A new malware has been spotted by security firm Malwarebytes, which is making rounds in the e-commerce space.
Primarily written in Golang version 1.9, this unnamed malware relied on brute-forcing to exploit shopping websites. In its analysis, the firm mentioned that sites mostly managed by Magento were affected. Malicious code injected into these sites to compromise user information.
Worth noting
Why it matters?
“Brute force attacks can be quite slow given the number of possible password combinations. For this reason, criminals usually leverage CMS or plugin vulnerabilities instead, as they provide a much faster return on investment. Having said that, using a botnet to perform login attempts allows threat actors to distribute the load onto a large number of workers,” said Jerome Segura, the researcher behind the malware’s analysis.
Therefore, it is suggested that site owners relying on content management systems (CMS) such as Magento, keep their sites updated with the latest security patches.
Publisher