In the relentless shadow war of e-commerce security, trust is the ultimate vulnerability. Threat actors are now weaponizing one of the internet’s most ubiquitous and trusted tools: Google Tag Manager (GTM).
By exploiting this platform, a notorious Magecart group is silently injecting custom scripts into e-commerce sites to siphon customer credit card details.
This tactic turns a legitimate, highly trusted domain into a devastating weapon for digital skimming.
Magecart Abuses Tag Manager
Security researchers have identified a massive surge in credit card skimmers planted directly inside GTM scripts. The group behind this campaign is linked to the ATMZOW skimmer.
This sophisticated malware strain has been infecting Magento websites since the dawn of the Magecart era in 2015. Eight years later, these hackers are still active, and their malware has evolved significantly.
Earlier this year, attackers heavily relied on a GTM container (GTM-WJ6S9J6) to inject malicious scripts disguised as analytics services.
While Google eventually deleted that specific tag, the attackers quickly adapted. They recently deployed a new container, GTM-TVKQ79ZS, which introduced an incredibly complex layer of obfuscation.
Unlike older variants that used simple base64 encoding, this new decoder relies on the exact character length of the script itself. If a researcher alters even a single character to analyze it, the code breaks entirely.
To bypass security filters, the attackers deployed a network of 40 newly registered domains to host their malicious payloads.
Instead of mimicking standard analytics sites, they used a clever naming pattern combining art-related terms, random connector words, and technical jargon (such as cdn. sketchinsightswatch[.]com or cdn. visualartinsights[.]com).
This “artistic” pattern helps the domains blend naturally into regular web traffic, tricking security solutions trained to flag misspelled tech brands.
The evasion tactics do not stop at clever naming. The malicious GTM script randomly selects just two of these 40 domains to inject into the victim’s browser, saving that pair in the user’s local storage.
This ensures that security researchers analyzing the network traffic will only see a fraction of the infrastructure at any given time, prolonging the lifespan of the campaign.
According to Sucurinet research, the attackers initially hid these domains behind a Cloudflare firewall to mask their true locations.
Once the firewall provider blocked the malicious traffic, researchers exposed the actual Hostinger-based IP addresses hosting the skimmer infrastructure.
Indicators of Compromise (IOCs)
| Type | Indicator | Description |
|---|---|---|
| GTM Container | GTM-WJ6S9J6 | Older deleted container |
| GTM Container | GTM-TVKQ79ZS | November variant (obfuscated) |
| GTM Container | GTM-NTV2JTB4, GTM-MX7L8F2M | Newest replacement containers |
| Domain | gtm-statistlc[.]com, gooqle-analytics[.]com | Fake analytics domains |
Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
