A malicious domain magento-analytics[.]com was tracked for months and was found to have been used to inject malicious JS script to various online shopping sites to steal the credit card owner / card number / expiration time / CVV information. The types of goods sold by the victim websites cover a wide range including but not limited to high-end bags, mountain bikes, baby products, wine, electronic products, etc., which shows that the campaign focuses on stealing credit card information only.
Theft of Credit Card Information
Indicators of Compromise
IP(s) / Hostname(s)
Following are the compromised websites/impacted domains which have this JS injected:
Block the threat indicators at their respective controls.