Meet the JS-Sniffers 2: G-Analytics Family
ID: afebd61b-2c7f-5e7e-ac2b-1765bd5c24cb
STIX ID: report--afebd61b-2c7f-5e7e-ac2b-1765bd5c24cb
Feed Name: Group-IB Blog
This Group-IB analysis examines the G-Analytics JS-sniffer family (active since 2016) that steals payment card data from e-commerce sites—especially Magento—by injecting obfuscated JavaScript into pages and in some cases modifying server-side PHP payment scripts. Operators use spoofed domains (dittm.org, jquery-js.com, g-analytics.com, etc.) and multiple versions to hide activity, and stolen card data is sold through underground cardshops (Cardsurfs/cardz) likely operated by the same actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
