logo

Active Magecart Campaign Targets Spain, Steals Card Data via Hijacked eStores for Bank Fraud 

ID: 482cc5ed-eac7-5275-93ed-58eca58398d2

STIX ID: report--482cc5ed-eac7-5275-93ed-58eca58398d2

Feed Name: ANY.RUN's Cybersecurity Blog

Threat Score
75/100

Date Published: 2026-03-26

Date Updated: 2026-04-26

Author: khr0x and raptur3

...
...

This report analyzes a 24+ month Magecart campaign that compromises e-commerce sites (17 confirmed WooCommerce infections) to inject multi-stage JavaScript skimmers which mimic legitimate payment providers (notably Spain's Redsys), exfiltrate cardholder data via WebSocket channels, and maintain resilience through rotating, obfuscated staging infrastructure spanning 100+ domains — creating significant fraud risk to banks and cardholders while evading conventional detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.