{"id":21034,"date":"2021-04-17T14:11:09","date_gmt":"2021-04-17T08:41:09","guid":{"rendered":"https:\/\/valeurbit.com\/blog\/?p=21034"},"modified":"2021-04-17T14:11:11","modified_gmt":"2021-04-17T08:41:11","slug":"visa-hackers-began-to-install-web-shells-more-often-to-steal-card-data","status":"publish","type":"post","link":"https:\/\/valeurbit.com\/blog\/visa-hackers-began-to-install-web-shells-more-often-to-steal-card-data\/","title":{"rendered":"VISA: Hackers began to install web shells more often to steal card data"},"content":{"rendered":"\n<p>The international payment system VISA warns of the activity of cyber criminals installing web shells on compromised servers. The aim of the cyber criminals is to extract the data of bank cards belonging to users of online stores. <\/p>\n\n\n\n<p>As a rule, web shells are understood as some kind of script or software, with the help of which criminals gain access to compromised servers, and later execute code remotely, move around the network and deliver additional malware. <\/p>\n\n\n\n<p>VISA analysts have been monitoring this activity throughout the past year and have come to the conclusion that the latter have begun to more often inject JavaScript code into the pages of online stores. <\/p>\n\n\n\n<p>Such scripts are commonly called web skimmers. If cyber criminals successfully implement a web skimmer, they will be able to intercept the payment information entered by the buyer, as well as extract the personal data of the visitor.<\/p>\n\n\n\n<p> \u201cIn 2020, the Visa Payment Fraud Disruption (PFD) team was able to detect many web skimmer attacks in which criminals used web shells and command servers (C2). <\/p>\n\n\n\n<p>The PFD has reported at least 45 cyber attacks, leading to the conclusion that the threat of web shells is growing, \u201dsaid VISA (reported by Bleeping Computer ). <\/p>\n\n\n\n<p>At the same time, the researchers emphasized that the attackers used different methods to hack the servers of online stores. <\/p>\n\n\n\n<p>Vulnerabilities in applications and website plugins, as well as unpatched or outdated versions of e-commerce platforms, were the most common targets for criminals.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The international payment system VISA warns of the activity of cyber criminals installing web shells on compromised servers. The aim of the cyber criminals is to extract the data of bank cards belonging to users of online stores. As a rule, web shells are understood as some kind of script or software, with the help&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v16.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>VISA: Hackers began to install web shells more often to steal card data | ValeurBit Infosec<\/title>\n<meta name=\"description\" content=\"The international payment system VISA warns of the activity of cyber criminals installing web shells on compromised servers. The aim of the\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/valeurbit.com\/blog\/visa-hackers-began-to-install-web-shells-more-often-to-steal-card-data\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"VISA: Hackers began to install web shells more often to steal card data | ValeurBit Infosec\" \/>\n<meta property=\"og:description\" content=\"The international payment system VISA warns of the activity of cyber criminals installing web shells on compromised servers. The aim of the\" \/>\n<meta property=\"og:url\" content=\"https:\/\/valeurbit.com\/blog\/visa-hackers-began-to-install-web-shells-more-often-to-steal-card-data\/\" \/>\n<meta property=\"og:site_name\" content=\"ValeurBit Infosec\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/valeurbitinfo\/\" \/>\n<meta property=\"article:published_time\" content=\"2021-04-17T08:41:09+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-04-17T08:41:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/valeurbit.com\/blog\/wp-content\/uploads\/2021\/04\/Valeurbit-Infosec-1-7.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1080\" \/>\n\t<meta property=\"og:image:height\" content=\"611\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@valeurbit\" \/>\n<meta name=\"twitter:site\" content=\"@valeurbit\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/valeurbit.com\/blog\/#organization\",\"name\":\"Valeurbit Infosec\",\"url\":\"https:\/\/valeurbit.com\/blog\/\",\"sameAs\":[\"https:\/\/www.facebook.com\/valeurbitinfo\/\",\"https:\/\/www.instagram.com\/valeurbit\",\"https:\/\/www.linkedin.com\/company\/valeurbit-infosec\/\",\"https:\/\/twitter.com\/valeurbit\"],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/valeurbit.com\/blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/valeurbit.com\/blog\/wp-content\/uploads\/2021\/02\/Valeurbit-new-logo-center.png\",\"contentUrl\":\"https:\/\/valeurbit.com\/blog\/wp-content\/uploads\/2021\/02\/Valeurbit-new-logo-center.png\",\"width\":1080,\"height\":512,\"caption\":\"Valeurbit Infosec\"},\"image\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/valeurbit.com\/blog\/#website\",\"url\":\"https:\/\/valeurbit.com\/blog\/\",\"name\":\"ValeurBit Infosec\",\"description\":\"Cyber Security Company\",\"publisher\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/valeurbit.com\/blog\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/valeurbit.com\/blog\/visa-hackers-began-to-install-web-shells-more-often-to-steal-card-data\/#webpage\",\"url\":\"https:\/\/valeurbit.com\/blog\/visa-hackers-began-to-install-web-shells-more-often-to-steal-card-data\/\",\"name\":\"VISA: Hackers began to install web shells more often to steal card data | ValeurBit Infosec\",\"isPartOf\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/#website\"},\"datePublished\":\"2021-04-17T08:41:09+00:00\",\"dateModified\":\"2021-04-17T08:41:11+00:00\",\"description\":\"The international payment system VISA warns of the activity of cyber criminals installing web shells on compromised servers. The aim of the\",\"breadcrumb\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/visa-hackers-began-to-install-web-shells-more-often-to-steal-card-data\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/valeurbit.com\/blog\/visa-hackers-began-to-install-web-shells-more-often-to-steal-card-data\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/valeurbit.com\/blog\/visa-hackers-began-to-install-web-shells-more-often-to-steal-card-data\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/valeurbit.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"VISA: Hackers began to install web shells more often to steal card data\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/valeurbit.com\/blog\/visa-hackers-began-to-install-web-shells-more-often-to-steal-card-data\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/visa-hackers-began-to-install-web-shells-more-often-to-steal-card-data\/#webpage\"},\"author\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/#\/schema\/person\/df20c1cd317765fa8677a3056caeccfa\"},\"headline\":\"VISA: Hackers began to install web shells more often to steal card data\",\"datePublished\":\"2021-04-17T08:41:09+00:00\",\"dateModified\":\"2021-04-17T08:41:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/visa-hackers-began-to-install-web-shells-more-often-to-steal-card-data\/#webpage\"},\"wordCount\":256,\"publisher\":{\"@id\":\"https:\/\/valeurbit.com\/blog\/#organization\"},\"articleSection\":[\"Valeurbit\"],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/valeurbit.com\/blog\/#\/schema\/person\/df20c1cd317765fa8677a3056caeccfa\",\"name\":\"ValeurBit\",\"sameAs\":[\"https:\/\/valeurbit.com\/blog\"],\"url\":\"https:\/\/valeurbit.com\/blog\/author\/valeurbit\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/posts\/21034"}],"collection":[{"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/comments?post=21034"}],"version-history":[{"count":0,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/posts\/21034\/revisions"}],"wp:attachment":[{"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/media?parent=21034"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/categories?post=21034"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/valeurbit.com\/blog\/wp-json\/wp\/v2\/tags?post=21034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}