Russian hackers aren’t as pro-Donald Trump as recent presidential debate talking points would have you believe, according to a report from the Netherlands, recounted Oct. 17 by Brian Krebs on his “Krebs on Security” blog.
Dutch researcher Willem De Groot of e-commerce site byte.nl identified and dissected credit card data skimming malware in the JavaScript of the National Republican Senatorial Committee’s web store. Since March 2016 until the first week of October, the malware had been calling back to destinations made to look legitimate as they siphoned the data to servers run by Dataflow.su, a Russian-language ISP incorporated in Belize and well-known on cybercrime forums.
This makes the NRSC web store one of 5,900 e-commerce sites (including Converse and Audi) accessed through security vulnerabilities or weak passwords by this group of foreign actors.
Many of the sites — including the NRSC — have been scrubbed of the malware since De Groot’s initial report, but he said new instances of compromised data continue to proliferate.
The reason the hacks have taken so long to identify, Krebs reported, is because the code is placed into constantly changing databases, not static HTML, where file-checking systems typically aren’t configured to look regularly. And too many merchants believe secure sockets layer technology adds the extra needed layer of protection, as information can be captured pre-encryption.




