Key Findings New research by Cyber R&D Lab detailed a method of bypassing EMV technology to monetize supposedly secure cards. This method, EMV-Bypass Cloning, leverages information from one technology (EMV chips) and converts it into another less-secure technology (magstripe), which allows fraudsters to rely on their familiar cloning techniques. To test this theory, they chose […]
Read more
Key Findings Gemini Advisory has previously reported on the Russian Federal Security Service (FSB) arresting 30 members of a hacker ring. This unusual action by Russian law enforcement included the arrest of known cybercriminal Aleksei Stroganov (AKA “Flint24”). Stroganov owns several businesses that appear to be legitimate, and in recent years increased his cybercriminal activities […]
Read more
Key Findings Gemini discovered that the “Keeper” Magecart group, which consists of an interconnected network of 64 attacker domains and 73 exfiltration domains, has targeted over 570 victim e-commerce sites in 55 different countries from April 1, 2017 until the present. The Keeper exfiltration and attacker domains use identical login panels and are linked to […]
Read more
Gemini has discovered approximately 165,000 compromised Card Present (CP) payment cards offered for sale on the dark web from a breach of the Southern fast-food restaurant Chicken Express. It affected at least 56 locations.
Read more
Key Findings Russian media reported that the Russian Federal Security Service (FSB) arrested 30 members of a hacker ring on March 20, 2020. The hackers purportedly specialized in selling compromised debit and credit cards stolen from foreign citizens. Around the same time as these arrests, Gemini noted that a popular dark web marketplace known as […]
Read more
By Stas Alforov and Christopher Thomas Key Findings In late 2019, the popular e-commerce platform Volusion was compromised in a Magecart attack. While some reports claimed that the breach affected up to 20,000 online stores, 6,589 were confirmed to be connected to the compromised domain. Gemini Advisory determined that the script was dynamically injected into […]
Read more