PULSE NAME
Baka JavaScript Skimmer Identified
WHITE AlienVault 2020-09-08 Modified: 2020-09-08
7
IOCs
LOW VOLUME
In February 2020, Visa Payment Fraud Disruption (PFD), using the eCommerce Threat Disruption (eTD) capability, identified a previously unknown ecommerce skimmer, and named the skimmer 'Baka'. PFD made the discovery while analyzing a command and control (C2) server that was previously observed hosting the ImageID skimmer variant. PFD's investigation revealed seven C2 servers hosting the Baka skimming kit. While the skimmer itself is basic and contains the expected features offered by many ecommerce skimming kits (e.g. data exfiltration using image requests and configurable target form fields), the Baka skimming kit's advanced design indicates it was created by a skilled developer.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Baka
Indicators of Compromise (7)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain pridecdn.com 2020-09-08
domain apienclave.com 2020-09-08
domain quicdn.com 2020-09-08
domain ordercheck.online 2020-09-08
domain apisquere.com 2020-09-08
domain jquery-cycle.com 2020-09-08
domain b-metric.com 2020-09-08