Here's how to defend your enterprise from Magecart
Full article590 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
With the body of forensic evidence tied to Magecart growing, researchers have released recommendations for defending against the group.
Magecart, a broad set of hackers that steal online payment data, has been rampant in recent months. The group has allegedly breached popular websites like those of British Airways and Ticketmaster UK by injecting malicious scripts directly or through third-parties to siphon off customer data en masse.
With the body of forensic evidence tied to Magecart growing, researchers with analytics company Securonix have released recommendations for defending against the groups. The goal is keep online vendors from being Magecart’s next high-profile scalp.
The threat data can “increase the chances of early detection of this, and potentially other future variants of the Magecart malicious threat actor activity on your network,” Securonix’s Oleg Kolesnikov and Harshvardhan Parashar wrote in a research paper.
There are at least three data channels that organizations need to monitor to boost their chances of detecting Magecart, according to Kolesnikov and Parashar: web server content and file integrity, along with SSL/TLS proxy logs and endpoint logs. The first category of monitoring can sniff out supply-chain attacks and Magecart’s attempts to install malicious scripts on servers; the latter two categories can pinpoint that script activity within a browser, they said.
At least some of the JavaScript implants used by Magecart need to bypass a target website’s same-origin policy (SOP), a security mechanism for allowing scripts on one webpage to access data on another. The researchers therefore advise network defenders to prevent the use of proxies that uniformly enable “cross-origin resource sharing,” which allows requests for webpage data to be made from one domain to another. In bypassing the SOP, Magecart hackers often use servers they control to extract the stolen personally identifiable information, according to the research.
In the case of the Tickmaster UK breach disclosed in June, the entertainment vendor said it was breached via a third-party customer service application. Given Magecart’s past use of supply-chain software as an attack spear, Kolesnikov and Parashar cautioned organizations to closely review third-party components used by their websites.
“Consider using in-house script mirroring instead of loading the script directly from the third party so that any malicious modification of the script at the third party doesn’t affect the code hosted on the website,” they wrote.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/magecart-securonix-how-to-defend/