Magecart, also referred to as Magecart groups, is an umbrella designation for multiple financially motivated cybercriminal groups and individual operators specializing in digital payment-card skimming. It does not identify a single organization or a uniformly attributed intrusion set. Operators compromise e-commerce websites to steal card numbers, security codes, expiration dates, billing addresses, and other customer information, then monetize stolen records through underground marketplaces. Historical victims include British Airways, Ticketmaster, Newegg, and VisionDirect. Magecart operations commonly inject malicious JavaScript into checkout pages, intercept payment-form values, or insert convincing counterfeit payment forms. Targets include Magento stores and WordPress retail sites using WooCommerce. Attackers exploit vulnerable web applications and third-party components, and abuse legitimate services such as Google Tag Manager to host or deliver skimmers. Some operations use server-side PHP skimmers that modify payment-processing code and collect transaction data without visibly loading malicious browser scripts. Evasion techniques include layered obfuscation, anti-debugging checks, impersonation of trusted analytics services, and concealment of malicious code or stolen data inside image and stylesheet assets. Operators have also abused GitHub-hosted assets to conceal or update exfiltration configuration. Stolen information is transmitted through HTTP requests disguised as image loads, POST requests, or WebSocket connections. Modified application code and malicious tag-manager containers support persistent collection; infrastructure rotation allows operators to change delivery and exfiltration destinations while retaining existing infections. The ecosystem encompasses distinct skimmer implementations and operational clusters rather than one standardized toolkit. One Google Tag Manager campaign infected 316 e-commerce sites worldwide and was linked to at least 88,000 stolen payment-card records offered on an underground marketplace. Multiple unrelated Magecart operators can compromise the same vulnerable store simultaneously.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
34 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
6 malware families attributed to this actor across reporting.
1 additional family tracked in Mallory.
135 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned only as a historical comparison for the dead-drop resolver technique. The report does not associate Magecart with the PhantomPolia operation or Remus Stealer delivery.
Conducting web skimming attacks against e-commerce checkout pages by abusing trusted services such as Google Tag Manager and Stripe to load payment-card skimmers and exfiltrate stolen customer payment and personal data.
Conducting web skimming attacks against e-commerce checkout pages by abusing trusted services such as Google Tag Manager, Stripe API infrastructure, and in a variant, Google Firestore, to load skimmer code and exfiltrate stolen payment data.
Payment-card skimming activity used in exploitation of the FunnelKit Funnel Builder vulnerability to steal checkout data from WooCommerce stores.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.