Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
financial-sector-threatthreat-infrastructure-trackingdata-exfiltration-methoddefense-evasion-method

Silent Push Uncovers Long-Running Magecart Web-Skimming Infrastructure Targeting Major Payment Networks

Updated 3mo agoFirst seen Jan 13, 20263 sources

Silent Push reported a large-scale Magecart-style web-skimming operation active since early 2022 that uses an extensive domain network to support client-side JavaScript skimmers on compromised e-commerce checkout pages. The activity is assessed to impact online shoppers and organizations that are clients of major payment providers, with targeting noted against American Express, Diners Club, Discover, JCB, Mastercard, and UnionPay; the skimmers are designed to quietly exfiltrate payment-card and other form data during transactions rather than disrupt systems.

Technical reporting tied the infrastructure to domains hosting highly obfuscated skimmer payloads (e.g., recorder.js, tab-gtm.js) and described evasion logic that attempts to avoid execution when site administrators are present (e.g., checking the DOM for WordPress’ wpadminbar). The infrastructure analysis also linked parts of the campaign to a domain associated with the sanctioned bulletproof hosting ecosystem around Stark Industries / PQ.Hosting, which has been described as rebranding to THE[.]Hosting under WorkTitans B.V., consistent with sanctions-evasion behavior; researchers emphasized that weak third-party script governance on payment pages remains a key enabling factor for this type of long-lived skimming operation.

Share:
Silent Push Uncovers Long-Running Magecart Web-Skimming Infrastructure Targeting Major Payment Networks
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jan 13, 20265mo ago

Silent Push publicly reports the long-running skimming campaign

Silent Push disclosed that the operation had been active since early 2022 and described its malicious domain network, skimmer behavior, and data theft methods affecting multiple major payment brands. The researchers also linked supporting infrastructure to Stark Industries/PQ.Hosting, which they said had rebranded to THE.Hosting under WorkTitans B.V.

Jan 1, 20224y ago

Attackers deploy Stripe and WooCommerce skimmers with admin-evasion features

The campaign used highly obfuscated JavaScript on compromised WooCommerce and Stripe checkout flows, replacing legitimate payment forms with fake ones to capture card details before showing an error. The malware also used conditional activation, self-removal when the WordPress admin bar was detected, and anti-repeat logic to reduce detection.

Magecart-style web skimming campaign begins targeting e-commerce checkouts

A large-scale web skimming operation became active by January 2022, compromising online checkout pages to steal payment card and personal data from shoppers. The campaign targeted merchants, payment portals, and third-party payment processors tied to major card networks.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

27 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Affected products
8 linked
WoocommerceWoocommerceWoocommerceStripeMagentoWordpressMagentoMagento
Organizations
17 linked
American ExpressDiscover Financial ServicesMastercardChina UnionPaySilent PushJCB Co., Ltd.Diners Club InternationalStripeWoocommerceKeeper SecurityXcape IncTHE.HostingStark Industries SolutionsWorkTitans B.V.PQHostingMastercard IncorporatedDiners Club
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Silent Push Uncovers Long-Running Magecart Web-Skimming Infrastructure Targeting Major Payment Networks | Mallory