UltraRank is a financially motivated cybercriminal web-skimming group focused on compromising e-commerce websites and harvesting payment-card data. The group has been linked to large-scale attacks against online stores and website service providers over multiple years, including hundreds of compromised e-commerce sites. Its operations center on JavaScript-based payment-card skimmers inserted into victim websites, typically activating on checkout-related pages, replacing or intercepting payment forms, and exfiltrating stolen card data to attacker-controlled infrastructure. UltraRank has used multiple JavaScript sniffer families, including Grelos-based variants and SnifLite, and has also been associated with FakeLogistics- and WebRank-related collection logic. In earlier activity, UltraRank used Grelos-based sniffers in attacks dating to at least 2015. Later campaigns used SnifLite from at least 2019 onward, including renewed activity observed in late 2020. The group has employed spoofed analytics or tag-management themed loaders, heavy JavaScript obfuscation, per-request payload mutation, randomized variable and function names, and page-trigger logic keyed to checkout-related URL patterns. Some observed samples used anti-detection measures such as server-side re-obfuscation and time-based deobfuscation. UltraRank is assessed to gain access to victim e-commerce environments through compromised CMS administrator credentials or brute-force attacks. After obtaining access, the group injects malicious code into site pages, stages skimmer payloads on attacker infrastructure, captures payment-card and related checkout data submitted by customers, and exfiltrates the stolen information for monetization. Infrastructure associated with UltraRank has also included what was assessed to be a control panel for collecting and managing stolen payment-card data. UltraRank is best characterized as a card-skimming threat actor specializing in online payment theft rather than ransomware or espionage. No high-confidence attribution to a nation state is supported.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
6 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
9 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A cybercriminal group conducting JS-sniffer/Magecart-style attacks against eCommerce stores and website service providers to steal payment card data for exfiltration and resale.
Referenced as a cybercriminal group known for using Grelos-based JavaScript sniffers in earlier attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.