A cybercrime group long associated with credit card theft has expanded into targeted information stealing from supply chain organizations in the manufacturing and distribution sectors. In some of these new attacks the threat actor, whom several vendors track as the XE Group and link to Vietnam, has exploited two zero-day vulnerabilities in VeraCore's warehouse management platform to install Web shells for executing a variety of malicious actions. In a joint report this week, researchers from Intezer and Solis described the activity they observed recently as a sign of the heightened threat the group presents to organizations. "XE Group's evolution from credit card skimming operations to exploiting zero-day vulnerabilities underscores their adaptability and growing sophistication," the researchers wrote. "By targeting supply chains in the manufacturing and distribution sectors, XE Group not only maximizes the impact of their operations but also demonstrates an acute understanding of systemic vulnerabilities." XE Group is a likely Vietnamese threat actor that multiple vendors, including Malwarebytes, Volexity, and Menlo security have tracked for years. The group first surfaced in 2013, and through at least late 2024 was known primarily for leveraging Web vulnerabilities to deploy malware for skimming credit card numbers and associated data from e-commerce sites. In June 2023, the US Cybersecurity and Infrastructure Security Agency (CISA) identified XE Group as one of several thr...
XE Group Shifts From Card Skimming to Supply Chain Attacks
Dark Reading
·Jai Vijayan
·Published Feb 10, 2025
·Updated
Affected Software
3 affected components
VeraCore warehouse management platform
Progress Telerik
VeraCore warehouse management platform
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the XE Group's shift from card skimming to targeting supply chain organizations for information theft.
2
What motivates the XE Group's shift to supply chain attacks?
The XE Group is expanding its criminal activities to exploit vulnerabilities in supply chain organizations in the manufacturing and distribution sectors.
3
What security implications are discussed in relation to supply chain attacks?
The article highlights the increased risk and potential impact of targeted attacks on supply chain entities, which can lead to significant data breaches.
4
What products or software are specifically mentioned as affected by these attacks?
The affected products include the VeraCore warehouse management platform and Progress Telerik software.
5
How does the XE Group's activity affect businesses in the supply chain industry?
Businesses in the supply chain industry are exposed to heightened security risks, necessitating enhanced protection measures against these emerging threats.