Magecart Hackers Exploit Over 100 Domains to Steal Credit Card Data
Key Takeaways A sophisticated Magecart campaign has been observed exploiting over 100 domains to illicitly obtain credit card details. Attackers are employing WebSocket traffic for data exfiltration,...
Key Takeaways
- A sophisticated Magecart campaign has been observed exploiting over 100 domains to illicitly obtain credit card details.
- Attackers are employing WebSocket traffic for data exfiltration, a method that often evades traditional HTTP-based security monitoring.
- The campaign includes a mobile component, prompting users to download malicious Android APKs under the guise of discounts, localized in multiple languages.
- This operation represents an evolution in Magecart tactics, shifting from opportunistic injections to a more persistent, infrastructure-backed approach with real-time command and control.
Magecart Evolves: New Campaign Targets Over 100 Domains with Advanced Exfiltration and Mobile Malware
A recent, highly organized Magecart campaign has been uncovered, demonstrating a significant escalation in the sophistication of web skimming attacks. This operation has compromised more than 100 domains, focusing on the theft of credit card information through advanced exfiltration techniques and the distribution of malicious Android applications.
Table Of Content
Stealthy Data Exfiltration via WebSockets
One of the defining characteristics of this new Magecart variant is its innovative use of WebSockets for data exfiltration. In a documented instance, a command-and-control (C2) server was cleverly camouflaged to appear as a legitimate Redsys domain, specifically redsysgate[.]com. This tactical choice is deliberate, as WebSocket traffic frequently bypasses many conventional HTTP-based security monitoring tools, substantially reducing the likelihood of immediate detection.

Mobile Vector Delivers Malicious Android APKs
Beyond traditional web skimming, the campaign significantly broadened its attack surface by leveraging the same malicious payload to deliver Android APK files. When users accessed infected online stores via their mobile devices, the embedded script would present a prompt. This prompt enticingly offered discounts or bonuses, contingent on the download and installation of a new application. Crucially, it provided explicit instructions for users to enable installations from “Unknown Sources,” a common prerequisite for sideloading unverified apps.
The global reach and meticulous planning of this mobile component are evident in its localization, with the malicious prompts translated into at least four languages. This multilingual approach underscores that the campaign’s underlying infrastructure was meticulously designed and purpose-built, rather than being a hastily improvised operation.
A Shift Towards Persistent, Infrastructure-Driven Operations
This latest Magecart campaign signals a notable maturation in the threat landscape. It marks a clear departure from the more opportunistic, quick-injection style attacks previously associated with Magecart. Instead, threat actors are now investing in persistent, infrastructure-driven operations that incorporate real-time command-and-control capabilities. This evolution makes these attacks more resilient, harder to detect, and significantly more dangerous for both consumers and businesses.
What You Should Do
- Monitor Outbound WebSocket Connections: Security teams must prioritize monitoring all outbound WebSocket connections originating from checkout pages and other sensitive areas of their websites.
- Enforce Strict Content Security Policies (CSP): Implement and rigorously enforce Content Security Policies to restrict which sources can load scripts and other resources on your web pages.
- Implement JavaScript File Integrity Monitoring: Utilize tools to continuously monitor the integrity of critical JavaScript files, alerting to any unauthorized modifications.
- Conduct Regular Third-Party Script Audits: Periodically audit all third-party scripts integrated into your website, ensuring they are legitimate and have not been compromised.
- For Financial Institutions: Enhance fraud detection capabilities for card-not-present transactions and actively participate in threat intelligence sharing to counter these adaptive payment threats.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.