Friday, June 26, 2020

Crooks Hiding Web Skimmers In Image Files

Imagine if criminals put this much effort into getting a real job.

We found skimming code hidden within the metadata of an image file (a form of steganography) and surreptitiously loaded by compromised online stores. This scheme would not be complete without yet another interesting variation to exfiltrate stolen credit card data. Once again, criminals used the disguise of an image file to collect their loot.