Threat actors leveraged a cloud video hosting service to carry out a supply chain attack on more than 100 real estate websites operated by Sotheby’s Realty that involved injecting malicious skimmers to steal sensitive personal information.
“The attacker altered the static script at its hosted location by attaching skimmer code. Upon the next player update, the video platform re-ingested the compromised file and served it along with the impacted player,” the researchers said, adding it worked with the video service and the real estate company to help remove the malware.
The campaign is said to have begun as early as January 2021, according to MalwareBytes, with the harvested information — names, emails, phone numbers, credit card data — exfiltrated to a remote server “cdn-imgcloud[.]com” that also functioned as a collection domain for a Magecart attack targeting Amazon CloudFront CDN in June 2019.
To detect and prevent injection of malicious code into online sites, it’s recommended to conduct web content integrity checks on a periodic basis, not to mention safeguard accounts from takeover attempts and watch out for potential social engineering schemes.
“The skimmer itself is highly polymorphic, elusive and continuously evolving,” the researchers said. “When combined with cloud distribution platforms, the impact of a skimmer of this type could be very large.”