Water Pamola is a financially motivated threat actor associated with attacks against online shops and e-commerce administration panels. The group has been observed submitting malicious shopping orders containing embedded cross-site scripting payloads designed to execute when viewed by merchant staff in vulnerable back-office interfaces. Once triggered in an administrator context, the scripts retrieve additional payloads from attacker-controlled infrastructure and enable follow-on intrusion activity. Observed tradecraft includes page grabbing to collect administrative interface content, credential phishing, deployment of webshell functionality, and delivery of additional malware. The campaign appears framework-agnostic, targeting e-commerce systems generally rather than a single shopping platform, with success dependent on the presence of exploitable XSS conditions in merchant workflows. Water Pamola has also used phishing infrastructure and customized scripts built on the XSS.ME framework, extending its basic capabilities to better fit victim environments. The actor’s operations are consistent with payment-card theft and broader e-commerce fraud. At least one compromised online shop later disclosed unauthorized server access and possible exposure of customer payment-card data, aligning the activity with Magecart-style objectives. Water Pamola is therefore best characterized as an e-crime actor focused on compromising online retail environments to steal credentials, capture sensitive administrative content, maintain access through server-side implants, and facilitate theft of payment information.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated campaign targeting e-commerce merchants by placing malicious orders containing embedded XSS scripts that execute in merchant management panels, enabling page grabbing, credential phishing, web shell infection, malware delivery, and likely theft of payment card data.
Named activity cluster associated in this content with phishing infrastructure and malware including ZEGOST, MAKOOB, and Gh0st RAT-related artifacts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.