logo

GrelosGTM group abuses Google Tag Manager to attack e-commerce websites

ID: 570bb2f3-9b0d-561d-88ca-d39810c30522

STIX ID: report--570bb2f3-9b0d-561d-88ca-d39810c30522

Feed Name: Group-IB Blog

Threat Score
70/100

Date Published: 2021-05-06

Date Updated: 2026-04-27

...
...

Group-IB reports a GrelosGTM campaign (active since Jan 2020, with a notable campaign from Feb 2021) that infected at least seven Magento e-commerce sites across multiple countries by injecting malicious Google Tag Manager scripts. The multi-stage attack loads obfuscated JavaScript sniffers (stored as files with .css or no extension), uses WebSocket to fetch payloads (wss://webfaset.com:80/bootstrap.min.css), and exfiltrates stolen payment card data to hxxps://webfaset.com/media/logo.img.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.