logo

Magecart Hackers Uses 100+ Domains to Hijack eStores Checkouts and Steal Card Data

ID: 8c298654-e15e-55b8-82c2-2ec7818c8d96

STIX ID: report--8c298654-e15e-55b8-82c2-2ec7818c8d96

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-04-01

Date Updated: 2026-04-21

Author: Balaji N

...
...

A long-running, infrastructure-driven Magecart campaign has compromised at least 17 WooCommerce e-stores across multiple countries since early 2024, using a layered JavaScript loader and over 100 malicious domains to inject high-fidelity fake payment UIs (notably impersonating Redsys and PayPlug) and exfiltrate full card data via encrypted WebSocket channels; the operation also pushed malicious Android APKs and demonstrates persistent, resilient command-and-control and multi-language targeting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.