Skip to main content
Mallory
2 malware families

MageCart

Also known asMageCart

Magecart is a collective umbrella term for financially motivated cybercriminal groups specialized in web skimming and payment-card theft from e-commerce sites. The activity is repeatedly described as targeting online retailers and checkout flows, especially Magento/Adobe Commerce, WooCommerce/WordPress, and related payment integrations such as Stripe, PayPal, Mollie, PagSeguro, OnePay, and Authorize.net. Reported victimology includes large retailers and service providers such as Ticketmaster and Newegg, as well as broad campaigns affecting hundreds of e-commerce sites globally, including Finnish online stores. Across the provided reporting, Magecart operations use malicious JavaScript injected into checkout pages to steal cardholder data, CVV, billing details, customer names, email addresses, phone numbers, and in some newer campaigns full identities, credentials, and account data. Commonly reported tactics include disguising skimmers as Google Tag Manager or analytics code; abusing trusted infrastructure such as Google Tag Manager, Stripe API, Google Firestore, Amazon S3, and Heroku; compromising third-party suppliers and shared script providers; modifying WooCommerce payment gateway plugin files; abusing vulnerable WooCommerce plugins such as Funnel Builder by FunnelKit to inject arbitrary JavaScript; using rogue plugins; hiding payloads in fake PNG or JPG files; storing malicious code in database rows; and using hidden SVG onload payloads to evade detection. Observed techniques in the content include fake payment overlays and phishing iframes, silent skimming, staged loaders, obfuscation, dynamic code retrieval and execution, WebSocket-based delivery or exfiltration, image-beacon exfiltration, local storage use for state and anti-duplication, self-removal when administrator indicators are present, and anti-forensics measures such as junk card generation and blending exfiltration into legitimate-looking traffic. Exfiltration and hosting have been reported through attacker-controlled lookalike domains as well as trusted services including Stripe customer metadata and records, Google Firestore, Amazon S3 buckets, and Heroku apps. The content also identifies sub-clusters or associated operators within Magecart activity, including ATMZOW, linked to long-running malicious Google Tag Manager container campaigns, and SMILODON, a skimmer reported targeting WooCommerce via a rogue plugin with payload hidden in a fake PNG image. Magecart is consistently characterized in the provided material as a cybercriminal, not nation-state, threat.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Consumer Discretionary Distribution & Retail
MITRE ATT&CK

Tradecraft

19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

9 of 15 tactics25 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0042
Resource Development
2 techniques
T1583
Acquire Infrastructure
T1583.003
Virtual Private Server
T1584
Compromise Infrastructure
TA0001
Initial Access
3 techniques
T1190
Exploit Public-Facing Application
T1195
Supply Chain Compromise
T1566
Phishing
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1059.007×3
JavaScript
T1204
User Execution
T1204.002
Malicious File
TA0005
Stealth
3 techniques
T1027
Obfuscated Files or Information
T1036×5
Masquerading
T1497
Virtualization/Sandbox Evasion
TA0006
Credential Access
1 technique
T1056×5
Input Capture
T1056.001×2
Keylogging
TA0007
Discovery
1 technique
T1497
Virtualization/Sandbox Evasion
TA0009
Collection
1 technique
T1056×5
Input Capture
T1056.001×2
Keylogging
TA0011
Command and Control
3 techniques
T1001×2
Data Obfuscation
T1008
Fallback Channels
T1071
Application Layer Protocol
TA0010
Exfiltration
3 techniques
T1041
Exfiltration Over C2 Channel
T1048
Exfiltration Over Alternative Protocol
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
T1567
Exfiltration Over Web Service
IOCS

Observables

48 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping19

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal2

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables48

Domains, IPs, and hashes tied to this actor, refreshed continuously.