Activity timeline
Magecart appears in 4 tracked threats between and ; the busiest month was 2026-03 with 1 report.
ATT&CK techniques observed
- T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
- T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 4 of 4 tracked threats
- T1056 Input Capture — Credential Accessobserved in 4 of 4 tracked threats
- T1059 Command and Scripting Interpreter — Executionobserved in 4 of 4 tracked threats
- T1005 Data from Local System — Collectionobserved in 3 of 4 tracked threats
- T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
- T1071 Application Layer Protocol — Command and Controlobserved in 3 of 4 tracked threats
- T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
- T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 4 tracked threats
- T1505 Server Software Component — Persistenceobserved in 3 of 4 tracked threats
- T1583 Acquire Infrastructure — Resource Developmentobserved in 3 of 4 tracked threats
- T1105 Ingress Tool Transfer — Command and Controlobserved in 2 of 4 tracked threats
- T1185 Browser Session Hijacking — Collectionobserved in 2 of 4 tracked threats
- T1195 Supply Chain Compromise — Initial Accessobserved in 2 of 4 tracked threats
- T1564 Hide Artifacts — Stealth (formerly Defense Evasion)observed in 2 of 4 tracked threats
Tracked threats
- Magecart Skimmer Abuses Stripe API + Google Tag Manager for Payload Hosting, C2 & Card ExfiltrationHIGH
- Magecart SVG Pixel Onload Skimmer Campaign Targeting 99 Magento StoresHIGH
- Active Magecart Campaign Targets Spain via Hijacked WooCommerce eStores for Bank Fraud Using WebSocket ExfiltrationHIGH
- NginRAT/CronRAT Server-Side Magecart Campaign — NGINX LD_PRELOAD Process Parasitism, Impossible Cron Date Persistence (February 31st), Fileless Payment Card Skimming, Dropbear SSH C2 Impersonation, Chinese-Nexus eCommerce TargetingHIGH