logo

Massive malicious campaign by FakeSecurity JS-sniffer

ID: c63866b5-2b1c-5c92-85b9-3248a75782d2

STIX ID: report--c63866b5-2b1c-5c92-85b9-3248a75782d2

Feed Name: Group-IB Blog

Threat Score
72/100

Date Published: 2019-11-08

Date Updated: 2026-04-27

...
...

Group-IB identified the FakeSecurity JS-sniffer campaign (Dec 2018–2019) where attackers used Mephistophilus phishing landing pages and spam to deliver Vidar password-stealer to e-commerce administrators, then leveraged stolen credentials to install JS-sniffers on Magento sites to capture customers' payment data; the report details the infection chain, associated infrastructure (domains, IPs), and file hashes for detection and remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.