Meet the JS-Sniffers 4: CoffeMokko Family
ID: 72bec80d-591f-51cf-9535-abd8ad121d96
STIX ID: report--72bec80d-591f-51cf-9535-abd8ad121d96
Feed Name: Group-IB Blog
**CoffeMokko JS-sniffers:** Group-IB’s analysis documents a long-running (since May 2017) JS-sniffer campaign that injects unique JavaScript on compromised Magento, OpenCart, WordPress, osCommerce and Shopify stores to harvest payment form fields and exfiltrate card data to attacker-controlled gates; the report details obfuscation algorithms, character-mapped Base64 encoding, infrastructure patterns (fake domains, /js or /src directories, gate scripts such as /path/savePayment/index.php and /tr/index.php), examples of decoded resources, and links to earlier Magecart/Group 1 activity suggesting tool or operator overlap.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
