IntelliOS Threat Intel Operating System
Sign In
© 2026 IntelliOS
AboutBlogsInsightsNewsroomContactLegal
IntelliOSPANDAModule|AIFlash Threat Intel Brief

Magecart / Magento Payment Skimming

Magecart is payment-skimming activity: unauthorized checkout code captures information a shopper enters, potentially before the legitimate payment completes. It describes multiple operators and access paths, not one newly published campaign. An attacker first needs a way to alter the storefront or code it loads; the shopper may then do nothing unusual beyond checking out.

Source-backed intelligenceSMB / MSP relevance
PUBLIC SOURCE WATCHAI
PANDAPETRAATLASFORGE
Edition
v2.1 · Updated 5 September 2026
Originally published
28 April 2026
Evidence
Public sources • source-bounded
Product
Flash Threat Intel Brief

Research Framing

Research Framing
FocusEvidence and implications
Decision question

Does platform exposure warrant incident investigation?

Should an organization with Magento or Adobe Commerce exposure investigate both server compromise and browser checkout integrity, and what evidence would establish the affected payment flow?

Interpreted questions

Exposure, evidence and response

Which vulnerabilities and configurations apply? What patches and prerequisites are required? What exploitation is confirmed? Which dates describe publication, observation or remediation? What artifacts support detection? What is known about actors, victims and related IntelliOS coverage?

Initial observations

Distinct evidence streams

Current Adobe guidance changes the patch-selection decision. Historical server compromise and separate browser-skimming reports require different evidence and response paths. PolyShell, SVG, WebRTC and WordPress examples are not one proven intrusion chain.[11] [12] [13] [14] [18] [19] [29] [30]

Evidence hierarchy

Authority depends on the question

Use Adobe for remediation and product scope, canonical vulnerability records for CVE and KEV metadata, original researchers for their observations, and PCI SSC for payment-security guidance. News and commercial summaries cannot resolve contradictory primary evidence by repetition. Registry tier and evidentiary authority are separate attributes.[3] [4] [16] [18] [20] [22] [25] [26]

Fact, analysis and unknown

Keep inference visible

Source-observed compromise is not proof of every shopper’s data theft. A vulnerability’s KEV status is not proof that a particular store was exploited. Similar code, infrastructure services or campaign names do not establish common operators. Discovery and sample-submission dates remain unavailable unless explicitly supported. No victim size or attribution is inferred from leak-site claims.

Tier 0–8 coverage

Scoped research with explicit coverage limits

Topic-specific primary evidence is retained with source-level exceptions. The 381-entry registry was screened through grouped domain-restricted searches; indexed screening is not direct review of all advisory feeds or proof of absence. No custom URLs or keyed integrations were used. DEFION and Source Defense are Tier 7 discovery retained separately as Tier 8 Expansion Research comparators.

Magecart Exposure Snapshot

Magecart Exposure Snapshot
FocusEvidence and implications
Primary surface

Checkout and its supporting systems

Magento/Adobe Commerce applications, checkout templates, CMS content, extensions, third-party scripts, administrator workflows and browser state.[1] [11] [12] [13] [14]

Current decision

Validate remediation and earlier exposure

Use the vendor sequence in CVE / Vulnerability References, then investigate the pre-remediation window and residual persistence.[18] [19] [24]

Business scope

Payment exposure must be demonstrated

Possible consequences include fraud, operational interruption and payment-security investigation. Determine affected fields and transactions; do not convert store counts into customer-loss totals.

Interpretation

Assess the actual merchant environment

Vendor patch guidance identifies remediation requirements; researcher observations describe particular incidents or store populations. Neither establishes that a particular merchant is compromised or has completed recovery.

Topic

Magecart payment skimming, with Magento and Adobe Commerce as the principal platform scope. The product covers platform exposure, server persistence, browser collection, payment-flow scoping and defensive response. WordPress/WooCommerce research is explicitly identified as comparator evidence.[1] [11] [12] [13] [14] [29] [30]

Magecart is an umbrella rather than a single actor, malware family or vulnerability. Geographic reach, merchant size and customer impact require evidence for each incident.

Persona / Audience Lens

Persona / Audience Lens
FocusEvidence and implications
Audience

Engineering, incident response and business stakeholders

For ecommerce operators, platform owners, SOC/DFIR teams, fraud teams, insurers, counsel and payment-security assessors. SMB owners are an intended audience; that does not classify any reported victim as an SMB.

BLUF

  • Magecart is payment-skimming activity: unauthorized checkout code captures information a shopper enters, potentially before the legitimate payment completes. It describes multiple operators and access paths, not one newly published campaign. An attacker first needs a way to alter the storefront or code it loads; the shopper may then do nothing unusual beyond checking out.[12] [13] [14]
  • The immediate blast radius is the checkout experience that served the malicious code and the shoppers whose information it could collect during that interval. A server compromise can expose more, but skimming alone does not prove access to stored card data or every order. Difficulty varies with the initial access path and checkout design; there is no single Magecart CVSS or universal exploit chain.[1] [11] [12] [13] [14]
  • Verify applicable fixes and exposed-secret remediation, inspect server integrity and browser-visible checkout behavior, and scope the collection window. Follow Adobe’s component-specific patch sequence; its August update is not proof of a new Magecart intrusion. Restore and test a trusted payment journey without treating a successful payment or server patch as evidence that earlier skimming did not occur.[18] [19] [24]

Executive Summary

A shopper can complete a genuine purchase while unauthorized code quietly captures information entered during checkout. Magecart is the umbrella term for this kind of ecommerce skimming, not a single attacker or vulnerability. A merchant can therefore have a customer-data exposure even when the legitimate payment processor receives the transaction and the shop appears to work normally.[12] [13] [14]

An attacker first needs a way to change the storefront or the code delivered to shoppers. The retained Magento reporting describes distinct access problems, including exposed application secrets in CosmicSting cases and upload-related compromise in PolyShell reporting. Those are different access paths across separate cases. In the separate browser-skimmer cases, the precise initial access is not always confirmed, so it would be wrong to assert that each skimmer arrived through the same CVE.[1] [11] [12] [13] [14] [24]

The common pattern is unauthorized access or code modification, insertion of a collector into the checkout experience, collection when a shopper enters information, and transmission to an attacker-controlled destination. Sansec describes both deceptive payment overlays and a WebRTC-based channel in separate investigations. These examples explain why checking only external script files or ordinary HTTP destinations can miss part of the activity; they do not prove a shared operator or that every skimmer uses both techniques.[13] [14]

The blast radius follows which storefront pages served the malicious code, how long it was present, and which shoppers actually submitted information it could observe. A shared compromised component could expose multiple storefronts, but each deployment still needs verification. Browser-form collection is also different from reading a database of stored payments: the latter would require separate access and evidence. Customer notifications and loss estimates should distinguish possible exposure, submission and confirmed exfiltration rather than using all site visitors or orders as a confirmed victim total.

There is no single difficulty rating for Magecart. Obtaining the initial access, integrating a collector with a particular checkout and keeping it operational are separate tasks; the effort depends on the vulnerability, credentials and payment design involved. Once malicious code is delivered, a shopper may need only to use the checkout as intended. An exploited server vulnerability has its own score and prerequisites, but that score does not describe every skimming operator or the entire theft process.[1] [11] [12] [13] [14]

The response must restore both server trust and the customer’s payment journey. Apply the relevant vendor fixes and exposed-secret guidance, preserve code and logs, investigate persistence, and validate checkout behavior from the browser. Adobe’s August remediation requires matching July fixes first across applicable components, and Adobe reported no known exploitation of that bulletin’s issues. That maintenance work is distinct from the earlier observed skimming cases. Do not declare recovery solely because the version changed or a test payment succeeded.[18] [19] [24]

AI Agent Delta Updates

AI Agent Delta Updates
FocusEvidence and implications
Material revision

Changes from the 18 July v2.0 edition

Adds vendor patch prerequisites, corrects historical publication dates, qualifies campaign linkage, expands observable coverage and distinguishes the August WordPress/WooCommerce investigations from Magento incidents.[18] [19] [23] [29] [30]

Decision impact

Patch sequencing and incident scope

Validate the applicable base release and July-to-August patch sequence, then investigate server persistence and unauthorized checkout behavior separately. The additional browser techniques broaden detection coverage without establishing common operators.

Why It Matters

Why It Matters
FocusEvidence and implications
Checkout trust

A legitimate payment can accompany malicious collection

Successful order processing does not establish checkout integrity. Investigators need evidence of the code delivered to customers and the fields it could access.[13] [14]

Recovery

Patch status is only one part of assurance

Response must address the access path, persistence, secrets, browser behavior and exposure window. Financial and reporting consequences depend on the demonstrated incident facts.[1] [11] [24]

Timeline

Timeline
Date / eventEvidence and implications
2022-02-13 / 2022-02-17

Adobe publication and substantive revision

APSB22-12 publication and subsequent affected-scope/CVE revision. These are advisory dates, not an established first-exploitation date.[22]

Read source
2022-11-15

Separate TrojanOrders publication

Sansec published the retained TrojanOrders report in November about the February vulnerability. The separate, inaccessible legacy URL does not establish a February research-publication date.[2] [23]

Read source
2024-06-11 / 2024-06-13

Vendor bulletin and NVD publication

APSB24-40 was published June 11; the NVD record was published June 13. Neither date alone establishes first exploitation.[3] [4]

2024-06-23

Researcher observation

Sansec’s living overview identifies its first observed CosmicSting attacks on this date. Preserve the researcher and observation boundary.[1]

2024-08-27

CosmicSting/CNEXT report

Publication describes a chained server-compromise case and includes August 9 log evidence. Publication is not the event’s first occurrence.[37]

Read source
2025-03-10

PCI SSC supplement announcement

Guidance publication; not a skimmer discovery or incident date.[16]

2025-09-09 / 2025-10-22 / 2025-10-24

SessionReaper disclosure and exploitation acknowledgement

Adobe published APSB25-88 in September, added its exploitation acknowledgement October 22 and changed priority October 24. The later page-update wrapper must not move those events into 2026.[20]

2025-10-22 / 2025-11-10

Sansec dates SessionReaper mass-attack observation to October 22 and its displayed common-probe inventory to November 10. Neither date is a new 2026 exploitation event.[33]

2026-03-10

March Adobe bulletin

APSB26-05 publication. Its August 11 page update is separate; it is no longer the newest bulletin reviewed.[15]

2026-03-16 to 2026-03-23

PolyShell chronology disagreement

The source prose dates probing to March 16 and mass scanning to March 19; its timeline gives first attacks March 19 and mass scanning March 23. Preserve this disagreement rather than selecting a universal first-seen date. Public warning: March 17.[11]

2026-03-24 / 2026-03-30 / 2026-04-07

Separate browser and compromise reports

WebRTC publication, the source-reported one-hour 471-store wave, and SVG publication respectively. Counts and entry-vector assessments remain distinct.[12] [13] [14]

2026-04-14

PolyShell telemetry update

Sansec’s timeline reports 82% of stores hit. The source’s denominator and “hit” definition do not establish U.S. SMB prevalence, successful execution or payment-data theft; this figure must not be added to separate incident counts.[11]

2026-05-12

Magento 2.4.9 release

Vendor release date. Sansec’s dated update identifies this release as containing the PolyShell fix.[11] [27]

2026-05-12

May base-release publication

APSB26-49 publication; later page refreshes and subsequent monthly patches are separate events. This date does not establish exploitation.[38]

2026-07-14 / 2026-08-11

Successive vendor security releases

July and August bulletin publication dates. The August bulletin displays an August 18 update; its installation article displays August 26.[18] [19] [32]

2026-08-09 / 2026-08-20

Distinct WordPress/WooCommerce research publications

Source Defense and DEFION publication dates. DEFION separately discusses late-March file ctime and backdated mtime; neither timestamp proves the universal start of the campaign.[29] [30]

Historical overview — year not restated in passage

Sansec’s living CosmicSting overview describes October 14, October 21 and November 13 waves without restating a year in those passages. They remain historical context, not newly dated 2026 incidents. Counts are source-defined and not additive.[1]

Incident Response Playbook Ideas

Incident Response Playbook Ideas
FocusEvidence and implications
1. Scope

Document the payment architecture

Identify exact platform and component versions, merchant-controlled fields, hosted pages or iframes, redirects, integrations and relevant deployment periods.

2. Preserve

Use the authorized incident-response process

Preserve relevant code, deployment history, CMS changes, server and browser telemetry, administrator activity and payment-page snapshots under appropriate access controls. Limit access to sensitive incident evidence to authorized responders.

3. Investigate

Correlate artifacts with unauthorized changes

Compare templates, extensions, static assets, CMS blocks, tag-manager history and upload-directory changes against trusted baselines. Review the structured observables with their campaign and false-positive qualifications.[11] [12] [13] [14] [23] [33]

4. Validate remediation

Prove coverage rather than infer it from a version string

Use the vendor patch sequence below. Address application-secret exposure separately from patch installation and verify that obsolete authentication capability has been invalidated.[19] [24]

5. Determine impact

Separate possible access from demonstrated loss

Establish the earliest supported unauthorized change, exposure window, affected payment fields, evidence of submissions and evidence of exfiltration. Assess stored-data access as a separate workstream.

6. Recover and validate

Remove persistence and test the customer journey

Authorized responders should remove unauthorized changes, rebuild from trusted code, remediate affected identities and secrets, and validate checkout behavior and monitoring. Preserve evidence before destructive cleanup.

7. Report

Communicate facts and remaining uncertainty

Provide business and payment-security stakeholders with scope, chronology, remediation evidence and unresolved questions. Reporting decisions belong to the organization’s authorized process.

Term Glossary

Term Glossary
FocusEvidence and implications
Magecart

Ecommerce skimming umbrella

A collective label for payment-skimming operations; it does not identify one operator.

Checkout skimming

Collection during the payment journey

Unauthorized code captures customer-entered information. JavaScript can read or alter accessible browser content; a web shell provides a different, server-side access mechanism.

Hosted payment and tokenization

Architecture controls

A provider-hosted page or iframe collects payment details; tokenization substitutes a token for card data. Neither label alone proves the integrity of merchant-controlled redirects or surrounding content.

Payment terminology

PAN, CVV/CVC and CDE

PAN is the primary account number; CVV/CVC is the card security code. CDE means cardholder data environment. PCI DSS is the payment-card security standard; QSA and PFI identify assessment and forensic-investigation roles.

Script governance

Extensions, tag managers and third-party scripts

Script governance assigns ownership and authorization to extensions, tag managers and third-party scripts that can change checkout behavior. Retain a record of approved changes and verify the code delivered to customers.[16]

Observable

Evidence requiring context

An IP, domain, path, fingerprint or behavior is an investigation lead. A DTLS certificate fingerprint is not a malware-file hash; a browser-storage marker is not an authentication credential or conclusive exfiltration receipt.

TTPs

TTPs
FocusEvidence and implications
Initial access

T1190

Analytic mapping for evidenced exploitation of public-facing applications. Apply it to the relevant intrusion, not automatically to every skimmer.[3] [11] [20] [22]

Read source
Execution and persistence

T1059.007 / T1505.003

Analytic mappings for malicious JavaScript and server web shells where the source describes those behaviors.[11] [12] [13] [14]

Collection

T1056; qualified T1056.003

Input capture is the general mapping. MITRE’s Web Portal Capture sub-technique specifically discusses credential collection; do not treat every payment-only form as an exact match without qualification.[36]

Read source
Exfiltration

T1041 where a C2 channel is established

HTTP, iframe and WebRTC examples require channel-specific evidence. Shared use of a protocol does not establish common operators.[13] [14]

Read source
Supply chain

T1195.002 is conditional

An extension or third-party script being present is not sufficient evidence of software supply-chain compromise. Establish the upstream compromise and delivery path before assigning this technique.

Read source

Common Questions Q&A

Common Questions Q&A
FocusEvidence and implications
Authentication and reachability

Can an attacker act without an administrator account?

The three retained exploited CVEs have unauthenticated network vectors in vendor metadata. PolyShell’s upload exposure must be distinguished from configuration-dependent execution. Confirm the actual reachable interfaces and deployment.[3] [11] [20] [22]

Patch selection

Is upgrading to 2.4.9 alone enough?

No general assurance follows from the base version alone. Review subsequent monthly security coverage, installed components, prior compromise and persistence using the detailed vendor sequence below.[18] [19]

Workarounds

Does blocking uploaded-file execution stop uploads?

No. Restricting web access or execution and preventing the vulnerable upload are separate controls. Existing files still require investigation.[11] [28]

Hosted checkout

Does processor hosting eliminate merchant risk?

It can reduce direct card-data handling. Validate iframe origin isolation, redirects and surrounding merchant content; a fraudulent overlay can create a separate collection path.[13] [16]

Attribution and ransomware

Are these one actor or ransomware operation?

No such conclusion is established here. Researcher cluster names, a related card’s imported aliases and leak-site claims cannot merge distinct operations. No topic-specific ransomware linkage is confirmed by this review.

Victims and size

Do aggregate store counts prove customer losses or SMB status?

No. Keep researcher-observed sets separate, preserve anonymous victims and require case-specific evidence for customer exposure and organization size.[12] [13] [14]

Existing coverage

How does this relate to existing IntelliOS products?

The existing CosmicSting and SessionReaper CVE cards already contain the retained CVE/KEV identities and deadlines; this is not new vulnerability discovery. The MageCart card provides umbrella context, not proof that all its imported aliases are equivalent. Operation Silent Skimmer is distinct Telerik/payment-database coverage. Klue and Salesloft are preserved trusted-integration comparators, not attributed Magecart campaigns.

How would an attacker set this up?

Obtain a way to alter storefront code, place a collector and receive captured submissions. Entry routes differ; an unconfirmed initial-access assessment must not become a universal Magecart CVE.[12] [13] [14]

How difficult is the attack?

There is no single rating: access, checkout integration and persistence are separate challenges. Shoppers may only need to use an affected checkout normally.[12] [13] [14]

What is the blast radius?

Identify the affected pages/components, exposure interval and submitted data. Skimming does not automatically establish stored-card access, every-order theft or compromise of all connected storefronts.[12] [13] [14]

CVE / Vulnerability References

CVE / Vulnerability References
FocusEvidence and implications
Current reviewed remediation

APSB26-92

Adobe Commerce: 2.4.9/2.4.8/2.4.7/2.4.6/2.4.5/2.4.4-2026-jul and earlier → corresponding -2026-aug coverage. Magento Open Source: 2.4.9/2.4.8/2.4.7/2.4.6 lines. B2B: 1.5.3/1.5.2/1.4.2/1.3.4/1.3.3 lines. Adobe reports no known in-the-wild exploitation of this bulletin’s issues.[18]

Read source
Installation prerequisites

Apply matching monthly patches in order

Base releases: 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17 or 2.4.4-p18 as applicable. Install matching July fixes before August, including required CE/EE/B2B components. Adobe calls the individual monthly files non-cumulative: the complete sequence is required. Verify coverage with the Commerce Version Tool. Cloud-patches coverage may already include the fix; duplicate application can fail. Older Commerce downloads require entitlement; Open Source downloads are limited to 2.4.6 or later.[19]

Read source
August vulnerability details

Separate remediation context

CVE-2026-71362: CWE-863, CVSS 3.1 9.1, network, no credentials/admin/user interaction. Other bulletin entries: CVE-2026-48414/CWE-79/7.7; 48413/CWE-79/8.7; 48415/CWE-863/7.6/B2B; 48416/CWE-863/7.5; 48411/CWE-863/6.8; 48412/CWE-863/2.7. Authentication is required for these except 48416; admin access is listed for 48414, 48411 and 48412. No Magecart linkage is established.[18]

Read source
CosmicSting

CVE-2024-34102

CWE-611; CVSS 3.1 9.8; unauthenticated network exposure. Historical affected→fixed pairs: 2.4.7→2.4.7-p1; 2.4.6-p5→p6; 2.4.5-p7→p8; 2.4.4-p8→p9, including earlier versions within each line. Commerce extended-support pairs: 2.4.3-ext-7→ext-8 and 2.4.2-ext-7→ext-8. ACSD-60241 was an isolated option for 2.4.4–2.4.7. These are historical fixes, not current target versions.[3] [4]

Read source
TrojanOrders vulnerability

CVE-2022-24086

CWE-20; CVSS 3.1 9.8; unauthenticated network exposure. Adobe lists 2.4.3-p1 and earlier and 2.3.7-p2 and earlier, excluding 2.3.0–2.3.3. Historical remediation includes both MDVA-43395 and the version-matched MDVA-43443; Cloud Patches 1.0.16 resolved the issue. The bulletin also covers CVE-2022-24087, which must not inherit 24086’s exploitation or KEV status.[22]

Read source
SessionReaper

CVE-2025-54236

CWE-20; CVSS 3.1 9.1; unauthenticated network exposure. Commerce affected lines through 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14 and 2.4.4-p15. Open Source’s listed scope omits 2.4.4. B2B scope includes 1.5.3-alpha2, 1.5.2-p2, 1.4.2-p7, 1.3.4-p14 and 1.3.3-p15 and earlier. See Adobe’s hotfix instructions for exact applicability.[20]

Read source
SessionReaper remediation

VULN-32437 and module prerequisites

Adobe’s detailed article covers VULN-32437 or a later security patch and directs installed Custom Attributes Serializable versions 0.1.0–0.3.0 to 0.4.0 or later. Its affected list also mentions 0.4.0, an internal inconsistency requiring clarification. Its old no-exploitation sentence is superseded by APSB25-88’s explicit October acknowledgement.[20] [21]

Read source
PolyShell

Upload and execution are different exposures

Sansec lists upload exposure through 2.4.9-alpha2 and a fix in alpha3 and released 2.4.9. Execution depends on web-server handling; older stock nginx, permissive PHP handlers and older Apache configurations are identified. Do not assign a CVE or numerical CVSS to the label without validated mapping. Backport status beyond the dated researcher update remains unresolved.[11] [28]

Read source
Historical release context

March and July are not current patch endpoints

APSB26-05 and APSB26-73 are retained to document the March and July release sequence, not as current patch endpoints or evidence of Magecart exploitation. Unrelated historical CVE rows and inconsistent authentication columns are not reproduced as campaign facts. Adobe’s current August matrix and its installation instructions control the patch sequence; the separately applicable Commerce Events update is identified below.[15] [32]

Base release versus monthly patches

May releases precede the July/August sequence

APSB26-49 (May 12, 2026) supplies Commerce base releases 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17 and 2.4.4-p18; Magento Open Source lists the 2.4.9 through 2.4.6 lines. Apply the matching July and then August packages to all installed applicable components; the base release alone does not prove August coverage. Historical March/May/July bulletin CVEs are not automatically attributed to skimming.[38] [19] [18]

July component scope

Commerce Events requires its own version check

APSB26-73 separately lists Commerce Events 1.6.0–1.20.0 as affected and 1.21.0 as the solution. Inventory this component independently of the storefront’s release number. This is vendor remediation context, not evidence that Commerce Events was the entry point in the skimming cases.[32]

Read source

IOCs / Observables

IOCs / Observables
FocusEvidence and implications
source_reported_scanning_addresses

ip address

3.12.250[.]83; 3.88.149[.]41; 3.150.234[.]247; 18.220.50[.]153; 23.22.254[.]35; 31.134.0[.]53; 31.134.1[.]34; 31.134.7[.]117; 31.134.11[.]173; 31.134.15[.]89; 31.134.15[.]251; 45.136.24[.]213; 45.136.26[.]181; 45.136.27[.]218; 45.147.233[.]211; 45.147.234[.]73; 45.155.166[.]228; 52.24.6[.]119; 64.49.38[.]96; 78.129.161[.]63; 79.130.2[.]23; 81.169.144[.]135; 91.132.124[.]183; 103.216.223[.]206; 109.107.178[.]102; 115.79.194[.]68; 136.244.92[.]114; 140.235.2[.]103; 140.235.171[.]72; 140.248.75[.]31; 140.248.75[.]114; 162.159.113[.]66; 185.3.235[.]111; 193.151.188[.]86; 193.233.216[.]217; 193.233.221[.]124; 194.180.233[.]186; 198.186.130[.]10; 199.96.165[.]186; 212.87.218[.]43; 216.38.6[.]137; 2001:19f0:6c01:15da:5400:6ff:fe05[:]e560 PolyShell source-listed scanner set. A historical address match does not prove successful exploitation. Includes infrastructure that may be shared or reassigned; do not block indiscriminately.[11]

campaign_specific_infrastructure

ip address

SVG: 23.137.249[.]67; Sansec WebRTC: 202.181.177[.]177; DEFION comparator: 103.141.13[.]26; historical CosmicSting/CNEXT: 165.231.182[.]98, 45.10.160[.]45, 193.93.193[.]74 Separate source-reported infrastructure sets. Do not merge campaigns by protocol or address proximity. Ownership and maliciousness are source-time observations.[13] [14] [29] [37]

campaign_specific_domains

domain fqdn

PolyShell: lanhd6549tdhse[.]top, jslibrary[.]net, canevaslab[.]com. SVG: statistics-for-you[.]com, statistics-renew[.]com, morningflexpleasure[.]com, reusable-flex[.]com, goingfatter[.]com, wellfacing[.]com. DEFION comparator: systmshield[.]com, init.systmshield[.]com. Source Defense comparator: woocompay[.]com, wpguarding[.]com. Defanged domains; campaign assignments remain separate. A domain string alone does not establish an affected transaction. Check historical context and authorized dependencies.[11] [12] [13] [29] [30]

loader_url_and_relative_endpoint

url

hxxps://lanhd6549tdhse[.]top/KZtBscgb; /fb_metrics.php PolyShell loader URL and SVG relative endpoint respectively. The relative path is not a complete URL or independently malicious. Do not contact the endpoints.[12] [13]

source_reported_filenames

filename

PolyShell: index.php, 780index.php, json-shell.php, bypass.phtml, c.php, r.php, rce.php, static.php, test.php, blocked-json.php, bypass-async.php, urlencode-shell.php, xx_malicious_file.php, ato_poc.html, mikhail.html, accesson.php, toggige-arrow.jpg, adman.429.txt, adman.309.txt, bypass.php. TrojanOrders: health_check.php. SessionReaper: bootstrap.php, sysapi.php, gsfa1faewf.txt. DEFION comparator: uninstall.php. Filename leads, not file-content signatures. Many are generic or legitimate; correlate path, content and change evidence.[11] [23] [29] [33]

sha256_dtls_certificate_fingerprint

hash

9E:BB:2A:E2:C5:B8:DC:0A:8B:A7:85:E1:9F:C4:F8:A8:09:2A:F4:1E:70:30:1B:AF:9F:26:97:BE:E2:6E:E3:1D Sansec WebRTC DTLS fingerprint, not a malware-file hash. Correlate with the described channel and checkout behavior. Certificate reuse is not independent actor attribution.[14]

malware_file_hash

hash

Unavailable in retained evidence No validated malware-file hash is promoted. Embedded credential-verification values are excluded.

distributed_backdoor_paths

persistence

var/assets/images/accesson.php; bamboo-specs/assets/images/accesson.php; lib/assets/images/accesson.php; app/assets/images/accesson.php; vendor/assets/images/accesson.php; pub/assets/images/accesson.php; bin/assets/images/accesson.php; setup/assets/images/accesson.php; generated/assets/images/accesson.php; phpserver/assets/images/accesson.php PolyShell source-reported distributed persistence paths. Validate actual unauthorized file content.[11]

cms_and_browser_state

persistence

Unauthorized CMS/static-block JavaScript; localStorage key 136c1e07507f4a97 Retained PolyShell wave persistence evidence. Browser state needs page and session context.[12]

investigation_paths

host artifact

pub/media/custom_options/; pub/media/custom_options/quote/; app/etc/env.php; pub/media/customer_address/*/*; ~/.config/htop/defunct; ~/.config/htop/defunct.dat Magento investigation locations and historical CNEXT persistence paths. Legitimate paths are not compromise indicators without unauthorized content.[1] [11] [33] [37]

wordpress_comparator

host artifact

wp_options: p_set, c_set, fields ce/dk/de/ia; hidden active plugin; uninstall.php persistence; mismatched mtime/ctime DEFION comparator artifacts; not Magento paths. Compare plugin inventory and database state with authorized deployment evidence.[29]

browser_marker_and_identity_hunts

identity session

SVG localStorage marker _mgx_cv; unexpected administrator creation, API activity, extension changes or configuration changes; DEFION hidden-user discrepancies The marker is source-described submission state, not standalone proof of receipt by an attacker. Administrator checks are analytic hunts. Authorized changes and browser-state manipulation can produce similar signals.[13] [29]

campaign_specific_channels

network behavior

Unexpected checkout WebRTC DataChannels over DTLS/UDP 3479; SVG POST to /fb_metrics.php with hidden-iframe fallback; historical CosmicSting WebSocket delivery; Source Defense image-request exfiltration resembling icon.gif Separate observed channels requiring correlation with unauthorized checkout code. WebRTC, iframes, WebSockets and image requests can be legitimate. Public infrastructure is not malicious merely because a campaign uses it.[13] [14] [30] [37]

blockchain_contract_references

network behavior

BSC Testnet: 0xAeF2ed8B69eFb5C1B9e75990A5F90D02Eb5f84F8; 0xeED9e134CE64BF74bE001A942Ee3e3Cb5C12c999 DEFION-published contract references; no contract, bytecode or payload was retrieved. Blockchain RPC traffic may be legitimate for some payment integrations. Do not block public RPC providers solely on these observations.[29]

analytic_hunt_patterns

behavioral detection

Unauthorized checkout JavaScript; unknown outbound destinations; unexplained template/static-asset changes; executable uploads; repeated backdoor placement; encoded inline SVG event handlers; fraudulent payment overlays; unexpected RTCPeerConnection; hidden plugins; runtime script removal or Blob execution Preserves baseline behavioral hunts and adds source-qualified comparator patterns. Encoding, Blob execution and browser APIs are not independently malicious. Validate business purpose and provenance.[11] [12] [13] [14] [29] [30]

sessionreaper_november_2025_addresses

ip address

23[.]146[.]184[.]93; 23[.]249[.]27[.]221; 34[.]227[.]25[.]4; 44[.]212[.]43[.]34; 45[.]32[.]66[.]51; 45[.]143[.]20[.]147; 46[.]39[.]230[.]243; 54[.]205[.]171[.]35; 54[.]226[.]181[.]219; 80[.]78[.]25[.]213; 86[.]203[.]185[.]51; 99[.]246[.]176[.]115; 103[.]215[.]237[.]26; 141[.]11[.]62[.]221; 143[.]244[.]44[.]172; 149[.]28[.]33[.]250; 155[.]117[.]84[.]134; 155[.]138[.]226[.]245; 156[.]244[.]16[.]170; 157[.]245[.]52[.]111; 159[.]89[.]12[.]166; 198[.]144[.]182[.]13; 212[.]8[.]248[.]191; 2001:19f0:6000:9a28:5400:5ff:feb8:8b4b; 2a0a:3840:8078:25:0:504e:19d5:1337 25 source-listed addresses in Sansec’s November 10, 2025 SessionReaper update; not a current reputation verdict. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[33]

sessionreaper_domain_spelling_conflict

domain fqdn

sagecrafft[.]com; safecrafft[.]com; worcksbot[.]com Sansec uses sagecrafft repeatedly but also spells safecrafft in prose. Retain the disagreement; the two strings are not silently treated as interchangeable. worcksbot is the November replacement described by the source. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[33]

sessionreaper_paths

url

hxxps://sagecrafft[.]com/a.php?a=…; /ttt/ref.php; hxxps://worcksbot[.]com/w.php?a=…; /o/o.php; hxxps://tecnokauf[.]ru/accesson20.html; /customer/address_file/upload Source-reported infrastructure and upload route. Ellipses indicate omitted variable query content, not complete URLs. The upload route is not the only possible attack path. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[33]

sessionreaper_webshell_artifacts

host artifact

pub/errors/404.php; pub/rootz.php; rootzwashere; pub/6376bad677a8.php; static.php; GuzzleHttp Cookie FileCookieJar / SetCookie Additional source-reported file and serialized-object leads. Names and class strings are not executable samples and can have legitimate uses. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[33]

cosmicsting_cnext_websocket_endpoints

url

wss[:]//accept[.]bar/common; wss[:]//amocha[.]xyz/common; wss[:]//cdn-webstats[.]com/ls; wss[:]//clearnetfab[.]net/common; wss[:]//fallodick87-78[.]sbs/common; wss[:]//cd[.]iconstaff[.]top/m; wss[:]//cdn[.]iconstaff[.]top/common; wss[:]//cdn[.]inspectdlet[.]net/ws; wss[:]//jqueryuslibs[.]com/common; wss[:]//jstatic201[.]com/common; wss[:]//lererikal[.]org/common; wss[:]//mamatmavali[.]ru/common; wss[:]//nothingillegal[.]bond/common; wss[:]//paie-locli[.]com/s; wss[:]//sellerstat[.]site/wss; wss[:]//statsseo[.]com/common; wss[:]//statstoday[.]org/common; wss[:]//vincaolet[.]xyz/socket; wss[:]//webexcelsior[.]org/common 19 historical WebSocket destinations in the August 27, 2024 CosmicSting/CNEXT report, kept separate from newer campaigns. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[37]

cosmicsting_cnext_process_and_cron

persistence

defunct-kernel cron marker; [raid5wq]; [kswapd0]; [slub_flushwq]; [card0-crtc8]; [netns] Source-reported masquerading and cron persistence; kernel-like names alone are not malicious. Correlate executable path, parent process, file content and scheduling. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[37]

polyshell_wave_beacon

identity session

8194460 Source-reported PolyShell wave marker; it is not an authentication credential or proof of successful card theft. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[12]

svg_campaign_marker

identity session

{site:'rand0m'}; _mgx_cv = 1 Source-published SVG payload and browser-state markers. Submission-state evidence is not independent confirmation of remote receipt. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[13]

defion_comparator_cookie_and_fields

identity session

wjxq_; c77d5cd5; lu; Cart number DEFION comparator: activation-cookie name, published loader XOR encoding constant, update field, and form typo. No cookie values or private credentials retained; these are source-specific hunting leads. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[29]

defion_assessed_initial_access

domain fqdn

wordpressnull[.]org; activations.ultrapackv2[.]com DEFION’s assessed nulled-page-builder distribution context, not proven initial access for all stores or an instruction to visit these sites. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[29]

Group Ondatry: High profile targets and custom payment forms URLs

url

hxxps://bellanatura[.]shop/health_check[.]php; hxxps://branchbrookpharmacy[.]com/pub/health_check[.]php; hxxps://byyvonn[.]nl/health_check[.]php; hxxps://cantes[.]com[.]br/pub/health_check[.]php; hxxps://casamilanoitaly[.]com/health_check[.]php; hxxps://galantha[.]nl/health_check[.]php; hxxps://giftboxedwines[.]com/health_check[.]php; hxxps://larecetta[.]com/pub/health_check[.]php; hxxps://magiglide[.]nl/health_check[.]php; hxxps://mercadoespiao[.]com[.]br/health_check[.]php; hxxps://missy-x[.]com/pub/health_check[.]php; hxxps://www[.]decentcustom[.]com/pub/health_check[.]php; hxxps://www[.]derickdesign[.]com/health_check[.]php; hxxps://www[.]dianahunt[.]hu/pub/health_check[.]php; hxxps://www[.]efashionwholesale[.]com/pub/health_check[.]php; hxxps://www[.]hakpro[.]nl/pub/health_check[.]php; hxxps://www[.]hebery[.]com/pub/health_check[.]php; hxxps://www[.]rtechmx[.]com/pub/health_check[.]php; hxxps://zetabg[.]com/pub/health_check[.]php Compromised merchant relay URLs reported by Sansec, not an attacker-ownership list or independently verified victim disclosure. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1]

Group Polyovki: Basic embed of cdnstatics.net URLs

url

hxxps://cdnstatics[.]net/lib[.]js; hxxps://cdnstatics[.]net/index[.]php?zz= Historical source-defined cluster, not a universal Magecart actor alias. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1]

Group Bobry: Hidden in plain sight URLs

url

hxxps://statspots[.]com/get/?s=; hxxps://quantunnquest[.]com/img/; hxxps://analytisgroup[.]com/img/; hxxps://analytisweb[.]com/img/; hxxps://bytesbazar[.]com/img/; hxxps://chartismart[.]com/get/?s=; hxxps://codecarawan[.]com/img/; hxxps://creativeslim[.]com/img/; hxxps://creatls[.]com/get/?s=; hxxps://cssmagic[.]shop/get/?s=; hxxps://cssmagic[.]shop/img/; hxxps://datifyny[.]com/img/; hxxps://dealhunt[.]website/get/?s=; hxxps://desiqnia[.]shop/img/; hxxps://desynlabtech[.]com/img/; hxxps://getstylify[.]com/get/?s=; hxxps://graphiqsw[.]com/img/; hxxps://happyllfe[.]online/get/?s=; hxxps://horlzonhub[.]com/get/?s=; hxxps://javaninja[.]shop/get/?s=; hxxps://marketiqhub[.]com/img/; hxxps://marketrom[.]shop/get/?s=; hxxps://marketsoilmart[.]com/img/; hxxps://metricsy[.]shop/get/?s=; hxxps://novastraem[.]com/get/?s=; hxxps://radlantroots[.]com/get/?s=; hxxps://sellifypro[.]com/get/?s=; hxxps://sellwisehub[.]com/get/?s=; hxxps://statify[.]online/get/?s=; hxxps://statlstic[.]shop/get/?s=; hxxps://techtnee[.]com/get/?s=; hxxps://trendgurupro[.]com/get/?s=; hxxps://trendor[.]website/img/; hxxps://trendori[.]shop/get/?s=; hxxps://vizualis[.]online/get/?s=; hxxps://www[.]googletagmanager[.]com/gtm[.]js?id=GTM-5T7T9QNG; hxxps://www[.]googletagmanager[.]com/gtm[.]js?id=GTM-5WG336MZ; hxxps://www[.]googletagmanager[.]com/gtm[.]js?id=GTM-K7XN937P; hxxps://www[.]googletagmanager[.]com/gtm[.]js?id=GTM-WTFWGVQ5; hxxps://advertiq[.]shop/get/; hxxps://advertispro[.]com/get/; hxxps://advertls[.]shop/get/; hxxps://artickon[.]shop/get/; hxxps://articon[.]shop/get/; hxxps://artistryhab[.]shop/get/; hxxps://artvislon[.]shop/get/; hxxps://brandilift[.]com/get/; hxxps://brandixi[.]shop/get/; hxxps://bytesbazar[.]com/get/; hxxps://chartify[.]shop/get/; hxxps://chartismart[.]com/get/; hxxps://codcraft[.]shop/get/; hxxps://codecarawan[.]com/get/; hxxps://codegenesis[.]shop/get/; hxxps://codemingle[.]shop/get/; hxxps://countilancer[.]com/get/?s=; hxxps://countora[.]shop/get/; hxxps://creatls[.]com/get/; hxxps://creatlva[.]shop/get/; hxxps://cssmagic[.]shop/get/; hxxps://datagen[.]shop/get/; hxxps://datawiz[.]shop/get/; hxxps://dealhunt[.]website/get/; hxxps://designlq[.]com/get/; hxxps://desiqnia[.]shop/get/; hxxps://desynlabtech[.]com/get/; hxxps://evaluatemingle[.]com/get/; hxxps://feedbackharvest[.]com/get/; hxxps://getstylify[.]com/get/; hxxps://gettinfo[.]com/get/?s=; hxxps://graphig[.]shop/get/; hxxps://graphiqsw[.]com/get/; hxxps://graphisprintstudio[.]com/get/; hxxps://graphize[.]shop/get/; hxxps://graphlq[.]shop/get/; hxxps://happyllfe[.]online/get/; hxxps://happynast[.]shop/get/; hxxps://happywave[.]shop/get/; hxxps://horlzonhub[.]com/get/; hxxps://insightharvesters[.]com/get/; hxxps://javaninja[.]shop/get/; hxxps://joyfullday[.]shop/get/; hxxps://luckipath[.]shop/get/; hxxps://luckkystar[.]shop/get/; hxxps://luckycharm[.]website/get/; hxxps://marketexpert[.]site/get/; hxxps://marketiqhub[.]com/get/; hxxps://marketro[.]shop/get/; hxxps://marketsoilmart[.]com/get/; hxxps://merchifly[.]shop/get/; hxxps://metricelevate[.]com/get/; hxxps://metricsy[.]shop/get/; hxxps://myhapperflowers[.]com/get/; hxxps://novastraem[.]com/get/; hxxps://pixelia[.]shop/get/; hxxps://pixella[.]shop/get/; hxxps://pixelsmith[.]shop/get/; hxxps://protocolhubinfo[.]com/get/?s=; hxxps://radlantroots[.]com/get/; hxxps://reviewharborhub[.]com/get/; hxxps://salesguru[.]online/get/; hxxps://secunnet[.]shop/get/; hxxps://seilsmart[.]shop/get/; hxxps://sellifypro[.]com/get/; hxxps://selllify[.]shop/get/; hxxps://selloria[.]shop/get/; hxxps://statify[.]shop/get/; hxxps://statistall[.]com/get/; hxxps://statlstic[.]shop/get/; hxxps://statmaster[.]shop/get/; hxxps://statspots[.]com/get/; hxxps://styllize[.]shop/get/?s=; hxxps://techtnee[.]com/get/; hxxps://trendgurupro[.]com/get/; hxxps://trendori[.]shop/get/; hxxps://trendset[.]website/get/; hxxps://vodog[.]shop/get/ Historical source-defined cluster, not a universal Magecart actor alias. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1]

Group Surki: Answer of life websockets URLs

url

wss[:]//accept[.]bar/common; wss[:]//amocha[.]xyz/common; wss[:]//cd[.]iconstaff[.]top/m; wss[:]//cdn-webstats[.]com/ls; wss[:]//cdn[.]iconstaff[.]top/common; wss[:]//cdn[.]inspectdlet[.]net/ws; wss[:]//clearnetfab[.]net/common; wss[:]//cloudflare-stat[.]net/common; wss[:]//fallodick87-78[.]sbs/common; wss[:]//iconstaff[.]top/common; wss[:]//jquerypackageus[.]com/common; wss[:]//jqueryuslibs[.]com/common; wss[:]//jstatic201[.]com/common; wss[:]//lererikal[.]org/common; wss[:]//mamatmavali[.]ru/common; wss[:]//nothingillegal[.]bond/common; wss[:]//paie-locli[.]com/s; wss[:]//sellerstat[.]site/wss; wss[:]//shoponlinemelike[.]shop/common; wss[:]//statsseo[.]com/common; wss[:]//statstoday[.]org/common; wss[:]//vincaolet[.]xyz/socket; wss[:]//webexcelsior[.]org/common; hxxps://udalzira[.]com/[.]well-known/cloud[.]js Historical source-defined cluster, not a universal Magecart actor alias. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1]

Group Khomyaki: Two letter exfil (JSC) URLs

url

//app[.]chwine[.]dev/us/; //cdn[.]myshopper[.]io/bo/; //fatrade[.]net/re/; //hostnotify[.]io/mu/; //img[.]wisepops[.]co/mo/; //infiniboosts[.]com/bu/; //itsemma[.]io/gb/; //m[.]bingforce[.]org/jo/; //m[.]bingforce[.]org/to/; //rextension[.]net/za/; //servicetoast[.]net/ne/; //sourcetrap[.]net/tu/; //subsales[.]net/qe/; //t[.]gearplace[.]net/fe/; //tag[.]convertpro[.]org/be/; //tag[.]wealthleaderinc[.]com/da/; //tr[.]hostnotify[.]io/nr/; //web[.]bystats[.]io/he/; //web[.]foptimize[.]net/we/; //www[.]consentime[.]com/br/; //www[.]ge4cdn[.]com/vu/; //www[.]myshopper[.]io/gb/; //www[.]youpilot[.]org/pg/ Historical source-defined cluster, not a universal Magecart actor alias. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1]

Group Khomyaki: Two letter exfil (JSC) addresses

ip address

82[.]202[.]165[.]8; 82[.]202[.]165[.]96; 82[.]202[.]165[.]55; 82[.]202[.]165[.]43; 82[.]202[.]165[.]36; 82[.]202[.]165[.]48; 82[.]202[.]161[.]191; 82[.]202[.]161[.]175; 82[.]202[.]161[.]192; 82[.]202[.]162[.]237; 82[.]202[.]163[.]228; 82[.]202[.]165[.]158; 82[.]202[.]165[.]152 Historical source-defined cluster, not a universal Magecart actor alias. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1]

Group Laski: Fake maintenance pages URLs

url

hxxps://deslgnhq[.]com/; hxxps://markettz[.]com/; hxxps://sellquestor[.]com/jquery[.]min[.]js Historical source-defined cluster, not a universal Magecart actor alias. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1]

Group Laski: Fake maintenance pages domains

domain fqdn

brandmynxt[.]com; countifyhub[.]com; creatowebhub[.]com; cssucess[.]com; datageen[.]com; datallqs[.]com; datavibers[.]com; desiginfest[.]com; designmetrlcs[.]com; designospro[.]com; deslgnhq[.]com; desynifynet[.]com; desynity[.]com; desynsy[.]com; graphwebpad[.]com; graphwebpro[.]com; graphorix[.]com; htmledge[.]com; marketgoweb[.]com; marketicsy[.]com; marketisplay[.]com; marteton360[.]com; marketprome[.]com; markettz[.]com; marketxxx[.]com; pixeloramy[.]com; pixelprosstudio[.]com; salesflowe[.]com; sellarcs[.]com; sellllink[.]com; selllvibe[.]com; sellpathhub[.]com; sellsageapp[.]com; sellspotweb[.]com; sellquestor[.]com; statdynanics[.]com; statepulseapp[.]com; statgennius[.]com; statibuzz[.]com; statrackers[.]com; visualldata[.]com Historical source-defined cluster, not a universal Magecart actor alias. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1]

Full list of attack indicators URLs

url

hxxps://checkout[.]lat/log[.]xml; hxxps://fars[.]ee/WuBQ[.]dtd; hxxps://m37gg41n[.]c5[.]rs/?exploited=%data Historical aggregate; campaign assignment and current reputation are not independently established. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1]

Full list of attack indicators addresses

ip address

104[.]36[.]229[.]32; 112[.]213[.]127[.]253; 116[.]49[.]75[.]88; 118[.]179[.]100[.]161; 129[.]208[.]21[.]161; 141[.]98[.]81[.]24; 141[.]98[.]82[.]3; 142[.]252[.]84[.]169; 146[.]185[.]207[.]94; 146[.]190[.]165[.]100; 159[.]223[.]136[.]255; 162[.]241[.]71[.]133; 165[.]231[.]182[.]98; 168[.]138[.]113[.]116; 172[.]104[.]28[.]240; 172[.]93[.]40[.]2; 173[.]255[.]242[.]28; 18[.]143[.]139[.]116; 184[.]31[.]15[.]39; 184[.]31[.]15[.]70; 185[.]125[.]50[.]108; 185[.]193[.]126[.]86; 185[.]208[.]158[.]16; 185[.]81[.]128[.]36; 192[.]82[.]21[.]247; 193[.]233[.]128[.]167; 193[.]233[.]129[.]150; 193[.]233[.]130[.]84; 193[.]233[.]216[.]201; 193[.]233[.]217[.]12; 193[.]233[.]91[.]78; 193[.]93[.]193[.]74; 194[.]55[.]186[.]174; 198[.]44[.]129[.]83; 198[.]98[.]48[.]53; 20[.]55[.]20[.]233; 200[.]109[.]156[.]28; 201[.]21[.]152[.]152; 202[.]138[.]73[.]99; 213[.]252[.]247[.]133; 217[.]148[.]142[.]54; 217[.]170[.]197[.]30; 217[.]182[.]199[.]126; 23[.]1[.]236[.]21; 23[.]1[.]236[.]31; 23[.]213[.]246[.]132; 23[.]219[.]77[.]202; 23[.]39[.]209[.]109; 23[.]39[.]209[.]113; 23[.]45[.]233[.]38; 23[.]46[.]157[.]161; 31[.]134[.]11[.]12; 31[.]134[.]11[.]69; 31[.]134[.]13[.]106; 31[.]134[.]2[.]109; 31[.]134[.]6[.]39; 31[.]134[.]8[.]214; 37[.]9[.]41[.]91; 37[.]9[.]42[.]158; 37[.]9[.]43[.]23; 37[.]9[.]44[.]76; 45[.]10[.]160[.]45; 45[.]90[.]58[.]1; 5[.]181[.]124[.]181; 51[.]81[.]126[.]7; 67[.]223[.]117[.]91; 68[.]224[.]33[.]168; 82[.]112[.]245[.]109; 85[.]239[.]43[.]38; 85[.]239[.]43[.]55; 89[.]110[.]87[.]211; 89[.]23[.]99[.]251; 91[.]218[.]123[.]68; 91[.]92[.]243[.]104; 91[.]92[.]243[.]83; 91[.]92[.]244[.]237; 91[.]92[.]247[.]205; 91[.]92[.]251[.]28; 92[.]112[.]184[.]102; 95[.]216[.]102[.]239; 15[.]204[.]207[.]175; 89[.]110[.]84[.]168 Historical aggregate; campaign assignment and current reputation are not independently established. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1]

Full list of attack indicators domains

domain fqdn

advertiq[.]shop; advertispro[.]com; advertls[.]shop; anality-google[.]com; artickon[.]shop; articon[.]shop; artistryhab[.]shop; artvislon[.]shop; bingforce[.]org; brandilift[.]com; brandixi[.]shop; bystats[.]io; bytesbazar[.]com; cdnstatics[.]net; chartify[.]shop; chartismart[.]com; codcraft[.]shop; codecarawan[.]com; codegenesis[.]shop; codemingle[.]shop; countilancer[.]com; countora[.]shop; creatls[.]com; creatlva[.]shop; cssmagic[.]shop; datagen[.]shop; datawiz[.]shop; dealhunt[.]website; designlq[.]com; desiqnia[.]shop; desynlabtech[.]com; easttrack[.]net; evaluatemingle[.]com; feedbackharvest[.]com; foptimize[.]net; gearplace[.]net; getstylify[.]com; gettinfo[.]com; graphig[.]shop; graphiqsw[.]com; graphisprintstudio[.]com; graphize[.]shop; graphlq[.]shop; graphorix[.]com; happyllfe[.]online; happynast[.]shop; happywave[.]shop; horlzonhub[.]com; infiniboosts[.]com; insightharvesters[.]com; javaninja[.]shop; joyfullday[.]shop; luckipath[.]shop; luckkystar[.]shop; luckycharm[.]website; marketexpert[.]site; marketiqhub[.]com; marketro[.]shop; marketsoilmart[.]com; merchifly[.]shop; metricelevate[.]com; metricsy[.]shop; myhapperflowers[.]com; novastraem[.]com; pixelia[.]shop; pixella[.]shop; pixeloramy[.]com; pixelsmith[.]shop; protocolhubinfo[.]com; quantlive[.]net; radlantroots[.]com; registertime[.]net; reviewharborhub[.]com; rextension[.]net; ruleslaw[.]org; saleapi[.]org; salesguru[.]online; sdtrack[.]io; secunnet[.]shop; seilsmart[.]shop; sellifypro[.]com; selllify[.]shop; selloria[.]shop; servicetoast[.]net; stackapt[.]com; statepulseapp[.]com; staticforce[.]org; statify[.]shop; statistall[.]com; statlstic[.]shop; statmaster[.]shop; statspots[.]com; styllize[.]shop; techtnee[.]com; trendgurupro[.]com; trendori[.]shop; trendset[.]website; vodog[.]shop; wealthleaderinc[.]com; yotpont[.]com Historical aggregate; campaign assignment and current reputation are not independently established. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1]

cosmicsting_inline_historical_markers

network behavior

wss[:]//jgueurystatic[.]xyz:8101; __ffsj; hxxps://106[.]14[.]40[.]200/?prod_hash=<data>; cardnumber-kao153; securitycode-kao153; holder-kao153; expirationdate-kao153; cardbutton-kao153; 185[.]175[.]225[.]116; 142[.]252[.]84[.]169; 2600:3c01::f03c:95ff:fede:ddb8 Historical source-defined Burunduki/Peschanki/Polyovki and scanner markers. The data placeholder is not an actual stolen value; legitimate payment-field identifiers alone are insufficient for compromise findings. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1]

cosmicsting_malformed_url_domain

domain fqdn

venum[.]com[.]cn The source prints a duplicated https scheme for this endpoint. Only the domain is retained; the malformed URL is not silently corrected or validated. Historical or source-specific evidence; correlate with unauthorized code and activity. A match alone does not establish compromise. Infrastructure may be shared, compromised or reassigned. Do not visit listed endpoints or apply a universal blocklist.[1]

Historical CosmicSting process masquerading

host artifact

.config/htop/defunct.dat; [slub_flushwq]; [raid5wq]; [card0-crtc8]; [netns]; [kswapd0] Historical CosmicSting process masquerading Kernel-thread-like names also have legitimate uses; correlate executable provenance and user-space behavior.[1]

SessionReaper diagnostic fragments

host artifact

E:\Tools\eclipse\php7.3\ext\php_bz2.dll; pub/media/customer_address/s/e/setest SessionReaper diagnostic fragments Researcher describes a non-working test and diagnostic leakage. Not a universal successful-compromise signature.[33]

DEFION claim-specific browser and plugin markers

identity session

wjxq_; front_inc; all_plugins; pre_user_query; lu; Cart number DEFION claim-specific browser and plugin markers Cookie name, script handle, standard filters and UI typo need case context. No activation credential or decryption key is included.[29]

DEFION suspected distribution context

domain fqdn

wordpressnull[.]org; activations.ultrapackv2[.]com DEFION suspected distribution context Suspected nulled-plugin origin, not a proven causal attribution. Never download from these endpoints.[29]

DEFION shared RPC context

network behavior

bsc-testnet-rpc.publicnode[.]com; data-seed-prebsc-1-s1.bnbchain[.]org:8545; eth_call DEFION shared RPC context Legitimate shared RPC infrastructure; correlate exact contracts and unexpected checkout behavior, not blanket domain blocking.[29]

CosmicSting DOM context

behavioral detection

checkout-payment-method-load; payment_method_container; checkout-payment-method; checkout-payment-step; paymentMethodContainer; HOOK_ADVANCED_PAYMENT; HOOK_SHOPPING_CART; payment-method; st-checkout-payment-step; klarna-checkout-container CosmicSting DOM context Legitimate payment selectors are not malicious alone; correlate unauthorized hiding or replacement.[1]

Threat Actor Glossary

Threat Actor Glossary
FocusEvidence and implications
Magecart

Umbrella label

Do not equate the entire umbrella with FIN6/G0037 or any single operator. Imported aliases in the existing MageCart card are not adopted as identity evidence in this edition.

Researcher labels

CosmicSting and TrojanOrders operators

Sansec describes distinct operator clusters. Its CosmicSting overview uses Ondatry, Polyovki, Bobry, Surki, Khomyaki, Burunduki, Belki, Laski and Peschanki. These are source-defined labels, not independently reconciled identities.[1] [23]

2026 examples

Keep intrusion sets separate

PolyShell is not a settled actor identity. SVG and WebRTC entry-vector assessments remain qualified. The August WordPress cases are separate observations; shared WebRTC use does not connect their operators.[11] [13] [14] [29] [30]

Talking Points

Talking Points
FocusEvidence and implications
Business briefing

Questions leaders should ask

What code did customers receive? Which fields could it observe? What proves the exposure window? Are server persistence and secret exposure resolved? What evidence supports customer-impact statements?

Payment architecture

Hosted checkout still needs validation

Document the provider-hosted boundary and the merchant-controlled journey around it. Keep browser skimming and stored-data compromise distinct.

Remediation assurance

Require evidence of completion

A base version, successful checkout or absence of a known domain does not prove recovery. Require patch-coverage evidence and verification of authorized checkout behavior.[19]

Decision Ready Actions

Decision Ready Actions
FocusEvidence and implications
Engineering · same business day

Produce a patch-coverage record

Record exact storefront, CE/EE/B2B and Commerce Events versions; identify the applicable vendor packages and July-to-August sequence. Test changes through the emergency-change process when exposed. Completion evidence: a version-tool result and package/component record, not merely a successful checkout.[18] [19] [32]

Incident response · immediately when compromise is suspected

Preserve and contain before cleanup

Capture authorized code/configuration history and relevant logs before removal. Restrict the affected payment journey or isolate compromised systems according to incident severity. Completion evidence: preserved artifacts, a supported exposure window and a documented containment decision. Absence of a listed IOC does not close the incident.[11] [12] [13] [14] [24]

Platform owner · before declaring recovery

Validate server and customer-browser integrity

Remove unauthorized persistence, remediate applicable secret exposure under vendor guidance and verify checkout from the customer’s perspective. Completion evidence: trusted-code comparison, appropriate secret remediation and browser/network observations showing only authorized behavior.[19] [24]

Claims, counsel and payment-security lead · during scoping

Approve a fact-bounded impact statement

Distinguish possible field visibility, submitted values, demonstrated exfiltration, stored-data access, fraud and operational loss. Completion evidence: a statement of confirmed facts and explicit unknowns, with reporting decisions handled through the authorized process.

Exploitable Technology Risks

Exploitable Technology Risks
FocusEvidence and implications
Priority exposure

Platform and administrator control

Review exploited platform vulnerabilities, reachable APIs, upload handling, extensions and administrator access. Apply vulnerability-specific severity rather than a universal Magecart CVSS score.[3] [11] [20] [22]

Residual exposure

Secrets and persistence

Review server backdoors, unauthorized CMS content, browser state and application-secret remediation. Installing a fix does not establish that earlier abuse was removed.[12] [24]

Visibility gaps

Inline and runtime behavior

Include inline content, overlays, browser storage and unexpected non-HTTP channels. Public RPC services or Blob execution are contextual signals, not automatic proof of compromise.[13] [14] [29] [30]

Data scope

Stored payment artifacts

Assess stored-data exposure separately through authorized responders. Public reporting does not establish the contents of a particular merchant’s stored payment records.

Social Media / Community Signals

Social Media / Community Signals
FocusEvidence and implications
Public community coverage

Limits of community evidence

No public social post controls a factual claim in this edition. That does not establish absence of relevant discussion. Authenticated communities, leak datasets and exploit or sample repositories were not used.

Classification

Research and registries are not social sources

Sansec research and CISA KEV belong in their respective evidence roles, not in a social-evidence count. Stamus’s detection update does not establish a new victim event or validate its FIN6/Magecart equivalence.[17] [31]

Tier 0 Through Tier 8 Source Summary

Tier 0 Through Tier 8 Source Summary
FocusEvidence and implications
Tier 0

Canonical registries

NVD, CISA and MITRE support canonical metadata and qualified technique mapping. CISA JSON was retrieved directly with HTTP 200 and its three retained KEV entries checked. NVD direct requests returned thin pages; retain the earlier indexed evidence with Adobe/CISA controlling consequential facts.

Tier 1

Primary authorities

Canadian Cyber Centre. Supports: Government corroboration. Limitations: Broader government walk incomplete; one version conflict retained.

Tier 2

Vendor/research registry

Akamai; Malwarebytes lineage. Supports: Configuration-dependent PolyShell context. Limitations: Malwarebytes retained URL failed.

Tier 3

Independent news

BleepingComputer lineage. Supports: Historical citation preservation. Limitations: Retained article unresolved.

Tier 4

Public social/community

None promoted. Supports: No output claims depend on social evidence. Limitations: Walk incomplete; no authenticated access.

Tier 5

User-defined URLs

No custom URL inputs were configured for this direct repair. No claim about other workspace or tenant configurations.

Tier 6

Keyed integrations

No keyed integrations were used for this direct repair. Public-source evidence only; no claim about tenant-wide connector readiness.

Tier 7

Unlisted-domain discovery

Sansec, Adobe, PCI SSC, SecurityMetrics, Qualys, DEFION, Source Defense, Stamus. Supports: Original research, vendor/standards evidence and preserved lineage. Limitations: Not predefined registry authorities; role determines weight; some retrievals failed.

Tier 8

Expansion Research

Expansion Research: DEFION and Source Defense add distinct WordPress/WooCommerce detection comparisons. Original discovery remains Tier 7; this retained contribution is separately labeled Tier 8 and does not override Adobe or merge campaigns.

Source Deconfliction

Source Deconfliction
FocusEvidence and implications
Patch chronology

Prefer explicit dated remediation

Sansec’s dated 2.4.9 correction supersedes its older no-production-fix prose. March and July bulletins remain historical context. Canadian AV26-808 lists some August Commerce versions as affected, conflicting with Adobe’s August solution matrix; Adobe controls patch selection.[11] [15] [18] [32] [35]

SessionReaper status

Old no-exploitation prose is stale

The detailed Adobe article retains September no-exploitation wording despite a later update wrapper. APSB25-88 explicitly acknowledges exploitation and records the October revision; that acknowledgement controls.[20] [21] [34]

Population and chronology

Unresolved population and date differences

The SVG headline reports 99 stores but its domain rows total 76; allocation and overlap remain unexplained. PolyShell’s probing and scanning dates also conflict internally. The evidence supports neither a corrected total nor a universal first-seen date.[11] [13]

Control limitations

Avoid absolute invisibility claims

DEFION’s own findings include database and plugin traces, so its broad invisibility language is not adopted. Source Defense explicitly qualifies Blob execution as dependent on CSP configuration. Ordinary HTTP monitoring alone does not cover all observed channels.[14] [29] [30]

Attribution

Imported labels require independent evidence

Stamus’s FIN6/Magecart wording and the related card’s alias list do not override the umbrella boundary. Similar techniques and shared hosting cannot resolve actor identity.[31]

Literal indicator errors

Do not repair source strings silently

The CosmicSting overview prints 157.230.230.193q and a duplicated https scheme for venum.com.cn. The malformed address is excluded from normalized IPs; the latter domain is retained without claiming the malformed URL is valid. Query placeholders are not collected victim data.[1]

Extraction exclusions

Code properties and partial service links are not IOC endpoints

The JavaScript property location.hostname is excluded from domains. A truncated Google Translate query is excluded from endpoint matching: the legitimate translation service alone is not an attacker indicator. Protocol-relative paths and open-ended query prefixes elsewhere remain literal hunting patterns, not complete validated destinations.[1]

SessionReaper execution precondition

The researcher’s reproduced RCE path appears to require file-based sessions; Redis or database sessions do not establish general immunity. Its historical residual-upload warning is distinct from proving code execution after patching.[33]

August advisory metadata

Adobe’s authentication/admin columns and vectors are not always equivalent: 48414, 48411 and 48412 list admin access while some vectors show PR:L. Preserve the vendor fields and seek vendor clarification when assessing prerequisites; do not silently rewrite the vector.[18]

Expansion chronology

DEFION’s relative deployment timestamps describe one anonymous WordPress case; its broad invisibility and automation assertions are not independently adopted. Source Defense’s August 9 publication describes a different Polygon-based chain, not the same BSC/WebRTC operator.[29] [30]

About the Contributors

About the Contributors
FocusEvidence and implications
Adobe

Highest weight for product remediation

The product vendor defines affected versions, fixes and installation prerequisites. Explicit revisions outrank stale paragraphs elsewhere in its documentation; inconsistencies remain identified.[3] [15] [18] [19] [20] [21] [22] [24] [27] [32]

Sansec

High weight for its observed ecommerce cases

Original campaign observations and defensive artifacts. Commercial telemetry, changing overview pages and inconsistent denominators limit population and chronology claims. Cluster labels remain source-defined.[1] [11] [12] [13] [14] [23] [33] [37]

NVD, CISA and MITRE

Canonical metadata and framework context

These sources support vulnerability status and technique definitions; they do not prove compromise of a particular merchant. Retrieval limitations are recorded per source.[4] [17] [25] [26] [36]

PCI SSC and SecurityMetrics

Standards authority and practitioner context

PCI SSC’s announcement supports payment-page governance context, but it cannot substitute for the inaccessible standard. SecurityMetrics is practitioner guidance, not a replacement standards authority.[6] [7] [16]

Akamai, DEFION and Source Defense

Configuration and comparator research

Akamai corroborates PolyShell’s execution prerequisites. DEFION and Source Defense add separate WordPress/WooCommerce observations. Their claims are bounded to the described cases.[28] [29] [30]

Other retained sources

Source-specific limitations

Canadian advisories corroborate vendor awareness but contain a version discrepancy. Stamus supplies detection-release context only. Failed historical Malwarebytes, BleepingComputer and Qualys URLs are preserved without treating their contents as newly verified.[8] [9] [10] [31] [34] [35]

Real World Examples

Real World Examples
FocusEvidence and implications
Historical Magento cases

CosmicSting and TrojanOrders

Examples of why platform fixes and removal of post-compromise access are different tasks. Historical operator and infrastructure evidence must retain its original scope.[1] [23] [37]

2026 Magento evidence

Compromise, overlay and WebRTC examples

The 471-store wave, 99-store SVG report and anonymous manufacturer investigation describe separate source-observed sets. Do not combine their counts or transfer one case’s access path to another.[12] [13] [14]

August comparators

WordPress/WooCommerce

DEFION describes a database/plugin loader and BSC Testnet/WebRTC delivery. Source Defense describes Polygon-based destination resolution, Blob execution and image-request exfiltration. These are distinct from the Magento cases and from each other.[29] [30]

Public Victims / Disclosure Matrix

Public Victims / Disclosure Matrix
FocusEvidence and implications
471 stores

Sansec-observed compromise wave

Retained source-specific aggregate; not 471 independently confirmed customer-data theft events.[12]

99 stores

Sansec SVG campaign headline

The headline reports 99 stores, while the displayed domain rows total 76. The source does not explain the allocation or overlap; these figures cannot be added or treated as separately verified populations.[13]

Anonymous manufacturer

WebRTC case

Preserve anonymity and the researcher’s reporting boundary. No independent victim disclosure or customer-loss total was established.[14]

Anonymous WordPress store

DEFION comparator

The client is anonymized. No business-size classification, exact incident start or connection to the Magento population is established.[29]

Historical CosmicSting examples

Infrastructure is not independent victim confirmation

Sansec’s source-defined clusters include merchant relay URLs. Their presence is retained as historical infrastructure context with a compromised/shared-infrastructure warning, not a new victim disclosure, attacker ownership finding or confirmation of customer loss. No additional named victim is asserted from those URLs.[1]

KEV and CVE Details

KEV and CVE Details
FocusEvidence and implications
CVE-2025-54236

CISA KEV confirmed

Added 2025-10-24; federal deadline 2025-11-14. CISA ransomware-use field: Unknown. Catalog dates are not first-exploitation dates; follow the vendor remediation and investigate actual exposure.[39]

Read source
CVE-2024-34102

CISA KEV confirmed

Added 2024-07-17; federal deadline 2024-08-07. CISA ransomware-use field: Unknown. Catalog dates are not first-exploitation dates; follow the vendor remediation and investigate actual exposure.[39]

Read source
CVE-2022-24086

CISA KEV confirmed

Added 2022-02-15; federal deadline 2022-03-01. CISA ransomware-use field: Unknown. Catalog dates are not first-exploitation dates; follow the vendor remediation and investigate actual exposure.[39]

Read source

MITRE ATT&CK Lifecycle Mapping

MITRE ATT&CK Lifecycle Mapping
FocusEvidence and implications
Access and persistence

Evidence before mapping

Determine whether access came through application exploitation, administration or a third party. Map web shells and unauthorized code persistence only when evidenced; uploaded files do not by themselves prove execution.[11] [28]

Execution and collection

Reconstruct browser behavior

Identify injected JavaScript, overlays and accessible fields. Use the qualified input-capture mapping in TTPs; framework labels do not establish attribution.[13] [14] [36]

Exfiltration and impact

Follow the actual channel

Correlate HTTP and non-HTTP behavior with collection evidence. Business impact requires separate transaction, fraud and operational evidence rather than inference from an ATT&CK technique.

PCI / Hosted Payment / Stored Card Data Notes

PCI / Hosted Payment / Stored Card Data Notes
FocusEvidence and implications
Payment-page governance

Requirements 6.4.3 and 11.6.1

PCI SSC’s announcement addresses script authorization, integrity and tamper monitoring, including security-impacting headers and pages surrounding embedded payment iframes. The supplement does not replace or extend the standard.[16]

Read source
Applicability boundary

Guidance is not an assessment

This brief relies on accessible PCI SSC public guidance, not an implementation compliance verdict. The legacy full-standard URL was inaccessible and is retained only as citation lineage. Specific assessment and reporting responsibilities must be confirmed with the organization managing the compliance program.[16]

Data and architecture

Keep evidence boundaries separate

Hosted payment, tokenization, browser collection and stored-data handling describe different facts. Authorized responders should establish them without transferring private customer data into a public intelligence product.

Additional IntelliOS Threat Intel Products on This Topic

Additional IntelliOS Threat Intel Products on This Topic
FocusEvidence and implications
Actor context

MageCart — Threat Actor Card

Existing umbrella-context card. Its imported FIN6/G0037 aliases are not accepted as universal Magecart identity. The umbrella label does not establish a single operator.

Read related product
Trusted-integration comparison

Klue Supply Chain Attack

Existing SaaS/OAuth comparator. The relationship concerns trusted integrations, not shared Magecart operators, infrastructure or initial access.

Read related product
Trusted-integration comparison

Salesloft Drift OAuth Supply-Chain Attack

Existing trusted-integration comparator. Its OAuth campaign and identity claims are not evidence for the Magento incidents.

Read related product
Vulnerability companion

CVE-2024-34102

Its CosmicSting identity and July 17, 2024 KEV / August 7 deadline match the retained facts. This PANDA adds merchant response, key remediation and source-qualified observables; it is not a new CVE discovery.

Read related product
Vulnerability companion

CVE-2025-54236

Its SessionReaper identity and October 24, 2025 KEV / November 14 deadline match the retained facts. This PANDA adds patch chronology and source-specific response context, not a new CVE discovery.

Read related product
Distinct existing coverage

Operation Silent Skimmer

It describes Telerik/web-server and payment-database activity, not a proven match to the Magento chains here. It provides a separate skimming comparison, not evidence of common operators.

Read related product

Notes

Notes
FocusEvidence and implications
Evidence handling

Public defensive intelligence

Source-reported indicators are included for authorized detection and investigation. No malicious endpoint was contacted, payload executed or victim-private dataset acquired for this product. Embedded executable or sensitive snippets in publisher pages are excluded from the reader.

Scope limits

No compliance or environment attestation

This product is not a PCI assessment, merchant compromise determination or worldwide census. Source retrieval exceptions, date conflicts and confidence boundaries remain explicit. Unavailable evidence is not reconstructed.

Interpretation

No universal blocklist

Indicators describe source-time observations. Preserve false-positive and shared-infrastructure warnings, victim anonymity and the distinction between reporting dates and incident dates.

Artifact exclusions

Executable snippets, backdoor activation credentials, decryption keys, stolen data and payload-download links are excluded. Standard WordPress filters, generic diagnostic fragments and payment selectors are retained only as contextual leads. Source-template images, marketing claims and unrelated historical CVEs do not establish this campaign’s facts. Historical installer hashes are not malware indicators.

Unverified legacy citations

Sources 2, 5–10 include inaccessible or thin legacy records. Their identities remain in Citations for lineage; no new consequential claim relies on them alone. Current official alternatives and original research are cited separately.

Version Change Log

Version Change Log
FocusEvidence and implications
v2.1 — 5 September 2026

Patch sequence, chronology and defensive evidence

Replaces March-only remediation framing with the May base-release and July/August patch sequence; adds source-qualified historical and 2026 observables; separates Magento evidence from WordPress/WooCommerce comparators; corrects publication/observation boundaries and KEV support.[18] [19] [23] [29] [30] [32] [38] [39]

Historical baseline v2.0 — 2026-07-18

Expanded skimming coverage

Added PolyShell, SVG and WebRTC research to the historical Magecart coverage. The current revision retains the distinctions between these source-reported cases.

Original publication — 28 April 2026

First publication of this Magecart / Magento payment-skimming brief. The September revision continues the same product; it is not a newly launched publication.

Citations

Citations
ReferenceEvidence and implications
1

CosmicSting attack & defense overview

Sansec; Tier 7; primary. Publication: Not established / living page. Living source-defined CosmicSting overview. Historical cluster infrastructure and secret-remediation context are retained with shared-infrastructure warnings; malformed address/scheme, a code property and a truncated translation-service link are explicitly excluded.

https://sansec.io/research/cosmicsting
2

TrojanOrders: critical Adobe Commerce/Magento attack

Sansec; Tier 7; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. Original baseline URL failed. Its February publication identity is not verified; source 23 is distinct.

https://sansec.io/research/trojanorder
3

Adobe Commerce security bulletin APSB24-40

Adobe; Tier 7; primary. Publication: 2024-06-11. Historical vendor scope and fixes for CosmicSting; explicit exploitation acknowledgement. Priority changes are not changes to CVSS severity.

https://helpx.adobe.com/security/products/magento/apsb24-40.html
4

CVE-2024-34102 Detail

NIST NVD; Tier 0; primary. Publication: 2024-06-13. Research role: canonical_registry. CVE metadata and KEV addition/deadline. Record modification is separate from exploitation chronology.

https://nvd.nist.gov/vuln/detail/CVE-2024-34102
5

APSB24-40 isolated patch and key rotation guidance

Adobe Experience League; Tier 7; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. Retained URL failed; related official guidance is separately cited as source 24.

https://experienceleague.adobe.com/en/docs/commerce-knowledge-base/kb/troubleshooting/known-issues-patches-attached/security-update-available-for-adobe-commerce-apsb24-40
6

PCI DSS v4.0.1 Requirements and Testing Procedures

PCI Security Standards Council; Tier 7; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. HTTP 403. Full requirements and testing-procedure validation remain blocked.

https://docs-prv.pcisecuritystandards.org/PCI%20DSS/Standard/PCI-DSS-v4_0_1.pdf
7

PCI DSS 4.0 Requirements 6.4.3 and 11.6.1 guidance

SecurityMetrics; Tier 7; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. Original URL failed; no publication date inferred.

https://www.securitymetrics.com/blog/pci-dss-4-0-requirements-6-4-3-and-11-6-1-everything-you-need-know
8

Magecart skimming attacks put major payment networks on alert

Malwarebytes; Tier 2; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. Original URL failed. The baseline November 2019 date is not newly authenticated.

https://www.malwarebytes.com/blog/news/2019/11/magecart-skimming-attacks-put-major-payment-networks-on-alert
9

Automated Magento attacks compromise stores with web shells

BleepingComputer; Tier 3; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. Original URL failed. The baseline September 2020 date is not newly authenticated.

https://www.bleepingcomputer.com/news/security/automated-magento-attacks-compromise-stores-with-web-shells/
10

Adobe Commerce and Magento Open Source SessionReaper vulnerability

Qualys ThreatPROTECT; Tier 7; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. Original URL failed. Vendor and NVD evidence are separately retained.

https://threatprotect.qualys.com/2025/09/09/adobe-commerce-and-magento-open-source-sessionreaper-vulnerability-cve-2025-54236/
11

PolyShell: unrestricted file upload in Magento and Adobe Commerce

Sansec; Tier 7; primary. Publication: 2026-03-17. Configuration-dependent consequences, indicators and a dated fix correction; internal chronology and population wording conflict.

https://sansec.io/research/magento-polyshell
12

Mass PolyShell attack wave hits 471 stores in one hour

Sansec; Tier 7; primary. Publication: 2026-03-30. Researcher-observed compromise wave and browser/server artifacts; not a confirmed customer-loss total.

https://sansec.io/research/polyshell-mass-attack-wave
13

SVG Onload Tag Hides Magecart Skimmer on 99 Stores

Sansec; Tier 7; primary. Publication: 2026-04-07. Overlay behavior and campaign indicators. Likely initial access is not confirmed; headline and domain-row population totals differ.

https://sansec.io/research/svg-onload-magecart-skimmer
14

Novel WebRTC skimmer bypasses security controls at a major car maker

Sansec; Tier 7; primary. Publication: 2026-03-24. Anonymous case, non-HTTP channel and DTLS fingerprint. Entry vector remains assessed; embedded code and credentials excluded.

https://sansec.io/research/webrtc-skimmer
15

Adobe Commerce security bulletin APSB26-05

Adobe; Tier 7; primary. Publication: 2026-03-10. March 10 bulletin, with a later August page wrapper. Retained for historical release chronology only; unrelated vulnerability rows and inconsistent authentication columns do not supply campaign or current-remediation claims.

https://helpx.adobe.com/security/products/magento/apsb26-05.html
16

New Information Supplement: Payment Page Security and Preventing E-Skimming

PCI Security Standards Council; Tier 7; primary. Publication: 2025-03-10. Official supplement announcement; does not replace the standard or establish implementation compliance.

https://blog.pcisecuritystandards.org/new-information-supplement-payment-page-security-and-preventing-e-skimming
17

Known Exploited Vulnerabilities Catalog

CISA; Tier 0; contextual. Publication: Not established / living page. Historical citation lineage only; not fresh claim support. Direct retrieval failed. Individual NVD records corroborate retained entries, not exhaustive current coverage.

https://www.cisa.gov/known-exploited-vulnerabilities-catalog
18

Adobe Commerce security bulletin APSB26-92

Adobe; Tier 7; primary. Publication: 2026-08-11. August remediation and vulnerability metadata; updated August 18.

https://helpx.adobe.com/security/products/magento/apsb26-92.html
19

Security update available for Adobe Commerce — APSB26-92

Adobe Experience League; Tier 7; primary. Publication: Not established / living page. Installation guidance updated August 26; prerequisites, component matching and coverage verification.

https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-40380
20

Adobe Commerce security bulletin APSB25-88

Adobe; Tier 7; primary. Publication: 2025-09-09. SessionReaper scope, severity and explicit exploitation revision.

https://helpx.adobe.com/security/products/magento/apsb25-88.html
21

Action Required: Critical Security Update Available for Adobe Commerce (APSB25-88)

Adobe Experience League; Tier 7; primary. Publication: Not established / living page. Hotfix and module instructions; September content conflicts with its later wrapper and the bulletin’s exploitation status.

https://experienceleague.adobe.com/en/docs/experience-cloud-kcs/kbarticles/ka-27397
22

Adobe Commerce security bulletin APSB22-12

Adobe; Tier 7; primary. Publication: 2022-02-13. Historical vulnerability and patch scope; substantive February 17 revision distinct from the later wrapper date.

https://helpx.adobe.com/security/products/magento/apsb22-12.html
23

Adobe Commerce merchants to be hit with TrojanOrders this season

Sansec; Tier 7; primary. Publication: 2022-11-15. Distinct November report; health_check.php may be legitimate or abused. Marketing claims and exploit-market acquisition details excluded.

https://sansec.io/research/trojanorder-magento
24

Guidance on securing your store and rotating encryption keys: CVE-2024-34102

Adobe Experience League; Tier 7; primary. Publication: Not established / living page. August 20, 2024 content heading; May 22, 2026 update. Rotation can retain older decryption keys and does not necessarily re-encrypt existing data.

https://experienceleague.adobe.com/en/docs/commerce-knowledge-base/kb/troubleshooting/known-issues-patches-attached/guidance-on-securing-your-store-and-rotating-encryptionkeys-cve-2024-34102
25

CVE-2022-24086 Detail

NIST NVD; Tier 0; primary. Publication: Not established / living page. Research role: canonical_registry. Retrieved record corroborates historical KEV dates.

https://nvd.nist.gov/vuln/detail/CVE-2022-24086
26

CVE-2025-54236 Detail

NIST NVD; Tier 0; primary. Publication: 2025-09-09. Research role: canonical_registry. Direct page empty; substantive indexed NVD content supports retained metadata and KEV dates.

https://nvd.nist.gov/vuln/detail/CVE-2025-54236
27

Released versions

Adobe Experience League; Tier 7; primary. Publication: Not established / living page. Release dates and distinct regular, extended and additional-security support periods; updated August 12.

https://experienceleague.adobe.com/en/docs/commerce-operations/release/versions
28

Magento Polyshell — The Latest Magento Threat (APSB25-94)

Akamai; Tier 2; corroborating. Publication: 2026-03-27. Research role: corroborating_research. Corroborates upload versus configuration-dependent execution; defensive rule deployment is not first exploitation.

https://www.akamai.com/blog/security-research/magento-polyshell-latest-magento-threat-apsb25-94
29

The ghost skimmer: Magecart with blockchain storage and WebRTC delivery

DEFION; Tier 7; primary. Publication: 2026-08-20. Research role: primary_comparator. Anonymized WordPress/WooCommerce case; traces and infrastructure support a separate comparator, not Magento attribution.

https://defion.security/en/blog/ghost-skimmer-magecart-blockchain-webrtc/
30

Blockchain C2 and Fileless Execution Make Magecart Harder to Disrupt

Source Defense; Tier 7; primary. Publication: 2026-08-09. Research role: primary_comparator. Separate Polygon/Blob/image-exfiltration report; CSP-dependent evasion, not a universal bypass.

https://sourcedefense.com/resources/sd-research/blockchain-c2-and-fileless-execution-make-magecart-harder-to-disrupt/
31

Threat Detection Update 25-August-2026

Stamus Networks; Tier 7; contradictory. Publication: 2026-08-25. Research role: deconfliction. Detection-release context. Its FIN6/Magecart equivalence is not adopted.

https://www.stamus-networks.com/threat-detection-update-25-august-2026-stamus-networks
32

Adobe Commerce security bulletin APSB26-73

Adobe; Tier 7; primary. Publication: 2026-07-14. July 14 bulletin supplies the intermediate component patch sequence and Commerce Events 1.6.0–1.20.0 to 1.21.0 remediation. No known exploitation stated. Other July CVE rows are not evidence of the skimming campaigns.

https://helpx.adobe.com/security/products/magento/apsb26-73.html
33

SessionReaper, unauthenticated RCE in Magento and Adobe Commerce

Sansec; Tier 7; primary. Publication: Not established / living page. Living SessionReaper research supplies conditional execution prerequisites, source-specific filenames, 25 November addresses, path patterns and a disclosed domain-spelling disagreement. Publication and update dates do not independently establish intrusion onset.

https://sansec.io/research/sessionreaper
34

Adobe security advisory AV25-583 — Update 1

Canadian Centre for Cyber Security; Tier 1; corroborating. Publication: 2025-09-10. Research role: government_corroboration. October 23 update records awareness of exploitation reporting on October 22; not first exploitation.

https://www.cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av25-583
35

Adobe security advisory AV26-808

Canadian Centre for Cyber Security; Tier 1; contradictory. Publication: 2026-08-12. Research role: deconfliction. Commerce affected-version wording conflicts with Adobe’s August matrix; vendor guidance controls remediation.

https://www.cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-808
36

Input Capture: Web Portal Capture — T1056.003

MITRE ATT&CK; Tier 0; contextual. Publication: Not established / living page. Research role: framework. Credential-collection definition used to qualify the baseline’s payment-form mapping.

https://attack.mitre.org/techniques/T1056/003/
37

Persistent backdoors injected on Adobe Commerce via new CosmicSting attack

Sansec; Tier 7; primary. Publication: 2024-08-27. Historical chained-compromise case, August log evidence and defensive persistence/network artifacts; not a September 2026 event.

https://sansec.io/research/cosmicsting-cnext-persistent-backdoor
38

Adobe Commerce security update APSB26-49

Adobe; Tier 7; primary. Publication: 2026-05-12. May base-release matrix: Commerce 2.4.9, 2.4.8-p5, 2.4.7-p10, 2.4.6-p15, 2.4.5-p17 and 2.4.4-p18. Later July and August patches remain separate prerequisites. August page wrapper is not the initial disclosure.

https://helpx.adobe.com/security/products/magento/apsb26-49.html
39

CISA Known Exploited Vulnerabilities JSON catalog

CISA; Tier 0; primary. Publication: 2026-09-04. Direct HTTP 200 retrieval verified the three retained CVEs, their KEV dates and deadlines. Ransomware campaign use is Unknown for all three; this is not a statement that ransomware use never occurred.

https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json

Related published intelligence

Catalog navigation. A relationship does not establish common actors or incidents.

  • CVE-2024-34102: Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability

    Its CosmicSting identity and July 17, 2024 KEV / August 7 deadline match the retained facts. This PANDA adds merchant response, key remediation and source-qualified observables; it is not a new CVE discovery.

  • CVE-2025-54236: Adobe Commerce and Magento Improper Input Validation Vulnerability

    Its SessionReaper identity and October 24, 2025 KEV / November 14 deadline match the retained facts. This PANDA adds patch chronology and source-specific response context, not a new CVE discovery.

  • Klue Supply Chain Attack

    Exact related IntelliOS product link retained from /vault/magecart-magento-payment-skimming.

  • MageCart

    Exact related IntelliOS product link retained from /vault/magecart-magento-payment-skimming.

  • Operation Silent Skimmer

    It describes Telerik/web-server and payment-database activity, not a proven match to the Magento chains here. It provides a separate skimming comparison, not evidence of common operators.

  • Salesloft Drift OAuth Supply-Chain Attack

    Exact related IntelliOS product link retained from /vault/magecart-magento-payment-skimming.