Group-IB reported that the FakeSecurity JavaScript sniffer was used in a large Magecart-style campaign targeting Magento-based e-commerce sites, where malicious code was implanted into checkout pages to steal customers' payment card data. The activity was tied to attacker-controlled domains including alloaypparel.com and firstofbanks.com, along with compromised websites used to host payloads and lure pages.
Investigators linked the skimming operation to an earlier malware campaign aimed at likely e-commerce administrators, in which spam emails and fake document-viewer landing pages delivered the Vidar password stealer through the Mephistophilus phishing kit. Group-IB said the apparent goal was to harvest administrator credentials, gain access to Magento and other e-commerce CMS panels, and then deploy the skimmer; infrastructure overlap with earlier LokiBot and AZORult activity suggests the same cybercrime group ran multiple credential-theft operations to support the card-skimming attacks.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Analysis of domains tied to FakeSecurity showed they were also used in a malware distribution campaign beginning in March 2019. The campaign used spam emails and fake document-viewer landing pages to deliver malware to likely e-commerce administrators.
Group-IB found that the same server infrastructure had previously hosted phishing infrastructure and admin panels for LokiBot and AZORult, linking the operation to malware spam activity in January 2019. This suggested the same cybercrime group may have conducted multiple credential-theft campaigns.
Group-IB reported that the FakeSecurity JavaScript sniffer family was detected in December 2018. The skimmer targeted Magento-based e-commerce sites and stole payment card data during checkout.
Later FakeSecurity activity used fiswedbesign.com and alloaypparel.com to store JS-sniffer source code. Group-IB also noted these domains, along with firstofbanks.com, were registered with the email address greenstreethunter@india.com.
Group-IB determined the attackers used the Mephistophilus phishing kit to build fake PDF-viewer pages that prompted victims to download malicious EXE files. The delivered malware was Vidar password stealer, intended to harvest credentials and enable access to e-commerce admin panels for JS-sniffer deployment.
In early attacks, the FakeSecurity operators used the domain magento-security[.]org as a gate for stolen credentials and to store sniffer source code. This reflects the campaign's initial infrastructure for exfiltration and payload hosting.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 52 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.