Original Release Date: 11/25/2020
As the holiday shopping season approaches with Black Friday and Cyber Monday, researchers from RiskIQ discovered a new variant of the Grelos skimmer, featuring a loader stage and skimmer stage to steal payment card data from e-commerce websites. The Grelos skimmer, similar to Magecart attacks, overlaps in infrastructure used to host different skimmers. In addition, a unique cookie was identified and connected to multiple skimming domains and several victim domains, which is uncommon.
The NJCCIC recommends website administrators block access to sensitive information entered into web forms and stored cookies. We also advise users to make purchases with credit cards when shopping online as they often have better consumer fraud protections than debit cards. For more technical details and IOCs, please review the RiskIQ article.