Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cybersecurity
    • Cybersecurity

    Newegg Is Latest Retailer to Be a Victim of Magecart Malware

    Written by

    Sean Michael Kerner
    Published September 20, 2018
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Online retailers have increasingly come under attack in 2018 from a hacking group known as Magecart. The latest victim is allegedly online computer parts retailer Newegg, which admitted on Sept. 19 that it was breached.

      Volexity Threat Research working in collaboration with RiskIQ identified the attack on Newegg. According to the two research groups, Newegg may have been breached for over a month, with attacks beginning on approximately Aug. 14. The research groups noted that the malicious code was removed from the Newegg site on Sept. 18.

      “Yesterday we learned one of our servers had been injected with malware which was identified and removed from our site,” Newegg wrote in a Twitter message. “We’re conducting extensive research to determine exactly what info was obtained and are sending emails to customers potentially impacted.”

      Magecart has been implicated in multiple high-profile attacks in recent months, including ones on British Airways on Sept. 7 and Ticketmaster on June 27. 

      Volexity reported that the Magecart attackers were able to inject a few lines of malicious JavaScript code onto a webpage that is shown to consumers during the Newegg checkout process. “The malicious code specifically appeared once when moving to the Billing Information page while checking out,” Volexity researchers wrote in a blog post. This page, located at the URL https://secure.newegg.com/GlobalShopping/CheckoutStep2.aspx, would collect form data, siphoning it back to the attackers over SSL/TLS via the domain neweggstats.com.”

      Attackers registered the neweggstats.com domain on Aug. 13, with an SSL/TLS certificate created for the site at the same time. According to Yonathan Klijnsma, threat researcher at RiskIQ, the Magecart attackers registered the domain in an attempt to blend in with Newegg’s primary domain.

      “Similar to the British Airways attack, these actors acquired a certificate issued for the domain by Comodo to lend an air of legitimacy to their page,” Klijnsma wrote in a blog post.

      Newegg has not publicly stated how many customers have been impacted by the data breach. The company has sent out a letter to customers, noting that it plans on publishing a complete set of details in an FAQ page by Sept. 21. In Klijnsma’s view, given that Newegg’s site gets approximately 50 million visitors a month and that the Magecart skimmer was active for a month, there could be a “massive” number of victims.

      Industry Reaction

      According to Craig Young, computer security researcher for Tripwire’s VERT (Vulnerability and Exposure Research Team), the Newegg breach is an example of how Certificate Transparency (CT) logs can be a useful source for threat intelligence. With CT logs, SSL/TLS certificates are logged and presented to the public, enabling organizations to identify any misissuance. There are multiple freely available tools for checking CT logs, including the Certificate Transparency Monitoring tool from social media giant Facebook.

      “In this case, the attack campaign started with the attackers setting up an HTTPS server at neweggstats.com,” Young wrote in an email to eWEEK. “For Newegg, seeing this domain come online wouldn’t immediately indicate a breach, but it should be enough for a security team to investigate further and likely reveal the newly added references to this domain in their checkout code.”

      There are several things that consumers can do to help protect themselves from being a victim of a Magecart-related attack. Leigh-Anne Galloway, cyber-security resilience lead at Positive Technologies, commented in an email to eWEEK that consumers can use the NoScript browser extension to block potentially malicious JavaScript from running. She also recommends that banks make use of 3-D Secure technology, which is a protocol-based approach that requires additional confirmation when paying.

      “It’s also a good practice to connect SMS notification service so that if you see the notification of a suspicious operation, you can immediately block the card in order to avoid further fraudulent operations,” she said.

      Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

      Sean Michael Kerner
      Sean Michael Kerner
      Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×