Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Keypoints

  • StyleSmuggler is a zero-day affecting Adobe Commerce and Magento.
  • Attackers inject PHP code through Magento’s template system using the styles properties.
  • The exploit works in two stages and can trigger code execution through failed payment emails.
  • Successful attacks install a Rust-based backdoor that connects to a C&C server.
  • The malware disguises itself as legitimate processes and hides communications as NTP replies.

Read More: https://www.securityweek.com/adobe-commerce-zero-day-exploited-to-backdoor-online-stores/