Group-IB reported that the UltraRank threat group resumed web-skimming attacks against eCommerce websites, using a SnifLite JavaScript sniffer to steal payment card data from online shoppers. Investigators identified 12 compromised stores in the observed wave, with eight still infected at the time of publication, and said the attackers likely gained access through stolen CMS administrator credentials or brute-force attacks. The malicious script was Radix-obfuscated and delivered from the spoofed domain googletagsmanager[.]co, which impersonated Google Tag Manager while also acting as a collection point for exfiltrated card data.
Infrastructure analysis tied the campaign to a backend server at 45.141.84[.]239, associated with Media Land LLC, and to s-panel[.]su, which was likely used as a control panel for managing stolen payment data. Group-IB said the activity fits UltraRank’s broader history of compromising hundreds of online stores and service providers in long-running payment-card theft operations, underscoring the continued risk that client-side JavaScript skimmers pose to retailers and their customers.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
Group-IB experts discovered a new wave of UltraRank attacks in November 2020 targeting eCommerce websites. The campaign used a Radix-obfuscated JavaScript sniffer from the SnifLite family.
In August 2020, Group-IB published a report titled “UltraRank: the unexpected twist of a JS-sniffer triple threat.” The report said UltraRank had attacked 691 eCommerce stores and 13 website service providers over five years.
Group-IB said UltraRank has used the SnifLite JavaScript sniffer family since at least January 2019, including an attack on the Adverline advertising network. This establishes the earlier use of the malware family later seen in the renewed campaign.
Group-IB found an unobfuscated sniffer sample matching one previously seen on UltraRank infrastructure and tied the operation to googletagsmanager[.]co, backend server 45.141.84[.]239, and s-panel[.]su. The researchers assessed s-panel[.]su was likely a control panel used to collect and manage stolen payment card data.
During the newly discovered campaign, Group-IB Threat Intelligence identified 12 infected online stores and found that eight were still infected at the time of publication. Group-IB also sent notifications to the affected websites.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.