logo

Magecart activity and campaign enhancements

ID: 0c869275-05b3-54bc-83a9-87a57cb8d2ce

STIX ID: report--0c869275-05b3-54bc-83a9-87a57cb8d2ce

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

This Zscaler ThreatLabZ report analyzes an active Magecart campaign that injects heavily obfuscated JavaScript (including RC4-encrypted and dynamically loaded payloads, and scripts hosted directly on compromised sites) into e-commerce checkout pages to capture and exfiltrate payment card and billing details; it documents injection methods, cookie-based deduplication and fake-field techniques, lists IOCs (malicious domains, URLs and an IP) and enumerates dozens of compromised sites, concluding that Magecart continues to evolve its skimming toolset.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.