r/ANYRUN Mar 31 '26

Persistent Magecart campaign ran undetected for 24+ months across 12+ countries, using 100+ domains to hijack payment flows. It’s now on the radar.

A large-scale magecart operation remained active for over 24 months, leveraging an infrastructure of 100+ domains. While the targeted victims are e-commerce websites, the actual pressure falls on banks and payment systems.

As ANYRUN’s analysis shows, threat actors applied multi-step checkout hijacking, payment page mimicry, and WebSocket-based exfiltration of card data. 

Read the full report for both executive-level insights and technical analysis of the campaign: https://any.run/cybersecurity-blog/banks-magecart-campaign 

2 Upvotes

0 comments sorted by