logo

Meet the JS-Sniffers 3: Illum Family

ID: 4d4ab053-092f-5d4f-b0a0-2f96cbc534d2

STIX ID: report--4d4ab053-092f-5d4f-b0a0-2f96cbc534d2

Feed Name: Group-IB Blog

Threat Score
72/100

Date Published: 2019-04-25

Date Updated: 2026-04-27

...
...

Group-IB analyzed the Illum family of JavaScript sniffers that target e-commerce sites (notably Magento) to inject fake payment forms, capture customers’ payment credentials, and exfiltrate stolen data to attacker-controlled gates; the report documents exploited vulnerabilities (including CVE-2016-4010 and plugin RCE), attacker infrastructure (malicious scripts, gates, SSL usage), and multiple JS-sniffer samples and fake payment forms used in the campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.