CosmicSting is the name used for CVE-2024-34102, a critical vulnerability affecting Adobe Commerce and Magento. The content describes it as an improper restriction of XML external entity reference (XXE) flaw with CVSS 9.8 that enables arbitrary file read on unpatched systems and, when chained with CNEXT (CVE-2024-2961 in glibc iconv), can lead to remote code execution and full system compromise. It has been actively exploited since June 2024 against Adobe Commerce and Magento stores, with reporting that at least 4,275 online stores were compromised and roughly 5% of all Adobe Commerce/Magento stores were affected.
Observed post-exploitation activity includes theft of Magento secret encryption keys, generation of forged JWTs with administrative API access, abuse of the Magento REST API to inject malicious JavaScript, and establishment of persistence on compromised hosts. The content states that attackers dropped files ~/.config/htop/defunct and ~/.config/htop/defunct.dat, installed cron-based persistence, and relaunched a disguised gsocket backdoor process under kernel-thread-like names including [raid5wq], [kswapd0], [slub_flushwq], [card0-crtc8], and [netns]. The dropped binary was identified as gsocket, used to provide persistent covert access. The campaign is described as financially motivated and consistent with Magecart activity, with injected JavaScript opening attacker-controlled WebSocket connections and executing attacker-supplied code to steal customer payment data.
The content associates exploitation with at least seven threat groups, including Bobry, Surki, Burunduki, Ondatry, Khomyaki, Belki, and an unnamed group. Group Belki is specifically described as combining CosmicSting with CNEXT to plant backdoors and skimmer malware. Victims mentioned in the reporting include Ray-Ban, National Geographic, Cisco, Whirlpool, and Segway. Example exploitation telemetry includes POST requests to /rest/all/V1/guest-carts/test-ambio/estimate-shipping-methods, user agent python-requests/2.32.3, and IP addresses 193.93.193.74, 5.231.182.98, and 45.10.160.45. WebSocket-related indicators mentioned include sellerstat.site, accept.bar, amocha.xyz, cdn-webstats.com, clearnetfab.net, cd.iconstaff.top, cdn.iconstaff.top, cdn.inspectdlet.net, jqueryuslibs.com, jstatic201.com, lererikal.org, mamatmavali.ru, nothingillegal.bond, paie-locli.com, statsseo.com, statstoday.org, vincaolet.xyz, and webexcelsior.org. The content also notes that patching alone may be insufficient after compromise unless merchants rotate and invalidate old encryption keys.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct technique documented for this family, organized by ATT&CK tactic.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CosmicSting is a malware campaign exploiting CVE-2024-34102 to steal secret cryptographic keys from Adobe Commerce and Magento stores, enabling attackers to inject payment skimmers and steal customer payment data. It is used by multiple groups, each with their own loader and exfiltration methods.
CosmicSting is a financially motivated web skimming malware campaign targeting Adobe Commerce/Magento stores. It exploits CVE-2024-34102 and CVE-2024-2961 to gain remote code execution, drops a persistent backdoor using the gsocket toolkit for covert access, and injects malicious JavaScript to steal customer payment data via dynamic WebSocket-based payloads.
CosmicSting is an exploit targeting a critical XXE vulnerability (CVE-2024-34102) in Adobe Commerce and Magento, allowing attackers to read arbitrary files and, when chained with other vulnerabilities, achieve remote code execution. It is used to steal payment data and establish persistent access via web skimmers and backdoors.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.