• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

Boom! Hacked page on mobile phone website is stealing customers’ card data

October 6, 2020
Share on FacebookShare on Twitter

Enlarge / Computer hacker character stealing money online. Vector flat cartoon illustration

If you’re in the market for a new mobile phone plan, it’s best to avoid turning to Boom! Mobile. That is, unless you don’t mind your sensitive payment card data being sent to criminals in an attack that remained ongoing in the last few hours.

According to researchers from security firm Malwarebytes, Boom! Mobile’s boom.us website is infected with a malicious script that skims payment card data and sends it to a server under the control of a criminal group researchers have dubbed Fullz House. The malicious script is called by a single line that comprises mostly nonsense characters when viewed with the human eye.

Malwarebytes

When decoded from Base64 format, the line translates to: paypal-debit[.]com/cdn/ga.js. The JavaScript code ga.js masquerades as a Google Analytics script at one of the many fraudulent domains operated by Fullz House members.

Malwarebytes

“This skimmer is quite noisy as it will exfiltrate data every time it detects a change in the fields displayed on the current page,” Malwarebytes researchers wrote in a post published on Monday. “From a network traffic point of view, you can see each leak as a single GET request where the data is Base64 encoded.”

Malwarebytes

Scrambling the data into Base64 strings helps to conceal the true content. Decoding the strings is trivial and is done once the Fullz House members have received it.

How, precisely, the malicious line got added to the Boom! website is not clear. As Malwarebytes noted, this site security checker from security company Sucuri shows that Boom.us is running PHP 5.6.40, a version that hasn’t been supported since January 2019 and has known security vulnerabilities. It’s possible that attackers found a way to exploit one or more PHP security flaws, but there may be other explanations as well.

The name Fullz House is a nod to Fullz, which is slang for the full or complete data from a credit or debit card. Typically, a fullz includes the holder’s full name and billing address; card number, expiration date and security code; and often a Social Security number and birth date. A Fullz sells for much more in underground markets than only partial information. Malwarebytes said it has seen Fullz House operate before.

People considering buying a new phone plan should steer clear of Boom!, at least until the skimmer script is removed. Antivirus protection from Malwarebytes and some other providers will also provide a warning when users are visiting a site that’s infected with one of these skimmers. Boom! representatives didn’t respond to messages seeking comment for this post.

Next Post

This awesome robotic vacuum is at its lowest price ever on Amazon right now (Sponsored)

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • I finally stopped letting my phone’s default settings limit me, thanks to this little-known Android power utility
  • Leaks suggest Xbox Cloud Gaming could bring back lost classics
  • Netflix must refund customers for price hikes, Italian court rules
  • I’ve taken hundreds of photos with the Galaxy S26 Ultra. Here’s how it compares to its biggest competitors
  • ‘SNL’ Weekend Update goes after both Pam Bondi and Kristi Noem

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously