{"id":7267,"date":"2025-02-10T15:58:30","date_gmt":"2025-02-10T21:58:30","guid":{"rendered":"https:\/\/www.darkreading.com\/cyber-risk\/xe-group-shifts-card-skimming-supply-chain-attacks"},"modified":"2025-02-10T15:58:30","modified_gmt":"2025-02-10T21:58:30","slug":"xe-group-shifts-from-card-skimming-to-supply-chain-attacks","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2025\/02\/10\/xe-group-shifts-from-card-skimming-to-supply-chain-attacks\/","title":{"rendered":"XE Group Shifts From Card Skimming to Supply Chain Attacks"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt8f0ea4e950d49a15\/67aa6dfc3e1cb234baf6a2c6\/vietnam_HakanGider_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/xe-group-shifts-from-card-skimming-to-supply-chain-attacks.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/xe-group-shifts-from-card-skimming-to-supply-chain-attacks.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A cybercrime group long associated with credit card theft has expanded into targeted information stealing from supply chain organizations in the manufacturing and distribution sectors.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In some of these new attacks the threat actor, whom several vendors track as the XE Group and link to Vietnam, has exploited two zero-day vulnerabilities in VeraCore&#8217;s warehouse management platform to install Web shells for executing a variety of malicious actions.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Zero-Day Exploits in Veracore\">Zero-Day Exploits in Veracore<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/intezer.com\/blog\/research\/xe-group-exploiting-zero-days\/\">a joint report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> this week, researchers from Intezer and Solis described the activity they observed recently as a sign of the heightened threat the group presents to organizations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;XE Group&#8217;s evolution from credit card skimming operations to exploiting zero-day vulnerabilities underscores their adaptability and growing sophistication,&#8221; the researchers wrote. &#8220;By targeting supply chains in the manufacturing and distribution sectors, XE Group not only maximizes the impact of their operations but also demonstrates an acute understanding of systemic vulnerabilities.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">XE Group is a likely Vietnamese threat actor that multiple vendors, including Malwarebytes, Volexity, and Menlo security have tracked for years. The group first surfaced in 2013, and through at least late 2024 was known primarily for leveraging Web vulnerabilities to deploy malware for skimming credit card numbers and associated data from e-commerce sites.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In June 2023, the US Cybersecurity and Infrastructure Security Agency (CISA) <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-074a\">identified XE Group<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> as one of several threat actors exploiting vulnerabilities in Progress Telerik software running on government IIS servers and executing remote commands on them. One of the vulnerabilities that CISA identified in its report (<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2017-9248\">CVE-2017-9248<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">) was the same one that Malwarebytes first observed XE Group exploiting back in 2020 in card skimmer attacks targeting <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/remote-workforce\/microsoft-public-asp-net-keys-web-server-rce\">ASP.Net sites<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. That campaign, as Intezer and Solis noted in their report, was notable for its focus on ASP.Net sites, which were rarely targeted at the time. In 2023, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.menlosecurity.com\/blog\/not-your-average-joe-an-analysis-of-the-xegroups-attack-techniques\">Menlo Security<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> reported seeing XE Group deploying multiple strategies, including supply chain attacks to deploy card skimmers on websites, and also setting up fake sites for stealing personal information and selling it in underground forums.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">What Solis and Intezer have observed now is a continued expansion of the threat actor&#8217;s activities, exploitation techniques, and malware since then. The group&#8217;s newer attack tactics include injecting malicious JavaScript into webpages, exploiting vulnerabilities in widely deployed products, and using custom ASPX Web shells to maintain access to compromised system.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"XE Group's Long-Term Cyberattack Objectives\">XE Group&#8217;s Long-Term Cyberattack Objectives<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In several of the recent attacks, the threat actor has used the two VeraCode zero-days (CVE-2024-57968, an upload validation vulnerability with a CVSS severity score of 9.9; and CVE-2025-25181, a SQL injection flaw with a 5.8 severity score) to deploy multiple Web shells on compromised systems.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;In at least one instance, Solis and Intezer researchers discovered the threat actor had exploited one of the VeraCode vulnerabilities as far back as January 2020 and had maintained persistent access to the victim&#8217;s compromised environment since then,&#8221; according to the joint report. &#8220;In 2024, the group reactivated a webshell initially deployed [in January 2020], highlighting their ability to remain undetected and reengage targets. Their ability to maintain persistent access to systems \u2026 years after initial deployment, highlights the group\u2019s commitment to long-term objectives.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The XE Group&#8217;s recent shift in tactics and targeting are consistent with a broader focus among threat actors on the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/lessons-largest-software-supply-chain-incidents\">software supply chain<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Though SolarWinds remains perhaps the best known example, there have been several other significant attacks on widely used software products and services. Examples include attacks on Progress Software&#8217;s <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/moveit-transfer-flaws-security-defense-attackers\">MOVEit<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> file transfer tool, a <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/application-security\/otka-breach-widens-entire-customer-base\">breach at Okta<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that affected all of its customers, and a breach at <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_self\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/accellion-data-breach-resulted-in-extortion-attempts-against-multiple-victims\">Accellion<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> that allowed attackers to deploy ransomware on some of the company&#8217;s customers.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyber-risk\/xe-group-shifts-card-skimming-supply-chain-attacks\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A cybercrime group long associated with credit card theft has<\/p>\n","protected":false},"author":12,"featured_media":7268,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-7267","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/xe-group-shifts-from-card-skimming-to-supply-chain-attacks.jpg?fit=1920%2C1080&ssl=1",1920,1080,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/xe-group-shifts-from-card-skimming-to-supply-chain-attacks.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/xe-group-shifts-from-card-skimming-to-supply-chain-attacks.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/xe-group-shifts-from-card-skimming-to-supply-chain-attacks.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/xe-group-shifts-from-card-skimming-to-supply-chain-attacks.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/xe-group-shifts-from-card-skimming-to-supply-chain-attacks.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/xe-group-shifts-from-card-skimming-to-supply-chain-attacks.jpg?fit=1920%2C1080&ssl=1",1920,1080,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/xe-group-shifts-from-card-skimming-to-supply-chain-attacks.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/xe-group-shifts-from-card-skimming-to-supply-chain-attacks.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/xe-group-shifts-from-card-skimming-to-supply-chain-attacks.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2025\/02\/xe-group-shifts-from-card-skimming-to-supply-chain-attacks.jpg?fit=1920%2C1080&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7267","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=7267"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/7267\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/7268"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=7267"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=7267"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=7267"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}