ATMZOW is a long-running Magecart-linked threat actor focused on ecommerce payment-card theft through client-side web skimming. The group is associated with compromises of Magento-based online stores and has been linked to activity dating back to 2015, including the Guruincsite infection cluster. ATMZOW is known for abusing trusted third-party web services to conceal malicious code, notably by embedding skimmers in malicious Google Tag Manager containers that execute on checkout pages and exfiltrate payment data in real time. The actor uses multi-stage, heavily obfuscated JavaScript and selective execution logic to reduce visibility and hinder automated scanning. Observed tradecraft includes activating skimmers only on payment-related pages, rotating payload delivery infrastructure, storing selected delivery endpoints in browser local storage for reuse, and rapidly replacing removed malicious containers to maintain access and reinfect victim sites. ATMZOW has also used custom decoding mechanisms designed to resist modification and static analysis. In some compromises, its skimming activity has overlapped with other web-skimming operations, indicating either shared victimology or concurrent compromises. ATMZOW’s operations are financially motivated and centered on stealing payment card data from ecommerce transactions. Its behavior demonstrates persistence, defense evasion, and adaptation in response to takedowns, making it a durable and recurring threat within the Magecart ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
5 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
47 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.