Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
financial-sector-threatthreat-infrastructure-trackingdata-exfiltration-methoddefense-evasion-method

Magecart Campaign Hid Payment Skimmers in Google Tag Manager Containers

Updated 15d agoFirst seen May 12, 20262 sources

A long-running Magecart operation linked to the ATMZOW skimmer family abused Google Tag Manager (GTM) to inject credit-card theft code into compromised ecommerce checkout pages, according to Sucuri. The attackers hid malicious JavaScript inside GTM containers served through googletagmanager.com, exploiting the trust many sites place in that domain while using multi-stage obfuscation to steal payment data. Sucuri said the activity affected hundreds of sites, with one malicious container, GTM-WJV6J6, detected 178 times before removal, and tied the campaign to Magento-focused compromises dating back to the 2015 Guruincsite infections.

Researchers said the operators rotated payload delivery through about 40 newly registered lookalike domains, used Cloudflare to shield infrastructure, and stored selected domains in browser local storage to complicate analysis and blocking. After Google removed malicious containers such as GTM-WJ6S9J6 and GTM-TVKQ79ZS, the attackers quickly replaced them with new IDs including GTM-NTV2JTB4 and GTM-MX7L8F2M, showing persistent reinfection efforts; in at least one case, the GTM-based skimmer ran alongside a separate WebSocket-based skimmer, indicating overlapping compromises and continued adaptation by the threat actor.

Share:
Magecart Campaign Hid Payment Skimmers in Google Tag Manager Containers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
May 12, 20261mo ago

Attackers replace removed GTM containers with new ones

Following the removals, the threat actors created replacement Google Tag Manager containers, including GTM-NTV2JTB4 and GTM-MX7L8F2M, to continue reinfecting sites. Sucuri also noted rapid replacement of removed containers and, in at least one case, overlap with a separate WebSocket-based skimmer.

Magecart Hackers Abuse Google Tag Manager to Inject Credit Card Skimmers

Sucuri detects malicious GTM containers on 327 sites in 2023

Sucuri reported detecting known malicious Google Tag Manager containers on 327 websites during the first 11 months of 2023. One container, GTM-WJV6J6, was seen 178 times before it was removed.

Magecart Hackers Abuse Google Tag Manager to Inject Credit Card Skimmers
Dec 7, 20233y ago

Google removes malicious GTM containers used in the skimming campaign

After malicious Google Tag Manager containers were identified, Google removed them. The removed containers included examples such as GTM-WJ6S9J6 and GTM-TVKQ79ZS referenced in Sucuri's analysis.

40 New Domains of Magecart Veteran ATMZOW Found in Google Tag Manager

Sucuri identifies ATMZOW campaign abusing Google Tag Manager

Sucuri documented an ecommerce malware campaign in which the ATMZOW threat actor hid credit card skimmers inside malicious Google Tag Manager containers on compromised checkout pages. The campaign used obfuscated multi-stage JavaScript, rotating newly registered domains, local storage, and Cloudflare to evade analysis and blocking.

40 New Domains of Magecart Veteran ATMZOW Found in Google Tag Manager
Jan 1, 201511y ago

Guruincsite Magento infections linked to ATMZOW begin

Sucuri linked the newer Google Tag Manager skimmer activity to the long-running ATMZOW skimmer family and said its history goes back to the 2015 Guruincsite campaign and the early Magecart era targeting Magento stores.

Magecart Hackers Abuse Google Tag Manager to Inject Credit Card Skimmers
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

11 LINKEDOpen in app
Threat actors
2 linked
Malware
2 linked
Affected products
2 linked
CloudflareMagento
Organizations
5 linked
CloudflareHostingerGoogleSucuriGroup-IB
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.