Formjacking

Malware Profile Updated a month ago
Download STIX
Preview STIX
Formjacking is a type of malware that hackers use to exploit vulnerabilities in third-party services and connections within an application's infrastructure. As server-side security continues to improve, cybercriminals are seeking new entry points, leading to the rise of formjacking. This malicious technique involves infecting web forms via third-party providers, allowing hackers to steal sensitive user information such as ID numbers, addresses, or credit card details. The method has seen a significant increase in popularity among hackers, with one report noting a 78% surge in this type of attack. In fact, two-thirds of companies have experienced a supply chain attack, often initiated through formjacking. Several significant formjacking attacks have occurred over the past few years. In 2018, hackers used formjacking to steal payment card data from 380,000 British Airways customers by embedding malicious scripts on the baggage claim information page of the airline’s website. These scripts collected data from visitors and relayed it back to the hackers' server. More recently, in January 2023, a massive formjacking attack compromised one of Canada's largest beverage retailers, highlighting the ongoing threat posed by this type of cybercrime. Despite organizations' best efforts to protect their application environments and customers' personal data, traditional Web Application Firewalls (WAFs) often prove inadequate against formjacking. However, emerging technologies like real-user behavioral detection offer a promising defense. This technology protects websites from JavaScript threats, including web skimming, formjacking, and Magecart attacks. Nevertheless, the escalating sophistication of these attacks underscores the need for continuous innovation in cybersecurity measures.
What's your take? (Question 1 of 4)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
JavaScript
At
Banking
Phishing
Associated Malware
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
MagecartUnspecified
1
Magecart is a consortium of malicious hacker groups known for their attacks on online shopping cart systems, specifically the Magento system, with the intent to steal customer payment card information. This malware, short for malicious software, can infiltrate systems through suspicious downloads, e
Associated Threat Actors
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Associated Vulnerabilities
To see the evidence that has resulted in this association, create a free account
IDTypeVotesProfile Description
No associations to display
Source Document References
Information about the Formjacking Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
SourceCreatedAtTitle
DARKReading
a month ago
Polyfill.io Supply Chain Attack Smacks Down 100K+ Websites
CERT-EU
6 months ago
The costs of cybercrime: $45 billion - Panda Security Mediacenter
CERT-EU
a year ago
Akamai Vs. Cloudflare WAF
CERT-EU
10 months ago
The application supply chain exposed
CERT-EU
7 months ago
Open banking must step up its fraud prevention