logo

Meet the JS-Sniffers 2: G-Analytics Family

ID: afebd61b-2c7f-5e7e-ac2b-1765bd5c24cb

STIX ID: report--afebd61b-2c7f-5e7e-ac2b-1765bd5c24cb

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2019-04-19

Date Updated: 2026-04-27

...
...

This Group-IB analysis examines the G-Analytics JS-sniffer family (active since 2016) that steals payment card data from e-commerce sites—especially Magento—by injecting obfuscated JavaScript into pages and in some cases modifying server-side PHP payment scripts. Operators use spoofed domains (dittm.org, jquery-js.com, g-analytics.com, etc.) and multiple versions to hide activity, and stolen card data is sold through underground cardshops (Cardsurfs/cardz) likely operated by the same actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.