Group Bobry is a financially motivated payment-skimming threat group active against Adobe Commerce and Magento online stores. It was among multiple groups exploiting the CosmicSting vulnerability, CVE-2024-34102, during 2024. The group used stolen Magento cryptographic keys to obtain privileged API access and inject malicious JavaScript into CMS content and checkout-related pages. Its distinctive tradecraft uses invisible Unicode whitespace characters to encode and conceal skimmer-loader code; a small JavaScript routine decodes the whitespace into executable content, which retrieves payment-skimming malware from attacker-controlled infrastructure. Group Bobry compromised more than 650 online stores, including major retail brands, to collect customer payment-card data. Its use of Unicode-based obfuscation is intended to evade casual inspection and signature-based detection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
73 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Using CosmicSting-compromised Magento stores to deploy concealed payment skimmers hidden with invisible Unicode whitespace encoding and remotely loaded second-stage scripts.
Bobry is known for using sophisticated whitespace encoding techniques to hide payment skimmer malware in online stores, leveraging the CosmicSting vulnerability to steal cryptographic keys and inject malicious scripts.
Group Bobry exploited the CosmicSting vulnerability (CVE-2024-34102) to compromise Adobe Commerce and Magento stores, using whitespace encoding to hide malicious code that activates a payment skimmer hosted externally.
Group Bobry is exploiting the CosmicSting (CVE-2024-34102) and CNEXT (CVE-2024-2961) vulnerabilities to compromise Adobe Commerce and Magento stores, using whitespace encoding to hide payment skimmer code.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.