Lazarus hackers use Magecart attack to steal card data from EU, US sites

Lazarus hackers use Magecart attack to steal card data from EU, US sites

Lazarus hackers are believed to be backed by the North Korean government.


The IT security researchers at Sansec have reported that North Korea backed Lazarus hacking group might be involved in stealing credit card information from mainstream European and US-based eCommerce stores since May 2019.


According to the latest report from Sansec, the hackers planted digital skimming code in the payment card information systems used by large retailers to make money for the Kim Jong-un regime. The claim does hold weightage as the UN reported back in 2019 that North Korea made $2bn only through cyberattacks.


See: How Bad is the North Korean Cyber Threat?


Lazarus’s name is largely associated with cyberattacks on cryptocurrency exchanges and banks, and this is the first time it is accused of targeting retail stores. As per the report from the security firm Group-IB, Lazarus managed to steal over $600m worth of crypto between 2017 and 2018.

Sansec reports that Lazarus is involved in attacks on several dozen large-scale retail stores. Their targets include the high-profile accessories retailer Claire’s, Focus Camera, Wongs Jewellers, CBD Armor, Jit Truck Parts, Paper Source, Realchems, and Microbattery.


Stealing payment card information from online stores’ customers is called the MageCart attack. In this attack, cybercriminals use web sk ..

Support the originator by clicking the read the rest link below.