The ondatry_loader is a custom malware loader used by the Ondatry threat group in the mass exploitation campaign targeting Adobe Commerce and Magento stores following the disclosure of CVE-2024-34102 (CosmicSting). Ondatry is known for previously exploiting the TrojanOrder vulnerability and now focuses on large merchants, particularly targeting Dutch stores by injecting fake MultiSafePay payment forms. The loader is used to deliver and execute skimming malware on checkout pages, enabling the theft of payment data. Ondatry's operations are characterized by the use of custom payment form malware and tailored attack techniques. The loader is part of a broader campaign involving multiple threat groups, each with distinct malware and exfiltration methods. High-profile victims of the campaign include major online retailers and brand stores. The infection vector is the exploitation of the CosmicSting vulnerability, with attackers leveraging stolen cryptographic keys and API tokens to inject malicious code. Ondatry's activity is ongoing and poses a significant threat to e-commerce platforms that have not patched or rotated their keys.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.