• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
ongoing xurum attacks on e commerce sites exploiting critical magento 2

Ongoing Xurum Attacks on E-commerce Sites Exploiting Critical Magento 2 Vulnerability

You are here: Home / General Cyber Security News / Ongoing Xurum Attacks on E-commerce Sites Exploiting Critical Magento 2 Vulnerability
August 14, 2023

E-commerce sites using Adobe’s Magento 2 computer software are the focus on of an ongoing campaign that has been lively because at minimum January 2023.

The attacks, dubbed Xurum by Akamai, leverage a now-patched critical security flaw (CVE-2022-24086, CVSS score: 9.8) in Adobe Commerce and Magento Open up Source that, if successfully exploited, could lead to arbitrary code execution.

“The attacker appears to be to be intrigued in payment stats from the orders in the victim’s Magento retail outlet placed in the earlier 10 times,” Akamai scientists reported in an examination revealed last week, attributing the marketing campaign to actors of Russian origin.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Some of the sites have also been noticed to be infected with easy JavaScript-based skimmers that’s built to obtain credit score card information and facts and transmit it to a distant server. The actual scale of the marketing campaign continues to be unclear.

Cybersecurity

In the attack chains noticed by the company, CVE-2022-24086 is weaponized for first accessibility, subsequently exploiting the foothold to execute malicious PHP code that gathers information and facts about the host and drops a web shell named wso-ng that masquerades as a Google Browsing Advertisements component.

Not only is the web shell backdoor run in memory, it also activated only when the attacker sends the cookie “magemojo000” in the HTTP request, following which facts about the profits buy payment approaches in the previous 10 days is accessed and exfiltrated.

The attacks culminate with the development of a rogue admin person with the name “mageworx” (or “mageplaza”) in what seems to be a deliberate try to camouflage their steps as benign, for the two monikers refer to common Magento 2 extension shops.

wso-ng is stated to be an evolution of the WSO web shell, incorporating a new concealed login webpage to steal qualifications entered by victims. It even more integrates with legit equipment like VirusTotal and SecurityTrails to glean the contaminated machine’s IP reputation and get aspects about other domains hosted on the similar server.

Cybersecurity

On the internet buying web-sites have been focused for many years by a class of attacks known as Magecart in which skimmer code is inserted into checkout internet pages with the goal of harvesting payment knowledge entered by victims.

“The attackers have demonstrated a meticulous solution, targeting precise Magento 2 occasions rather than indiscriminately spraying their exploits across the internet,” the researchers reported.

“They reveal a higher stage of experience in Magento and commit sizeable time in being familiar with its internals, location up attack infrastructure, and testing their exploits on real targets.”

Discovered this post appealing? Comply with us on Twitter  and LinkedIn to browse much more exclusive content we write-up.


Some components of this post are sourced from:
thehackernews.com

Previous Post: «identity threat detection and response: rips in your identity fabric Identity Threat Detection and Response: Rips in Your Identity Fabric
Next Post: QwixxRAT: New Remote Access Trojan Emerges via Telegram and Discord qwixxrat: new remote access trojan emerges via telegram and discord»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.