Magecart Hackers Uses 100+ Domains to Hijack eStores Checkouts and Steal Card Data
ID: 8c298654-e15e-55b8-82c2-2ec7818c8d96
STIX ID: report--8c298654-e15e-55b8-82c2-2ec7818c8d96
Feed Name: cybersecurityNews.com
A long-running, infrastructure-driven Magecart campaign has compromised at least 17 WooCommerce e-stores across multiple countries since early 2024, using a layered JavaScript loader and over 100 malicious domains to inject high-fidelity fake payment UIs (notably impersonating Redsys and PayPlug) and exfiltrate full card data via encrypted WebSocket channels; the operation also pushed malicious Android APKs and demonstrates persistent, resilient command-and-control and multi-language targeting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
