logo

FakeClicky Activity: Skimmers Hit Again

ID: 19050108-1cb4-5eb6-806a-4570e7457521

STIX ID: report--19050108-1cb4-5eb6-806a-4570e7457521

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabz describes the FakeClicky skimmer campaign that injects a fake Google Analytics loader into e-commerce sites to load obfuscated JavaScript on checkout pages and exfiltrate payment details; the campaign leverages newly registered lookalike domains (many resolving to 195.54.160.61 and 195.54.160.161), various evasion techniques, and includes variants that replace legitimate payment forms (including Braintree). The report provides the skimmer flow, sample payload behavior, a list of related domains and IP indicators of compromise, and high-level recommendations for shoppers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.