MageCart
Magecart is a collective umbrella term for financially motivated cybercriminal groups specialized in web skimming and payment-card theft from e-commerce sites. The activity is repeatedly described as targeting online retailers and checkout flows, especially Magento/Adobe Commerce, WooCommerce/WordPress, and related payment integrations such as Stripe, PayPal, Mollie, PagSeguro, OnePay, and Authorize.net. Reported victimology includes large retailers and service providers such as Ticketmaster and Newegg, as well as broad campaigns affecting hundreds of e-commerce sites globally, including Finnish online stores. Across the provided reporting, Magecart operations use malicious JavaScript injected into checkout pages to steal cardholder data, CVV, billing details, customer names, email addresses, phone numbers, and in some newer campaigns full identities, credentials, and account data. Commonly reported tactics include disguising skimmers as Google Tag Manager or analytics code; abusing trusted infrastructure such as Google Tag Manager, Stripe API, Google Firestore, Amazon S3, and Heroku; compromising third-party suppliers and shared script providers; modifying WooCommerce payment gateway plugin files; abusing vulnerable WooCommerce plugins such as Funnel Builder by FunnelKit to inject arbitrary JavaScript; using rogue plugins; hiding payloads in fake PNG or JPG files; storing malicious code in database rows; and using hidden SVG onload payloads to evade detection. Observed techniques in the content include fake payment overlays and phishing iframes, silent skimming, staged loaders, obfuscation, dynamic code retrieval and execution, WebSocket-based delivery or exfiltration, image-beacon exfiltration, local storage use for state and anti-duplication, self-removal when administrator indicators are present, and anti-forensics measures such as junk card generation and blending exfiltration into legitimate-looking traffic. Exfiltration and hosting have been reported through attacker-controlled lookalike domains as well as trusted services including Stripe customer metadata and records, Google Firestore, Amazon S3 buckets, and Heroku apps. The content also identifies sub-clusters or associated operators within Magecart activity, including ATMZOW, linked to long-running malicious Google Tag Manager container campaigns, and SMILODON, a skimmer reported targeting WooCommerce via a rogue plugin with payload hidden in a fake PNG image. Magecart is consistently characterized in the provided material as a cybercriminal, not nation-state, threat.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Consumer Discretionary Distribution & Retail
Tradecraft
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Observables
48 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting web skimming attacks against e-commerce checkout pages by abusing trusted services such as Google Tag Manager, Stripe API infrastructure, and in a variant, Google Firestore, to load skimmer code and exfiltrate stolen payment data.
Conducting web skimming/payment card theft by injecting malicious JavaScript into ecommerce checkout pages and disguising it as legitimate analytics or tag manager code.
Conducting web skimming/payment card theft campaigns by injecting malicious JavaScript via Google Tag Manager containers on compromised e-commerce sites.
Conducting web skimming attacks against Magento e-commerce stores by injecting inline SVG-based credit card skimmers into checkout pages to steal payment data while evading detection.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.