Source Defense researchers have discovered a Magecart digital skimming campaign that uses Ethereum smart contracts as command-and-control infrastructure. By storing routing information inside smart contracts rather than hardcoded domains, attackers can dynamically rotate infrastructure and evade takedown efforts. The campaign involves over 15 Ethereum smart contracts, multiple infrastructure clusters, and dozens of domains. The malware hijacks e-commerce checkout flows, clones payment elements, and harvests card data and personal information. Researchers warn that blockchain-based C2 makes disruption significantly harder, and that PCI DSS 4.0 compliance gaps and under-prioritized client-side security leave many organizations exposed.

3m read timeFrom securityboulevard.com
Post cover image
361 Impressions