logo

Magecart Hackers Abuse Google Tag Manager to Inject Credit Card Skimmers

ID: 3b14dc98-e8b2-5515-95e0-6d2a847d3c5b

STIX ID: report--3b14dc98-e8b2-5515-95e0-6d2a847d3c5b

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Tushar Subhra Dutta

...
...

Security researchers at Sucuri tracked an active Magecart-linked campaign (attributed to ATMZOW) that hides payment-card skimmers inside malicious Google Tag Manager containers to exfiltrate checkout data; the campaign uses heavy obfuscation, rotating lookalike CDN domains (registered in batches via Hostinger), Cloudflare-protected infrastructure, and persistent reinfection via replacement GTM containers, and the report provides multiple GTM container IDs, domains and IPs as IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.