Threadlinqs IntelligenceStart free

Threat actorN/ATracked since 2021-11

Magecart

Also known as:Magecart GroupServer-side Magecart

As of 2026-07-02, Magecart is a N/A-nexus threat actor tracked by Threadlinqs Intelligence across 4 threats spanning malware, supply chain. Also known as Magecart Group, Server-side Magecart. ATT&CK coverage spans 52 techniques across 12 tactics in 4 of 4 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel), T1056 (Input Capture).

Tracked threats
44 high
First seen
2021-11-25
Last seen
2026-06-07
ATT&CK techniques
52across 4 of 4 threats
Related CVEs
0None referenced
Attribution
N/ANation or origin
Nation: N/A · 4 tracked threat(s) · Categories: MALWARE, SUPPLY_CHAIN

Activity timeline

Magecart appears in 4 tracked threats between and ; the busiest month was 2026-03 with 1 report.

ATT&CK techniques observed

52 techniques observed across 4 of 4 tracked threats · Stealth (formerly Defense Evasion) (14), Command and Control (8), Collection (5), Persistence (5), Execution (4), Resource Development (4)
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 4 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 4 of 4 tracked threats
  • T1056 Input Capture — Credential Accessobserved in 4 of 4 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 4 of 4 tracked threats
  • T1005 Data from Local System — Collectionobserved in 3 of 4 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 3 of 4 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 3 of 4 tracked threats
  • T1505 Server Software Component — Persistenceobserved in 3 of 4 tracked threats
  • T1583 Acquire Infrastructure — Resource Developmentobserved in 3 of 4 tracked threats
  • T1105 Ingress Tool Transfer — Command and Controlobserved in 2 of 4 tracked threats
  • T1185 Browser Session Hijacking — Collectionobserved in 2 of 4 tracked threats
  • T1195 Supply Chain Compromise — Initial Accessobserved in 2 of 4 tracked threats
  • T1564 Hide Artifacts — Stealth (formerly Defense Evasion)observed in 2 of 4 tracked threats

Tracked threats