• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar

virusword.com

Learn Wordpress

  • Home
  • WordPress Shop
    • Fotopress
    • SEO Tool Kit
    • Social Contact
    • Tag Machine 2
    • Video Profits
  • Latest News
  • WordPress
    • Plugins
    • Themes
    • Tutorials
    • Videos
    • Woocommerce
  • About Us
  • Contact Us
    • Terms of Service
    • Privacy Policy
  • Show Search
Hide Search
Home/Plugins/New Caesar Cipher Card Skimmer Lurks in WordPress and More

New Caesar Cipher Card Skimmer Lurks in WordPress and More

Payment Card Held in Hand
  • A new credit card skimming threat with increased activity affects several popular CMS platforms. 
  • Caesar Cipher Skimmer infects the checkout pages of WordPress, Magento, and OpenCart.
  • The actors use a clever obfuscation method to prevent their payload from being detected.

A new variation of the “gtag” credit card skimming attack impacted almost 80 sites in the first two weeks after its discovery, a new Sucuri report says. Called Caesar Cipher Skimmer, this new malware was deployed to several different CMS platforms, infecting WordPress, Magento, and OpenCart. 

The security researchers and analysts focused on a case where the card information stealer infected the WordPress WooCommerce plugin, triggering their antivirus program on their computer while on the website’s checkout page due to the suspicious code injected in the ‘form-checkout.php’ script.

Skimming Malware WordPress

Skimming Malware WordPress
Image Source: Succuri

Lately, the injections have changed to look less suspicious than a long obfuscated script. They pretend to be simultaneously the Google Analytics and Google Tag Manager plugins, using String.fromCharCode to obfuscate their code. 

The malware uses techniques like splitting the string into individual characters, reversing the character order, subtracting by three and converting back the character code of each character’s Unicode value, and joining the characters back into a string to hide its payload – essentially using a Caesar Cipher on the Unicode values rather than letters.

Infected WordPress Plugin Code

Infected WordPress Plugin Code
Image Source: Succuri

The scripts load an extra layer that creates a WebSocket to a URL and connects to a remote server that sends another layer of the skimmer. This second layer sometimes checks if a logged-in WordPress user loads it and sends a customized response for each infected site. Older versions of the second layer contain code in Russian.

In some cases, the attackers also leveraged the ‘Insert Headers and Footers WPCode’ plugin to inject the malware into the website database, which other malicious actors have employed to add server-side redirects within website code.

Credit card skimming JavaScript is often found in the ‘core_config_data’ database table on Magento websites, which stores custom code inserted into the Magento admin.

Source link

Written by:
Abdul Wahid
Published on:
June 21, 2024

Categories: Plugins

Primary Sidebar

Wordpress

  • Content Management Systems (2)
  • Digital Marketing (4)
  • Internet Marketing (6)
  • Latest News (458)
  • Online Business (2)
  • Plugins (519)
  • Themes (521)
  • Videos (1,350)
  • Website Development (1)
  • Woocommerce (589)
  • WordPress (6)

Recent Articles

Unlock Your Internet Marketing Success with WordPress: The Ultimate CMS for Achieving Online Goals

WordPress: A Powerhouse for Achieving Internet …

Continue Reading about Unlock Your Internet Marketing Success with WordPress: The Ultimate CMS for Achieving Online Goals

Unlock Your Internet Marketing Potential with WordPress: A Comprehensive Guide

How to Use WordPress to Achieve Your Internet …

Continue Reading about Unlock Your Internet Marketing Potential with WordPress: A Comprehensive Guide

Search our site

Explore more

Get our Wordpress Guide Get Plugins Get Connected

Footer

VirusWord by Promaps, Inc.

Barnes Place
Colombo 7, Western 00700

Copyright © 2025 · Promaps, Inc.

Keep In Touch

  • Email
  • Facebook
  • Instagram
  • Pinterest
  • Twitter