logo

Magecart Attacks in 2021

ID: 78c50c58-f84f-5c4e-88ad-832115c76217

STIX ID: report--78c50c58-f84f-5c4e-88ad-832115c76217

Feed Name: Zscaler Security Research Blog

Threat Score
70/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ details a surge in JavaScript skimmer (Magecart) campaigns that compromise e-commerce platforms to exfiltrate payment card data. Attackers increasingly use newly registered domains (NRDs) that are lexically similar to legitimate services, host malicious scripts on CDNs/cloud services or compromised third-party scripts, and abuse analytics/communication services (e.g., Google Analytics, Telegram) to evade detection; the report includes case studies with specific domains, IP addresses, Base64-encoded exfiltration URLs, and recommendations to mitigate such skimmers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.