Magecart is an umbrella term for multiple financially motivated cybercriminal groups that specialize in web skimming, especially the theft of payment card and customer data from e-commerce sites. The name originated from early activity targeting Magento, but Magecart operations have expanded to a wide range of online retail platforms and payment workflows, including Magento and Adobe Commerce, WooCommerce, WordPress-based stores, and third-party checkout integrations. Magecart actors typically compromise online stores or their supply chain and inject malicious client-side JavaScript into checkout pages. Common intrusion vectors include vulnerable plugins and extensions, compromised third-party suppliers, tampered content delivery infrastructure, writable cloud storage, malicious tag-management containers, and direct modification of storefront templates or payment gateway code. Their skimmers often activate only on checkout or payment pages, impersonate legitimate payment forms, analytics tags, or tag-management code, and blend into trusted services to evade detection. Core Magecart tradecraft centers on digital skimming of payment data, including card numbers, expiration dates, CVV values, cardholder names, billing details, email addresses, phone numbers, and in some campaigns broader identity and account data. Observed techniques include fake payment overlays, iframe-based form replacement, DOM manipulation to inject counterfeit fields, real-time interception of user input, local browser storage for temporary staging, obfuscation and encryption of stolen data, anti-debugging logic, selective execution based on page context, and exfiltration through trusted or disguised infrastructure. Some campaigns have abused services such as Google Tag Manager, Stripe, cloud application platforms, and cloud-hosted storage to host payloads or store stolen data, helping traffic blend with legitimate business activity. Magecart is associated with numerous high-profile retail and e-commerce compromises, including incidents involving British Airways, Ticketmaster, and Newegg, as well as broad campaigns affecting hundreds of online stores through shared third-party providers or mass exploitation of exposed infrastructure. The ecosystem includes multiple clusters and sub-groups rather than a single unified organization. Reporting has linked long-running skimming activity and related clusters such as ATMZOW and earlier Magento-focused infections under the broader Magecart umbrella. Recent activity shows continued adaptation beyond simple card theft. Some Magecart campaigns now use modular payloads tailored to specific payment processors, harvest credentials and full customer identities in addition to payment data, and support follow-on fraud such as account takeover and persistent compromise of e-commerce environments. Magecart remains one of the most significant criminal threats to online retail because of its focus on client-side compromise, supply-chain abuse, and stealthy monetization of checkout traffic.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
23 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
50 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting web skimming attacks against e-commerce checkout pages by abusing trusted services such as Google Tag Manager and Stripe to load payment-card skimmers and exfiltrate stolen customer payment and personal data.
Conducting web skimming attacks against e-commerce checkout pages by abusing trusted services such as Google Tag Manager, Stripe API infrastructure, and in a variant, Google Firestore, to load skimmer code and exfiltrate stolen payment data.
Payment-card skimming activity used in exploitation of the FunnelKit Funnel Builder vulnerability to steal checkout data from WooCommerce stores.
Conducting web skimming/payment card theft by injecting malicious JavaScript into ecommerce checkout pages and disguising it as legitimate analytics or tag manager code.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.