ISC StormCast for Monday, July 15th 2019
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 15 July 2019
⏱️ 6 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello, welcome to the Monday, July 15th, 2019 edition of the Sandcent Storm Center's Stormcast. |
| 0:07.0 | My name is Johannes Ulrich, and the time recording from Swinton, England. |
| 0:13.0 | Magerd is just not going away, and the latest version of this thread was written up in a nice blog post by Jonathan Kleinsma. |
| 0:22.6 | MageCard usually manifests itself in a JavaScript library being injected into checkout |
| 0:29.5 | pages in order to steal payment card data. |
| 0:34.3 | Now in the past, one of the favorite modes for M MageCard to operate was essentially as a supply chain attack. |
| 0:41.7 | The website itself wasn't as much a target as in many cases libraries that these websites included. |
| 0:51.1 | While there are a number of different Magecard families out there, the one that |
| 0:57.0 | probably caused the most of concern was the one that would inject itself into various tracking |
| 1:03.1 | scripts and the like, and then websites would include this JavaScript, including the malicious |
| 1:09.7 | mageard part. |
| 1:11.5 | Now, the latest version of this is sort of a little bit of different kind of supply chain |
| 1:16.0 | attack, not necessarily going after third-party libraries, but in general going after |
| 1:22.8 | open S3 buckets. |
| 1:25.9 | Now, Amazon's S3 service has had a number of issues with attackers finding readable buckets. |
| 1:34.5 | In this case, the attacker needs to find a bucket that's not only readable, but also writable. |
| 1:41.0 | And this particular group will then inject this magecard JavaScript into |
| 1:47.4 | whatever writeable JavaScript file they can find as risk IQ points out that this of |
| 1:54.5 | course will hit a large number of websites that don't even deal with payment card data |
| 1:59.9 | or not even the pages that |
| 2:03.2 | actually received the data, but still probably successful enough by just emphasizing |
| 2:10.1 | quantity over quality, which is a little bit of different approach for Mage card. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

