Malicious DLL targets e-commerce sites for customer credit card data

By
Follow google news

The malware, dubbed "ISN," is masked as a module for Microsoft Internet Information Services web-hosting software.

E-commerce website operators should be vigilant of malware that targets servers in order to pilfer credit card data site customers fill out, a security firm warns.

Malicious DLL targets e-commerce sites for customer credit card data

In addition to stealing sensitive data, the malicious DLL (dynamic link library), dubbed “ISN,” is masked as a module for Microsoft Internet Information Services (IIS) web-hosting software, researchers on Trustwave's SpiderLabs team found.

John Miller, a security research manager at Trustwave, told SCMagazine.com on Wednesday that saboteurs “broke into the web servers” of victims in a few, limited instances and installed ISN. The malware was named as such because of character strings that showed up in all of the malware's exfiltration commands.

Miller said that ISN steals data by capturing POST requests, which are sent while submitting form data on sites.

“Anytime you are filling out a form in your browser, it captures [the data] on the server side,” Miller said. “We've only seen it going after credit card numbers currently, but it could go after any information you submit on a website.”

Since Trustwave published a blog post about the threat on Monday, more antivirus software has begun detecting the malware, Miller said.

According to researchers, the installer component of the malware has four embedded DLLs, which are used at discretion. The DLL installed depends on which Microsoft software the target runs – IIS6 or IIS7+ (in 32- and 64-bit versions for both).

This article originally appeared at scmagazineus.com

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:

Most Read Articles

ASD warns of Australian attacks on N-able N-central RMM

ASD warns of Australian attacks on N-able N-central RMM

How a Texas student blew the whistle on a rogue AI hacking attempt

How a Texas student blew the whistle on a rogue AI hacking attempt

Researchers chain Tesla charger bug into a four-vendor EV worm

Researchers chain Tesla charger bug into a four-vendor EV worm

ASD warns Australian TeamCity servers under attack

ASD warns Australian TeamCity servers under attack

Log In

  |  Forgot your password?