| Tool / Process | Client-side payment-card skimmer4 | Silent Push |
| Tool / Process | Magecart / web skimmer JavaScript3 | Malpedia |
| Tool / Process | Malicious JavaScript used to steal payment card data from e-commerce sites2 | MITRE |
| Tool / Process | Metasploit used by FIN6 for named-pipe impersonation and PowerShell modules2 | MITRE |
| Tool / Process | Obfuscated JavaScript injector4 | Silent Push |
| Tool / Process | Stealer One credential stealer2 | MITRE |
| ATT&CK ID | T1005 - Data from Local System / payment-card data collection2 | MITRE |
| ATT&CK ID | T1027 - Obfuscated Files or Information4 | Silent Push |
| ATT&CK ID | T1041 - Exfiltration Over C2 Channel2 | MITRE |
| ATT&CK ID | T1059 - Command and Scripting Interpreter2 | MITRE |
| ATT&CK ID | T1059.007 - JavaScript/JScript4 | Silent Push |
| ATT&CK ID | T1119 - Automated Collection2 | MITRE |
| ATT&CK ID | T1189 - Drive-by Compromise / compromised e-commerce page execution context4 | Silent Push |
| ATT&CK ID | T1195 - Supply Chain Compromise / third-party script or website compromise context4 | Silent Push |
| ATT&CK ID | T1555 - Credentials from Password Stores2 | MITRE |
| Network Indicator | cdn-cookie[.]com4 | Silent Push |
| Network Indicator | colunexshop[.]com4 | Silent Push |
| Campaign Context | IntelliOS keeps Magento, WooCommerce, Google Tag Manager, FIN6, Storm/Camouflage-style names, and individual web-skimmer campaigns source-scoped until specific source evidence supports a merge.3 | Malpedia |
| Campaign Context | Malpedia's MageCart/js.magecart relationship is retained for malware-family context and source reconciliation.3 | Malpedia |
| Campaign Context | MITRE FIN6/G0037 rows are retained as a source-backed overlap for Magecart Group 6, not proof that all Magecart-style skimming belongs to FIN6.2 | MITRE |
| Campaign Context | Silent Push's 2026 reporting is retained for current web-skimmer infrastructure and umbrella-label explanation.4 | Silent Push |
| Campaign Context | SOCRadar MageCart remains the baseline card, but IntelliOS treats Magecart as a web-skimming ecosystem and umbrella label rather than a single monolithic operator.4 | Silent Push |
| OBSERVABLE | Malpedia frames Magecart as web-based card-skimmer activity tracked by RiskIQ since 2016 and retains js.magecart as the related malware-family entry.3 | Malpedia |
| OBSERVABLE | MITRE describes FIN6 as a cybercrime group that stole payment-card data and sold it for profit, aggressively targeting PoS systems in hospitality and retail.2 | MITRE |
| OBSERVABLE | MITRE tracks FIN6 / G0037 with associated names including Magecart Group 6, ITG08, Skeleton Spider, TAAL, and Camouflage Tempest.2 | MITRE |
| OBSERVABLE | Silent Push explains that Magecart has evolved from specific Magento-focused groups into an umbrella term for client-side web-skimming and formjacking attacks.4 | Silent Push |
| OBSERVABLE | Silent Push reports a long-running Magecart web-skimmer campaign active since approximately 2022 and targeting payment networks including American Express, Diners Club, Discover, JCB, Mastercard, and UnionPay.4 | Silent Push |
| OBSERVABLE | Web skimmers execute in the user's browser during checkout and can be difficult for site owners or users to observe directly.4 | Silent Push |
| SECTOR | E-commerce stores and checkout flows4 | Silent Push |
| SECTOR | Global payment networks and their enterprise customers4 | Silent Push |
| SECTOR | Hospitality2 | MITRE |
| SECTOR | Magento / Adobe Commerce ecosystems3 | Malpedia |
| SECTOR | Retail2 | MITRE |
| SECTOR | WooCommerce and other web-commerce platforms3 | Malpedia |