Register the firm first learnt something was wrong when PayPal, its chosen payments processor, alerted them that 18 customers reported being victims of fraud after making purchases from Páramo. Upon examining the site for any clues, Martin's team discovered all was not as it should have been.
"Specifically, in our case," Martin explained, "the hackers' method used a PHP file which modified out IFRAME src so that it still loaded the PayPal code, but also loaded an external JavaScript file." The JS file, named gcore.js , was externally hosted on an unremarkable third-party URL.
El Reg passed the malicious JS file to a security researcher who asked not to be named. They told us the file was part of the infamous Magecart card skimmer malware and had been observed in the wild since summer 2019, fitting the Páramo hack.
We also asked Cisco Talos to take a look at the malware sample for confirmation. A company spokesman agreed that it looked like Magecart and told us: "Criminals often seek unpatched web systems, or use compromised credentials, in order to take control of a system and subtly introduce malicious functionality that will execute in the browser. In this way, malware such as Magecart is able to capture personal data as web visitors enter it in their browser, exfiltrating it to the criminals without the stolen information necessarily touching the originally compromised system."
Supply chain attacks, where malicious persons target those third-party sources, have [1]long been a thorn in the side of the ecommerce world .
While the Páramo hack is relatively small fry for a jaded cybersecurity industry that barely notices such compromises unless millions of people's data is stolen, many reading this will probably wipe their foreheads and mutter "there but for the grace of the gods".
A couple of years ago Magecart was the attack method that [2]stole 380,000 peoples' card details from British Airways , while the malware [3]continues to evolve as researchers desperately try to halt its spread. ®
[1] https://www.theregister.co.uk/2019/09/19/it_supply_chain_attack/
[2] https://www.theregister.co.uk/2018/09/11/british_airways_website_scripts/
[3] https://www.theregister.co.uk/2019/10/04/magecart/
Re: Wait
A website that only has around 3,500 customers in the space of 8 months probably isn't being updated anywhere near as much as you'd hope.
Re: Wait
It's seems they may of doing the right thing and employing an outside company to check out their systems.
So the question is why didn't they pick it up?
Re: Wait
The issue here appears to be when Paypal is called, so unless the company is doing test orders and clicking Paypal the js is never loaded (Services like Qualys WAS).
If the sourcecode files are scanned, as its offsite the scanner has to scans this external URL (I don't know if there is such an app or service to support this?).
Quarterly
I'm no expert in this, but is a quarterly check normal/adequate for this level of security?
Re: Quarterly
Given that it was operating over 8 months and hence I assume two scans, I'd suggest the frequency wasn't the issue.
To be fair to the scanning company, you need to understand the terms of reference they were engaged on.
I had no idea they had an online shop...
I'd have thought most people buying Paramo clothing would (under normal circumstances) be buying from physical stores. If you're paying their prices, it's nice to know the coat will fit. (Saying that, I doubt they've sold very much at all in the last couple of months, given that it's for use out on the hills....)
Paramo is like marmite... you either love their stuff, or you hate it. For the record, I'm in the "love it" camp, but my wife hates it and prefers Goretex coats. (Paramo optimises breathability of the fabric whilst keeping it waterproof(ish), Goretex optimises the waterproofness whilst making it breathable(ish). Different people want different things in a coat for use when out on the hills - I owned a Goretex waterproof for a while and didn't find it to be much more breathable than a £15 pac-a-mac.
Wait
How did they not notice this?
Websites which collect card data (my own incl) deploy many security methods to ensure precisely this does not happen.
One of the many methods that we (and most others) use is an Intrusion Detection System (In my case, as a small business owner, Tripwire on Linux), this monitors for filesytem changes, including monitoring the websites files.
This means, if a PHP file is edited, via an exploit or other hack then that file will immediately flag up on the IDS.
This hack absolutely should have been spotted immediately on their IDS, how did they miss this for so long?