logo

MageCart Campaign Targets eCommerce Platform

ID: 89722190-ad0b-53e4-b5a3-c671c0d166ec

STIX ID: report--89722190-ad0b-53e4-b5a3-c671c0d166ec

Feed Name: Zscaler Security Research Blog

Threat Score
75/100

Date Published: 2025-04-02

Date Updated: 2026-05-01

...
...

Zscaler ThreatLabZ describes an ongoing Magecart campaign that compromises e-commerce sites by injecting obfuscated JavaScript skimmers which capture payment and personal data and exfiltrate it to attacker-controlled domains; the report includes screenshots, deobfuscated code, hosting details (AS24936, Moscow), newly registered malicious domains, observed campaign activity, and IOCs (e.g., 83.166.243.206 and mage/mage.js and mail2.php paths), and provides references and monitoring guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.