GrelosGTM group abuses Google Tag Manager to attack e-commerce websites
ID: 570bb2f3-9b0d-561d-88ca-d39810c30522
STIX ID: report--570bb2f3-9b0d-561d-88ca-d39810c30522
Feed Name: Group-IB Blog
Group-IB reports a GrelosGTM campaign (active since Jan 2020, with a notable campaign from Feb 2021) that infected at least seven Magento e-commerce sites across multiple countries by injecting malicious Google Tag Manager scripts. The multi-stage attack loads obfuscated JavaScript sniffers (stored as files with .css or no extension), uses WebSocket to fetch payloads (wss://webfaset.com:80/bootstrap.min.css), and exfiltrates stolen payment card data to hxxps://webfaset.com/media/logo.img.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
