North Korean hackers linked to Magecart attack spree
North Korean hackers with ties to Lazarus Group have pivoted to skimming online shopping platforms in recent months, following in the footsteps of the Magecart hacking collective.
Security researchers have found links between recent global skimming activity and previously documented North Korean hacking operations, particularly cyber criminals linked with the group known as Lazarus, or HIDDEN COBRA.
The infrastructure used by Lazarus Group operations has been reused for Magecart-like attacks, with distinctive patterns in the malware code identified, linking multiple hacks to the same group, according to a report published by Sansec. Digital skimming activity is the interception of credit cards during online purchases and was a practice traditionally dominated by Russian and Indonesian cyber criminals. This is no longer the case, however, with North Korean hackers ramping up activity in this space aggressively since May 2019.