logo

JavaScript sniffers’ new tricks

ID: e0f7a09b-3fba-517a-865e-80658f9601da

STIX ID: report--e0f7a09b-3fba-517a-865e-80658f9601da

Feed Name: Group-IB Blog

Threat Score
70/100

Date Published: 2021-03-15

Date Updated: 2026-04-27

...
...

In January 2021 Group-IB identified and unpacked the E1RB JavaScript sniffer family (a Grelos variant) that infects e-commerce sites by replacing checkout payment forms with Base64-encoded fakes and capturing card data; attackers deploy the sniffer via modified Google Analytics-like injectors, use server-side per-request obfuscation (including time-based deobfuscation and randomized variable/function names) to evade detection, and exfiltrate data to lookalike domains (e.g., google-analitics.org, cdn-gstat.com), with the report providing technical deobfuscation, IOCs/infrastructure linkage, and mitigation recommendations for banks, merchants, and payment processors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.