Welcome

Join the leading Carding Forum for carders worldwide. Connect, discuss, and explore carding topics and free carding stuff like cc, dumps with pin, leaked deatabse, bank accounts and much more in a trusted community hub for beginners and pros.

  • Contact : for Purchasing Advertisement and TELEGRAM : @Cardersforum_Admin
adv ex on 22 February 2024

Hackers deployed a network of 120,000 fake stores to steal credit card data

Pro Carders

Admin
Staff member
Joined
Apr 5, 2024
Messages
155
Points
28

Hackers deployed a network of 120,000 fake stores to steal credit card data.​

04a8f5fd1b803c50.webp

Hackers deployed a network of 120,000 fake stores to steal credit card data.
The DoppelCart network uses a record number of domains to imitate nearly 45,000 different well-known brands. The number of imitating sites for each brand can reach 30 or more.

Raking wide across the yard​

Over 119,000 domains are used by a large-scale network of fake online stores whose primary purpose is to intercept and steal payment information from defrauded consumers. The researchers who discovered it have dubbed it DoppelCart.
Most domains are in the .SHOP top-level domain, accounting for 2.72% of all sites in this zone.
German cybersecurity startup Nebty, whose specialists discovered DoppelCart, described the cluster as the largest publicly documented. Its closest competitor, BogusBazaar, operated a network of 75,000 websites that processed a total of 850,000 fraudulent transactions.
Fraudsters are creating networks of tens of thousands of fake online stores to steal payment data.
According to the latest data from Nebty, more than 105,000 DoppelCart stores are still active.
Nebty CEO Benedikt Scheungraber told BleepingComputer that 96% of the fake stores proven to be DoppelCart have identical build files and use a large, but still limited, set of e-commerce platforms (27).
These websites pose as legitimate platforms by copying their product catalogs, descriptions, branding, and images; sometimes, the materials are downloaded directly from the real company's servers.
Shengraber says stores imitate 44,182 different brands, with an average of two clones for each brand.
Some - SodaStream, Velasca, CurrentBody, Daniel Wellington, Dreame, Horze, MOVA and SPARK PAWS - have received more attention, with over 30 fake stores each.

You shouldn't be chasing cheapness, priest.​

The main way to attract victims is by promising large discounts (up to 65%).
Nebty experts, after examining several checkout pages, discovered code that collected sensitive information related to payment cards and their holders: card numbers, expiration dates, security codes, cardholder names, email addresses, phone numbers, and physical addresses.
Data from each such field is transmitted via the WebSockets protocol to the control server in real time.
The order code may also redirect a one-time verification code from the victim's bank, which attackers can then use to bypass security measures.
Some counterfeit stores list the customer service address of the imitated brand so that victims who have not received their purchases can file complaints there.
According to Shengraber, the company attempted to contact the primary hosting provider for DoppelCart's websites but received no response. This may indicate the hosting provider's criminal nature.
"What makes this fraudulent operation remarkable is its industrial scale," says Alexander Zonov , an information security expert at SEQ. "Otherwise, it demonstrates the full range of fraudulent features. Unfortunately, it's becoming increasingly difficult to visually distinguish fake e-commerce sites from genuine stores. In this regard, the work of security specialists who conduct reconnaissance of fraudulent networks is becoming critically important for both the customers of such stores and their owners."
Nebty has created a searchable database of counterfeit stores to help businesses identify instances of DoppelCart account spoofing and brand abuse, and take appropriate action to protect themselves.
 
Top