Group Surki, also known as Surki, is a financially motivated web-skimming threat group active in the 2024 mass exploitation of CVE-2024-34102 (CosmicSting) affecting Adobe Commerce and Magento stores. The group used the vulnerability-derived access to inject malicious JavaScript into e-commerce environments and steal customer payment data. Its malware delivery employed WebSocket-based infrastructure, while its JavaScript payloads and loaders used XOR encoding, including a loader using the value 42, to hinder inspection and detection. Group Surki was one of several distinct criminal groups competing to monetize compromised Adobe Commerce and Magento merchants during the CosmicSting campaigns.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
12 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
24 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Deploying Magento skimmers delivered through WebSocket-based loaders, using XOR obfuscation and occasionally CSP-evasion techniques such as loading through Google Translate.
Surki uses custom encryption (notably the number 42) to obfuscate their skimmer payloads and leverages CosmicSting to compromise online stores.
Group Surki exploited the CosmicSting vulnerability, using XOR encoding to obfuscate malicious JavaScript code and evade detection while stealing payment data.
Group Surki leverages XOR encoding to obfuscate malicious JavaScript code injected into e-commerce sites, exploiting the same vulnerabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.