
Malicious AI Agents Steal 600K Credit Cards, Infect 100+ Sites with Skimmers Threat Campaign
Indicators of Compromise
Campaign Guidance
Remediation, mitigation, notes, history and related intelligence
REMEDIATION
DETECTION
Technique ID | Technique Name | Detection Strategy |
T1595 | Monitor for reconnaissance-style traffic patterns and repeated automated requests probing web applications from a small set of source IPs/ASNs ahead of exploitation attempts. | |
T1190 | Monitor web server and application logs for anomalous request patterns, spikes in 4xx/5xx errors, or unexpected process spawns (webshell-like behavior) from the web/application server process following inbound requests. | |
T1059 | Detect execution of scripting or command interpreters (e.g., shell, PHP eval, Node.js child_process) from web application contexts that do not normally spawn interpreters, especially with obfuscated or encoded arguments. | |
T1053 | Monitor for creation or modification of cron jobs or scheduled tasks on web/application servers, particularly ones that periodically re-write or restore files - consistent with the cron-based skimmer restoration observed in this campaign. | |
T1070 | Monitor for bulk deletion or modification of database fields (e.g., stored card data) shortly after unusual outbound data transfer, consistent with the post-exfiltration cleanup routine observed in this campaign. | |
T1485 | Monitor for mass field-level data wiping or overwrite operations in transaction/database tables that do not correspond to legitimate application workflows. |