Magecart / Magento Payment Skimming
Magecart is payment-skimming activity: unauthorized checkout code captures information a shopper enters, potentially before the legitimate payment completes. It describes multiple operators and access paths, not one newly published campaign. An attacker first needs a way to alter the storefront or code it loads; the shopper may then do nothing unusual beyond checking out.
- Edition
- v2.1 · Updated 5 September 2026
- Originally published
- 28 April 2026
- Evidence
- Public sources • source-bounded
- Product
- Flash Threat Intel Brief
Research Framing
| Focus | Evidence and implications |
|---|---|
| Decision question | Does platform exposure warrant incident investigation? Should an organization with Magento or Adobe Commerce exposure investigate both server compromise and browser checkout integrity, and what evidence would establish the affected payment flow? |
| Interpreted questions | Exposure, evidence and response Which vulnerabilities and configurations apply? What patches and prerequisites are required? What exploitation is confirmed? Which dates describe publication, observation or remediation? What artifacts support detection? What is known about actors, victims and related IntelliOS coverage? |
| Initial observations | Distinct evidence streams Current Adobe guidance changes the patch-selection decision. Historical server compromise and separate browser-skimming reports require different evidence and response paths. PolyShell, SVG, WebRTC and WordPress examples are not one proven intrusion chain.[11] [12] [13] [14] [18] [19] [29] [30] |
| Evidence hierarchy | Authority depends on the question Use Adobe for remediation and product scope, canonical vulnerability records for CVE and KEV metadata, original researchers for their observations, and PCI SSC for payment-security guidance. News and commercial summaries cannot resolve contradictory primary evidence by repetition. Registry tier and evidentiary authority are separate attributes.[3] [4] [16] [18] [20] [22] [25] [26] |
| Fact, analysis and unknown | Keep inference visible Source-observed compromise is not proof of every shopper’s data theft. A vulnerability’s KEV status is not proof that a particular store was exploited. Similar code, infrastructure services or campaign names do not establish common operators. Discovery and sample-submission dates remain unavailable unless explicitly supported. No victim size or attribution is inferred from leak-site claims. |
| Tier 0–8 coverage | Scoped research with explicit coverage limits Topic-specific primary evidence is retained with source-level exceptions. The 381-entry registry was screened through grouped domain-restricted searches; indexed screening is not direct review of all advisory feeds or proof of absence. No custom URLs or keyed integrations were used. DEFION and Source Defense are Tier 7 discovery retained separately as Tier 8 Expansion Research comparators. |
Magecart Exposure Snapshot
| Focus | Evidence and implications |
|---|---|
| Primary surface | Checkout and its supporting systems Magento/Adobe Commerce applications, checkout templates, CMS content, extensions, third-party scripts, administrator workflows and browser state.[1] [11] [12] [13] [14] |
| Current decision | Validate remediation and earlier exposure Use the vendor sequence in CVE / Vulnerability References, then investigate the pre-remediation window and residual persistence.[18] [19] [24] |
| Business scope | Payment exposure must be demonstrated Possible consequences include fraud, operational interruption and payment-security investigation. Determine affected fields and transactions; do not convert store counts into customer-loss totals. |
| Interpretation | Assess the actual merchant environment Vendor patch guidance identifies remediation requirements; researcher observations describe particular incidents or store populations. Neither establishes that a particular merchant is compromised or has completed recovery. |
Topic
Magecart payment skimming, with Magento and Adobe Commerce as the principal platform scope. The product covers platform exposure, server persistence, browser collection, payment-flow scoping and defensive response. WordPress/WooCommerce research is explicitly identified as comparator evidence.[1] [11] [12] [13] [14] [29] [30]
Magecart is an umbrella rather than a single actor, malware family or vulnerability. Geographic reach, merchant size and customer impact require evidence for each incident.
Persona / Audience Lens
| Focus | Evidence and implications |
|---|---|
| Audience | Engineering, incident response and business stakeholders For ecommerce operators, platform owners, SOC/DFIR teams, fraud teams, insurers, counsel and payment-security assessors. SMB owners are an intended audience; that does not classify any reported victim as an SMB. |
BLUF
- Magecart is payment-skimming activity: unauthorized checkout code captures information a shopper enters, potentially before the legitimate payment completes. It describes multiple operators and access paths, not one newly published campaign. An attacker first needs a way to alter the storefront or code it loads; the shopper may then do nothing unusual beyond checking out.[12] [13] [14]
- The immediate blast radius is the checkout experience that served the malicious code and the shoppers whose information it could collect during that interval. A server compromise can expose more, but skimming alone does not prove access to stored card data or every order. Difficulty varies with the initial access path and checkout design; there is no single Magecart CVSS or universal exploit chain.[1] [11] [12] [13] [14]
- Verify applicable fixes and exposed-secret remediation, inspect server integrity and browser-visible checkout behavior, and scope the collection window. Follow Adobe’s component-specific patch sequence; its August update is not proof of a new Magecart intrusion. Restore and test a trusted payment journey without treating a successful payment or server patch as evidence that earlier skimming did not occur.[18] [19] [24]
Executive Summary
A shopper can complete a genuine purchase while unauthorized code quietly captures information entered during checkout. Magecart is the umbrella term for this kind of ecommerce skimming, not a single attacker or vulnerability. A merchant can therefore have a customer-data exposure even when the legitimate payment processor receives the transaction and the shop appears to work normally.[12] [13] [14]
An attacker first needs a way to change the storefront or the code delivered to shoppers. The retained Magento reporting describes distinct access problems, including exposed application secrets in CosmicSting cases and upload-related compromise in PolyShell reporting. Those are different access paths across separate cases. In the separate browser-skimmer cases, the precise initial access is not always confirmed, so it would be wrong to assert that each skimmer arrived through the same CVE.[1] [11] [12] [13] [14] [24]
The common pattern is unauthorized access or code modification, insertion of a collector into the checkout experience, collection when a shopper enters information, and transmission to an attacker-controlled destination. Sansec describes both deceptive payment overlays and a WebRTC-based channel in separate investigations. These examples explain why checking only external script files or ordinary HTTP destinations can miss part of the activity; they do not prove a shared operator or that every skimmer uses both techniques.[13] [14]
The blast radius follows which storefront pages served the malicious code, how long it was present, and which shoppers actually submitted information it could observe. A shared compromised component could expose multiple storefronts, but each deployment still needs verification. Browser-form collection is also different from reading a database of stored payments: the latter would require separate access and evidence. Customer notifications and loss estimates should distinguish possible exposure, submission and confirmed exfiltration rather than using all site visitors or orders as a confirmed victim total.
There is no single difficulty rating for Magecart. Obtaining the initial access, integrating a collector with a particular checkout and keeping it operational are separate tasks; the effort depends on the vulnerability, credentials and payment design involved. Once malicious code is delivered, a shopper may need only to use the checkout as intended. An exploited server vulnerability has its own score and prerequisites, but that score does not describe every skimming operator or the entire theft process.[1] [11] [12] [13] [14]
The response must restore both server trust and the customer’s payment journey. Apply the relevant vendor fixes and exposed-secret guidance, preserve code and logs, investigate persistence, and validate checkout behavior from the browser. Adobe’s August remediation requires matching July fixes first across applicable components, and Adobe reported no known exploitation of that bulletin’s issues. That maintenance work is distinct from the earlier observed skimming cases. Do not declare recovery solely because the version changed or a test payment succeeded.[18] [19] [24]
AI Agent Delta Updates
| Focus | Evidence and implications |
|---|---|
| Material revision | Changes from the 18 July v2.0 edition Adds vendor patch prerequisites, corrects historical publication dates, qualifies campaign linkage, expands observable coverage and distinguishes the August WordPress/WooCommerce investigations from Magento incidents.[18] [19] [23] [29] [30] |
| Decision impact | Patch sequencing and incident scope Validate the applicable base release and July-to-August patch sequence, then investigate server persistence and unauthorized checkout behavior separately. The additional browser techniques broaden detection coverage without establishing common operators. |
Why It Matters
| Focus | Evidence and implications |
|---|---|
| Checkout trust | A legitimate payment can accompany malicious collection Successful order processing does not establish checkout integrity. Investigators need evidence of the code delivered to customers and the fields it could access.[13] [14] |
| Recovery | Patch status is only one part of assurance Response must address the access path, persistence, secrets, browser behavior and exposure window. Financial and reporting consequences depend on the demonstrated incident facts.[1] [11] [24] |
Timeline
| Date / event | Evidence and implications |
|---|---|
| 2022-02-13 / 2022-02-17 | Adobe publication and substantive revision APSB22-12 publication and subsequent affected-scope/CVE revision. These are advisory dates, not an established first-exploitation date.[22] Read source |
| 2022-11-15 | Separate TrojanOrders publication Sansec published the retained TrojanOrders report in November about the February vulnerability. The separate, inaccessible legacy URL does not establish a February research-publication date.[2] [23] Read source |
| 2024-06-11 / 2024-06-13 | Vendor bulletin and NVD publication APSB24-40 was published June 11; the NVD record was published June 13. Neither date alone establishes first exploitation.[3] [4] |
| 2024-06-23 | Researcher observation Sansec’s living overview identifies its first observed CosmicSting attacks on this date. Preserve the researcher and observation boundary.[1] |
| 2024-08-27 | CosmicSting/CNEXT report Publication describes a chained server-compromise case and includes August 9 log evidence. Publication is not the event’s first occurrence.[37] Read source |
| 2025-03-10 | PCI SSC supplement announcement Guidance publication; not a skimmer discovery or incident date.[16] |
| 2025-09-09 / 2025-10-22 / 2025-10-24 | SessionReaper disclosure and exploitation acknowledgement Adobe published APSB25-88 in September, added its exploitation acknowledgement October 22 and changed priority October 24. The later page-update wrapper must not move those events into 2026.[20] |
| 2025-10-22 / 2025-11-10 | Sansec dates SessionReaper mass-attack observation to October 22 and its displayed common-probe inventory to November 10. Neither date is a new 2026 exploitation event.[33] |
| 2026-03-10 | March Adobe bulletin APSB26-05 publication. Its August 11 page update is separate; it is no longer the newest bulletin reviewed.[15] |
| 2026-03-16 to 2026-03-23 | PolyShell chronology disagreement The source prose dates probing to March 16 and mass scanning to March 19; its timeline gives first attacks March 19 and mass scanning March 23. Preserve this disagreement rather than selecting a universal first-seen date. Public warning: March 17.[11] |
| 2026-03-24 / 2026-03-30 / 2026-04-07 | Separate browser and compromise reports WebRTC publication, the source-reported one-hour 471-store wave, and SVG publication respectively. Counts and entry-vector assessments remain distinct.[12] [13] [14] |
| 2026-04-14 | PolyShell telemetry update Sansec’s timeline reports 82% of stores hit. The source’s denominator and “hit” definition do not establish U.S. SMB prevalence, successful execution or payment-data theft; this figure must not be added to separate incident counts.[11] |
| 2026-05-12 | Magento 2.4.9 release Vendor release date. Sansec’s dated update identifies this release as containing the PolyShell fix.[11] [27] |
| 2026-05-12 | May base-release publication APSB26-49 publication; later page refreshes and subsequent monthly patches are separate events. This date does not establish exploitation.[38] |
| 2026-07-14 / 2026-08-11 | Successive vendor security releases July and August bulletin publication dates. The August bulletin displays an August 18 update; its installation article displays August 26.[18] [19] [32] |
| 2026-08-09 / 2026-08-20 | Distinct WordPress/WooCommerce research publications Source Defense and DEFION publication dates. DEFION separately discusses late-March file ctime and backdated mtime; neither timestamp proves the universal start of the campaign.[29] [30] |
| Historical overview — year not restated in passage | Sansec’s living CosmicSting overview describes October 14, October 21 and November 13 waves without restating a year in those passages. They remain historical context, not newly dated 2026 incidents. Counts are source-defined and not additive.[1] |
Incident Response Playbook Ideas
| Focus | Evidence and implications |
|---|---|
| 1. Scope | Document the payment architecture Identify exact platform and component versions, merchant-controlled fields, hosted pages or iframes, redirects, integrations and relevant deployment periods. |
| 2. Preserve | Use the authorized incident-response process Preserve relevant code, deployment history, CMS changes, server and browser telemetry, administrator activity and payment-page snapshots under appropriate access controls. Limit access to sensitive incident evidence to authorized responders. |
| 3. Investigate | Correlate artifacts with unauthorized changes Compare templates, extensions, static assets, CMS blocks, tag-manager history and upload-directory changes against trusted baselines. Review the structured observables with their campaign and false-positive qualifications.[11] [12] [13] [14] [23] [33] |
| 4. Validate remediation | Prove coverage rather than infer it from a version string Use the vendor patch sequence below. Address application-secret exposure separately from patch installation and verify that obsolete authentication capability has been invalidated.[19] [24] |
| 5. Determine impact | Separate possible access from demonstrated loss Establish the earliest supported unauthorized change, exposure window, affected payment fields, evidence of submissions and evidence of exfiltration. Assess stored-data access as a separate workstream. |
| 6. Recover and validate | Remove persistence and test the customer journey Authorized responders should remove unauthorized changes, rebuild from trusted code, remediate affected identities and secrets, and validate checkout behavior and monitoring. Preserve evidence before destructive cleanup. |
| 7. Report | Communicate facts and remaining uncertainty Provide business and payment-security stakeholders with scope, chronology, remediation evidence and unresolved questions. Reporting decisions belong to the organization’s authorized process. |
Term Glossary
| Focus | Evidence and implications |
|---|---|
| Magecart | Ecommerce skimming umbrella A collective label for payment-skimming operations; it does not identify one operator. |
| Checkout skimming | Collection during the payment journey Unauthorized code captures customer-entered information. JavaScript can read or alter accessible browser content; a web shell provides a different, server-side access mechanism. |
| Hosted payment and tokenization | Architecture controls A provider-hosted page or iframe collects payment details; tokenization substitutes a token for card data. Neither label alone proves the integrity of merchant-controlled redirects or surrounding content. |
| Payment terminology | PAN, CVV/CVC and CDE PAN is the primary account number; CVV/CVC is the card security code. CDE means cardholder data environment. PCI DSS is the payment-card security standard; QSA and PFI identify assessment and forensic-investigation roles. |
| Script governance | Extensions, tag managers and third-party scripts Script governance assigns ownership and authorization to extensions, tag managers and third-party scripts that can change checkout behavior. Retain a record of approved changes and verify the code delivered to customers.[16] |
| Observable | Evidence requiring context An IP, domain, path, fingerprint or behavior is an investigation lead. A DTLS certificate fingerprint is not a malware-file hash; a browser-storage marker is not an authentication credential or conclusive exfiltration receipt. |
TTPs
| Focus | Evidence and implications |
|---|---|
| Initial access | T1190 Analytic mapping for evidenced exploitation of public-facing applications. Apply it to the relevant intrusion, not automatically to every skimmer.[3] [11] [20] [22] Read source |
| Execution and persistence | T1059.007 / T1505.003 Analytic mappings for malicious JavaScript and server web shells where the source describes those behaviors.[11] [12] [13] [14] |
| Collection | T1056; qualified T1056.003 Input capture is the general mapping. MITRE’s Web Portal Capture sub-technique specifically discusses credential collection; do not treat every payment-only form as an exact match without qualification.[36] Read source |
| Exfiltration | T1041 where a C2 channel is established HTTP, iframe and WebRTC examples require channel-specific evidence. Shared use of a protocol does not establish common operators.[13] [14] Read source |
| Supply chain | T1195.002 is conditional An extension or third-party script being present is not sufficient evidence of software supply-chain compromise. Establish the upstream compromise and delivery path before assigning this technique. Read source |
Common Questions Q&A
| Focus | Evidence and implications |
|---|---|
| Authentication and reachability | Can an attacker act without an administrator account? The three retained exploited CVEs have unauthenticated network vectors in vendor metadata. PolyShell’s upload exposure must be distinguished from configuration-dependent execution. Confirm the actual reachable interfaces and deployment.[3] [11] [20] [22] |
| Patch selection | Is upgrading to 2.4.9 alone enough? No general assurance follows from the base version alone. Review subsequent monthly security coverage, installed components, prior compromise and persistence using the detailed vendor sequence below.[18] [19] |
| Workarounds | Does blocking uploaded-file execution stop uploads? No. Restricting web access or execution and preventing the vulnerable upload are separate controls. Existing files still require investigation.[11] [28] |
| Hosted checkout | Does processor hosting eliminate merchant risk? It can reduce direct card-data handling. Validate iframe origin isolation, redirects and surrounding merchant content; a fraudulent overlay can create a separate collection path.[13] [16] |
| Attribution and ransomware | Are these one actor or ransomware operation? No such conclusion is established here. Researcher cluster names, a related card’s imported aliases and leak-site claims cannot merge distinct operations. No topic-specific ransomware linkage is confirmed by this review. |
| Victims and size | Do aggregate store counts prove customer losses or SMB status? No. Keep researcher-observed sets separate, preserve anonymous victims and require case-specific evidence for customer exposure and organization size.[12] [13] [14] |
| Existing coverage | How does this relate to existing IntelliOS products? The existing CosmicSting and SessionReaper CVE cards already contain the retained CVE/KEV identities and deadlines; this is not new vulnerability discovery. The MageCart card provides umbrella context, not proof that all its imported aliases are equivalent. Operation Silent Skimmer is distinct Telerik/payment-database coverage. Klue and Salesloft are preserved trusted-integration comparators, not attributed Magecart campaigns. |
| How would an attacker set this up? | Obtain a way to alter storefront code, place a collector and receive captured submissions. Entry routes differ; an unconfirmed initial-access assessment must not become a universal Magecart CVE.[12] [13] [14] |
| How difficult is the attack? | There is no single rating: access, checkout integration and persistence are separate challenges. Shoppers may only need to use an affected checkout normally.[12] [13] [14] |
| What is the blast radius? | Identify the affected pages/components, exposure interval and submitted data. Skimming does not automatically establish stored-card access, every-order theft or compromise of all connected storefronts.[12] [13] [14] |
CVE / Vulnerability References
| Focus | Evidence and implications |
|---|---|
| Current reviewed remediation | APSB26-92 Adobe Commerce: 2.4.9/2.4.8/2.4.7/2.4.6/2.4.5/2.4.4-2026-jul and earlier → corresponding -2026-aug coverage. Magento Open Source: 2.4.9/2.4.8/2.4.7/2.4.6 lines. B2B: 1.5.3/1.5.2/1.4.2/1.3.4/1.3.3 lines. Adobe reports no known in-the-wild exploitation of this bulletin’s issues.[18] Read source |
| Installation prerequisites | Apply matching monthly patches in order Base releases: 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17 or 2.4.4-p18 as applicable. Install matching July fixes before August, including required CE/EE/B2B components. Adobe calls the individual monthly files non-cumulative: the complete sequence is required. Verify coverage with the Commerce Version Tool. Cloud-patches coverage may already include the fix; duplicate application can fail. Older Commerce downloads require entitlement; Open Source downloads are limited to 2.4.6 or later.[19] Read source |
| August vulnerability details | Separate remediation context CVE-2026-71362: CWE-863, CVSS 3.1 9.1, network, no credentials/admin/user interaction. Other bulletin entries: CVE-2026-48414/CWE-79/7.7; 48413/CWE-79/8.7; 48415/CWE-863/7.6/B2B; 48416/CWE-863/7.5; 48411/CWE-863/6.8; 48412/CWE-863/2.7. Authentication is required for these except 48416; admin access is listed for 48414, 48411 and 48412. No Magecart linkage is established.[18] Read source |
| CosmicSting | CVE-2024-34102 CWE-611; CVSS 3.1 9.8; unauthenticated network exposure. Historical affected→fixed pairs: 2.4.7→2.4.7-p1; 2.4.6-p5→p6; 2.4.5-p7→p8; 2.4.4-p8→p9, including earlier versions within each line. Commerce extended-support pairs: 2.4.3-ext-7→ext-8 and 2.4.2-ext-7→ext-8. ACSD-60241 was an isolated option for 2.4.4–2.4.7. These are historical fixes, not current target versions.[3] [4] Read source |
| TrojanOrders vulnerability | CVE-2022-24086 CWE-20; CVSS 3.1 9.8; unauthenticated network exposure. Adobe lists 2.4.3-p1 and earlier and 2.3.7-p2 and earlier, excluding 2.3.0–2.3.3. Historical remediation includes both MDVA-43395 and the version-matched MDVA-43443; Cloud Patches 1.0.16 resolved the issue. The bulletin also covers CVE-2022-24087, which must not inherit 24086’s exploitation or KEV status.[22] Read source |
| SessionReaper | CVE-2025-54236 CWE-20; CVSS 3.1 9.1; unauthenticated network exposure. Commerce affected lines through 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14 and 2.4.4-p15. Open Source’s listed scope omits 2.4.4. B2B scope includes 1.5.3-alpha2, 1.5.2-p2, 1.4.2-p7, 1.3.4-p14 and 1.3.3-p15 and earlier. See Adobe’s hotfix instructions for exact applicability.[20] Read source |
| SessionReaper remediation | VULN-32437 and module prerequisites Adobe’s detailed article covers VULN-32437 or a later security patch and directs installed Custom Attributes Serializable versions 0.1.0–0.3.0 to 0.4.0 or later. Its affected list also mentions 0.4.0, an internal inconsistency requiring clarification. Its old no-exploitation sentence is superseded by APSB25-88’s explicit October acknowledgement.[20] [21] Read source |
| PolyShell | Upload and execution are different exposures Sansec lists upload exposure through 2.4.9-alpha2 and a fix in alpha3 and released 2.4.9. Execution depends on web-server handling; older stock nginx, permissive PHP handlers and older Apache configurations are identified. Do not assign a CVE or numerical CVSS to the label without validated mapping. Backport status beyond the dated researcher update remains unresolved.[11] [28] Read source |
| Historical release context | March and July are not current patch endpoints APSB26-05 and APSB26-73 are retained to document the March and July release sequence, not as current patch endpoints or evidence of Magecart exploitation. Unrelated historical CVE rows and inconsistent authentication columns are not reproduced as campaign facts. Adobe’s current August matrix and its installation instructions control the patch sequence; the separately applicable Commerce Events update is identified below.[15] [32] |
| Base release versus monthly patches | May releases precede the July/August sequence APSB26-49 (May 12, 2026) supplies Commerce base releases 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17 and 2.4.4-p18; Magento Open Source lists the 2.4.9 through 2.4.6 lines. Apply the matching July and then August packages to all installed applicable components; the base release alone does not prove August coverage. Historical March/May/July bulletin CVEs are not automatically attributed to skimming.[38] [19] [18] |
| July component scope | Commerce Events requires its own version check APSB26-73 separately lists Commerce Events 1.6.0–1.20.0 as affected and 1.21.0 as the solution. Inventory this component independently of the storefront’s release number. This is vendor remediation context, not evidence that Commerce Events was the entry point in the skimming cases.[32] Read source |
IOCs / Observables
| Focus | Evidence and implications |
|---|---|
| source_reported_scanning_addresses | ip address 3.12.250[.]83; 3.88.149[.]41; 3.150.234[.]247; 18.220.50[.]153; 23.22.254[.]35; 31.134.0[.]53; 31.134.1[.]34; 31.134.7[.]117; 31.134.11[.]173; 31.134.15[.]89; 31.134.15[.]251; 45.136.24[.]213; 45.136.26[.]181; 45.136.27[.]218; 45.147.233[.]211; 45.147.234[.]73; 45.155.166[.]228; 52.24.6[.]119; 64.49.38[.]96; 78.129.161[.]63; 79.130.2[.]23; 81.169.144[.]135; 91.132.124[.]183; 103.216.223[.]206; 109.107.178[.]102; 115.79.194[.]68; 136.244.92[.]114; 140.235.2[.]103; 140.235.171[.]72; 140.248.75[.]31; 140.248.75[.]114; 162.159.113[.]66; 185.3.235[.]111; 193.151.188[.]86; 193.233.216[.]217; 193.233.221[.]124; 194.180.233[.]186; 198.186.130[.]10; 199.96.165[.]186; 212.87.218[.]43; 216.38.6[.]137; 2001:19f0:6c01:15da:5400:6ff:fe05[:]e560 PolyShell source-listed scanner set. A historical address match does not prove successful exploitation. Includes infrastructure that may be shared or reassigned; do not block indiscriminately.[11] |
| campaign_specific_infrastructure | ip address SVG: 23.137.249[.]67; Sansec WebRTC: 202.181.177[.]177; DEFION comparator: 103.141.13[.]26; historical CosmicSting/CNEXT: 165.231.182[.]98, 45.10.160[.]45, 193.93.193[.]74 Separate source-reported infrastructure sets. Do not merge campaigns by protocol or address proximity. Ownership and maliciousness are source-time observations.[13] [14] [29] [37] |
| campaign_specific_domains | domain fqdn PolyShell: lanhd6549tdhse[.]top, jslibrary[.]net, canevaslab[.]com. SVG: statistics-for-you[.]com, statistics-renew[.]com, morningflexpleasure[.]com, reusable-flex[.]com, goingfatter[.]com, wellfacing[.]com. DEFION comparator: systmshield[.]com, init.systmshield[.]com. Source Defense comparator: woocompay[.]com, wpguarding[.]com. Defanged domains; campaign assignments remain separate. A domain string alone does not establish an affected transaction. Check historical context and authorized dependencies.[11] [12] [13] [29] [30] |
| loader_url_and_relative_endpoint | url hxxps://lanhd6549tdhse[.]top/KZtBscgb; /fb_metrics.php PolyShell loader URL and SVG relative endpoint respectively. The relative path is not a complete URL or independently malicious. Do not contact the endpoints.[12] [13] |
| source_reported_filenames | filename PolyShell: index.php, 780index.php, json-shell.php, bypass.phtml, c.php, r.php, rce.php, static.php, test.php, blocked-json.php, bypass-async.php, urlencode-shell.php, xx_malicious_file.php, ato_poc.html, mikhail.html, accesson.php, toggige-arrow.jpg, adman.429.txt, adman.309.txt, bypass.php. TrojanOrders: health_check.php. SessionReaper: bootstrap.php, sysapi.php, gsfa1faewf.txt. DEFION comparator: uninstall.php. Filename leads, not file-content signatures. Many are generic or legitimate; correlate path, content and change evidence.[11] [23] [29] [33] |
| sha256_dtls_certificate_fingerprint | hash 9E:BB:2A:E2:C5:B8:DC:0A:8B:A7:85:E1:9F:C4:F8:A8:09:2A:F4:1E:70:30:1B:AF:9F:26:97:BE:E2:6E:E3:1D Sansec WebRTC DTLS fingerprint, not a malware-file hash. Correlate with the described channel and checkout behavior. Certificate reuse is not independent actor attribution.[14] |
| malware_file_hash | hash Unavailable in retained evidence No validated malware-file hash is promoted. Embedded credential-verification values are excluded. |
| distributed_backdoor_paths | persistence var/assets/images/accesson.php; bamboo-specs/assets/images/accesson.php; lib/assets/images/accesson.php; app/assets/images/accesson.php; vendor/assets/images/accesson.php; pub/assets/images/accesson.php; bin/assets/images/accesson.php; setup/assets/images/accesson.php; generated/assets/images/accesson.php; phpserver/assets/images/accesson.php PolyShell source-reported distributed persistence paths. Validate actual unauthorized file content.[11] |
| cms_and_browser_state | persistence Unauthorized CMS/static-block JavaScript; localStorage key 136c1e07507f4a97 Retained PolyShell wave persistence evidence. Browser state needs page and session context.[12] |
| investigation_paths | host artifact pub/media/custom_options/; pub/media/custom_options/quote/; app/etc/env.php; pub/media/customer_address/*/*; ~/.config/htop/defunct; ~/.config/htop/defunct.dat Magento investigation locations and historical CNEXT persistence paths. Legitimate paths are not compromise indicators without unauthorized content.[1] [11] [33] [37] |
| wordpress_comparator | host artifact wp_options: p_set, c_set, fields ce/dk/de/ia; hidden active plugin; uninstall.php persistence; mismatched mtime/ctime DEFION comparator artifacts; not Magento paths. Compare plugin inventory and database state with authorized deployment evidence.[29] |
| browser_marker_and_identity_hunts | identity session SVG localStorage marker _mgx_cv; unexpected administrator creation, API activity, extension changes or configuration changes; DEFION hidden-user discrepancies The marker is source-described submission state, not standalone proof of receipt by an attacker. Administrator checks are analytic hunts. Authorized changes and browser-state manipulation can produce similar signals.[13] [29] |
| campaign_specific_channels | network behavior Unexpected checkout WebRTC DataChannels over DTLS/UDP 3479; SVG POST to /fb_metrics.php with hidden-iframe fallback; historical CosmicSting WebSocket delivery; Source Defense image-request exfiltration resembling icon.gif Separate observed channels requiring correlation with unauthorized checkout code. WebRTC, iframes, WebSockets and image requests can be legitimate. Public infrastructure is not malicious merely because a campaign uses it.[13] [14] [30] [37] |
| blockchain_contract_references | network behavior BSC Testnet: 0xAeF2ed8B69eFb5C1B9e75990A5F90D02Eb5f84F8; 0xeED9e134CE64BF74bE001A942Ee3e3Cb5C12c999 DEFION-published contract references; no contract, bytecode or payload was retrieved. Blockchain RPC traffic may be legitimate for some payment integrations. Do not block public RPC providers solely on these observations.[29] |
| analytic_hunt_patterns | behavioral detection Unauthorized checkout JavaScript; unknown outbound destinations; unexplained template/static-asset changes; executable uploads; repeated backdoor placement; encoded inline SVG event handlers; fraudulent payment overlays; unexpected RTCPeerConnection; hidden plugins; runtime script removal or Blob execution Preserves baseline behavioral hunts and adds source-qualified comparator patterns. Encoding, Blob execution and browser APIs are not independently malicious. Validate business purpose and provenance.[11] [12] [13] [14] [29] [30] |
| sessionreaper_november_2025_addresses | ip address 23[.]146[.]184[.]93; 23[.]249[.]27[.]221; 34[.]227[.]25[.]4; 44[.]212[.]43[.]34; 45[.]32[.]66[.]51; 45[.]143[.]20[.]147; 46[.]39[.]230[.]243; 54[.]205[.]171[.]35; 54[.]226[.]181[.]219; 80[.]78[.]25[.]213; 86[.]203[.]185[.]51; 99[.]246[.]176[.]115; 103[.]215[.]237[.]26; 141[.]11[.]62[.]221; 143[.]244[.]44[.]172; 149[.]28[.]33[.]250; 155[.]117[.]84[.]134; 155[.]138[.]226[.]245; 156[.]244[.]16[.]170; 157[.]245[.]52[.]111; 159[.]89[.]12[.]166; 198[.]144[.]182[.]13; 212[.]8[.]248[.]191; 2001:19f0:6000:9a28:5400:5ff:feb8:8b4b; 2a0a:3840:8078:25:0:504e:19d5:1337 25 source-listed addresses in Sansec’s November 10, 2025 SessionReaper update; not a current reputation verdict. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[33] |
| sessionreaper_domain_spelling_conflict | domain fqdn sagecrafft[.]com; safecrafft[.]com; worcksbot[.]com Sansec uses sagecrafft repeatedly but also spells safecrafft in prose. Retain the disagreement; the two strings are not silently treated as interchangeable. worcksbot is the November replacement described by the source. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[33] |
| sessionreaper_paths | url hxxps://sagecrafft[.]com/a.php?a=…; /ttt/ref.php; hxxps://worcksbot[.]com/w.php?a=…; /o/o.php; hxxps://tecnokauf[.]ru/accesson20.html; /customer/address_file/upload Source-reported infrastructure and upload route. Ellipses indicate omitted variable query content, not complete URLs. The upload route is not the only possible attack path. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[33] |
| sessionreaper_webshell_artifacts | host artifact pub/errors/404.php; pub/rootz.php; rootzwashere; pub/6376bad677a8.php; static.php; GuzzleHttp Cookie FileCookieJar / SetCookie Additional source-reported file and serialized-object leads. Names and class strings are not executable samples and can have legitimate uses. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[33] |
| cosmicsting_cnext_websocket_endpoints | url wss[:]//accept[.]bar/common; wss[:]//amocha[.]xyz/common; wss[:]//cdn-webstats[.]com/ls; wss[:]//clearnetfab[.]net/common; wss[:]//fallodick87-78[.]sbs/common; wss[:]//cd[.]iconstaff[.]top/m; wss[:]//cdn[.]iconstaff[.]top/common; wss[:]//cdn[.]inspectdlet[.]net/ws; wss[:]//jqueryuslibs[.]com/common; wss[:]//jstatic201[.]com/common; wss[:]//lererikal[.]org/common; wss[:]//mamatmavali[.]ru/common; wss[:]//nothingillegal[.]bond/common; wss[:]//paie-locli[.]com/s; wss[:]//sellerstat[.]site/wss; wss[:]//statsseo[.]com/common; wss[:]//statstoday[.]org/common; wss[:]//vincaolet[.]xyz/socket; wss[:]//webexcelsior[.]org/common 19 historical WebSocket destinations in the August 27, 2024 CosmicSting/CNEXT report, kept separate from newer campaigns. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[37] |
| cosmicsting_cnext_process_and_cron | persistence defunct-kernel cron marker; [raid5wq]; [kswapd0]; [slub_flushwq]; [card0-crtc8]; [netns] Source-reported masquerading and cron persistence; kernel-like names alone are not malicious. Correlate executable path, parent process, file content and scheduling. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[37] |
| polyshell_wave_beacon | identity session 8194460 Source-reported PolyShell wave marker; it is not an authentication credential or proof of successful card theft. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[12] |
| svg_campaign_marker | identity session {site:'rand0m'}; _mgx_cv = 1 Source-published SVG payload and browser-state markers. Submission-state evidence is not independent confirmation of remote receipt. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[13] |
| defion_comparator_cookie_and_fields | identity session wjxq_; c77d5cd5; lu; Cart number DEFION comparator: activation-cookie name, published loader XOR encoding constant, update field, and form typo. No cookie values or private credentials retained; these are source-specific hunting leads. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[29] |
| defion_assessed_initial_access | domain fqdn wordpressnull[.]org; activations.ultrapackv2[.]com DEFION’s assessed nulled-page-builder distribution context, not proven initial access for all stores or an instruction to visit these sites. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[29] |
| Group Ondatry: High profile targets and custom payment forms URLs | url hxxps://bellanatura[.]shop/health_check[.]php; hxxps://branchbrookpharmacy[.]com/pub/health_check[.]php; hxxps://byyvonn[.]nl/health_check[.]php; hxxps://cantes[.]com[.]br/pub/health_check[.]php; hxxps://casamilanoitaly[.]com/health_check[.]php; hxxps://galantha[.]nl/health_check[.]php; hxxps://giftboxedwines[.]com/health_check[.]php; hxxps://larecetta[.]com/pub/health_check[.]php; hxxps://magiglide[.]nl/health_check[.]php; hxxps://mercadoespiao[.]com[.]br/health_check[.]php; hxxps://missy-x[.]com/pub/health_check[.]php; hxxps://www[.]decentcustom[.]com/pub/health_check[.]php; hxxps://www[.]derickdesign[.]com/health_check[.]php; hxxps://www[.]dianahunt[.]hu/pub/health_check[.]php; hxxps://www[.]efashionwholesale[.]com/pub/health_check[.]php; hxxps://www[.]hakpro[.]nl/pub/health_check[.]php; hxxps://www[.]hebery[.]com/pub/health_check[.]php; hxxps://www[.]rtechmx[.]com/pub/health_check[.]php; hxxps://zetabg[.]com/pub/health_check[.]php Compromised merchant relay URLs reported by Sansec, not an attacker-ownership list or independently verified victim disclosure. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1] |
| Group Polyovki: Basic embed of cdnstatics.net URLs | url hxxps://cdnstatics[.]net/lib[.]js; hxxps://cdnstatics[.]net/index[.]php?zz= Historical source-defined cluster, not a universal Magecart actor alias. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1] |
| Group Bobry: Hidden in plain sight URLs | url hxxps://statspots[.]com/get/?s=; hxxps://quantunnquest[.]com/img/; hxxps://analytisgroup[.]com/img/; hxxps://analytisweb[.]com/img/; hxxps://bytesbazar[.]com/img/; hxxps://chartismart[.]com/get/?s=; hxxps://codecarawan[.]com/img/; hxxps://creativeslim[.]com/img/; hxxps://creatls[.]com/get/?s=; hxxps://cssmagic[.]shop/get/?s=; hxxps://cssmagic[.]shop/img/; hxxps://datifyny[.]com/img/; hxxps://dealhunt[.]website/get/?s=; hxxps://desiqnia[.]shop/img/; hxxps://desynlabtech[.]com/img/; hxxps://getstylify[.]com/get/?s=; hxxps://graphiqsw[.]com/img/; hxxps://happyllfe[.]online/get/?s=; hxxps://horlzonhub[.]com/get/?s=; hxxps://javaninja[.]shop/get/?s=; hxxps://marketiqhub[.]com/img/; hxxps://marketrom[.]shop/get/?s=; hxxps://marketsoilmart[.]com/img/; hxxps://metricsy[.]shop/get/?s=; hxxps://novastraem[.]com/get/?s=; hxxps://radlantroots[.]com/get/?s=; hxxps://sellifypro[.]com/get/?s=; hxxps://sellwisehub[.]com/get/?s=; hxxps://statify[.]online/get/?s=; hxxps://statlstic[.]shop/get/?s=; hxxps://techtnee[.]com/get/?s=; hxxps://trendgurupro[.]com/get/?s=; hxxps://trendor[.]website/img/; hxxps://trendori[.]shop/get/?s=; hxxps://vizualis[.]online/get/?s=; hxxps://www[.]googletagmanager[.]com/gtm[.]js?id=GTM-5T7T9QNG; hxxps://www[.]googletagmanager[.]com/gtm[.]js?id=GTM-5WG336MZ; hxxps://www[.]googletagmanager[.]com/gtm[.]js?id=GTM-K7XN937P; hxxps://www[.]googletagmanager[.]com/gtm[.]js?id=GTM-WTFWGVQ5; hxxps://advertiq[.]shop/get/; hxxps://advertispro[.]com/get/; hxxps://advertls[.]shop/get/; hxxps://artickon[.]shop/get/; hxxps://articon[.]shop/get/; hxxps://artistryhab[.]shop/get/; hxxps://artvislon[.]shop/get/; hxxps://brandilift[.]com/get/; hxxps://brandixi[.]shop/get/; hxxps://bytesbazar[.]com/get/; hxxps://chartify[.]shop/get/; hxxps://chartismart[.]com/get/; hxxps://codcraft[.]shop/get/; hxxps://codecarawan[.]com/get/; hxxps://codegenesis[.]shop/get/; hxxps://codemingle[.]shop/get/; hxxps://countilancer[.]com/get/?s=; hxxps://countora[.]shop/get/; hxxps://creatls[.]com/get/; hxxps://creatlva[.]shop/get/; hxxps://cssmagic[.]shop/get/; hxxps://datagen[.]shop/get/; hxxps://datawiz[.]shop/get/; hxxps://dealhunt[.]website/get/; hxxps://designlq[.]com/get/; hxxps://desiqnia[.]shop/get/; hxxps://desynlabtech[.]com/get/; hxxps://evaluatemingle[.]com/get/; hxxps://feedbackharvest[.]com/get/; hxxps://getstylify[.]com/get/; hxxps://gettinfo[.]com/get/?s=; hxxps://graphig[.]shop/get/; hxxps://graphiqsw[.]com/get/; hxxps://graphisprintstudio[.]com/get/; hxxps://graphize[.]shop/get/; hxxps://graphlq[.]shop/get/; hxxps://happyllfe[.]online/get/; hxxps://happynast[.]shop/get/; hxxps://happywave[.]shop/get/; hxxps://horlzonhub[.]com/get/; hxxps://insightharvesters[.]com/get/; hxxps://javaninja[.]shop/get/; hxxps://joyfullday[.]shop/get/; hxxps://luckipath[.]shop/get/; hxxps://luckkystar[.]shop/get/; hxxps://luckycharm[.]website/get/; hxxps://marketexpert[.]site/get/; hxxps://marketiqhub[.]com/get/; hxxps://marketro[.]shop/get/; hxxps://marketsoilmart[.]com/get/; hxxps://merchifly[.]shop/get/; hxxps://metricelevate[.]com/get/; hxxps://metricsy[.]shop/get/; hxxps://myhapperflowers[.]com/get/; hxxps://novastraem[.]com/get/; hxxps://pixelia[.]shop/get/; hxxps://pixella[.]shop/get/; hxxps://pixelsmith[.]shop/get/; hxxps://protocolhubinfo[.]com/get/?s=; hxxps://radlantroots[.]com/get/; hxxps://reviewharborhub[.]com/get/; hxxps://salesguru[.]online/get/; hxxps://secunnet[.]shop/get/; hxxps://seilsmart[.]shop/get/; hxxps://sellifypro[.]com/get/; hxxps://selllify[.]shop/get/; hxxps://selloria[.]shop/get/; hxxps://statify[.]shop/get/; hxxps://statistall[.]com/get/; hxxps://statlstic[.]shop/get/; hxxps://statmaster[.]shop/get/; hxxps://statspots[.]com/get/; hxxps://styllize[.]shop/get/?s=; hxxps://techtnee[.]com/get/; hxxps://trendgurupro[.]com/get/; hxxps://trendori[.]shop/get/; hxxps://trendset[.]website/get/; hxxps://vodog[.]shop/get/ Historical source-defined cluster, not a universal Magecart actor alias. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1] |
| Group Surki: Answer of life websockets URLs | url wss[:]//accept[.]bar/common; wss[:]//amocha[.]xyz/common; wss[:]//cd[.]iconstaff[.]top/m; wss[:]//cdn-webstats[.]com/ls; wss[:]//cdn[.]iconstaff[.]top/common; wss[:]//cdn[.]inspectdlet[.]net/ws; wss[:]//clearnetfab[.]net/common; wss[:]//cloudflare-stat[.]net/common; wss[:]//fallodick87-78[.]sbs/common; wss[:]//iconstaff[.]top/common; wss[:]//jquerypackageus[.]com/common; wss[:]//jqueryuslibs[.]com/common; wss[:]//jstatic201[.]com/common; wss[:]//lererikal[.]org/common; wss[:]//mamatmavali[.]ru/common; wss[:]//nothingillegal[.]bond/common; wss[:]//paie-locli[.]com/s; wss[:]//sellerstat[.]site/wss; wss[:]//shoponlinemelike[.]shop/common; wss[:]//statsseo[.]com/common; wss[:]//statstoday[.]org/common; wss[:]//vincaolet[.]xyz/socket; wss[:]//webexcelsior[.]org/common; hxxps://udalzira[.]com/[.]well-known/cloud[.]js Historical source-defined cluster, not a universal Magecart actor alias. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1] |
| Group Khomyaki: Two letter exfil (JSC) URLs | url //app[.]chwine[.]dev/us/; //cdn[.]myshopper[.]io/bo/; //fatrade[.]net/re/; //hostnotify[.]io/mu/; //img[.]wisepops[.]co/mo/; //infiniboosts[.]com/bu/; //itsemma[.]io/gb/; //m[.]bingforce[.]org/jo/; //m[.]bingforce[.]org/to/; //rextension[.]net/za/; //servicetoast[.]net/ne/; //sourcetrap[.]net/tu/; //subsales[.]net/qe/; //t[.]gearplace[.]net/fe/; //tag[.]convertpro[.]org/be/; //tag[.]wealthleaderinc[.]com/da/; //tr[.]hostnotify[.]io/nr/; //web[.]bystats[.]io/he/; //web[.]foptimize[.]net/we/; //www[.]consentime[.]com/br/; //www[.]ge4cdn[.]com/vu/; //www[.]myshopper[.]io/gb/; //www[.]youpilot[.]org/pg/ Historical source-defined cluster, not a universal Magecart actor alias. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1] |
| Group Khomyaki: Two letter exfil (JSC) addresses | ip address 82[.]202[.]165[.]8; 82[.]202[.]165[.]96; 82[.]202[.]165[.]55; 82[.]202[.]165[.]43; 82[.]202[.]165[.]36; 82[.]202[.]165[.]48; 82[.]202[.]161[.]191; 82[.]202[.]161[.]175; 82[.]202[.]161[.]192; 82[.]202[.]162[.]237; 82[.]202[.]163[.]228; 82[.]202[.]165[.]158; 82[.]202[.]165[.]152 Historical source-defined cluster, not a universal Magecart actor alias. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1] |
| Group Laski: Fake maintenance pages URLs | url hxxps://deslgnhq[.]com/; hxxps://markettz[.]com/; hxxps://sellquestor[.]com/jquery[.]min[.]js Historical source-defined cluster, not a universal Magecart actor alias. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1] |
| Group Laski: Fake maintenance pages domains | domain fqdn brandmynxt[.]com; countifyhub[.]com; creatowebhub[.]com; cssucess[.]com; datageen[.]com; datallqs[.]com; datavibers[.]com; desiginfest[.]com; designmetrlcs[.]com; designospro[.]com; deslgnhq[.]com; desynifynet[.]com; desynity[.]com; desynsy[.]com; graphwebpad[.]com; graphwebpro[.]com; graphorix[.]com; htmledge[.]com; marketgoweb[.]com; marketicsy[.]com; marketisplay[.]com; marteton360[.]com; marketprome[.]com; markettz[.]com; marketxxx[.]com; pixeloramy[.]com; pixelprosstudio[.]com; salesflowe[.]com; sellarcs[.]com; sellllink[.]com; selllvibe[.]com; sellpathhub[.]com; sellsageapp[.]com; sellspotweb[.]com; sellquestor[.]com; statdynanics[.]com; statepulseapp[.]com; statgennius[.]com; statibuzz[.]com; statrackers[.]com; visualldata[.]com Historical source-defined cluster, not a universal Magecart actor alias. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1] |
| Full list of attack indicators URLs | url hxxps://checkout[.]lat/log[.]xml; hxxps://fars[.]ee/WuBQ[.]dtd; hxxps://m37gg41n[.]c5[.]rs/?exploited=%data Historical aggregate; campaign assignment and current reputation are not independently established. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1] |
| Full list of attack indicators addresses | ip address 104[.]36[.]229[.]32; 112[.]213[.]127[.]253; 116[.]49[.]75[.]88; 118[.]179[.]100[.]161; 129[.]208[.]21[.]161; 141[.]98[.]81[.]24; 141[.]98[.]82[.]3; 142[.]252[.]84[.]169; 146[.]185[.]207[.]94; 146[.]190[.]165[.]100; 159[.]223[.]136[.]255; 162[.]241[.]71[.]133; 165[.]231[.]182[.]98; 168[.]138[.]113[.]116; 172[.]104[.]28[.]240; 172[.]93[.]40[.]2; 173[.]255[.]242[.]28; 18[.]143[.]139[.]116; 184[.]31[.]15[.]39; 184[.]31[.]15[.]70; 185[.]125[.]50[.]108; 185[.]193[.]126[.]86; 185[.]208[.]158[.]16; 185[.]81[.]128[.]36; 192[.]82[.]21[.]247; 193[.]233[.]128[.]167; 193[.]233[.]129[.]150; 193[.]233[.]130[.]84; 193[.]233[.]216[.]201; 193[.]233[.]217[.]12; 193[.]233[.]91[.]78; 193[.]93[.]193[.]74; 194[.]55[.]186[.]174; 198[.]44[.]129[.]83; 198[.]98[.]48[.]53; 20[.]55[.]20[.]233; 200[.]109[.]156[.]28; 201[.]21[.]152[.]152; 202[.]138[.]73[.]99; 213[.]252[.]247[.]133; 217[.]148[.]142[.]54; 217[.]170[.]197[.]30; 217[.]182[.]199[.]126; 23[.]1[.]236[.]21; 23[.]1[.]236[.]31; 23[.]213[.]246[.]132; 23[.]219[.]77[.]202; 23[.]39[.]209[.]109; 23[.]39[.]209[.]113; 23[.]45[.]233[.]38; 23[.]46[.]157[.]161; 31[.]134[.]11[.]12; 31[.]134[.]11[.]69; 31[.]134[.]13[.]106; 31[.]134[.]2[.]109; 31[.]134[.]6[.]39; 31[.]134[.]8[.]214; 37[.]9[.]41[.]91; 37[.]9[.]42[.]158; 37[.]9[.]43[.]23; 37[.]9[.]44[.]76; 45[.]10[.]160[.]45; 45[.]90[.]58[.]1; 5[.]181[.]124[.]181; 51[.]81[.]126[.]7; 67[.]223[.]117[.]91; 68[.]224[.]33[.]168; 82[.]112[.]245[.]109; 85[.]239[.]43[.]38; 85[.]239[.]43[.]55; 89[.]110[.]87[.]211; 89[.]23[.]99[.]251; 91[.]218[.]123[.]68; 91[.]92[.]243[.]104; 91[.]92[.]243[.]83; 91[.]92[.]244[.]237; 91[.]92[.]247[.]205; 91[.]92[.]251[.]28; 92[.]112[.]184[.]102; 95[.]216[.]102[.]239; 15[.]204[.]207[.]175; 89[.]110[.]84[.]168 Historical aggregate; campaign assignment and current reputation are not independently established. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1] |
| Full list of attack indicators domains | domain fqdn advertiq[.]shop; advertispro[.]com; advertls[.]shop; anality-google[.]com; artickon[.]shop; articon[.]shop; artistryhab[.]shop; artvislon[.]shop; bingforce[.]org; brandilift[.]com; brandixi[.]shop; bystats[.]io; bytesbazar[.]com; cdnstatics[.]net; chartify[.]shop; chartismart[.]com; codcraft[.]shop; codecarawan[.]com; codegenesis[.]shop; codemingle[.]shop; countilancer[.]com; countora[.]shop; creatls[.]com; creatlva[.]shop; cssmagic[.]shop; datagen[.]shop; datawiz[.]shop; dealhunt[.]website; designlq[.]com; desiqnia[.]shop; desynlabtech[.]com; easttrack[.]net; evaluatemingle[.]com; feedbackharvest[.]com; foptimize[.]net; gearplace[.]net; getstylify[.]com; gettinfo[.]com; graphig[.]shop; graphiqsw[.]com; graphisprintstudio[.]com; graphize[.]shop; graphlq[.]shop; graphorix[.]com; happyllfe[.]online; happynast[.]shop; happywave[.]shop; horlzonhub[.]com; infiniboosts[.]com; insightharvesters[.]com; javaninja[.]shop; joyfullday[.]shop; luckipath[.]shop; luckkystar[.]shop; luckycharm[.]website; marketexpert[.]site; marketiqhub[.]com; marketro[.]shop; marketsoilmart[.]com; merchifly[.]shop; metricelevate[.]com; metricsy[.]shop; myhapperflowers[.]com; novastraem[.]com; pixelia[.]shop; pixella[.]shop; pixeloramy[.]com; pixelsmith[.]shop; protocolhubinfo[.]com; quantlive[.]net; radlantroots[.]com; registertime[.]net; reviewharborhub[.]com; rextension[.]net; ruleslaw[.]org; saleapi[.]org; salesguru[.]online; sdtrack[.]io; secunnet[.]shop; seilsmart[.]shop; sellifypro[.]com; selllify[.]shop; selloria[.]shop; servicetoast[.]net; stackapt[.]com; statepulseapp[.]com; staticforce[.]org; statify[.]shop; statistall[.]com; statlstic[.]shop; statmaster[.]shop; statspots[.]com; styllize[.]shop; techtnee[.]com; trendgurupro[.]com; trendori[.]shop; trendset[.]website; vodog[.]shop; wealthleaderinc[.]com; yotpont[.]com Historical aggregate; campaign assignment and current reputation are not independently established. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1] |
| cosmicsting_inline_historical_markers | network behavior wss[:]//jgueurystatic[.]xyz:8101; __ffsj; hxxps://106[.]14[.]40[.]200/?prod_hash=<data>; cardnumber-kao153; securitycode-kao153; holder-kao153; expirationdate-kao153; cardbutton-kao153; 185[.]175[.]225[.]116; 142[.]252[.]84[.]169; 2600:3c01::f03c:95ff:fede:ddb8 Historical source-defined Burunduki/Peschanki/Polyovki and scanner markers. The data placeholder is not an actual stolen value; legitimate payment-field identifiers alone are insufficient for compromise findings. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1] |
| cosmicsting_malformed_url_domain | domain fqdn venum[.]com[.]cn The source prints a duplicated https scheme for this endpoint. Only the domain is retained; the malformed URL is not silently corrected or validated. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1] |
| Historical CosmicSting process masquerading | host artifact .config/htop/defunct.dat; [slub_flushwq]; [raid5wq]; [card0-crtc8]; [netns]; [kswapd0] Historical CosmicSting process masquerading Kernel-thread-like names also have legitimate uses; correlate executable provenance and user-space behavior.[1] |
| SessionReaper diagnostic fragments | host artifact E:\Tools\eclipse\php7.3\ext\php_bz2.dll; pub/media/customer_address/s/e/setest SessionReaper diagnostic fragments Researcher describes a non-working test and diagnostic leakage. Not a universal successful-compromise signature.[33] |
| DEFION claim-specific browser and plugin markers | identity session wjxq_; front_inc; all_plugins; pre_user_query; lu; Cart number DEFION claim-specific browser and plugin markers Cookie name, script handle, standard filters and UI typo need case context. No activation credential or decryption key is included.[29] |
| DEFION suspected distribution context | domain fqdn wordpressnull[.]org; activations.ultrapackv2[.]com DEFION suspected distribution context Suspected nulled-plugin origin, not a proven causal attribution. Never download from these endpoints.[29] |
| DEFION shared RPC context | network behavior bsc-testnet-rpc.publicnode[.]com; data-seed-prebsc-1-s1.bnbchain[.]org:8545; eth_call DEFION shared RPC context Legitimate shared RPC infrastructure; correlate exact contracts and unexpected checkout behavior, not blanket domain blocking.[29] |
| CosmicSting DOM context | behavioral detection checkout-payment-method-load; payment_method_container; checkout-payment-method; checkout-payment-step; paymentMethodContainer; HOOK_ADVANCED_PAYMENT; HOOK_SHOPPING_CART; payment-method; st-checkout-payment-step; klarna-checkout-container CosmicSting DOM context Legitimate payment selectors are not malicious alone; correlate unauthorized hiding or replacement.[1] |
Threat Actor Glossary
| Focus | Evidence and implications |
|---|---|
| Magecart | Umbrella label Do not equate the entire umbrella with FIN6/G0037 or any single operator. Imported aliases in the existing MageCart card are not adopted as identity evidence in this edition. |
| Researcher labels | CosmicSting and TrojanOrders operators Sansec describes distinct operator clusters. Its CosmicSting overview uses Ondatry, Polyovki, Bobry, Surki, Khomyaki, Burunduki, Belki, Laski and Peschanki. These are source-defined labels, not independently reconciled identities.[1] [23] |
| 2026 examples | Keep intrusion sets separate PolyShell is not a settled actor identity. SVG and WebRTC entry-vector assessments remain qualified. The August WordPress cases are separate observations; shared WebRTC use does not connect their operators.[11] [13] [14] [29] [30] |
Talking Points
| Focus | Evidence and implications |
|---|---|
| Business briefing | Questions leaders should ask What code did customers receive? Which fields could it observe? What proves the exposure window? Are server persistence and secret exposure resolved? What evidence supports customer-impact statements? |
| Payment architecture | Hosted checkout still needs validation Document the provider-hosted boundary and the merchant-controlled journey around it. Keep browser skimming and stored-data compromise distinct. |
| Remediation assurance | Require evidence of completion A base version, successful checkout or absence of a known domain does not prove recovery. Require patch-coverage evidence and verification of authorized checkout behavior.[19] |
Decision Ready Actions
| Focus | Evidence and implications |
|---|---|
| Engineering · same business day | Produce a patch-coverage record Record exact storefront, CE/EE/B2B and Commerce Events versions; identify the applicable vendor packages and July-to-August sequence. Test changes through the emergency-change process when exposed. Completion evidence: a version-tool result and package/component record, not merely a successful checkout.[18] [19] [32] |
| Incident response · immediately when compromise is suspected | Preserve and contain before cleanup Capture authorized code/configuration history and relevant logs before removal. Restrict the affected payment journey or isolate compromised systems according to incident severity. Completion evidence: preserved artifacts, a supported exposure window and a documented containment decision. Absence of a listed IOC does not close the incident.[11] [12] [13] [14] [24] |
| Platform owner · before declaring recovery | Validate server and customer-browser integrity Remove unauthorized persistence, remediate applicable secret exposure under vendor guidance and verify checkout from the customer’s perspective. Completion evidence: trusted-code comparison, appropriate secret remediation and browser/network observations showing only authorized behavior.[19] [24] |
| Claims, counsel and payment-security lead · during scoping | Approve a fact-bounded impact statement Distinguish possible field visibility, submitted values, demonstrated exfiltration, stored-data access, fraud and operational loss. Completion evidence: a statement of confirmed facts and explicit unknowns, with reporting decisions handled through the authorized process. |
Exploitable Technology Risks
| Focus | Evidence and implications |
|---|---|
| Priority exposure | Platform and administrator control Review exploited platform vulnerabilities, reachable APIs, upload handling, extensions and administrator access. Apply vulnerability-specific severity rather than a universal Magecart CVSS score.[3] [11] [20] [22] |
| Residual exposure | Secrets and persistence Review server backdoors, unauthorized CMS content, browser state and application-secret remediation. Installing a fix does not establish that earlier abuse was removed.[12] [24] |
| Visibility gaps | Inline and runtime behavior Include inline content, overlays, browser storage and unexpected non-HTTP channels. Public RPC services or Blob execution are contextual signals, not automatic proof of compromise.[13] [14] [29] [30] |
| Data scope | Stored payment artifacts Assess stored-data exposure separately through authorized responders. Public reporting does not establish the contents of a particular merchant’s stored payment records. |
Tier 0 Through Tier 8 Source Summary
| Focus | Evidence and implications |
|---|---|
| Tier 0 | Canonical registries NVD, CISA and MITRE support canonical metadata and qualified technique mapping. CISA JSON was retrieved directly with HTTP 200 and its three retained KEV entries checked. NVD direct requests returned thin pages; retain the earlier indexed evidence with Adobe/CISA controlling consequential facts. |
| Tier 1 | Primary authorities Canadian Cyber Centre. Supports: Government corroboration. Limitations: Broader government walk incomplete; one version conflict retained. |
| Tier 2 | Vendor/research registry Akamai; Malwarebytes lineage. Supports: Configuration-dependent PolyShell context. Limitations: Malwarebytes retained URL failed. |
| Tier 3 | Independent news BleepingComputer lineage. Supports: Historical citation preservation. Limitations: Retained article unresolved. |
| Tier 4 | Public social/community None promoted. Supports: No output claims depend on social evidence. Limitations: Walk incomplete; no authenticated access. |
| Tier 5 | User-defined URLs No custom URL inputs were configured for this direct repair. No claim about other workspace or tenant configurations. |
| Tier 6 | Keyed integrations No keyed integrations were used for this direct repair. Public-source evidence only; no claim about tenant-wide connector readiness. |
| Tier 7 | Unlisted-domain discovery Sansec, Adobe, PCI SSC, SecurityMetrics, Qualys, DEFION, Source Defense, Stamus. Supports: Original research, vendor/standards evidence and preserved lineage. Limitations: Not predefined registry authorities; role determines weight; some retrievals failed. |
| Tier 8 | Expansion Research Expansion Research: DEFION and Source Defense add distinct WordPress/WooCommerce detection comparisons. Original discovery remains Tier 7; this retained contribution is separately labeled Tier 8 and does not override Adobe or merge campaigns. |
Source Deconfliction
| Focus | Evidence and implications |
|---|---|
| Patch chronology | Prefer explicit dated remediation Sansec’s dated 2.4.9 correction supersedes its older no-production-fix prose. March and July bulletins remain historical context. Canadian AV26-808 lists some August Commerce versions as affected, conflicting with Adobe’s August solution matrix; Adobe controls patch selection.[11] [15] [18] [32] [35] |
| SessionReaper status | Old no-exploitation prose is stale The detailed Adobe article retains September no-exploitation wording despite a later update wrapper. APSB25-88 explicitly acknowledges exploitation and records the October revision; that acknowledgement controls.[20] [21] [34] |
| Population and chronology | Unresolved population and date differences The SVG headline reports 99 stores but its domain rows total 76; allocation and overlap remain unexplained. PolyShell’s probing and scanning dates also conflict internally. The evidence supports neither a corrected total nor a universal first-seen date.[11] [13] |
| Control limitations | Avoid absolute invisibility claims DEFION’s own findings include database and plugin traces, so its broad invisibility language is not adopted. Source Defense explicitly qualifies Blob execution as dependent on CSP configuration. Ordinary HTTP monitoring alone does not cover all observed channels.[14] [29] [30] |
| Attribution | Imported labels require independent evidence Stamus’s FIN6/Magecart wording and the related card’s alias list do not override the umbrella boundary. Similar techniques and shared hosting cannot resolve actor identity.[31] |
| Literal indicator errors | Do not repair source strings silently The CosmicSting overview prints 157.230.230.193q and a duplicated https scheme for venum.com.cn. The malformed address is excluded from normalized IPs; the latter domain is retained without claiming the malformed URL is valid. Query placeholders are not collected victim data.[1] |
| Extraction exclusions | Code properties and partial service links are not IOC endpoints The JavaScript property location.hostname is excluded from domains. A truncated Google Translate query is excluded from endpoint matching: the legitimate translation service alone is not an attacker indicator. Protocol-relative paths and open-ended query prefixes elsewhere remain literal hunting patterns, not complete validated destinations.[1] |
| SessionReaper execution precondition | The researcher’s reproduced RCE path appears to require file-based sessions; Redis or database sessions do not establish general immunity. Its historical residual-upload warning is distinct from proving code execution after patching.[33] |
| August advisory metadata | Adobe’s authentication/admin columns and vectors are not always equivalent: 48414, 48411 and 48412 list admin access while some vectors show PR:L. Preserve the vendor fields and seek vendor clarification when assessing prerequisites; do not silently rewrite the vector.[18] |
| Expansion chronology | DEFION’s relative deployment timestamps describe one anonymous WordPress case; its broad invisibility and automation assertions are not independently adopted. Source Defense’s August 9 publication describes a different Polygon-based chain, not the same BSC/WebRTC operator.[29] [30] |
About the Contributors
| Focus | Evidence and implications |
|---|---|
| Adobe | Highest weight for product remediation The product vendor defines affected versions, fixes and installation prerequisites. Explicit revisions outrank stale paragraphs elsewhere in its documentation; inconsistencies remain identified.[3] [15] [18] [19] [20] [21] [22] [24] [27] [32] |
| Sansec | High weight for its observed ecommerce cases Original campaign observations and defensive artifacts. Commercial telemetry, changing overview pages and inconsistent denominators limit population and chronology claims. Cluster labels remain source-defined.[1] [11] [12] [13] [14] [23] [33] [37] |
| NVD, CISA and MITRE | Canonical metadata and framework context These sources support vulnerability status and technique definitions; they do not prove compromise of a particular merchant. Retrieval limitations are recorded per source.[4] [17] [25] [26] [36] |
| PCI SSC and SecurityMetrics | Standards authority and practitioner context PCI SSC’s announcement supports payment-page governance context, but it cannot substitute for the inaccessible standard. SecurityMetrics is practitioner guidance, not a replacement standards authority.[6] [7] [16] |
| Akamai, DEFION and Source Defense | Configuration and comparator research Akamai corroborates PolyShell’s execution prerequisites. DEFION and Source Defense add separate WordPress/WooCommerce observations. Their claims are bounded to the described cases.[28] [29] [30] |
| Other retained sources | Source-specific limitations Canadian advisories corroborate vendor awareness but contain a version discrepancy. Stamus supplies detection-release context only. Failed historical Malwarebytes, BleepingComputer and Qualys URLs are preserved without treating their contents as newly verified.[8] [9] [10] [31] [34] [35] |
Real World Examples
| Focus | Evidence and implications |
|---|---|
| Historical Magento cases | CosmicSting and TrojanOrders Examples of why platform fixes and removal of post-compromise access are different tasks. Historical operator and infrastructure evidence must retain its original scope.[1] [23] [37] |
| 2026 Magento evidence | Compromise, overlay and WebRTC examples The 471-store wave, 99-store SVG report and anonymous manufacturer investigation describe separate source-observed sets. Do not combine their counts or transfer one case’s access path to another.[12] [13] [14] |
| August comparators | WordPress/WooCommerce DEFION describes a database/plugin loader and BSC Testnet/WebRTC delivery. Source Defense describes Polygon-based destination resolution, Blob execution and image-request exfiltration. These are distinct from the Magento cases and from each other.[29] [30] |
Public Victims / Disclosure Matrix
| Focus | Evidence and implications |
|---|---|
| 471 stores | Sansec-observed compromise wave Retained source-specific aggregate; not 471 independently confirmed customer-data theft events.[12] |
| 99 stores | Sansec SVG campaign headline The headline reports 99 stores, while the displayed domain rows total 76. The source does not explain the allocation or overlap; these figures cannot be added or treated as separately verified populations.[13] |
| Anonymous manufacturer | WebRTC case Preserve anonymity and the researcher’s reporting boundary. No independent victim disclosure or customer-loss total was established.[14] |
| Anonymous WordPress store | DEFION comparator The client is anonymized. No business-size classification, exact incident start or connection to the Magento population is established.[29] |
| Historical CosmicSting examples | Infrastructure is not independent victim confirmation Sansec’s source-defined clusters include merchant relay URLs. Their presence is retained as historical infrastructure context with a compromised/shared-infrastructure warning, not a new victim disclosure, attacker ownership finding or confirmation of customer loss. No additional named victim is asserted from those URLs.[1] |
KEV and CVE Details
| Focus | Evidence and implications |
|---|---|
| CVE-2025-54236 | CISA KEV confirmed Added 2025-10-24; federal deadline 2025-11-14. CISA ransomware-use field: Unknown. Catalog dates are not first-exploitation dates; follow the vendor remediation and investigate actual exposure.[39] Read source |
| CVE-2024-34102 | CISA KEV confirmed Added 2024-07-17; federal deadline 2024-08-07. CISA ransomware-use field: Unknown. Catalog dates are not first-exploitation dates; follow the vendor remediation and investigate actual exposure.[39] Read source |
| CVE-2022-24086 | CISA KEV confirmed Added 2022-02-15; federal deadline 2022-03-01. CISA ransomware-use field: Unknown. Catalog dates are not first-exploitation dates; follow the vendor remediation and investigate actual exposure.[39] Read source |
MITRE ATT&CK Lifecycle Mapping
| Focus | Evidence and implications |
|---|---|
| Access and persistence | Evidence before mapping Determine whether access came through application exploitation, administration or a third party. Map web shells and unauthorized code persistence only when evidenced; uploaded files do not by themselves prove execution.[11] [28] |
| Execution and collection | Reconstruct browser behavior Identify injected JavaScript, overlays and accessible fields. Use the qualified input-capture mapping in TTPs; framework labels do not establish attribution.[13] [14] [36] |
| Exfiltration and impact | Follow the actual channel Correlate HTTP and non-HTTP behavior with collection evidence. Business impact requires separate transaction, fraud and operational evidence rather than inference from an ATT&CK technique. |
PCI / Hosted Payment / Stored Card Data Notes
| Focus | Evidence and implications |
|---|---|
| Payment-page governance | Requirements 6.4.3 and 11.6.1 PCI SSC’s announcement addresses script authorization, integrity and tamper monitoring, including security-impacting headers and pages surrounding embedded payment iframes. The supplement does not replace or extend the standard.[16] Read source |
| Applicability boundary | Guidance is not an assessment This brief relies on accessible PCI SSC public guidance, not an implementation compliance verdict. The legacy full-standard URL was inaccessible and is retained only as citation lineage. Specific assessment and reporting responsibilities must be confirmed with the organization managing the compliance program.[16] |
| Data and architecture | Keep evidence boundaries separate Hosted payment, tokenization, browser collection and stored-data handling describe different facts. Authorized responders should establish them without transferring private customer data into a public intelligence product. |
Additional IntelliOS Threat Intel Products on This Topic
| Focus | Evidence and implications |
|---|---|
| Actor context | MageCart — Threat Actor Card Existing umbrella-context card. Its imported FIN6/G0037 aliases are not accepted as universal Magecart identity. The umbrella label does not establish a single operator. Read related product |
| Trusted-integration comparison | Klue Supply Chain Attack Existing SaaS/OAuth comparator. The relationship concerns trusted integrations, not shared Magecart operators, infrastructure or initial access. Read related product |
| Trusted-integration comparison | Salesloft Drift OAuth Supply-Chain Attack Existing trusted-integration comparator. Its OAuth campaign and identity claims are not evidence for the Magento incidents. Read related product |
| Vulnerability companion | CVE-2024-34102 Its CosmicSting identity and July 17, 2024 KEV / August 7 deadline match the retained facts. This PANDA adds merchant response, key remediation and source-qualified observables; it is not a new CVE discovery. Read related product |
| Vulnerability companion | CVE-2025-54236 Its SessionReaper identity and October 24, 2025 KEV / November 14 deadline match the retained facts. This PANDA adds patch chronology and source-specific response context, not a new CVE discovery. Read related product |
| Distinct existing coverage | Operation Silent Skimmer It describes Telerik/web-server and payment-database activity, not a proven match to the Magento chains here. It provides a separate skimming comparison, not evidence of common operators. Read related product |
Notes
| Focus | Evidence and implications |
|---|---|
| Evidence handling | Public defensive intelligence Source-reported indicators are included for authorized detection and investigation. No malicious endpoint was contacted, payload executed or victim-private dataset acquired for this product. Embedded executable or sensitive snippets in publisher pages are excluded from the reader. |
| Scope limits | No compliance or environment attestation This product is not a PCI assessment, merchant compromise determination or worldwide census. Source retrieval exceptions, date conflicts and confidence boundaries remain explicit. Unavailable evidence is not reconstructed. |
| Interpretation | No universal blocklist Indicators describe source-time observations. Preserve false-positive and shared-infrastructure warnings, victim anonymity and the distinction between reporting dates and incident dates. |
| Artifact exclusions | Executable snippets, backdoor activation credentials, decryption keys, stolen data and payload-download links are excluded. Standard WordPress filters, generic diagnostic fragments and payment selectors are retained only as contextual leads. Source-template images, marketing claims and unrelated historical CVEs do not establish this campaign’s facts. Historical installer hashes are not malware indicators. |
| Unverified legacy citations | Sources 2, 5–10 include inaccessible or thin legacy records. Their identities remain in Citations for lineage; no new consequential claim relies on them alone. Current official alternatives and original research are cited separately. |
Version Change Log
| Focus | Evidence and implications |
|---|---|
| v2.1 — 5 September 2026 | Patch sequence, chronology and defensive evidence Replaces March-only remediation framing with the May base-release and July/August patch sequence; adds source-qualified historical and 2026 observables; separates Magento evidence from WordPress/WooCommerce comparators; corrects publication/observation boundaries and KEV support.[18] [19] [23] [29] [30] [32] [38] [39] |
| Historical baseline v2.0 — 2026-07-18 | Expanded skimming coverage Added PolyShell, SVG and WebRTC research to the historical Magecart coverage. The current revision retains the distinctions between these source-reported cases. |
| Original publication — 28 April 2026 | First publication of this Magecart / Magento payment-skimming brief. The September revision continues the same product; it is not a newly launched publication. |
Citations
| Reference | Evidence and implications |
|---|---|
| 1 | CosmicSting attack & defense overview Sansec; Tier 7; primary. Publication: Not established / living page. Living source-defined CosmicSting overview. Historical cluster infrastructure and secret-remediation context are retained with shared-infrastructure warnings; malformed address/scheme, a code property and a truncated translation-service link are explicitly excluded. https://sansec.io/research/cosmicsting |
| 2 | TrojanOrders: critical Adobe Commerce/Magento attack Sansec; Tier 7; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. Original baseline URL failed. Its February publication identity is not verified; source 23 is distinct. https://sansec.io/research/trojanorder |
| 3 | Adobe Commerce security bulletin APSB24-40 Adobe; Tier 7; primary. Publication: 2024-06-11. Historical vendor scope and fixes for CosmicSting; explicit exploitation acknowledgement. Priority changes are not changes to CVSS severity. https://helpx.adobe.com/security/products/magento/apsb24-40.html |
| 4 | CVE-2024-34102 Detail NIST NVD; Tier 0; primary. Publication: 2024-06-13. Research role: canonical_registry. CVE metadata and KEV addition/deadline. Record modification is separate from exploitation chronology. https://nvd.nist.gov/vuln/detail/CVE-2024-34102 |
| 5 | APSB24-40 isolated patch and key rotation guidance Adobe Experience League; Tier 7; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. Retained URL failed; related official guidance is separately cited as source 24. https://experienceleague.adobe.com/en/docs/commerce-knowledge-base/kb/troubleshooting/known-issues-patches-attached/security-update-available-for-adobe-commerce-apsb24-40 |
| 6 | PCI DSS v4.0.1 Requirements and Testing Procedures PCI Security Standards Council; Tier 7; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. HTTP 403. Full requirements and testing-procedure validation remain blocked. https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0_1.pdf |
| 7 | PCI DSS 4.0 Requirements 6.4.3 and 11.6.1 guidance SecurityMetrics; Tier 7; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. Original URL failed; no publication date inferred. https://www.securitymetrics.com/blog/pci-dss-4-0-requirements-6-4-3-and-11-6-1-everything-you-need-know |
| 8 | Magecart skimming attacks put major payment networks on alert Malwarebytes; Tier 2; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. Original URL failed. The baseline November 2019 date is not newly authenticated. https://www.malwarebytes.com/blog/news/2019/11/magecart-skimming-attacks-put-major-payment-networks-on-alert |
| 9 | Automated Magento attacks compromise stores with web shells BleepingComputer; Tier 3; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. Original URL failed. The baseline September 2020 date is not newly authenticated. https://www.bleepingcomputer.com/news/security/automated-magento-attacks-compromise-stores-with-web-shells/ |
| 10 | Adobe Commerce and Magento Open Source SessionReaper vulnerability Qualys ThreatPROTECT; Tier 7; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. Original URL failed. Vendor and NVD evidence are separately retained. https://threatprotect.qualys.com/2025/09/09/adobe-commerce-and-magento-open-source-sessionreaper-vulnerability-cve-2025-54236/ |
| 11 | PolyShell: unrestricted file upload in Magento and Adobe Commerce Sansec; Tier 7; primary. Publication: 2026-03-17. Configuration-dependent consequences, indicators and a dated fix correction; internal chronology and population wording conflict. https://sansec.io/research/magento-polyshell |
| 12 | Mass PolyShell attack wave hits 471 stores in one hour Sansec; Tier 7; primary. Publication: 2026-03-30. Researcher-observed compromise wave and browser/server artifacts; not a confirmed customer-loss total. https://sansec.io/research/polyshell-mass-attack-wave |
| 13 | SVG Onload Tag Hides Magecart Skimmer on 99 Stores Sansec; Tier 7; primary. Publication: 2026-04-07. Overlay behavior and campaign indicators. Likely initial access is not confirmed; headline and domain-row population totals differ. https://sansec.io/research/svg-onload-magecart-skimmer |
| 14 | Novel WebRTC skimmer bypasses security controls at a major car maker Sansec; Tier 7; primary. Publication: 2026-03-24. Anonymous case, non-HTTP channel and DTLS fingerprint. Entry vector remains assessed; embedded code and credentials excluded. https://sansec.io/research/webrtc-skimmer |
| 15 | Adobe Commerce security bulletin APSB26-05 Adobe; Tier 7; primary. Publication: 2026-03-10. March 10 bulletin, with a later August page wrapper. Retained for historical release chronology only; unrelated vulnerability rows and inconsistent authentication columns do not supply campaign or current-remediation claims. https://helpx.adobe.com/security/products/magento/apsb26-05.html |
| 16 | New Information Supplement: Payment Page Security and Preventing E-Skimming PCI Security Standards Council; Tier 7; primary. Publication: 2025-03-10. Official supplement announcement; does not replace the standard or establish implementation compliance. https://blog.pcisecuritystandards.org/new-information-supplement-payment-page-security-and-preventing-e-skimming |
| 17 | Known Exploited Vulnerabilities Catalog CISA; Tier 0; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. Direct retrieval failed. Individual NVD records corroborate retained entries, not exhaustive current coverage. https://www.cisa.gov/known-exploited-vulnerabilities-catalog |
| 18 | Adobe Commerce security bulletin APSB26-92 Adobe; Tier 7; primary. Publication: 2026-08-11. August remediation and vulnerability metadata; updated August 18. https://helpx.adobe.com/security/products/magento/apsb26-92.html |
| 19 | Security update available for Adobe Commerce — APSB26-92 Adobe Experience League; Tier 7; primary. Publication: Not established / living page. Installation guidance updated August 26; prerequisites, component matching and coverage verification. https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-40380 |
| 20 | Adobe Commerce security bulletin APSB25-88 Adobe; Tier 7; primary. Publication: 2025-09-09. SessionReaper scope, severity and explicit exploitation revision. https://helpx.adobe.com/security/products/magento/apsb25-88.html |
| 21 | Action Required: Critical Security Update Available for Adobe Commerce (APSB25-88) Adobe Experience League; Tier 7; primary. Publication: Not established / living page. Hotfix and module instructions; September content conflicts with its later wrapper and the bulletin’s exploitation status. https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397 |
| 22 | Adobe Commerce security bulletin APSB22-12 Adobe; Tier 7; primary. Publication: 2022-02-13. Historical vulnerability and patch scope; substantive February 17 revision distinct from the later wrapper date. https://helpx.adobe.com/security/products/magento/apsb22-12.html |
| 23 | Adobe Commerce merchants to be hit with TrojanOrders this season Sansec; Tier 7; primary. Publication: 2022-11-15. Distinct November report; health_check.php may be legitimate or abused. Marketing claims and exploit-market acquisition details excluded. https://sansec.io/research/trojanorder-magento |
| 24 | Guidance on securing your store and rotating encryption keys: CVE-2024-34102 Adobe Experience League; Tier 7; primary. Publication: Not established / living page. August 20, 2024 content heading; May 22, 2026 update. Rotation can retain older decryption keys and does not necessarily re-encrypt existing data. https://experienceleague.adobe.com/en/docs/commerce-knowledge-base/kb/troubleshooting/known-issues-patches-attached/guidance-on-securing-your-store-and-rotating-encryptionkeys-cve-2024-34102 |
| 25 | CVE-2022-24086 Detail NIST NVD; Tier 0; primary. Publication: Not established / living page. Research role: canonical_registry. Retrieved record corroborates historical KEV dates. https://nvd.nist.gov/vuln/detail/CVE-2022-24086 |
| 26 | CVE-2025-54236 Detail NIST NVD; Tier 0; primary. Publication: 2025-09-09. Research role: canonical_registry. Direct page empty; substantive indexed NVD content supports retained metadata and KEV dates. https://nvd.nist.gov/vuln/detail/CVE-2025-54236 |
| 27 | Released versions Adobe Experience League; Tier 7; primary. Publication: Not established / living page. Release dates and distinct regular, extended and additional-security support periods; updated August 12. https://experienceleague.adobe.com/en/docs/commerce-operations/release/versions |
| 28 | Magento Polyshell — The Latest Magento Threat (APSB25-94) Akamai; Tier 2; corroborating. Publication: 2026-03-27. Research role: corroborating_research. Corroborates upload versus configuration-dependent execution; defensive rule deployment is not first exploitation. https://www.akamai.com/blog/security-research/magento-polyshell-latest-magento-threat-apsb25-94 |
| 29 | The ghost skimmer: Magecart with blockchain storage and WebRTC delivery DEFION; Tier 7; primary. Publication: 2026-08-20. Research role: primary_comparator. Anonymized WordPress/WooCommerce case; traces and infrastructure support a separate comparator, not Magento attribution. https://defion.security/en/blog/ghost-skimmer-magecart-blockchain-webrtc/ |
| 30 | Blockchain C2 and Fileless Execution Make Magecart Harder to Disrupt Source Defense; Tier 7; primary. Publication: 2026-08-09. Research role: primary_comparator. Separate Polygon/Blob/image-exfiltration report; CSP-dependent evasion, not a universal bypass. https://sourcedefense.com/resources/sd-research/blockchain-c2-and-fileless-execution-make-magecart-harder-to-disrupt/ |
| 31 | Threat Detection Update 25-August-2026 Stamus Networks; Tier 7; contradictory. Publication: 2026-08-25. Research role: deconfliction. Detection-release context. Its FIN6/Magecart equivalence is not adopted. https://www.stamus-networks.com/threat-detection-update-25-august-2026-stamus-networks |
| 32 | Adobe Commerce security bulletin APSB26-73 Adobe; Tier 7; primary. Publication: 2026-07-14. July 14 bulletin supplies the intermediate component patch sequence and Commerce Events 1.6.0–1.20.0 to 1.21.0 remediation. No known exploitation stated. Other July CVE rows are not evidence of the skimming campaigns. https://helpx.adobe.com/security/products/magento/apsb26-73.html |
| 33 | SessionReaper, unauthenticated RCE in Magento and Adobe Commerce Sansec; Tier 7; primary. Publication: Not established / living page. Living SessionReaper research supplies conditional execution prerequisites, source-specific filenames, 25 November addresses, path patterns and a disclosed domain-spelling disagreement. Publication and update dates do not independently establish intrusion onset. https://sansec.io/research/sessionreaper |
| 34 | Adobe security advisory AV25-583 — Update 1 Canadian Centre for Cyber Security; Tier 1; corroborating. Publication: 2025-09-10. Research role: government_corroboration. October 23 update records awareness of exploitation reporting on October 22; not first exploitation. https://www.cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av25-583 |
| 35 | Adobe security advisory AV26-808 Canadian Centre for Cyber Security; Tier 1; contradictory. Publication: 2026-08-12. Research role: deconfliction. Commerce affected-version wording conflicts with Adobe’s August matrix; vendor guidance controls remediation. https://www.cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-808 |
| 36 | Input Capture: Web Portal Capture — T1056.003 MITRE ATT&CK; Tier 0; contextual. Publication: Not established / living page. Research role: framework. Credential-collection definition used to qualify the baseline’s payment-form mapping. https://attack.mitre.org/techniques/T1056/003/ |
| 37 | Persistent backdoors injected on Adobe Commerce via new CosmicSting attack Sansec; Tier 7; primary. Publication: 2024-08-27. Historical chained-compromise case, August log evidence and defensive persistence/network artifacts; not a September 2026 event. https://sansec.io/research/cosmicsting-cnext-persistent-backdoor |
| 38 | Adobe Commerce security update APSB26-49 Adobe; Tier 7; primary. Publication: 2026-05-12. May base-release matrix: Commerce 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17 and 2.4.4-p18. Later July and August patches remain separate prerequisites. August page wrapper is not the initial disclosure. https://helpx.adobe.com/security/products/magento/apsb26-49.html |
| 39 | CISA Known Exploited Vulnerabilities JSON catalog CISA; Tier 0; primary. Publication: 2026-09-04. Direct HTTP 200 retrieval verified the three retained CVEs, their KEV dates and deadlines. Ransomware campaign use is Unknown for all three; this is not a statement that ransomware use never occurred. https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json |

Social Media / Community Signals
Limits of community evidence
No public social post controls a factual claim in this edition. That does not establish absence of relevant discussion. Authenticated communities, leak datasets and exploit or sample repositories were not used.
Research and registries are not social sources
Sansec research and CISA KEV belong in their respective evidence roles, not in a social-evidence count. Stamus’s detection update does not establish a new victim event or validate its FIN6/Magecart equivalence.[17] [31]