Home Cyber Security News Magecart Campaign Uses Google Tag Manager To Steal Credit Card Data

Magecart Campaign Uses Google Tag Manager To Steal Credit Card Data

0
Magecart Abuses Tag Manager

In the relentless shadow war of e-commerce security, trust is the ultimate vulnerability. Threat actors are now weaponizing one of the internet’s most ubiquitous and trusted tools: Google Tag Manager (GTM).

By exploiting this platform, a notorious Magecart group is silently injecting custom scripts into e-commerce sites to siphon customer credit card details.

This tactic turns a legitimate, highly trusted domain into a devastating weapon for digital skimming.

Magecart Abuses Tag Manager

Security researchers have identified a massive surge in credit card skimmers planted directly inside GTM scripts. The group behind this campaign is linked to the ATMZOW skimmer.

This sophisticated malware strain has been infecting Magento websites since the dawn of the Magecart era in 2015. Eight years later, these hackers are still active, and their malware has evolved significantly.

Earlier this year, attackers heavily relied on a GTM container (GTM-WJ6S9J6) to inject malicious scripts disguised as analytics services.

While Google eventually deleted that specific tag, the attackers quickly adapted. They recently deployed a new container, GTM-TVKQ79ZS, which introduced an incredibly complex layer of obfuscation.

Unlike older variants that used simple base64 encoding, this new decoder relies on the exact character length of the script itself. If a researcher alters even a single character to analyze it, the code breaks entirely.

Magecart Abuses Tag Manager (Source: sucurinet)

To bypass security filters, the attackers deployed a network of 40 newly registered domains to host their malicious payloads.

Instead of mimicking standard analytics sites, they used a clever naming pattern combining art-related terms, random connector words, and technical jargon (such as cdn. sketchinsightswatch[.]com or cdn. visualartinsights[.]com).

Magecart Abuses Tag Manager (Source: sucurinet)

This “artistic” pattern helps the domains blend naturally into regular web traffic, tricking security solutions trained to flag misspelled tech brands.

The evasion tactics do not stop at clever naming. The malicious GTM script randomly selects just two of these 40 domains to inject into the victim’s browser, saving that pair in the user’s local storage.

Magecart Abuses Tag Manager (Source: sucurinet)

This ensures that security researchers analyzing the network traffic will only see a fraction of the infrastructure at any given time, prolonging the lifespan of the campaign.

According to Sucurinet research, the attackers initially hid these domains behind a Cloudflare firewall to mask their true locations.

Once the firewall provider blocked the malicious traffic, researchers exposed the actual Hostinger-based IP addresses hosting the skimmer infrastructure.

Indicators of Compromise (IOCs)

TypeIndicatorDescription
GTM ContainerGTM-WJ6S9J6Older deleted container
GTM ContainerGTM-TVKQ79ZSNovember variant (obfuscated)
GTM ContainerGTM-NTV2JTB4, GTM-MX7L8F2MNewest replacement containers
Domaingtm-statistlc[.]com, gooqle-analytics[.]comFake analytics domains

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version