Web Skimmers, IoT Botnets, and Search Engine Fraud: Trust Under Attack

Web Skimmers, IoT Botnets, and Search Engine Fraud: Trust Under Attack

Episode description

Web Skimmers, IoT Botnets, and Search Engine Fraud: Trust Under Attack

Three active cybercriminal campaigns are exploiting trust in routine business systems. GrelosGTM injects payment skimmers into Google Tag Manager containers on compromised e-commerce sites, bypassing traditional file integrity checks and PCI compliance tools. Two IoT malware families, KATARU and Evooo1Bot, are scanning for unpatched edge devices using vulnerabilities dating back to 2007, turning compromised routers and network appliances into proxy infrastructure. Meanwhile, criminals are creating convincing fake versions of legitimate financial portals that surface in organic search results through typosquatting and Punycode manipulation. Each campaign targets a different attack surface, but all exploit the same underlying assumption: that familiar tools, devices, and search results are inherently trustworthy. Mauven MacLeod examines the behavioural incentives that make these attacks effective and outlines practical steps UK businesses can take today to audit their Google Tag Manager containers, verify firmware on internet-facing devices, and reduce social engineering risks through simple URL management practices.

Chapters

  • Introduction Overview of three active campaigns exploiting trust in marketing tools, network hardware, and search engine results.
  • GrelosGTM: Payment Skimming Hidden Inside a Marketing Tool Group-IB research on a cybercriminal group injecting malicious scripts into Google Tag Manager containers on Magento e-commerce sites. Practical audit steps for UK businesses.
  • Call to Action Encouragement to follow the show and share with small business owners.
  • KATARU and Evooo1Bot: Two IoT Botnets Scanning for Unpatched Devices Two Mirai-derived botnets exploiting weak credentials and decades-old vulnerabilities in internet-facing edge devices. Includes FortiGate SSL-VPN intrusion campaign detail and firmware audit checklist.
  • Search Engine Fraud: Fake Crypto Gift Card Checkouts Criminals creating convincing fake versions of legitimate portals that appear in organic search results through typosquatting and Punycode manipulation. Simple URL management mitigations.
  • Closing Connecting thread across all three campaigns and practical takeaway: audit the things you have stopped looking at.

Links