Cyber Actors Scrape Credit Card Data from US Business' Online Checkout Page and Maintain Persistence by Injecting Malicious PHP Code
released on 2022-05-18 @ 02:13:04 PM
As of January 2022, unidentified cyber actors unlawfully scraped credit card data from a US
business by injecting malicious PHP Hypertext Preprocessor (PHP) code into the business’ online
checkout page and sending the scraped data to an actor-controlled server that spoofed a
legitimate card processing server. The unidentified cyber actors also established backdoor
access to the victim’s system by modifying two files within the checkout page. The FBI has
identified and is sharing new indicators of compromise (IOCs), which may assist in network
defense.